Draft. This page is a starting skeleton, not a legally reviewed document. The passages in brackets ([TO BE COMPLETED]) need filling in, and the whole must be reviewed by a lawyer before it goes live.
Cookie policy
Last updated: 11 September 2026
1. What a cookie is
A cookie is a small file placed on your device when you visit a site, so that the site can recognise it on your next visits.
2. The cookies Mailmus uses
Mailmus uses two cookies, and only two. Neither serves any advertising purpose, neither is passed to a third party, and neither follows you outside our own pages.
- Security cookie (
mailmus_oauth_nonce): when you sign in with Google, GitHub or Apple, this cookie protects the sign-in in progress against impersonation attempts. It holds nothing but a single-use identifier, it is valid for ten minutes, and it is deleted as soon as the sign-in completes. It cannot be turned off without disabling that way of signing in. - Language cookie (
mailmus_locale): the language you pick is remembered so that the page is served in the right language from the very first byte, rather than switching in front of you once it has loaded. It holds nothing but the two-letter language code, and it is only ever set once you choose a language.
What Mailmus does not use. No audience-measurement cookie, no advertising cookie, no third-party tracker: no analytics tool, no ad network, no behavioural tracking. Your dashboard session and your other display preferences (light or dark theme, for instance) are kept locally in your browser, which involves no cookie at all and sends nothing to our servers.
3. Consent
Mailmus shows no consent banner, and that is not an oversight: neither of the two cookies above requires one. The security cookie is strictly necessary for the service you asked for, since without it a Google, GitHub or Apple sign-in cannot be protected. The language cookie is only set in response to your own choice, and it does not exist until you make one.
A banner asking you to approve those two would make you click without letting you decide anything. We would rather place nothing than ask your permission to place it.
You can delete these cookies at any time, or set your browser to refuse them. Two consequences follow, and no others: signing in with Google, GitHub or Apple will stop working, and your choice of language will no longer be remembered from one visit to the next.
Were an audience-measurement cookie ever introduced, it would require your prior consent, and this page would be updated before it went live.
4. How long they last
- Security cookie: ten minutes, and deleted sooner than that as soon as the sign-in succeeds.
- Language cookie: one year from your choice, renewed every time you change it.
These are the durations actually applied, not theoretical maximums.
5. Contact
For any question, write to us at hello@mailmus.io.