Skip to content
SavaSync
← All legal documents

Cookie Policy

Effective 2026-09-10 · v1.5

Effective: September 10, 2026

This Policy is published by Tricky Labs LLC, a New Hampshire limited liability company doing business as SavaSync ("SavaSync," "we," "us," "our").

1. What this Policy covers

This Cookie Policy explains how SavaSync uses cookies and similar technologies (collectively, "cookies") when you visit our website at savasync.com, use our web application, or load the embeddable booking widget on a Studio's site. It is incorporated into our Privacy Policy by reference.

A "cookie" is a small text file a website stores in your browser. Cookies let a site remember you (so you don't have to log in on every page), keep your session secure, and store your preferences. The same word is used loosely for similar technologies like localStorage, sessionStorage, and pixel tags. We use cookies, localStorage and — for one item, only with your consent — sessionStorage. We use no pixel tags of any kind.

Your choice from the consent banner is itself recorded in a first-party cookie named sv_consent. It holds three things and nothing else: which categories you allowed, when you answered, and the version of this Policy you answered under. It is shared across savasync.com and app.savasync.com so that one answer covers both, and when we change our cookie usage in a way that requires fresh consent we bump that version and the banner asks again.

SavaSync is offered only in the United States, and United States law does not require us to ask before switching on the aggregate, non-identifying measurement described in Section 2.2. So if you are in the United States you may never have been shown the banner and may have no sv_consent cookie at all — in which case the defaults in Section 2.2 apply and the controls in Section 4 are how you change them. Everywhere else, and anywhere our network cannot tell where you are, nothing in Section 2.2 runs until you say so.

We also use localStorage in two places. In the dashboard web app it holds your login session token and a small number of interface-state entries — which of your accounts you last had open, whether you chose light or dark, whether the sidebar was collapsed, and the choices you made on the signup screen while a signup is in progress. On the marketing site it holds one entry: which pricing audience you last chose, so a return visit opens on the same ladder. Section 5 lists every one of them by name. None of them is used for tracking, none is shared with anyone, and the session token is the only one that identifies your account.

In the mobile apps, once they are released, the same entries will live in the app's own on-device storage rather than in a browser. That storage is private to SavaSync — the operating system keeps one app's files out of every other app's reach — but it is ordinary app storage and we do not claim it is separately encrypted by us.

2. Cookies we use

The consent banner offers exactly two categories, and this Policy names every item in both: Essential (2.1), which is always on, and Analytics & diagnostics (2.2), which is yours to decide. There is no advertising or marketing category, because we run no advertising — see Section 3. Section 2.3 covers cookies set by a third party whose code you load by using one of its features.

2.1 Essential storage

These items are required for the Platform to function. They are always on, and the banner does not offer to switch them off, because switching them off would mean not using the Platform at all. Their sole purpose is to deliver the service you asked for.

  • Authentication session (Supabase Auth): a session token, stored in localStorage in the web dashboard (not as a cookie) and, in the mobile apps once released, in the app's own on-device storage, that keeps you logged in across page loads. Without it, you would have to log in every time you click a link.
  • Interface state: entries the dashboard writes as the direct result of something you did in it — savasync_active_context (which of your accounts you last switched to), savasync_color_scheme (light, dark, or follow the device), savasync_sidebar_collapsed (whether you collapsed the sidebar), savasync.legal.pending-dismissed.<your account id> (which upcoming-document notice you pressed "Got it" on, so it stays dismissed instead of returning on the next screen — one entry per account you sign in as on that device, so dismissing it as one account does not dismiss it for another), and savasync.pendingSignup (the account type, plan, billing interval and legal consents you chose on the signup screen, plus the country our edge network determined from your IP address at that moment, which your browser neither reports nor asks you for and which is only stored here — held so those choices survive the redirect to your email or identity provider, and deleted the moment you finish signing up). They carry no browsing history and no tracking identifier; savasync_active_context holds the identifier of an account you belong to, and is deleted when you sign out.
  • sv_authed: a signed-in indicator (the literal value 1 — it contains no credentials and cannot be used to access your account) set by the dashboard when you log in, so the savasync.com marketing site can show "Go to Dashboard" instead of "Log In." It is shared across savasync.com subdomains, expires after 30 days, and is cleared when you log out.
  • sv_consent: your answer to the consent banner, described in Section 1. A record of a choice is itself essential — without it we would have to ask again on every page.
  • savasync.persona: which pricing audience you picked on savasync.com — instructors, or studios and gyms. It is written when you click the toggle yourself and it remembers one of two words, so a plain visit to /pricing opens where you left it. It is not a tracking identifier and it is not shared with anyone.

