Cookie Policy
Last updated September 29, 2026
This is a short one, on purpose: every cookie MagflowAI sets is strictly necessary — nothing here tracks you, and there's no "customize your preferences" screen with toggles for tracking categories that don't exist here.
The cookies we set
| Cookie | Purpose | Type | Expiry |
|---|---|---|---|
magflow_session | Keeps you signed in between requests. Without it, the app cannot know who you are. | Strictly necessary | 30 days, or when you sign out |
magflow_resource_unlock | Remembers that you've entered the password for a gated free resource, so you're not asked again on the same browser. | Strictly necessary | 180 days |
magflow_admin_unlock | Internal use only — keeps our own team signed in to founder-only admin tooling. Set only if you have our internal admin token. | Strictly necessary | 30 days |
All three are httpOnly (invisible to page scripts), secure (sent only over HTTPS in production) and SameSite=Lax. None are readable by any third party, and we don't share them with anyone.
What we don't use
No analytics cookies, no advertising or retargeting pixels, no third-party tracking scripts, no cross-site tracking. We don't currently run any analytics tooling on this site at all.
If that changes
If we ever add analytics or any other non-essential cookie, we will update this page, add a real accept/reject choice to the cookie banner before that cookie is set, and — for EU/UK visitors — only set it after you've given consent. Because the cookies above are all strictly necessary and exempt from consent requirements under ePrivacy/GDPR (each is required for the specific thing you're asking for — staying signed in, or staying unlocked on a page you already entered a password for), the banner you see today doesn't ask for a choice; there isn't one to make yet.