Cookie Policy
Last Updated: August 5, 2026
This Cookie Policy explains how Muse AI (“Muse,” “we,” or “us”) uses cookies, web beacons, pixels, and similar tracking technologies when you access https://justmuse.app (the “Service”).
1. What Are Cookies & Tracking Technologies?
A. Cookies
Cookies are small text files stored on your browser or device by web servers. They allow websites to remember your preferences, session state, security information, and behavior over time.
Types of Cookies by Lifespan:
- Session Cookies: Deleted automatically when you close your browser
- Persistent Cookies: Stored on your device until manually deleted or they reach their expiration date
B. Similar Technologies
Beyond cookies, we also use:
- Web Beacons: Tiny transparent pixels embedded in web pages or emails to track views and clicks
- Local Storage & SessionStorage: Browser storage mechanisms that persist user preferences and state
- Pixels & Tags: Code snippets that track user interactions and page performance
2. Categories of Cookies We Use
| Category | Purpose | Essential / Optional | Provider | Retention |
|---|---|---|---|---|
| Strictly Necessary (Functional) | Session authentication, CSRF protection, security state, account access control | Essential (cannot be disabled) | Clerk, Vercel | Session-based (24 hours to 30 days) |
| Performance & Analytics | Session duration, page load times, feature usage, error tracking, user behavior analysis | Optional | PostHog | 90 days (active), 12 months (anonymized) |
| Functional Preferences | Dark mode toggle, UI language preference, sidebar state, saved filters | Optional | Muse Local Storage | Until manually cleared |
| Third-Party Social | Authentication with Instagram/YouTube/Threads, sharing functionality | Optional* | Instagram, YouTube, Google | Varies by platform (see Section 4) |
*Required if you choose to connect social media accounts
3. Detailed Cookie Descriptions
A. Strictly Necessary Cookies
Clerk Authentication Cookies
- Cookie Names:
__session,__sessionId,iss,sub,aud,exp,iat - Purpose: Authenticate your identity, maintain secure session state, prevent unauthorized access
- Provider: Clerk (US-based authentication service)
- Retention: 24 hours to 30 days depending on session activity
- Disabling Impact: You will be unable to log in or access your account
Vercel Cookies
- Cookie Names:
__Host-next-auth.csrf-token,__Secure-next-auth.callback-url - Purpose: CSRF (Cross-Site Request Forgery) protection, secure routing between edge nodes
- Provider: Vercel (US-based hosting infrastructure)
- Retention: Session-based (deleted on browser close)
- Disabling Impact: Security features disabled; increased risk of unauthorized actions
Muse Session Cookies
- Cookie Names:
muse_session,csrf_token,device_fingerprint - Purpose: Track your active session, validate CSRF tokens, identify your device for security
- Provider: Muse AI
- Retention: 24 hours
- Disabling Impact: Frequent re-authentication required; some platform features may not function
B. Performance & Analytics Cookies
PostHog Analytics
- Cookie Names:
ph_phc_*,PostHogSessionID,PostHog_Opt_Out_Token - Purpose: Track page loads, feature interactions, session duration, user flows, error rates
- Provider: PostHog (EU-based analytics platform)
- Data Collected: Anonymized event names, session IDs, timestamps, page URLs (no PII by default)
- Retention: 90 days in active storage; anonymized data retained for 12 months
- Opt-Out: You can opt out of PostHog tracking by:
- Disabling analytics cookies in your browser settings
- Emailing support@justmuse.app with “Analytics Opt-Out” in the subject line
- Using the PostHog opt-out cookie:
PostHog_Opt_Out_Token=true
- Privacy: PostHog processes data under Data Processing Agreements; see our Privacy Policy for details
C. Functional Preference Cookies
Muse Preference Storage (LocalStorage)
- Data Stored:
muse_theme(light/dark mode),muse_language(UI language),muse_sidebar_state(sidebar collapsed/expanded),muse_last_tab(last active tab) - Purpose: Remember your UI preferences to customize your experience on return visits
- Provider: Muse AI
- Retention: Until manually cleared from browser storage
- Disabling Impact: UI preferences reset to defaults on each visit
4. Third-Party Cookies & Social Media Integration
A. Instagram Cookies
When you connect your Instagram account or view Instagram embeds:
- Provider: Meta Platforms, Inc.
