Skip to Content

How It Works

Locally. Every Time.

The architecture is the privacy guarantee. Sessyn does not receive your browsing history, so it cannot leak it. Nothing about your browsing leaves your device unless you choose to send a report, and you see exactly what it contains first.

Everything Sessyn Does

The whole feature set, and what each one is actually doing. Where a browser cannot deliver something, it says so here and in the extension rather than claiming it anyway.

Sessyn features, what each does, and which browsers support it
Feature What it actually does Where it works
Block known trackers Hands the browser block rules for endpoints classified as advertising, analytics or fingerprinting with strong enough evidence to enforce. Chromium, Firefox
Keep sign-in working First-party requests are never touched. A short, reviewed list of payment and CDN hosts stays allowed even in the strictest mode. Chromium, Firefox
Let a site load its own assets Many sites serve their scripts and images from a second domain. Those are allowed on that site only, from pairs we checked by hand, and stay blocked everywhere else. A named tracker is never unblocked this way. Chromium, Firefox
Stop cross-site cookies Removes the Cookie and Set-Cookie headers on third-party requests, so a third party cannot carry identity between sites. Content still loads. Chromium, Firefox — needs site access
Block unknown third parties In Lockdown only, blocks cross-site requests Sessyn has no classification for, instead of trusting them by default. This half needs no permission, so choosing Lockdown blocks whether or not site access is granted. Chromium, Firefox
Allow one site A narrow exception, scoped to that site and that rule, that expires by itself. It can never disable a security control. Chromium, Firefox
Explain cookies Lists the cookies the current site can read and says what each one is for, who owns it, and whether the site needs it to work. Values are not read for this; Export Cookies copies or saves them, on your device, only when you ask. All, incl. Safari — per-site permission
Group cookies by purpose Sorts the list under Sign-In & Security, Site Settings, Analytics, Advertising and Not Yet Identified, from Sessyn's sourced catalog. A cookie with no entry is placed under Sign-In & Security only when its browser attributes point that way, and the row says Likely and why; otherwise it is Not Yet Identified, never guessed from its name. All, incl. Safari — per-site permission
Show when cookies expire Each cookie shows its exact expiry date and time in your own date format with a plain duration, or that it ends when you close the browser. Sign-In & Security opens with how long your sign-in is set to last, and the reminder that the site can end it sooner. Browsers do not give extensions a creation date, and Sessyn does not note when it first saw a cookie, because that would be a record of your browsing. Reports still say only whether a cookie is stored. All, incl. Safari — per-site permission
Forget a cookie Deletes it and confirms by re-reading, so it cannot report success on a no-op. Anything needed to stay signed in asks twice first. All, incl. Safari — per-site permission
Show what is really in force Reads the installed rules back out of the browser and reports that, rather than assuming the rules it asked for were applied. All
A console A full page behind the popup: what the browser confirms is installed, every rule this build acts on, the full cookie table for a site, and the sites you have allowed with a way to revoke any of them. All
Look up a cookie A searchable catalog of every cookie Sessyn has an entry for, each one sourced and dated, so you can look one up without visiting a site that sets it. All
Hand back a bug report Capture what Sessyn saw on a page, including the third-party sites it loaded, then save it as a file or send it to Sessyn. Before anything is sent you see a summary and the exact report, and nothing goes without your click. It names the sites you captured, so it is not anonymous. Cookie values, page addresses and times are never included. Sessyn keeps it 30 days, and you can delete it from the popup. All

What It Deliberately Does Not Do

Capabilities Sessyn does not have, and why
Not availableWhy
Blocking on Safari Safari does not expose the blocking API. Sessyn explains and analyzes cookies there, and says in the interface that it is not blocking.
Blurring your location Location masking ships with one strategy only: report a fixed point you chose. The engine also implements displacing your real position by random noise (geo-indistinguishability), but that strategy needs your real position first, which means routing it through the extension — the exact data this feature exists to protect. It is built and tested but not installed.
Ask me before each decision The browser applies rules without consulting the extension, so there is no point to interrupt at. So the extension does not offer it, and an old saved choice of it is treated as Essential Only rather than silently weakened.
Watching your requests Sessyn never requests the webRequest permission, so it cannot see the URLs you load — and neither can we.
Cleaning links In Private and Lockdown the extension removes known click identifiers such as gclid and fbclid from addresses you navigate to, which needs your permission to access sites. It acts on top-level page loads only, never on form submissions, and removal is allowlist-only: a parameter it has no evidence for is left alone. The fuller cleaner runs as a paste-in tool on sessyn.app.

The Two Choices You Make

Sessyn intent and strictness settings
SettingOptionsDefault
What to Allow Essential Only — or additionally permit measurement that cannot profile you, which is restricted rather than blocked. Essential Only
How Strict Standard acts only on named rules. Private also strips cross-site cookies and removes known click identifiers from addresses, both of which need your permission to access sites. Lockdown additionally blocks third parties it cannot identify — which breaks any site serving its own images or scripts from another domain, so it is a deliberate choice rather than the default. Private

What Each Mode Actually Changes

Read down a column to see what that mode does, and read the last three rows to see what none of them do. A privacy tool that lets you believe it covers those is worse than one that says plainly it does not.