A note on request forgery (CSRF): SavaSync does not need a CSRF-token cookie. The Platform authenticates every request with the session token described above, which the app attaches explicitly — browsers never send it automatically the way they send cookies — so cross-site request forgery does not apply. This is reinforced by SameSite attributes on the cookies we do set, and a strict content-security policy.

2.2 Analytics and diagnostics — your choice

What happens before you have chosen depends on where you are.

  • Outside the United States, and anywhere our network cannot determine your country, none of the following are loaded, started, or stored unless you have allowed this category. If you have not answered the banner, or you declined, none of them run at all.
  • In the United States, all three are on unless you switch them off. No United States privacy law requires prior consent for what is described here — it is measurement of how our own site is used, and masked, error-triggered diagnostics; none of it is used for advertising or profiling, and we neither sell nor share personal information. Section 4 has the two controls that turn it off, and they are on every page and in your account settings respectively.

Whichever applies to you, an answer you give is the answer we follow — in either direction, from then on, wherever you gave it. And if your browser sends a Global Privacy Control signal we treat that as a no and switch nothing on, without asking you first.

One answer covers both savasync.com and app.savasync.com, but the items do not all run on both: the analytics scripts are on the marketing site only, and session replay is in the dashboard only.

  • Cloudflare Web Analytics: a small script on the savasync.com marketing site. It is cookieless — it sets no cookie, uses no localStorage, and does not fingerprint or identify individual visitors; it gives us aggregate page-view and performance metrics. Outside the United States the script is not sent to your browser at all unless you have allowed this category; in the United States it is sent unless you have declined or your browser sends Global Privacy Control. See Cloudflare's Web Analytics documentation for details.
  • Google Analytics 4 — on the savasync.com marketing site only, and never in the dashboard: it tells us which pages people read before they sign up, and which sources sent them. Unlike the Cloudflare counter above it does set cookies (_ga and _ga_<measurement-id>, described in the table in Section 5) so that two page views by the same browser can be counted as one visit. Google truncates your IP address before storing it and we never receive it. We have switched off the settings that would make this an advertising tool: Google Signals is disabled, we do not share this data with Google for its own ad personalisation or ad targeting, and it is not linked to any advertising account. It is not used to profile you, to follow you onto other websites, or to make decisions about you as an individual. Outside the United States the script is not sent to your browser at all unless you have allowed this category; in the United States it is sent unless you have declined or your browser sends Global Privacy Control. We keep this data for 14 months.
  • Sentry session replay — in the dashboard (app.savasync.com), and in the mobile apps once released, only: when an error occurs there, our error-tracking tool records a masked replay of the screens that led to it, and stores a session identifier in your browser's sessionStorage (sentryReplaySession) while it does. Typed text is masked and images and video are blocked before anything leaves your browser. It is diagnostics only: it is never used for advertising, profiling, or cross-site tracking. Outside the United States it does not run until you allow this category; in the United States it runs unless you have declined or your browser sends Global Privacy Control. If you withdraw consent, the recording stops and that entry is deleted. The savasync.com marketing site does not record session replays at all, whether or not you allow this category — the recorder is not part of that site's code.

Sentry's error reports, performance traces and diagnostic logs are not in this category and are not switched off by declining it. They store nothing in your browser, and we rely on them to keep the Platform secure and working — including for errors that happen before you have had a chance to answer the banner. They are described in the Privacy Policy §2.2 and §6.

2.3 Third-party cookies

  • Stripe sets cookies when you reach a Stripe Checkout page or any embedded Stripe iframe. Stripe uses these for fraud detection and session management. They are strictly necessary to take a payment you asked to make. See Stripe's Cookies Policy for details.

Stripe's cookies are set directly by Stripe; SavaSync cannot read or control them. You can manage them through your browser settings or through the third party's own opt-out mechanisms.

