The short version
This website sets three cookies. One remembers the interface language you selected and disappears when you close your browser. The other two belong to Microsoft Clarity, which we use for heatmaps and session replay, and they exist to read your page views as a single visit. If you are in the EEA, the United Kingdom or Switzerland, Clarity sets neither: it withholds its cookies unless the site tells it consent was given, and we do not tell it.
There is no advertising on this site, no conversion pixels and no audience lists. Clarity is the only third-party script on the page. When it loads, Microsoft can also set cookies on its own domains, and one of those, MUID, is an identifier Microsoft uses across its own sites, including for advertising there. We do not use it and cannot read it. Everything either of us can set is named below.
What cookies are
A cookie is a small text file a website asks your browser to store and send back on subsequent requests. A first-party cookie is set by the site you are visiting; a third-party cookie is set by another domain embedded in the page, which is the mechanism most cross-site tracking depends on. A session cookie is discarded when you close the browser; a persistent cookie survives until its stated expiry.
Similar technologies, local storage, session storage, pixels, device fingerprinting, perform comparable functions and are treated the same way in this policy.
Cookies this website sets
| Name | Purpose | Type | Duration |
|---|---|---|---|
NEXT_LOCALE | Records the interface language you chose, so the site opens in that language instead of guessing from your browser settings on every request. | First-party, strictly necessary. SameSite=Lax. | Session, deleted when you close the browser. |
_clck | Microsoft Clarity's identifier for your browser, so a second visit is recognised as the same reader rather than counted as a second person. | First-party, not strictly necessary. Set by the Clarity script. | 1 year. |
_clsk | Joins the pages you view into one Clarity session, so a replay reads as a single visit rather than a series of unrelated page loads. | First-party, not strictly necessary. Set by the Clarity script. | 1 day. |
- Name
NEXT_LOCALE- Purpose
- Records the interface language you chose, so the site opens in that language instead of guessing from your browser settings on every request.
- Type
- First-party, strictly necessary.
SameSite=Lax. - Duration
- Session, deleted when you close the browser.
- Name
_clck- Purpose
- Microsoft Clarity's identifier for your browser, so a second visit is recognised as the same reader rather than counted as a second person.
- Type
- First-party, not strictly necessary. Set by the Clarity script.
- Duration
- 1 year.
- Name
_clsk- Purpose
- Joins the pages you view into one Clarity session, so a replay reads as a single visit rather than a series of unrelated page loads.
- Type
- First-party, not strictly necessary. Set by the Clarity script.
- Duration
- 1 day.
The language cookie is written only when the language you are viewing differs from the one your browser would have been given automatically, in practice, when you pick a language from the switcher. Its value is a language code such as en or ar. It holds no identifier, and it is never transmitted to a third party.
The two Clarity cookies are not set for visitors Microsoft places in the EEA, the United Kingdom or Switzerland. Clarity requires the site to pass it a consent signal before it will store anything for those visitors, we do not pass one, and it therefore measures those visits without cookies: heatmaps still work, and a visit that crosses several pages is counted as several separate sessions.
Cookies Microsoft can set
Clarity is fetched from clarity.ms. When your browser asks Microsoft for it, Microsoft can set the following on its own domains. We do not choose them, we cannot read them, and a browser set to block third-party cookies, which most now are by default, refuses them without any action from you.
| Name | Purpose | Type | Duration |
|---|---|---|---|
CLID | Records the first time Clarity saw this browser on any website that uses Clarity. | Third-party, set on clarity.ms. | 1 year. |
MUID | Microsoft's identifier for a browser across its own sites. Microsoft uses it for site analytics, operational purposes and advertising on Microsoft properties. | Third-party, set on Microsoft domains. | Up to 13 months. |
ANONCHK, MR, SM | Housekeeping for MUID: whether it should be refreshed, whether it is passed to Microsoft's advertising identifier, which Clarity sets to zero because it does not use it, and synchronising it across Microsoft domains. | Third-party, set on Microsoft domains. | From ten minutes to a few days. |
- Name
CLID- Purpose
- Records the first time Clarity saw this browser on any website that uses Clarity.
- Type
- Third-party, set on
clarity.ms. - Duration
- 1 year.
- Name
MUID- Purpose
- Microsoft's identifier for a browser across its own sites. Microsoft uses it for site analytics, operational purposes and advertising on Microsoft properties.
- Type
- Third-party, set on Microsoft domains.
- Duration
- Up to 13 months.
- Name
ANONCHK,MR,SM- Purpose
- Housekeeping for
MUID: whether it should be refreshed, whether it is passed to Microsoft's advertising identifier, which Clarity sets to zero because it does not use it, and synchronising it across Microsoft domains. - Type
- Third-party, set on Microsoft domains.
- Duration
- From ten minutes to a few days.
These are Microsoft's cookies under Microsoft's practices rather than ours. If you want none of them, block clarity.ms, see Controlling cookies.
Other storage on your device
One thing, in one place. The diagnostic keeps your answers in session storage while you work through it, so a reload does not lose fifteen answers. It holds no identifier, it is never transmitted anywhere, and the browser discards it when you close the tab. Beyond that this website does not write to local storage, does not use IndexedDB, and does not employ pixels, web beacons or fingerprinting. Our page counting keeps nothing on your device at all; what Clarity keeps is the two cookies named above.
What we deliberately do not use
- Advertising. No advertising cookies of ours, no conversion pixels, no retargeting tags, no audience lists. We do not participate in real-time bidding, and we do not sell or share data with advertising networks. Microsoft's
MUID, above, is the one identifier on this page that its owner also uses for advertising, on Microsoft's own properties rather than here. - Any analytics beyond the two described. No Google Analytics, no product analytics, no A/B testing tools. Cookieless page counting and Clarity are the whole of it, and both are set out in the Privacy Notice rather than left in a vendor list.
- Social media. No embedded like buttons, share widgets or tracking pixels. Links to our social profiles are ordinary links that do nothing until you click them.
- Assets from other people's servers. Fonts are served from our own domain rather than a font service, images from our own infrastructure, and the page-view counter from our own domain too. Clarity is the only script on the page that is not ours.
- Fingerprinting and data brokerage. We do not fingerprint devices, and we neither buy nor sell behavioural data.
Browser signals such as Do Not Track and Global Privacy Control are not wired to Clarity by us, and we would rather say that than imply a switch works when we have not built it. The reliable way to refuse Clarity is to block it, which the next sections cover.
Server logs
Separately from anything stored on your device, our hosting provider records standard server logs, the IP address the request came from, the time, the URL requested, the response status and the browser's user agent string. These are generated by the act of delivering a web page, not by a cookie, and we use them to keep the site available and to investigate abuse. Retention is covered in the Privacy Notice.
Controlling cookies
Every major browser lets you view, block and delete cookies, in Settings under Privacy. You can block cookies from this site entirely; the consequence is that the site falls back to the language indicated by your browser on each visit, and Clarity stops recognising a returning reader. Nothing on the site breaks either way.
To refuse Clarity outright rather than only its cookies, block the domain clarity.ms. Most tracker blockers already do, and any content blocker or network-level blocker can be told to. Microsoft's own cookies are third-party, so a browser that blocks third-party cookies, which most now do by default, refuses those without any action from you. Blocking any of this leaves the pages, the diagnostic and the forms working exactly as they do now.
Changes and contact
This policy is reviewed when we change the site. The version in force is the one published here, with its date at the top of the page.
Questions about this policy, or about anything this site stores, go to privacy@sayfi.ai.
This policy is published in English. Any translation is provided for convenience only; the English text prevails in the event of a conflict.