Privacy

Privacy policy

Last updated: 2026-10-07

This page describes what cosyte.com collects when you visit it, what happens to a message you send us or an address you give us for email updates, and what we do not do with any of it. It describes how the site works. It is not legal advice.

What this policy covers

This policy covers cosyte.com, the site you are reading, and nothing else. It says what the site collects when you visit it, what happens to a message you send through the contact form or an address you give us for email updates, and how long any of it lasts.

It does not cover the open-source software we publish. That software runs on your own machines and sends us nothing. It does not cover a consulting engagement either: the written agreement for that engagement governs what happens to anything you share with us under it.

What we collect

Three things reach us, and nothing else. The first is the analytics described in the next section. The second is whatever you type into the contact form and send us. The third is an email address you give us on the sign-up page, if you choose to. Both are described below the analytics section.

There are no accounts on this site and no profile to fill in. The pages themselves are a static artifact with no database behind them and no customer record system. The one thing we keep on a server is the email list described below, and it holds only what that section names. We do not know your name unless you choose to tell us.

The analytics cookies described in the next section sit on your device as well. So does your theme choice: if you switch the site between light and dark, your browser stores that choice in local storage under the name theme, so the next page you open starts the way you left it. Nothing sends that choice anywhere, and clearing site data for cosyte.com removes it.

Analytics

A Google Analytics 4 tag runs on the deployed site. It sends a page view for each page you open, carrying the page title, the page address and the page path. The analytics property can also record events of its own, such as scrolling to the end of a page or how long a page was in view; which ones is set in the property, outside this site. Every event carries the page address with the query string and the fragment removed, and the address you came from shortened the same way, so the parameters on a link you followed are not carried into the measurement.

There is one exception, and it covers five parameters only. When the link you followed to this site carries campaign tags (utm_source, utm_medium, utm_campaign, utm_content and utm_term), the page view for your arrival also carries those values, so we can tell which of our posts and links brought you here. We put those tags on the links we publish. A value is sent only if it is a short label of letters, digits, dots, hyphens, underscores or tildes, no longer than 100 characters, and nothing else in the query string is sent. Once the page has read the tags, it removes the query string from the address bar, so nothing the tag reads afterwards can carry it.

The last byte of your IP address is truncated. The cookies the tag writes are first-party to cosyte.com and are configured to expire after 13 months, rather than the two years a tag that configures nothing inherits by default.

There is no experimentation code, no personalisation code and no advertising code anywhere on this site. What the receiving analytics property is configured to do with what it receives is set outside this site, so we describe what we send rather than what happens to it afterwards.

The contact form

The contact form posts what you typed to an endpoint we run ourselves, so a message describing an integration problem does not travel through a form service run by somebody else. We rent the cloud infrastructure that endpoint runs on rather than owning the machines, so the provider hosting it carries your message on the way to us. No form product, no customer record system and no marketing tool is in that path.

A successful submission means our mail service accepted the message. It does not mean the message was delivered, and we do not promise a reply time. You can write to hello@cosyte.com instead, which is a route that does not involve the form at all.

Please do not put patient data or other sensitive personal data in a message. This site touches none of it today and should not start receiving it. If you need to show us a real message to explain a problem, ask us first and we will agree a safe way to do it.

Read how the contact form works

Email updates

The sign-up page posts the email address you enter to an endpoint we run ourselves, the same way the contact form does. That endpoint keeps the address on our own email list, held in Amazon Simple Email Service, the email service we rent. No newsletter product and no marketing tool is in that path.

Signing up sends one email to that address with a link to confirm. Nothing is subscribed until the link is clicked, and the link stops working after 48 hours. An address that is never confirmed stays on the list marked unconfirmed and receives nothing more from us, unless someone signs it up again, which sends one more confirmation email and never more than one every ten minutes.

With the address, the list records whether it is confirmed and when the confirmation email went out and was confirmed. It records nothing else about you. Once you confirm, we send occasional email about Cosyte releases and news. Every one of those emails carries a one-click unsubscribe link, run by the same email service, which records the choice on the list straight away.

Go to the sign-up page

What we do not do

We do not sell personal data. We do not run an advertising network and we ship no advertising code. We do not track you across other sites and we build no profile of you.

We do not combine what the analytics tag reports with anything else: not with the email list, and not with anything we hold, because there are no accounts and no customer record system to combine it with. Apart from the cloud provider that carries it, described above, we do not pass a message you send through the form to anyone outside Cosyte, and we do not sell the email list or give it to anyone.

How long we keep information

The analytics cookies this site writes are configured to expire after 13 months rather than the two years that configuring nothing would mean. A cookie already on your device keeps the expiry it was written with until a later visit rewrites it, so nothing we change here shortens one that is already there.

How long the analytics vendor keeps the events it receives is set in that property, outside this site, and we describe it here rather than assert it. A message you send us arrives as email and stays in our mailbox until we delete it; we keep it while the conversation it belongs to is live.

An address on the email list stays there until you ask us to delete it. Unsubscribing stops the email at once and leaves the address on the list marked unsubscribed, so that we do not email it again. To have the address deleted from the list entirely, confirmed or not, write to hello@cosyte.com.

The theme choice your browser stores is not a cookie and carries no expiry date. It stays on your device until you clear site data for cosyte.com, and it reaches us at no point.

Your choices

This site has no consent banner and no opt-out control. We would rather say that plainly than imply a control we do not offer.

Your routes to declining are your own browser controls: a setting that blocks cookies or scripts, a private window, or an extension that blocks the analytics tag. All of them work here. Every route serves its text as HTML, so the reading you came for does not depend on a script, and the footer links at the bottom of every page work with scripts off.

Some parts of this site need JavaScript, and naming the ones you are most likely to meet is more use to you than a blanket promise. The message form on the contact page posts what you typed as JSON, so with scripts off the form is hidden and the page offers the direct address in its place. Writing to hello@cosyte.com needs no scripts and reaches the same inbox. The sign-up form posts JSON in the same way and is hidden with scripts off, and the page that confirms a subscription needs a script to send the confirmation. On a narrow screen the menu button in the header opens with a script, so the footer links are the way around the site instead.

The header also carries a button that switches the site between light and dark, and a code block carries a button that copies it. Both of those run in a script. With scripts off they stay on screen and do nothing when you press them: the site stays dark, and selecting a code block by hand is the way to copy it.

Changes to this policy

We change this page when what the site does changes. The date at the top of the page records the last time we changed it, and the version published here is the current one.

We do not keep earlier versions on the site and we do not notify anyone of a change: there are no accounts to notify, and the email list is for Cosyte releases and news, not for notices about this page. If this page matters to your decision, the date at the top is the thing to check.

Contact

Write to hello@cosyte.com with a question about this policy or about what the site holds. That address reaches us directly and we answer our own email. We do not promise a reply time.

If your question is about a consulting engagement, the written agreement for that engagement governs it and nothing on this page changes it.

hello@cosyte.com