3. Cookies we do NOT use

To be explicit about what we don't do:

  • No advertising cookies. SavaSync does not run advertising campaigns through Google Ads, Meta Pixel, TikTok Pixel, or any similar advertising platform.
  • No analytics that profile you or follow you off our site. We use two measurement tools, both on the savasync.com marketing site only and both switchable off at any time from the Cookie settings link in the footer of every page (see Sections 2.2 and 4): Cloudflare Web Analytics, which is cookieless and aggregate-only, and Google Analytics 4, which sets the two cookies named in Section 5 so that repeat page views by one browser count as one visit. Google Analytics is configured for measurement and nothing else — Google Signals off, no data shared with Google for its own ad personalisation or targeting, and no link to any advertising account — so it is not used to build a profile of you, to target advertising, or to track you across other websites. Neither runs in the dashboard at app.savasync.com, where the only item in this category is the masked session replay described in Section 2.2. We do not use Mixpanel, Segment, Amplitude, or any product that follows individual users across the Platform. Other aggregate product analytics, if any, are computed from anonymized server-side logs that cannot be linked back to an individual user.
  • No cross-site tracking. We do not use cookies to track you across other websites.
  • No fingerprinting. We do not use device-fingerprinting techniques (canvas fingerprinting, audio fingerprinting, font enumeration) to identify users without cookies.

If any of this changes in the future, we will update this Policy and prompt you to renew your cookie consent before activating new tracking.

4. How to control cookies

You have four ways to manage cookies on SavaSync:

4.1 The consent banner, and changing your mind

If you are outside the United States, or our network cannot tell where you are, a banner appears at the bottom of the page the first time you visit savasync.com, before anything in Section 2.2 loads. If you are in the United States it does not appear on its own, for the reason given in Section 2.2 — but you can open exactly the same controls whenever you like, from the Cookie settings link in the footer of every page.

However you reach it, it names both categories — Essential, which is always on, and Analytics & diagnostics, which is yours to decide — links to this Policy, tells you which way Analytics & diagnostics is currently set, and offers two controls of equal prominence:

  • Accept — allows Analytics & diagnostics. On savasync.com, the Cloudflare Web Analytics and Google Analytics scripts load on your next page view, and Google Analytics sets its two cookies. In the dashboard, Sentry session replay may record a masked replay if an error occurs.
  • Reject — declines it. Neither analytics script is sent to your browser, no _ga cookie is set, no session replay is recorded in the dashboard, and any replay already in progress is stopped and its stored session identifier deleted.

Essential storage has no switch, because a switch that cannot be moved is not a choice. Neither control is favoured over the other; declining is exactly as easy as accepting.

You can change your answer at any time. Withdrawing takes effect immediately: in the dashboard, session replay stops the moment you decline and its stored session identifier is deleted; on savasync.com, if an analytics script is already running on the page, the page is reloaded without it — the only way to stop a script a browser has already started — and any _ga cookies already set are deleted. Allowing takes effect on your next full page load, which is when the analytics scripts are served — the same timing as the Accept bullet above. On savasync.com, use the Cookie settings link in the footer of every page. In the dashboard, use Account settings → Analytics and diagnostics. Your answer is shared between savasync.com and app.savasync.com, so you only have to give it once and you can change it from either place. You can also write to us at legal@savasync.com. When we change our cookie usage in a way that requires fresh consent, we bump the version recorded in sv_consent and the banner asks again.

4.2 Global Privacy Control

If your browser sends a Global Privacy Control signal — Brave and DuckDuckGo send it by default, and extensions add it to Chrome, Firefox and Edge — we treat it as a "no" to Analytics & diagnostics and switch nothing on, without asking you first. This matters most in the United States, where the banner does not appear on its own: a browser that sends GPC gets the same result as somebody who was shown the banner and pressed Reject.

We honour it even though nothing obliges us to. GPC is defined as a signal to opt out of the sale or sharing of personal information, and SavaSync does neither (see the Privacy Policy §7). We treat it as the broader "do not switch things on for me" that people plainly mean by it.

One thing it does not do is override you. If you have pressed Accept or switched the toggle on in Account settings → Analytics and diagnostics, that is a more recent and more specific choice about this Platform than a browser-wide setting, and we follow it. Turn it back off from either control at any time.

