Cookie Policy

Last Updated: August 5, 2026

This Cookie Policy explains how Muse AI (“Muse,” “we,” or “us”) uses cookies, web beacons, pixels, and similar tracking technologies when you access https://justmuse.app (the “Service”).


1. What Are Cookies & Tracking Technologies?

A. Cookies

Cookies are small text files stored on your browser or device by web servers. They allow websites to remember your preferences, session state, security information, and behavior over time.

Types of Cookies by Lifespan:

  • Session Cookies: Deleted automatically when you close your browser
  • Persistent Cookies: Stored on your device until manually deleted or they reach their expiration date

B. Similar Technologies

Beyond cookies, we also use:

  • Web Beacons: Tiny transparent pixels embedded in web pages or emails to track views and clicks
  • Local Storage & SessionStorage: Browser storage mechanisms that persist user preferences and state
  • Pixels & Tags: Code snippets that track user interactions and page performance

2. Categories of Cookies We Use

CategoryPurposeEssential / OptionalProviderRetention
Strictly Necessary (Functional)Session authentication, CSRF protection, security state, account access controlEssential (cannot be disabled)Clerk, VercelSession-based (24 hours to 30 days)
Performance & AnalyticsSession duration, page load times, feature usage, error tracking, user behavior analysisOptionalPostHog90 days (active), 12 months (anonymized)
Functional PreferencesDark mode toggle, UI language preference, sidebar state, saved filtersOptionalMuse Local StorageUntil manually cleared
Third-Party SocialAuthentication with Instagram/YouTube/Threads, sharing functionalityOptional*Instagram, YouTube, GoogleVaries by platform (see Section 4)

*Required if you choose to connect social media accounts


3. Detailed Cookie Descriptions

A. Strictly Necessary Cookies

Clerk Authentication Cookies

  • Cookie Names: __session, __sessionId, iss, sub, aud, exp, iat
  • Purpose: Authenticate your identity, maintain secure session state, prevent unauthorized access
  • Provider: Clerk (US-based authentication service)
  • Retention: 24 hours to 30 days depending on session activity
  • Disabling Impact: You will be unable to log in or access your account

Vercel Cookies

  • Cookie Names: __Host-next-auth.csrf-token, __Secure-next-auth.callback-url
  • Purpose: CSRF (Cross-Site Request Forgery) protection, secure routing between edge nodes
  • Provider: Vercel (US-based hosting infrastructure)
  • Retention: Session-based (deleted on browser close)
  • Disabling Impact: Security features disabled; increased risk of unauthorized actions

Muse Session Cookies

  • Cookie Names: muse_session, csrf_token, device_fingerprint
  • Purpose: Track your active session, validate CSRF tokens, identify your device for security
  • Provider: Muse AI
  • Retention: 24 hours
  • Disabling Impact: Frequent re-authentication required; some platform features may not function

B. Performance & Analytics Cookies

PostHog Analytics

  • Cookie Names: ph_phc_*, PostHogSessionID, PostHog_Opt_Out_Token
  • Purpose: Track page loads, feature interactions, session duration, user flows, error rates
  • Provider: PostHog (EU-based analytics platform)
  • Data Collected: Anonymized event names, session IDs, timestamps, page URLs (no PII by default)
  • Retention: 90 days in active storage; anonymized data retained for 12 months
  • Opt-Out: You can opt out of PostHog tracking by:
    • Disabling analytics cookies in your browser settings
    • Emailing support@justmuse.app with “Analytics Opt-Out” in the subject line
    • Using the PostHog opt-out cookie: PostHog_Opt_Out_Token=true
  • Privacy: PostHog processes data under Data Processing Agreements; see our Privacy Policy for details

C. Functional Preference Cookies

Muse Preference Storage (LocalStorage)

  • Data Stored: muse_theme (light/dark mode), muse_language (UI language), muse_sidebar_state (sidebar collapsed/expanded), muse_last_tab (last active tab)
  • Purpose: Remember your UI preferences to customize your experience on return visits
  • Provider: Muse AI
  • Retention: Until manually cleared from browser storage
  • Disabling Impact: UI preferences reset to defaults on each visit

4. Third-Party Cookies & Social Media Integration

A. Instagram Cookies

When you connect your Instagram account or view Instagram embeds:

  • Provider: Meta Platforms, Inc.
  • Cookies Set: datr, wd, ig_nrcb_cl, fbp_nmt, ig_did
  • Purpose: Authenticate Instagram account connection, track Instagram sharing/embedding
  • Retention: 30 days to 2 years (varies by cookie)
  • Your Control: Instagram account settings, browser cookie management, or disconnect Muse from Instagram in Settings > Integrations

B. YouTube Cookies

When you connect your YouTube account or view YouTube video previews:

  • Provider: Google/YouTube
  • Cookies Set: VISITOR_INFO1_LIVE, YSC, CONSENT, NID
  • Purpose: Authenticate YouTube account, track video playback metrics, serve video player functionality
  • Retention: 6 months to 2 years (varies by cookie)
  • Your Control: YouTube account settings, Google Account privacy controls, or disconnect Muse from YouTube in Settings > Integrations

C. Threads Integration Cookies

When you connect your Threads account:

  • Provider: Meta Platforms, Inc.
  • Purpose: Authenticate Threads account, enable content posting/scheduling (future feature)
  • Retention: Varies by Meta policies
  • Your Control: Threads account settings or disconnect Muse from Threads in Settings > Integrations

D. Google reCAPTCHA

If you encounter a CAPTCHA during sign-up or high-risk activities:

