Cookies / public site
Nothing hidden
behind the
button.
The cookies and local-storage choices used by SynthCrew first-party measurement, including revoke and deletion controls.
Current state
The public site sets no optional measurement cookie before consent. After you choose “Allow measurement,” the same-origin service sets one Secure, HttpOnly visitor cookie; page JavaScript cannot read it. Optional first-party measurement and optional Sentry error monitoring otherwise stay off. The access form remains a separate necessary request path and does not require optional measurement.
First-party local storage
synthcrew.measurement.consent records “accepted” or “declined” so the prompt does not return on every page. After acceptance, synthcrew.measurement.visitor_id stores only the server-issued SHA-256 visitor digest. The underlying random token stays in a Secure, HttpOnly, same-origin cookie and is never exposed to page JavaScript or included in an event body. Declining does not create either value. Revoking always asks the server to clear its cookie, even when this browser has no local digest; a failed request remains retryable.
Legacy synthcrew.analytics.* PostHog values are removed rather than migrated. The navigation menu keeps state only in the current page.
Allowlisted events only
The same-origin endpoint accepts only six browser event names from this site: page view, CTA click, pricing view, pricing interval choice, signup click, and docs view. Event properties are fixed categorical values. The JSON event body does not contain contact-form values, email addresses, messages, credentials, raw tokens, full URLs, query strings, referrers, or a raw IP field. The browser attaches the HttpOnly cookie only to the same-origin consent-protected request; the service does not persist its raw value.
Provider boundaries
PostHog is not used by this public-site measurement flow. Sentry is optional and nonblocking; it is inactive while its DSN is empty and remains consent-gated if configured. Its bounded report omits original error text and stacks. Google Analytics, a tag manager, CRM tracker, advertising pixel, and session replay are not enabled.
Your measurement choices
Revoking prevents new optional events. Deleting always attempts the same-origin deletion endpoint. When available it sends the one-way visitor identifier—not the HttpOnly token—and the HttpOnly cookie remains the server authority. The page reports success only if that endpoint accepts the request; otherwise the one-way identifier remains available for a retry. Reviewing the choice clears only the stored choice and opens the consent prompt again.
Stored preference: Unset · no optional measurement choice is stored
No measurement preference was changed on this visit.
For broader data handling, read the privacy notice.
Keep the record current
Clarity before
collection.
Read the broader privacy preview for current site and email handling. Neither page claims a configured production stack beyond the explicitly described access delivery path.
Create workspace