Cookie Policy
Last updated: 23 September 2026
Your choice
We ask before we store anything on your device that is not strictly necessary. Until you press Accept cookies, none of the analytics or advertising items on this page load: the Google tag is not requested, PostHog is not started, Vercel Web Analytics does not load, Sentry Session Replay does not record, our own page-view record is not sent, the Trustpilot badge does not load, and no affiliate referral cookie is written.
You can change or withdraw that choice at any time — it takes one click, the same as giving it, and it is the same control either way:
Withdrawing consent deletes the identifiers we can reach from your browser and reloads the page so nothing non-essential is left running. Some third-party cookies (for example Google's test_cookie on doubleclick.net) can only be removed by your browser, because they are not readable by this site.
We rely on your consent under regulation 6 of the Privacy and Electronic Communications Regulations 2003 (PECR) and Article 6(1)(a) UK GDPR. Strictly necessary items are used under the PECR exemption, which does not require consent.
Google Consent Mode
Before any Google tag can run, the page sets Google Consent Mode v2 to denied for advertising storage, advertising user data, advertising personalisation and analytics storage. If you accept, we send an update granting those four. If you do not, the Google tag is never loaded at all, so the denial is the only state it would ever see.
Strictly necessary — used without consent
These make the site work: signing in, keeping you signed in, remembering your theme, and recording the cookie choice itself. Turning them off would break the service, so PECR does not require consent for them.
| Name / key | Stored as | Set by | Purpose | Duration |
|---|---|---|---|---|
| zm_consent | cookie | ZenMode (first-party) | Records whether you accepted or rejected non-essential cookies, so we do not ask again and every gate can read your choice. | 6 months |
| __client, __client_uat, __session | cookie | Clerk (third-party) | Keeps you signed in and protects the sign-in flow. Set on zen-mode.io by our authentication provider. | __client up to ~13 months; __session ~1 minute, refreshed |
| __clerk_environment | localStorage | Clerk (third-party) | Caches the sign-in configuration so the sign-in form renders without a round trip. | Until cleared |
| __cf_bm, _cfuvid | cookie | Cloudflare (third-party) | Bot filtering in front of our authentication provider. Set when the sign-in components load. | __cf_bm 30 minutes; _cfuvid until the browser closes |
| zen_affiliate | cookie | ZenMode (first-party) | Signed session for the affiliate partner portal. Only set after an affiliate signs in. | 30 days |
| sf_code_verifier | cookie | ZenMode (first-party) | One-time PKCE verifier for connecting a Salesforce account. Only set while an integration is being authorised. | 10 minutes |
| zm_recovery | cookie | ZenMode (first-party) | Identifies you when you follow a sign-up recovery link from one of our emails. | 30 days |
| zenmode_demo | cookie | ZenMode (first-party) | Marks a session that entered the read-only product demo, so the demo dashboard renders. | 2 hours |
| theme | localStorage | ZenMode (first-party) | Remembers light or dark mode. | Until cleared |
| zm_chunk_reload_at | sessionStorage | ZenMode (first-party) | Stops a reload loop when a deploy invalidates the page's JavaScript while your tab is open. | Until the tab closes |
Analytics and advertising — only after you accept
None of these load until you press Accept. Durations are the maximum lifetime the provider sets; a cookie can be removed sooner by you or your browser.
| Name / key | Stored as | Set by | Purpose | Duration |
|---|---|---|---|---|
| _gcl_au, _gcl_aw, _gcl_gb | cookie | Google (Google Ads) (first-party) | Attributes a sign-up to the Google ad that brought you here, and builds remarketing audiences. Loading the Google tag also contacts google.com and google.co.uk. | 90 days |
| _gcl_ls | localStorage | Google (Google Ads) (first-party) | Google's first-party linker store, used for the same ad attribution. | Until cleared |
| test_cookie | cookie | Google (doubleclick.net) (third-party) | Checks whether your browser accepts cookies before Google sets advertising identifiers. | 15 minutes |
| zm_trial_conv_fired_*, zm_email_signup_conv_*, zm_ads_conv_* | localStorage | ZenMode (first-party) | Stops us counting the same Google Ads conversion twice for the same person. | Until cleared (zm_ads_conv_* until the tab closes) |
| ph_<project key>_posthog | cookie | PostHog (EU region) (first-party) | Product analytics: pages viewed, features used, and which marketing source you arrived from. Requests are proxied through zen-mode.io/ingest to eu.i.posthog.com. | 1 year |
| PostHog storage keys (ph_*) | localStorage | PostHog (EU region) (first-party) | Holds the same analytics identifier and the queue of events not yet sent. | Until cleared |
| zm_first_touch_*, zm_signup_complete_* | localStorage | ZenMode (first-party) | Stops us re-sending your first-touch marketing source and sign-up event on every page load. | Until cleared |
| sentryReplaySession | sessionStorage | Sentry (first-party) | Session Replay: records a reconstruction of what happened on screen so we can debug a fault. Text inputs are masked. Requests are proxied through zen-mode.io/monitoring. | Until the tab closes |
| Vercel Web Analytics | Nothing stored on your device | Vercel (first-party) | Page-level traffic counts. Sets no cookie and no storage, but each page view sends a request to zen-mode.io/_vercel/insights/view. | No storage on your device |
| ZenMode page-view record | Nothing stored on your device | ZenMode (first-party) | Sets nothing on your device, but records on our servers: the page path, the referring URL, any utm_* parameters, your browser's user agent, your screen width, the country and city your IP resolves to, and — if you are signed in — your user id. | No storage on your device; the server record is kept while your account is active |
| zen_ref, zen_ref_at | cookie | ZenMode (first-party) | Credits an affiliate partner if you arrived from their referral link. Recording the click also stores your IP address on our servers. | 90 days |
| Trustpilot TrustBox | Nothing stored on your device | Trustpilot (third-party) | Renders the Trustpilot badge on the homepage in an embedded frame. Trustpilot receives the page address and the referring URL, and may set its own storage inside that frame. | Set by Trustpilot |
Where this data goes
Google LLC (United States), Sentry (United States), Vercel (United States) and Trustpilot (Denmark) process data outside the UK. PostHog is on its EU region (Germany) and our requests reach it through a proxy on our own domain. Where data leaves the UK/EEA we rely on the provider's Standard Contractual Clauses or the UK International Data Transfer Agreement. The full list of processors is in our Privacy Policy.
Questions
Email hello@zen-mode.io. You can also complain to the UK Information Commissioner's Office at ico.org.uk.