  • Provider: Google (US-based)
  • Cookies Set: rc::a, rc::c, rc::b, rc::hash
  • Purpose: Prevent bot abuse and fraud on sign-up/password reset forms
  • Retention: Session-based
  • Data: Google may process your IP address, user agent, and interaction data per Google's Privacy Policy
  • Opt-Out: Limited; reCAPTCHA is required for account security

5. How to Control Cookies

A. Browser-Level Cookie Management

You can control all cookies (except strictly necessary ones) through your browser settings:

Google Chrome:

  1. Click Menu (…) → Settings → Privacy and security → Cookies and other site data
  2. Choose: Allow all cookies / Block all cookies / Manage exceptions
  3. Under “Sites that can always use cookies,” add or remove justmuse.app

Apple Safari:

  1. Preferences → Privacy tab
  2. Choose: “Always Block” / “Block from third parties only” / “Allow”
  3. Clear cookies manually: Develop → Empty Caches

Mozilla Firefox:

  1. Settings → Privacy & Security → Cookies and Site Data
  2. Choose: Accept all / Reject all / Manage exceptions
  3. Click “Manage Exceptions” to add/remove justmuse.app

Microsoft Edge:

  1. Settings → Privacy, search, and services → Cookies and other site data
  2. Choose: Allow all cookies / Block all in InPrivate / Manage exceptions

Note: Blocking strictly necessary cookies will impact your ability to log in and use core platform features.

B. Disabling Analytics & Functional Cookies

To opt out of optional analytics tracking without disabling essential cookies:

Option 1 — Email Opt-Out:

  • Email support@justmuse.app with “Analytics Opt-Out” in the subject line
  • We will add you to our opt-out list and disable PostHog tracking on your account

Option 2 — PostHog Direct Opt-Out:

Option 3 — Local Storage Clearing:

  • Open Developer Tools (F12 or right-click → Inspect)
  • Go to Application → Local Storage → justmuse.app
  • Delete preference keys (muse_theme, muse_language, etc.)

C. Do Not Track (DNT) Signals

If your browser sends a “Do Not Track” signal, we will honor it for analytics cookies. However, strictly necessary cookies cannot be disabled as they are required for account security and platform functionality.


6. Regional Compliance & Cookie Consent

A. European Union & United Kingdom (GDPR)

Under GDPR, cookies are considered personal data. We comply as follows:

  • Consent Mechanism: On first visit, you will see a cookie consent banner asking permission for optional analytics and functional cookies
  • Consent Types:
    • Accept All: Enables strictly necessary, performance, and functional cookies
    • Reject All (except essential): Disables optional cookies; only strictly necessary cookies remain active
    • Manage Preferences: Granular control per cookie category
  • Consent Storage: Your choice is stored in a cookie (muse_cookie_consent) that persists for 365 days
  • Withdrawal: You can change your consent choices at any time via Settings > Privacy > Cookie Preferences or by clicking “Cookie Settings” in the website footer
  • Legal Basis: Strictly necessary cookies are justified by contractual necessity (account access); optional cookies require your explicit consent

B. California (CCPA / CPRA)

California residents have the right to:

  • Know what cookies we use and their purposes
  • Opt out of cookies used for cross-context behavioral advertising (we do not engage in this)
  • Delete cookies associated with your account

We do not sell or share cookie data for behavioral advertising. Optional analytics cookies are used solely to improve the Service.

C. India (DPDP Act 2023)

Under DPDP Act, we are transparent about cookie usage and retention. Cookies that process personal data require:

  • Clear notification of use (this policy)
  • Your consent for optional cookies
  • Secure retention and processing

Users can request cookie data deletion via support@justmuse.app.


7. Cookie Retention & Data Lifecycle

Cookie TypeRetention PeriodDeletion Method
Session Authentication24 hours to 30 daysAutomatic on logout or browser close
Strictly Necessary FunctionalSession-based to 30 daysAutomatic; manual deletion via browser settings
PostHog Analytics90 days (active), 12 months (anonymized)Automatic purge; manual opt-out available
UI Preferences (LocalStorage)Until manual deletionManual deletion via browser Dev Tools or Settings
Third-Party (Instagram/YouTube)30 days to 2 yearsControlled by third-party platform; manual deletion via browser

8. Security & Data Protection

A. Encryption in Transit

All cookies are transmitted via secure HTTPS (TLS 1.3) connections. Cookies marked Secure are only transmitted over encrypted HTTPS connections.

B. HttpOnly Flag

Session and authentication cookies use the HttpOnly flag, meaning they cannot be accessed by JavaScript code, protecting against XSS (cross-site scripting) attacks.

C. SameSite Attribute

Cookies use SameSite=Strict or SameSite=Lax to prevent CSRF (cross-site request forgery) attacks.


9. Updates to This Cookie Policy

We may update this Cookie Policy periodically to reflect:

  • New cookies or tracking technologies we introduce
  • Changes in third-party integrations
  • Regulatory updates (GDPR, CCPA, DPDP Act changes)
  • Improvements to privacy practices

Material changes will be communicated via email or a prominent banner on justmuse.app. Continued use of the Service after updates constitutes acceptance of the revised policy.


10. Questions & Contact

For questions about cookies, tracking technologies, or to request cookie data deletion, please contact:

Muse AI Cookie Support

  • Email: support@justmuse.app
  • Subject Line: “Cookie Policy Question” or “Analytics Opt-Out”
  • Response Time: 5-7 business days

For Privacy-Related Cookie Questions:


11. Related Policies

This Cookie Policy is part of our broader privacy framework:


Effective as of August 5, 2026. Last updated August 5, 2026.

By using justmuse.app, you consent to our use of cookies as described in this policy.