What happens to each kind of request under Standard, Private and Lockdown
What happens to… Standard Private (default) Lockdown
Trackers Sessyn has a sourced rule for Blocked Blocked Blocked
Cookies sent to a third party across sites Left alone Stripped needs site access Stripped needs site access
Click identifiers in a link you followed (fbclid, gclid) Left alone Removed needs site access Removed needs site access
Third parties Sessyn cannot identify Left alone Left alone Restricted may break sites
Measurement that cannot follow you across sites Decided by your other setting, not by mode. Blocked on Essential Only; Restricted if you allow it.
Your login, payment and anti-fraud cookies Kept working in every mode, and an exception cannot override it.
Browser and device fingerprinting Not addressed — Sessyn explains it and does not measure or mask it.
Your IP address and rough location it implies Not addressed — Sessyn is not a VPN.
A location a site explicitly asks for (the Geolocation API) Optional — a site that requests your location can be given one you chose instead, once you turn it on. Off by default; needs its own permission.
What a site's own server already recorded Not addressed — nothing in a browser can reach it.

Lockdown is stricter, not complete. The difference between the columns is how much Sessyn acts on things it has not identified — and the last three rows are the same whichever column you pick.

Two Things Mode Does Not Control

Everything above is decided by Standard, Private or Lockdown. These two are their own toggles, on by default, independent of which mode you pick.

Telling Every Site: Essential Cookies Only

Sessyn sends Global Privacy Control (Sec-GPC: 1) with every request once you have granted site access — a standing, machine-readable refusal to have your data sold or shared, legally binding in several US states. It states the preference you already made by choosing Essential Only. It does not click a consent banner for you, and Sessyn cannot verify a site honored it — the interface says exactly that rather than claiming the site agreed.

Clearing the Cookies You No Longer Need

“Clear Known Trackers” removes, in one click, every cookie on the current site that Sessyn has a sourced catalog entry for and knows is not necessary — things like _ga or _fbp. It shows you the exact names before you confirm. It is deliberately narrower than “non-essential” might suggest: a cookie with no catalog entry is left alone rather than guessed about, because SID and HSID are real Google session cookies and this is the mistake that matters most to avoid. The cookie list also states how many of a site's cookies will still be there after you close the browser, so persistence is something you can see, not just infer.

The Data Flow

Two flows run on their own, and only one of them touches a network. A third runs only when you choose to send a report.

Your Device

1 · Page Loads

A site asks your browser for a script, an image, a beacon.

2 · Browser Checks Rules

The rules are already on disk. Sessyn is not in the request path and never sees the URL.

3 · Verdict Applied

Decided by your mode and the confidence of the entry.

  • Allow
  • Partition
  • Restrict
  • Block

↓ Coming In — Roughly Every Six Hours

A signed, versioned ruleset from sessyn.io, carrying no account and no identifier. Its signature (ECDSA‑P384, from a key held in a hardware security module and used only after a person approves the change) is verified on your device against a key pinned in the extension, and it is kept only if it is newer than the bundled copy. Sessyn never asks a server “is this a tracker?”, because the question itself would reveal what you are reading.

↑ Going Out — Only What You Choose to Send

On its own, Sessyn sends no browsing event, cookie name or value, page address, or identifier. There is no Sessyn account and no analytics. The one thing that can go out is a report you send yourself, after reading exactly what it contains.

The second flow is the rule update, checked roughly every six hours. Sessyn downloads a signed, versioned dataset from sessyn.io and verifies it locally before trusting it — it never asks a server “is this a tracker?”, because that question would reveal what you are reading. The request carries no account and no identifier: credentials are omitted, no referrer is sent, and the response must carry a valid ECDSA-P384 signature, made by a key held in a hardware security module and used only after a person approves the change with a passkey, against a key pinned in the extension itself. A ruleset that fails that check, or is not newer than what shipped in the build, is discarded and the bundled rules keep enforcing — the bundled copy is always the floor, never replaced by something worse.

sessyn.io
    ↓
Signed, versioned ruleset (ECDSA-P384, hardware-held key)
    ↓
Extension verifies the signature against a pinned key
    ↓
Only kept if newer than the bundled ruleset
    ↓
Rules stored locally
    ↓
Browsing evaluated on device

The Report You Choose to Send

In the popup's Help Improve the Beta section, Capture This Page records the site's name, your settings there, its cookie names and the names of the third-party sites the page loaded. What is sent is cut down further: the site's main name only, and any part of a third-party name that could identify a person or company replaced by *. Send to Sessyn then shows you a summary and the exact report. Nothing is sent until you press Send, the choice is never remembered, and nothing is sent in the background or retried later.

The report goes straight to Sessyn's own server at reports.sessyn.io, deliberately not through Cloudflare, and is sealed the moment it arrives: the service that receives it cannot read it. It is kept 30 days, then deleted. Maintainers see only a summary across reports — third-party sites no rule blocks yet, and cookie names the catalog does not know — and a lead becomes a rule only after someone checks a published source. It is not anonymous: it names the sites you captured. Page addresses, cookie values, page content, times and identifiers are never in it.

Why Blocking Does Not Reveal Anything

Sessyn uses the browser's own declarativeNetRequest engine. We hand the browser a list of rules and the browser applies them. Sessyn is not in the request path and does not observe what it blocks. This is why Sessyn does not request the webRequest permission that would expose every URL you load.

Classification, With Its Working Shown

Every entry carries a confidence level, and Sessyn acts accordingly:

ConfidenceMeaningSessyn will
VerifiedDocumented by the provider or directly observedEnforce
HighStrong corroborating evidenceEnforce
LikelyConsistent with known behaviorEnforce, and say it is likely
PossibleWeak signal onlyExplain, not enforce
UnknownNo classificationLeave alone, unless you chose Lockdown

A blocker that treats a guess as a fact breaks websites and loses your trust. Sessyn would rather tell you it does not know.

What Sessyn Will Not Claim

Sessyn can tell you a privacy signal was sent. It cannot tell you a company honored it, because that happens on their servers. You will never see "this website agreed not to track you", because we cannot verify that.

Equally, a cookie usually holds an identifier — not a dossier. Sessyn will say "this identifier may let the provider associate this browser with data on its servers". It will not invent what that data contains.