- Cookies Set:
datr,wd,ig_nrcb_cl,fbp_nmt,ig_did - Purpose: Authenticate Instagram account connection, track Instagram sharing/embedding
- Retention: 30 days to 2 years (varies by cookie)
- Your Control: Instagram account settings, browser cookie management, or disconnect Muse from Instagram in Settings > Integrations
B. YouTube Cookies
When you connect your YouTube account or view YouTube video previews:
- Provider: Google/YouTube
- Cookies Set:
VISITOR_INFO1_LIVE,YSC,CONSENT,NID - Purpose: Authenticate YouTube account, track video playback metrics, serve video player functionality
- Retention: 6 months to 2 years (varies by cookie)
- Your Control: YouTube account settings, Google Account privacy controls, or disconnect Muse from YouTube in Settings > Integrations
C. Threads Integration Cookies
When you connect your Threads account:
- Provider: Meta Platforms, Inc.
- Purpose: Authenticate Threads account, enable content posting/scheduling (future feature)
- Retention: Varies by Meta policies
- Your Control: Threads account settings or disconnect Muse from Threads in Settings > Integrations
D. Google reCAPTCHA
If you encounter a CAPTCHA during sign-up or high-risk activities:
- Provider: Google (US-based)
- Cookies Set:
rc::a,rc::c,rc::b,rc::hash - Purpose: Prevent bot abuse and fraud on sign-up/password reset forms
- Retention: Session-based
- Data: Google may process your IP address, user agent, and interaction data per Google's Privacy Policy
- Opt-Out: Limited; reCAPTCHA is required for account security
5. How to Control Cookies
A. Browser-Level Cookie Management
You can control all cookies (except strictly necessary ones) through your browser settings:
Google Chrome:
- Click Menu (…) → Settings → Privacy and security → Cookies and other site data
- Choose: Allow all cookies / Block all cookies / Manage exceptions
- Under “Sites that can always use cookies,” add or remove justmuse.app
Apple Safari:
- Preferences → Privacy tab
- Choose: “Always Block” / “Block from third parties only” / “Allow”
- Clear cookies manually: Develop → Empty Caches
Mozilla Firefox:
- Settings → Privacy & Security → Cookies and Site Data
- Choose: Accept all / Reject all / Manage exceptions
- Click “Manage Exceptions” to add/remove justmuse.app
Microsoft Edge:
- Settings → Privacy, search, and services → Cookies and other site data
- Choose: Allow all cookies / Block all in InPrivate / Manage exceptions
Note: Blocking strictly necessary cookies will impact your ability to log in and use core platform features.
B. Disabling Analytics & Functional Cookies
To opt out of optional analytics tracking without disabling essential cookies:
Option 1 — Email Opt-Out:
- Email support@justmuse.app with “Analytics Opt-Out” in the subject line
- We will add you to our opt-out list and disable PostHog tracking on your account
Option 2 — PostHog Direct Opt-Out:
- Visit: https://posthog.com/docs/advanced-ways-to-integrate/proxy
- Or set cookie:
PostHog_Opt_Out_Token=truein your browser
Option 3 — Local Storage Clearing:
- Open Developer Tools (F12 or right-click → Inspect)
- Go to Application → Local Storage → justmuse.app
- Delete preference keys (muse_theme, muse_language, etc.)
C. Do Not Track (DNT) Signals
If your browser sends a “Do Not Track” signal, we will honor it for analytics cookies. However, strictly necessary cookies cannot be disabled as they are required for account security and platform functionality.
