Cookie Policy
Last updated: September 11, 2026
What mythos stores on your device, what each item does, and how to manage it. For how we handle personal data more broadly, see the Privacy Policy.
The short version
The mythos.new app sets only the cookies and browser storage it needs to run: keeping you signed in, protecting sign-in and account-connection flows from forgery, and remembering essential preferences. A project published through Mythos can also set one first-party, host-only 30-minute session cookie when its owner leaves Visitor analytics enabled. We set no advertising cookies, third-party analytics cookies, or marketing tracking pixels.
Every item we store on your device is listed on this page, with its lifetime and what it is for.
Cookies are small text files a website stores on your device so it can remember things between requests — for example, that you are signed in. Cookies can be first-party (set by the site you are visiting) or third-party (set by another domain whose content is embedded in the page). Similar technologies such as localStorage, sessionStorage, and IndexedDB keep data in your browser without sending it to the server on every request. On this page “cookies” covers all of them, and the tables below list each type separately.
Cookies we set
The mythos.new app cookies in the first table are strictly necessary for sign-in, security, and essential preferences, so they cannot be switched off. The second table is separate: its analytics cookie is set only on a live published site whose owner has Visitor analytics enabled. It is never set in Preview or while a project is unpublished.
Cookies set by the mythos.new app
Cookie set on analytics-enabled published sites
mythos.new is served through Cloudflare, our CDN and security provider. Cloudflare may set its own strictly-necessary security cookies (such as __cf_bm) to distinguish humans from automated traffic; those are governed by Cloudflare’s privacy policy.
Browser storage we use
Beyond cookies, mythos uses localStorage for durable recovery and preferences, sessionStorage for tab-scoped recovery, and IndexedDB for attachment bodies that are too large for key-value storage. Names containing angle-bracket placeholders describe a key family rather than a literal key; for example, one owner-scoped key can be created for each account.
A record can reach its stated logical expiry and stop being read before the browser physically deletes its bytes. Where cleanup is best-effort, the duration row says so. You can remove all remaining records at any time by clearing site data for mythos.new.
localStorage keys set by mythos
sessionStorage keys set by mythos
IndexedDB storage used by mythos
Analytics, advertising, and error monitoring
We run no third-party analytics (no Google Analytics, no session recording) and no advertising technology of any kind. Three bounded telemetry paths exist:
- Performance and error beacons — anonymous reports (page timing, a JavaScript error) posted to our own endpoints to keep the product fast and working.
- Error monitoring (Sentry) — when something breaks, a technical error report is sent through our own domain to Sentry (EU) so we can fix it. The Sentry browser SDK sets no cookies here, session replay is disabled, and reports do not include personal data by default.
- Published-site Visitor analytics — only on a live published project whose owner leaves the setting enabled. A first-party script uses the
mythos_analytics_sessioncookie above to group page views into a 30-minute visit. It records only a query-free pathname, referrer hostname or Direct, coarse device class, and country code. It does not retain IP, full user-agent, full referrer, query parameters, a fingerprint, or a cross-visit profile.
Managing cookies
The Manage cookie preferences button above controls the mythos.new app, where the listed categories are informational because those app cookies are strictly necessary. It does not control a different published hostname. Project owners can stop new visitor events immediately under More → Project settings → Publishing → Visitor analytics. Visitors can also block or delete the analytics cookie in their browser; the site owner remains responsible for any notice or consent required by local law.
Your browser also lets you inspect, delete, or block cookies for any site. Clearing mythos.new app cookies signs you out. Clearing a published site’s analytics cookie starts a new anonymous visit if you later return while analytics remains enabled. Cookie settings are per hostname, device, and browser.
Because we do not sell or share personal data for advertising, browsers sending a Global Privacy Control signal are already getting the behaviour it asks for.
Changes and contact
If we add a cookie or storage key, change a lifetime, or introduce a third party that can set cookies, we will update this page and the date shown above.
Questions about our use of cookies: privacy@mythos.new.