Legal
Cookie Policy
Last updated September 2026
The short version. One cookie, and only once you sign in. Nothing on these pages sets a cookie — you can read the whole site without one. Chatting needs an account, and signing in to it sets mc_sess, which is what keeps you signed in; signing out deletes it. No analytics, no advertising, no ad network and no cross-site tracking, ever.
Retired in September 2026. The "Remember me on this device" checkbox and the mc_uid cookie it set are gone: chatting needs an account now, and the account remembers you instead. Nothing sets mc_uid any more; if your browser still holds one from before, it is inert and expires on its own, and you can clear it with your site data. The description below is kept for the record.
The one cookie, and how to refuse it
mc_uid holds a random identifier we generated. It is not derived from your device, your network or anything about you — it is a number whose only meaning is "this browser again".
- Was set only on the chat screen, and only after you pressed Remember me. Reading the home page, the room pages, the blog or these policies never set it.
- Lasted a year, was
HttpOnly(no script on the page could read it) andSameSite=Lax. - What it bought you: your nickname stayed reserved so nobody else could take it, and switching language or opening a second tab did not make you a new visitor.
- Refusing cost you nothing else. Pressing No thanks left every part of the chat working; your details simply stayed in that browser.
- It could be undone at any time with Forget me on the chat screen, which expired the cookie and deleted the record behind it. That button went with the checkbox: a record left over from before expires on its own, or write to us and we will delete it.
Because it was not needed to deliver the chat itself, this cookie was not "strictly necessary" under the ePrivacy rules, which is why it was never set until you said yes.
If you sign in: mc_sess
Creating an account or signing in sets a second cookie, mc_sess, holding a random session token. It is what keeps you signed in, it is HttpOnly andSameSite=Lax, and it lasts 30 days of inactivity. Only a hash of it is stored on our side, so the database cannot be used to impersonate you.
This one is strictly necessary: it is not possible to stay signed in without it, and you only get one by choosing to sign in. Signing out deletes it and the session behind it. Chatting needs an account — the privacy policy covers what one records.
Strictly necessary storage
One item, in your browser's local storage rather than a cookie, and never sent to our server:
mc_profile— the nickname and matching preferences you typed on the chat screen, so you do not have to retype them every visit. Your age is not in it; that comes from your account's birthdate. It stays on your device; the values are sent to the chat server only for the duration of a conversation, and nothing is written to a database.
mc_remember— the yes or no you gave the retired "Remember me" checkbox. Storing a refusal was the only way to honour it, and putting that record in the very thing you refused would have been absurd, so it lived here. Nothing writes it any more; clearing site data removes an old one.
Both are exempt from consent under the ePrivacy rules: they hold settings you entered yourself to get the service you asked for. Clearing site data in your browser removes them.
Analytics — none
We used to run Microsoft Clarity for heatmaps and session replays of the marketing pages, behind an opt-in banner. It was removed in September 2026: the script is gone, the banner went with it, and nothing has replaced it. No analytics, product-analytics or session-recording tool runs on this site.
If you accepted analytics before the removal, your browser may still be holding the_clck and _clsk cookies Clarity set on our domain. Nothing reads them any more, and rather than leave them to run out on their own — up to a year for _clck — the site now expires both on your next visit.
One honest caveat, unchanged by the removal: CLID was set onclarity.ms, Microsoft's own domain. Browser security rules mean no script of ours can delete a cookie belonging to another domain, so that one stays until it expires or you clear site data in your browser. It is inert — nothing on this site reads or sends it — but we would rather say so than pretend otherwise.
What we do not do
- No analytics, heatmaps or session recording, on any page.
- No advertising cookies, and no ad network of any kind.
- No cross-site or cross-device tracking, and no data brokers.
- No selling or sharing of personal data.
- No fingerprinting standing in for a cookie you declined.
- No cookie on any page except the chat screen, and none there until you sign in.
Your rights
If you are in the UK, EU or EEA, you have the right to access, correct, erase and port your personal data, and to object to processing. If you have no account we hold nothing about you at all. If you do, signing out deletes that session's record immediately; to delete the account itself, or for access, correction, portability or any objection, write to[email protected] and we will respond.