6. Regional Compliance & Cookie Consent
A. European Union & United Kingdom (GDPR)
Under GDPR, cookies are considered personal data. We comply as follows:
- Consent Mechanism: On first visit, you will see a cookie consent banner asking permission for optional analytics and functional cookies
- Consent Types:
- Accept All: Enables strictly necessary, performance, and functional cookies
- Reject All (except essential): Disables optional cookies; only strictly necessary cookies remain active
- Manage Preferences: Granular control per cookie category
- Consent Storage: Your choice is stored in a cookie (
muse_cookie_consent) that persists for 365 days - Withdrawal: You can change your consent choices at any time via Settings > Privacy > Cookie Preferences or by clicking “Cookie Settings” in the website footer
- Legal Basis: Strictly necessary cookies are justified by contractual necessity (account access); optional cookies require your explicit consent
B. California (CCPA / CPRA)
California residents have the right to:
- Know what cookies we use and their purposes
- Opt out of cookies used for cross-context behavioral advertising (we do not engage in this)
- Delete cookies associated with your account
We do not sell or share cookie data for behavioral advertising. Optional analytics cookies are used solely to improve the Service.
C. India (DPDP Act 2023)
Under DPDP Act, we are transparent about cookie usage and retention. Cookies that process personal data require:
- Clear notification of use (this policy)
- Your consent for optional cookies
- Secure retention and processing
Users can request cookie data deletion via support@justmuse.app.
7. Cookie Retention & Data Lifecycle
| Cookie Type | Retention Period | Deletion Method |
|---|---|---|
| Session Authentication | 24 hours to 30 days | Automatic on logout or browser close |
| Strictly Necessary Functional | Session-based to 30 days | Automatic; manual deletion via browser settings |
| PostHog Analytics | 90 days (active), 12 months (anonymized) | Automatic purge; manual opt-out available |
| UI Preferences (LocalStorage) | Until manual deletion | Manual deletion via browser Dev Tools or Settings |
| Third-Party (Instagram/YouTube) | 30 days to 2 years | Controlled by third-party platform; manual deletion via browser |
8. Security & Data Protection
A. Encryption in Transit
All cookies are transmitted via secure HTTPS (TLS 1.3) connections. Cookies marked Secure are only transmitted over encrypted HTTPS connections.
B. HttpOnly Flag
Session and authentication cookies use the HttpOnly flag, meaning they cannot be accessed by JavaScript code, protecting against XSS (cross-site scripting) attacks.
C. SameSite Attribute
Cookies use SameSite=Strict or SameSite=Lax to prevent CSRF (cross-site request forgery) attacks.
9. Updates to This Cookie Policy
We may update this Cookie Policy periodically to reflect:
- New cookies or tracking technologies we introduce
- Changes in third-party integrations
- Regulatory updates (GDPR, CCPA, DPDP Act changes)
- Improvements to privacy practices
Material changes will be communicated via email or a prominent banner on justmuse.app. Continued use of the Service after updates constitutes acceptance of the revised policy.
10. Questions & Contact
For questions about cookies, tracking technologies, or to request cookie data deletion, please contact:
Muse AI Cookie Support
- Email: support@justmuse.app
- Subject Line: “Cookie Policy Question” or “Analytics Opt-Out”
- Response Time: 5-7 business days
For Privacy-Related Cookie Questions:
- See our full Privacy Policy at https://justmuse.app/privacy
- See our Master Terms of Service at https://justmuse.app/terms
11. Related Policies
This Cookie Policy is part of our broader privacy framework:
- Privacy Policy: https://justmuse.app/privacy (how we collect, use, and protect data)
- Master Terms of Service: https://justmuse.app/terms (account usage, liability, dispute resolution)
Effective as of August 5, 2026. Last updated August 5, 2026.
By using justmuse.app, you consent to our use of cookies as described in this policy.