4.3 Browser settings

All major browsers let you view, block, and delete cookies from their settings. Here's where to start:

  • Chrome: Settings → Privacy and security → Cookies and other site data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Cookies and website data
  • Edge: Settings → Privacy, search, and services → Cookies and site permissions

If you block all cookies, parts of the Platform (such as authentication) will not work. Blocking cookies also removes the sv_consent record of your answer, so the banner will ask again.

4.4 Third-party opt-outs

For cookies set by third parties, use the third party's own controls:

5. Cookie and storage list

Every first-party item, with nothing omitted. If you find something in your browser's storage for savasync.com or app.savasync.com that is not on this list, it is not ours and we would like to hear about it. Where a row names the app's own on-device storage, that describes the mobile apps once they are released; today every one of these items lives in your browser:

NameTypeCategoryPurposeDuration
Supabase Auth sessionlocalStorage (web) / app's own on-device storage (mobile)EssentialKeeps you signed in to the dashboardUntil logout
sv_authedCookie (.savasync.com)EssentialSigned-in indicator for the marketing site navbar; contains no credentials30 days or logout
sv_consentCookie (.savasync.com) on the web / app's own on-device storage (mobile)EssentialRecords your consent-banner answer and the version of this Policy you answered under180 days, or until you change it
savasync_active_contextlocalStorage (web) / app's own on-device storage (mobile)EssentialWhich of your accounts the dashboard last had openUntil you sign out
savasync_color_schemelocalStorage (web) / app's own on-device storage (mobile)EssentialWhether you chose light, dark, or to follow your deviceUntil you change or clear it
savasync_sidebar_collapsedlocalStorage (web) / app's own on-device storage (mobile)EssentialWhether you collapsed the dashboard sidebarUntil you change or clear it
savasync.legal.pending-dismissed.<your account id>localStorage (web) / app's own on-device storage (mobile)EssentialWhich upcoming-document notice you dismissed — the slug and version of the documents it named, and nothing else — so pressing "Got it" keeps it dismissed. One entry per account you sign in as on that deviceUntil those documents take effect and the notice is replaced, or you clear the site's storage
savasync.pendingSignuplocalStorage (web) / app's own on-device storage (mobile)EssentialThe account type, plan, billing interval and legal consents you chose on the signup screen, and the country our edge network determined from your IP address at that moment, carried across the redirect to your email or identity providerDeleted when you finish signing up. If you abandon signup part-way it is not cleared, and stays until you complete a signup or clear the site's storage
savasync.personalocalStorage (savasync.com)EssentialWhich pricing audience you chose on the marketing site — the literal word instructor or business, and nothing else — so a return visit opens on the ladder you last looked atUntil you change it or clear the site's storage
Cloudflare Web Analytics beaconScript; sets no cookie and no storageAnalytics & diagnosticsAggregate page-view and performance counts for the marketing site. Not sent to your browser at all unless you allowed this categoryNothing is stored
_gaCookie (.savasync.com, set by Google Analytics on savasync.com only)Analytics & diagnosticsDistinguishes one browser from another so repeat page views count as one visit. Not set at all unless you allowed this category13 months, or until you decline
_ga_<measurement-id>Cookie (.savasync.com, set by Google Analytics on savasync.com only)Analytics & diagnosticsKeeps the state of the current visit for the same purpose. Not set at all unless you allowed this category13 months, or until you decline
sentryReplaySessionsessionStorage (app.savasync.com only — the marketing site records no replays)Analytics & diagnosticsIdentifies a masked, error-triggered session recording while it is being madeUntil you close the tab; deleted when you withdraw consent

Stripe sets its own cookies on checkout pages, described in Section 2.3, per its own policy. If you need more detail for compliance reporting, email us at legal@savasync.com.

6. Changes to this Policy

We may update this Policy when our cookie usage changes. If a change requires fresh consent — a new item in the Analytics & diagnostics category, or a new category altogether — we bump the version recorded in sv_consent and the banner asks again rather than carrying your old answer forward. The current effective date is at the top of this Policy.

7. Questions

Email legal@savasync.com with any questions about how we use cookies.