Privacy
What Sessyn Knows About You
As little as technically possible. Here is the exhaustive list.
Sessyn Never Collects
None of the following reaches Sessyn infrastructure, by architecture rather than by policy:
- Browsing history, or any URL you visit (a report you choose to send names sites, but never full addresses)
- Page contents or search history
- Cookie values, authentication cookies, or session tokens
- localStorage, sessionStorage, or IndexedDB contents
- Passwords, form contents, or clipboard contents
- Advertising or fingerprinting identifiers
- Your privacy timeline or per-site tracker map
- IP addresses used for profiling, or precise location
If we are ever technically unable to keep one of these promises, the correct response is to change the architecture — not the wording.
What the Websites Measure
This site sets no cookies and loads no third-party resources. There are no fonts from a CDN, no tag manager, no social widgets, and no session replay. You can verify all of this in your browser's network tab, which is rather the point.
Where we do measure product usage, it is aggregate and non-identifying: counts of page views and feature invocations, error rates, and coarse platform distribution. No cross-site identifiers, no raw IP retention, no advertising profiles. The implementation is documented publicly, and the full analytics policy is published alongside the source.
What the Extension Sends
On its own, one request, roughly every six hours: a check for a signed rule update at
sessyn.io. Credentials are omitted, no referrer is sent, and
the request carries no account and no identifier — it reveals that
some browser asked for the current ruleset, and nothing about what you
were browsing. The response must carry two valid signatures against keys
pinned in the extension before it is trusted, and is only kept if newer
than the ruleset already compiled into the build. Every other request the
browser makes on your behalf — blocking, cookie stripping, click-ID
removal, the Global Privacy Control header — is the browser applying
rules Sessyn already handed it; Sessyn is not in that request path and
does not see it.
Nothing about your browsing leaves your device unless you choose
to send a report, and you see exactly what it contains first.
If you press Send to Sessyn and then Send, the extension
posts one report to reports.sessyn.io, which goes straight to
Sessyn's own server rather than through Cloudflare. For each page you captured it
contains the site's main name only (substack.com, not
jdoe.substack.com), your Sessyn settings there, its cookie
names and what they are for (never their values), and the names of the
third-party sites the page loaded, with any part that could name a person
or company replaced by *; plus your extension version, your
browser's name and major version, and your operating system. Like any
request, it also carries your IP address and browser name; Sessyn does
not keep them. It never contains page addresses, cookie values, page content,
when you captured anything, the list of sites you have allowed, or any
identifier. It is not anonymous, because it names the sites you captured.
Export Cookies (from 0.2.73) is the one time the extension reads a cookie's value. It happens only when you click Copy or Download for the site you are looking at, after a warning, and the values go only to your clipboard or a file you save on your device. Sessyn does not keep them, send them, or put them in a report.
It is sealed when it arrives, so the service that receives it cannot read it; no request log is kept; and it is deleted after 30 days. It is used only to find trackers the rules miss and cookies the catalog does not know, and it is never sold or shared. Delete the Reports You Sent, in the popup, deletes it sooner, and Delete All Sessyn Data deletes your sent reports before clearing anything else.
How You Delete a Report Nobody Can Trace to You
Sessyn has no accounts, so it cannot look up “your” reports. Deleting works like a coat-check ticket instead:
- When a report arrives, the server makes up a random receipt — 22 characters that come from nothing about you, your browser or the report — and hands it back to your browser.
- The server does not keep the receipt. It keeps only a one-way fingerprint of it (a SHA-256 hash), which it uses as the stored report's file name. A fingerprint cannot be turned back into the receipt, so even a full copy of the server's disk could not be used to delete or claim your report.
- Your browser keeps the receipt, in the extension's own storage. That is how Delete the Reports You Sent knows what you sent: it reads its own list, and asks nothing of the server.
- To delete, the extension sends each receipt back. The server fingerprints it, deletes the matching file, and answers the same way whether or not a report existed, so nobody can use it to check what was sent.
Every report gets a different receipt, so two reports from the same browser cannot be linked by them. Reports are deleted after 30 days anyway, and the extension forgets receipts after 31. One limit, stated plainly: when you press Delete, your receipts arrive together, so for that moment the server could tell those reports came from one place. Nothing was stored that linked them before, and they are deleted right after.
Server Logs
Serving a web page necessarily involves receiving an IP address. Sessyn does not persist it for profiling: access logs are minimized, IPs are truncated, query strings are redacted, and retention is short. Abuse and security logging is kept separate from any product measurement.
Your Rights, and the One Record We Might Hold
Data-subject requests usually ask a company to disclose or delete what it holds about you. Sessyn creates no identifier and has no account, so the only record that can exist is a report you chose to send, kept 30 days. Nothing in it says who sent it, so we cannot look yours up. Your browser keeps a receipt for each one instead, and Delete the Reports You Sent in the popup uses those receipts to delete them. If this ever changes, this page changes first.