Cookie Policy
The cookies Muzings sets, what they are for, and how long they last.
Last updated: 2026-08-03
| Cookie | Category | Purpose | Duration |
|---|---|---|---|
mz_access | strictly-necessary | Short-lived access token that keeps you signed in. httpOnly. | ~1 hour (matches the access token lifetime; renewed via mz_refresh) |
mz_refresh | strictly-necessary | Refresh token used to renew your session without re-entering your password. httpOnly. | 30 days |
mz_oauth_state | strictly-necessary | One-time anti-forgery nonce for “Sign in with Google”, so a sign-in can only be completed by the browser that started it. Set when you begin Google sign-in and deleted the moment it completes. httpOnly, and scoped to the sign-in path only. | 10 minutes (deleted on completion) |
This list is complete: Muzings sets only the three strictly-necessary cookies above, and no analytics or marketing cookies. All three are HttpOnly and Secure, with SameSite=Lax, so they are never readable by client-side scripts and are only sent over HTTPS. Because we set no non-essential cookies, no cookie-consent banner is required; the short notice you may have seen is exactly that — a notice, with nothing to reject. If that ever changes, this page and the categories below will be updated before any new cookie is set.
Other storage on your device. Alongside those cookies, the app keeps a few small values in your browser's local storage: which library view you last used, a count used to decide whether to show first-run guidance, whether you have dismissed that guidance, and whether you have acknowledged the cookie notice. These are preferences kept on your own device, are never sent to us as identifiers, and are not used to track you. Clearing your browser storage removes them. If you sign in through Google, the sign-in page hosted by our identity provider (Amazon Cognito) may also set its own cookies on its own domain to run that sign-in; those are set by the provider, not by us.
Cookie categories
- Strictly necessary. Required for the service to work — for example keeping you signed in. These cannot be switched off without breaking core functionality.
- Functional. Remember your preferences and choices to give you a more tailored experience.
- Analytics. Help us understand how the service is used so we can improve it, in aggregate.
- Marketing. Used to measure or deliver advertising. Muzings does not set marketing cookies.