Four cookies, all of them necessary, none of them advertising. Here is each one and what it does.
Effective 25 July 2026.
| Cookie | What it does | Lasts |
|---|---|---|
better-auth.session_token | Keeps you signed in. Without it every page would ask for your password again. | Until the session expires or you sign out |
better-auth.state, better-auth.pkce | Short-lived values that complete a sign-in or an OAuth authorisation safely, and stop someone else finishing it for you. | Minutes, deleted once the sign-in completes |
mm_ws | Remembers which workspace you were last working in, so the dashboard opens there. | 1 year |
mm_ref | Records which affiliate link you arrived on, so the affiliate is credited if you sign up later. Set only if you arrive on a link containing a referral code. | 90 days |
MCPmailer can add an invisible image to an outgoing message to count whether it was opened. That is a tracking pixel in someone's email, not a cookie on this website, and it sets nothing in your browser.
It is off by default and is switched on per message by the customer sending it. If you receive tracked mail, blocking remote images in your mail client stops it, and the sender, not us, decides whether to use it. See the Privacy Policy for what is recorded.
You can delete or block cookies in your browser settings. Blocking ours will sign you out and stop the dashboard working, because the sign-in itself depends on them. Blocking only the referral cookie is harmless: an affiliate simply will not be credited.
Questions about anything on this page: use the contact form.