Cookie & Local Storage Policy

Last updated: 2026-07-31Every cookie APERTURESyndicate sets, what it is for, how long it lives — and an honest account of how our consent banner currently works.

Cookie & Local Storage Policy

This policy explains how APERTURESyndicate OÜ ("APERTURESyndicate", "AS", "we", "our") uses cookies and similar browser storage across aperturesyndicate.com and its subdomains. It is published under the EU General Data Protection Regulation (GDPR) and the ePrivacy rules as implemented in Estonia. Read it together with our Privacy Policy.

Our platform is intended for users aged 16 and over.

This document is pending review by qualified EU/Estonian legal counsel and may be revised following that review.

1. What we use, in one sentence

Every cookie we set is first-party and functional: it keeps you signed in, remembers a preference you chose, or records your cookie choice. We set no advertising cookies, no third-party tracking cookies, and — today — no analytics cookies at all. There is no ad network, no tag manager, and no third-party analytics or error-monitoring script anywhere in our front-end code.

Earlier versions of this page listed an "error monitoring" cookie category based on a provider we had never actually deployed. That category is gone, because it described something that did not exist.

Lifetimes are given as they are configured. "Host-only" means the cookie belongs to the exact domain that set it and is not sent to other subdomains; the others are scoped to .aperturesyndicate.com so that one sign-in works across the platform.

CookieWhat it doesReadable by page scripts?LifetimeScopeCategory
syndicate_refreshThe token that keeps you signed in and lets us issue new short-lived access tokens. Rotated every refresh.No (HttpOnly)30 days.aperturesyndicate.comStrictly necessary
syndicate_userDisplay data for the interface — your nickname, avatar URL and role — so the navigation bar can render you before any network call. Base64-encoded JSON, which is encoding, not encryption.Yes30 days at sign-in, refreshed to 7 days on later visits.aperturesyndicate.comStrictly necessary
syndicate_adminShort-lived step-up token issued after a passkey challenge, for staff using administrative tooling. Never set on a normal account.No (HttpOnly)15 minutes.aperturesyndicate.comStrictly necessary
pkce_verifierOne half of the PKCE handshake that protects the sign-in redirect.No (HttpOnly)10 minutesHost-only, /api/authStrictly necessary
pkce_stateAnti-CSRF value for the same sign-in redirect.No (HttpOnly)10 minutesHost-only, /api/authStrictly necessary
lq_refreshThe equivalent sign-in token for Lysicon Quanture.No (HttpOnly)30 daysHost-onlyStrictly necessary
synx_sessionServer session for the SYNX portal, which is not a Next.js app and keeps its own session.No (HttpOnly)7 days.aperturesyndicate.com, or host-only where no shared domain is configuredStrictly necessary
as_themeYour light/dark theme choice, read by a small inline script so the page does not flash the wrong colours.Yes1 year.aperturesyndicate.comStrictly necessary (a preference you set)
as_cookie_consentRecords the choice you made in the banner — all or essential.Yes1 yearHost-onlyStrictly necessary (consent record)

Sign-in cookies are marked Secure in production and use SameSite=Lax or Strict depending on which part of the sign-in flow issued them.

Some data lives in localStorage or sessionStorage instead. It is never sent to us automatically the way a cookie is — our code reads it when it needs it.

KeyWhat it holdsStorage
syndicate_access_jwtYour short-lived access token (about 15 minutes), refreshed in the backgroundlocalStorage
as_theme, as_theme_mode, asai:theme, lq_theme, studio_themeTheme choices per applicationlocalStorage
as_privacy_prefs, as_notif_prefsPrivacy and notification settings you toggledlocalStorage
as:pkce, rs_pkce_verifier, rs_oauth_state, sso_state, sso_code_verifierTemporary sign-in handshake valuessession/localStorage
syndicate_is_creator, syndicate_has_studioWhether to show creator or studio links in the menusessionStorage
Assorted panel and layout keys (for example asai:world-panel:collapsed)Which panels you left openlocalStorage

Clearing your browser storage signs you out and resets these preferences. It breaks nothing permanently.

Reduced motion is not stored in your browser by us. Where animation is reduced, it is because your operating system asks for it, or because you turned animations off in the product's own settings — see our Accessibility Statement.

Under the ePrivacy rules, strictly necessary cookies — the ones needed to deliver a service you actively asked for, such as signing in — do not require consent. Everything in the tables above falls into that class today. We do not currently set a single cookie that would need consent.

You should nonetheless know exactly how our consent banner behaves right now, because it is not as complete as a banner implies:

  • The banner is shown on the main site only. It is rendered by aperturesyndicate.com and is not present on our other subdomains. If you land directly on a subdomain, you will not see it.
  • Your choice does not travel between subdomains. The as_cookie_consent cookie is host-only, so a choice recorded on the main site is not visible to the rest of the platform.
  • Nothing currently depends on the choice. Because no non-essential cookie is set anywhere, choosing "essential only" and choosing "accept all" produce the same result today: only the functional cookies above.

We are stating this rather than glossing over it. Fixing the scope of the banner and the consent record is planned work, and until it lands, this section is the accurate description of what happens. If and when we introduce a cookie that genuinely requires consent, it will be off until you agree, the banner will cover every subdomain, and this page will be updated first.

Withdrawing consent is as easy as giving it: clear the as_cookie_consent cookie in your browser, or clear cookies for our sites, and the banner will ask again. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.

5. How we measure product usage

We do measure which features are used, but not with cookies and not through a third party. Usage events are recorded on our own servers against your account — so a signed-out visitor is not profiled — and the raw events are deleted after 30 days, leaving only aggregate counts that are no longer linked to you. This is described in our Data Retention policy.

6. No advertising or cross-site tracking

We do not set or allow third-party advertising cookies, and we do not engage in cross-site or cross-device behavioural tracking. We do not sell or share your browsing activity with advertising networks or data brokers.

7. How to control cookies

Every major browser lets you view, block, or delete cookies and clear local storage; look in the privacy or cookie section of its settings. You can also use a private window.

Blocking the cookies in section 2 will prevent you from staying signed in, and may break sign-in entirely — those cookies carry the session, not a preference.

8. Third parties that receive technical data

Even though no third party sets a cookie in your browser through us, some providers necessarily see technical request data. Cloudflare sits in front of every public domain as our CDN and firewall and therefore processes the IP address, User-Agent and URL of every request. Pages that embed external content — a video player, a market chart — cause your browser to contact that provider directly, and it may set its own cookies under its own policy.

The complete list is on the Data Processing & Sub-processors page, which is generated from a registry checked against our source code.

9. Changes to this policy

We may update this policy as the platform changes. When we make a material change, we update the "last updated" date and, where appropriate, ask for renewed consent.

Contact

Questions about this policy or your cookie choices: [email protected]

APERTURESyndicate OÜ — registry code 17384111 · VAT EE102972654 · Priisle tee 8, Lasnamäe linnaosa, Tallinn, Harju maakond, 13914, Estonia. Company details: Company Registration.

This policy is governed by the laws of Estonia, with disputes subject to the courts of Tallinn. The English version is the controlling version.

Version history

  • v1.1 — 2026-07-31 — Corrected the domain, removed the error-monitoring category (the provider was never deployed), replaced the prose categories with the real cookie names, and documented the actual scope of the consent banner.
  • v1.0 — 2026-06-22 — Initial publication.
Cookie & Local Storage Policy | AS Docs