Cookies
Last updated 1 October 2026
Symplist sets no advertising cookies, no tracking cookies and no third-party cookies. There is no cookie banner because there is nothing to consent to: every cookie below is needed for the thing you asked the service to do.
What is set
- Session
- Keeps you signed in.
HttpOnly,SecureandSameSite-restricted, so it cannot be read by scripts and does not travel to other sites. Removed when you sign out. - CSRF token
- Paired with a header on every write, so another site cannot make a change on your behalf.
- Appearance
- Remembers your theme and light/dark choice so the first paint after a reload is not the wrong colour. It holds a theme name and nothing about you.
- Shared link access
- Set only on the separate artifact host, and only once you unlock a password-protected shared page. It is scoped to that host, so it never touches your workspace.
Analytics
Product analytics is off until you explicitly accept it, and it uses a random analytics-only identifier rather than a cookie that identifies you. Session replay and autocapture are disabled. If you decline — or never answer — nothing analytics-related is loaded at all, and nothing about your access changes. You can change your mind in Settings → Account → Privacy. See Privacy for what is and is not collected.
Clearing them
Signing out removes the session. Clearing site data in your browser removes the rest; you will simply be signed out and back on the default theme. Questions to privacy@symplist.app.