M3LYCookies & storage

Cookies & device storage

No advertising tracker hidden behind a banner.

This notice describes the browser and Android storage used by the current private beta. Last updated 2 September 2026.

Web session

Authentication storage is necessary.

After successful browser authentication, M3LY uses a secure session mechanism so the browser can stay signed in. The current design uses a Secure, HttpOnly, SameSite session cookie and server-side token hash/state. This storage is used for account access and security, not advertising.

Preference storage

Theme choice can stay on your device.

The Web client may store a local theme/display preference in browser storage after you choose it. This preference is not used to profile you across sites.

Android

Local app state is separated from browser auth.

The Android app stores its M3LY identity/device credential locally using platform-protected storage. Android backup is disabled for the current app and device credential material is kept in no-backup storage. The app's local WebView rejects cookies and blocks external network resources; account entry opens the canonical m3ly.me origin in the system browser.

No ad/analytics SDK

No non-essential advertising storage today.

The current Web and Android release source does not include advertising or behavioural-analytics SDKs. If M3LY later introduces non-essential storage, this notice and the consent mechanism will be updated before that storage is used where consent is required.

Your control

Clear browser data or revoke sessions.

You can clear site data using your browser controls. Persistent-account users can also review/revoke sessions and devices through M3LY Settings. Clearing browser data may sign you out and can remove local preferences; it does not by itself delete the M3LY account. For deletion, use Account deletion.