Cookie Policy

Last updated: 23 September 2026

Your choice

We ask before we store anything on your device that is not strictly necessary. Until you press Accept cookies, none of the analytics or advertising items on this page load: the Google tag is not requested, PostHog is not started, Vercel Web Analytics does not load, Sentry Session Replay does not record, our own page-view record is not sent, the Trustpilot badge does not load, and no affiliate referral cookie is written.

You can change or withdraw that choice at any time — it takes one click, the same as giving it, and it is the same control either way:

Withdrawing consent deletes the identifiers we can reach from your browser and reloads the page so nothing non-essential is left running. Some third-party cookies (for example Google's test_cookie on doubleclick.net) can only be removed by your browser, because they are not readable by this site.

We rely on your consent under regulation 6 of the Privacy and Electronic Communications Regulations 2003 (PECR) and Article 6(1)(a) UK GDPR. Strictly necessary items are used under the PECR exemption, which does not require consent.

Google Consent Mode

Before any Google tag can run, the page sets Google Consent Mode v2 to denied for advertising storage, advertising user data, advertising personalisation and analytics storage. If you accept, we send an update granting those four. If you do not, the Google tag is never loaded at all, so the denial is the only state it would ever see.

Strictly necessary — used without consent

These make the site work: signing in, keeping you signed in, remembering your theme, and recording the cookie choice itself. Turning them off would break the service, so PECR does not require consent for them.

Strictly necessary cookies and storage
Name / keyStored asSet byPurposeDuration
zm_consentcookieZenMode (first-party)Records whether you accepted or rejected non-essential cookies, so we do not ask again and every gate can read your choice.6 months
__client, __client_uat, __sessioncookieClerk (third-party)Keeps you signed in and protects the sign-in flow. Set on zen-mode.io by our authentication provider.__client up to ~13 months; __session ~1 minute, refreshed
__clerk_environmentlocalStorageClerk (third-party)Caches the sign-in configuration so the sign-in form renders without a round trip.Until cleared
__cf_bm, _cfuvidcookieCloudflare (third-party)Bot filtering in front of our authentication provider. Set when the sign-in components load.__cf_bm 30 minutes; _cfuvid until the browser closes
zen_affiliatecookieZenMode (first-party)Signed session for the affiliate partner portal. Only set after an affiliate signs in.30 days
sf_code_verifiercookieZenMode (first-party)One-time PKCE verifier for connecting a Salesforce account. Only set while an integration is being authorised.10 minutes
zm_recoverycookieZenMode (first-party)Identifies you when you follow a sign-up recovery link from one of our emails.30 days
zenmode_democookieZenMode (first-party)Marks a session that entered the read-only product demo, so the demo dashboard renders.2 hours
themelocalStorageZenMode (first-party)Remembers light or dark mode.Until cleared
zm_chunk_reload_atsessionStorageZenMode (first-party)Stops a reload loop when a deploy invalidates the page's JavaScript while your tab is open.Until the tab closes

Analytics and advertising — only after you accept

None of these load until you press Accept. Durations are the maximum lifetime the provider sets; a cookie can be removed sooner by you or your browser.

Analytics and advertising cookies and storage
Name / keyStored asSet byPurposeDuration
_gcl_au, _gcl_aw, _gcl_gbcookieGoogle (Google Ads) (first-party)Attributes a sign-up to the Google ad that brought you here, and builds remarketing audiences. Loading the Google tag also contacts google.com and google.co.uk.90 days
_gcl_lslocalStorageGoogle (Google Ads) (first-party)Google's first-party linker store, used for the same ad attribution.Until cleared
test_cookiecookieGoogle (doubleclick.net) (third-party)Checks whether your browser accepts cookies before Google sets advertising identifiers.15 minutes
zm_trial_conv_fired_*, zm_email_signup_conv_*, zm_ads_conv_*localStorageZenMode (first-party)Stops us counting the same Google Ads conversion twice for the same person.Until cleared (zm_ads_conv_* until the tab closes)
ph_<project key>_posthogcookiePostHog (EU region) (first-party)Product analytics: pages viewed, features used, and which marketing source you arrived from. Requests are proxied through zen-mode.io/ingest to eu.i.posthog.com.1 year
PostHog storage keys (ph_*)localStoragePostHog (EU region) (first-party)Holds the same analytics identifier and the queue of events not yet sent.Until cleared
zm_first_touch_*, zm_signup_complete_*localStorageZenMode (first-party)Stops us re-sending your first-touch marketing source and sign-up event on every page load.Until cleared
sentryReplaySessionsessionStorageSentry (first-party)Session Replay: records a reconstruction of what happened on screen so we can debug a fault. Text inputs are masked. Requests are proxied through zen-mode.io/monitoring.Until the tab closes
Vercel Web AnalyticsNothing stored on your deviceVercel (first-party)Page-level traffic counts. Sets no cookie and no storage, but each page view sends a request to zen-mode.io/_vercel/insights/view.No storage on your device
ZenMode page-view recordNothing stored on your deviceZenMode (first-party)Sets nothing on your device, but records on our servers: the page path, the referring URL, any utm_* parameters, your browser's user agent, your screen width, the country and city your IP resolves to, and — if you are signed in — your user id.No storage on your device; the server record is kept while your account is active
zen_ref, zen_ref_atcookieZenMode (first-party)Credits an affiliate partner if you arrived from their referral link. Recording the click also stores your IP address on our servers.90 days
Trustpilot TrustBoxNothing stored on your deviceTrustpilot (third-party)Renders the Trustpilot badge on the homepage in an embedded frame. Trustpilot receives the page address and the referring URL, and may set its own storage inside that frame.Set by Trustpilot

Where this data goes

Google LLC (United States), Sentry (United States), Vercel (United States) and Trustpilot (Denmark) process data outside the UK. PostHog is on its EU region (Germany) and our requests reach it through a proxy on our own domain. Where data leaves the UK/EEA we rely on the provider's Standard Contractual Clauses or the UK International Data Transfer Agreement. The full list of processors is in our Privacy Policy.

Questions

Email hello@zen-mode.io. You can also complain to the UK Information Commissioner's Office at ico.org.uk.