Cookie Policy

Last updated: 25 August 2026

This Cookie Policy explains how Mammouth AI uses cookies and similar technologies to operate and secure mammouth.ai.

1. What cookies are

Cookies are small files that a website stores in your browser. They can keep you signed in, remember a language, or save a preference. Similar technologies include localStorage, the browser Cache API, scripts, embedded frames, and telemetry requests.

2. How we use cookies and similar technologies

At Mammouth AI, we use cookies and similar technologies to:

  • keep you signed in and protect authenticated sessions;
  • support features that you request, such as MCP connector authorization;
  • remember your interface language and limited interface preferences;
  • protect the service against automated or malicious traffic through Cloudflare; and
  • support service monitoring and third-party features when you use them.

We also use localStorage, a browser storage area, for local application state. This includes keeping unfinished message drafts, remembering selected category lines and layout preferences, storing PWA installation status, preserving display preferences, and temporarily disabling the unique router after a recent failure. These values stay in your browser and are not used to track your browsing or create marketing profiles. A draft is sent to Mammouth only when you submit it.

Mammouth AI does not use tracking cookies for marketing or advertising. We do not use cookies to follow your activity across websites or build marketing profiles.

3. Cookie categories we use

Strictly necessary cookies

These cookies are needed to provide a service you request or to keep mammouth.ai secure and operational. They are set without consent because the service cannot work as intended without them.

Cookie nameProviderPurposeCategoryDurationFirst/third partySeparate cookie preference
nuxt-sessionMammouth AIKeeps you signed in and protects your authenticated session.Strictly necessary30 daysFirst-partyNo
gcp_tokenMammouth AIUsed to authenticate to our backend service to analyze documents when at least one document is added to a prompt.Strictly necessary for the requested featureUp to 30 daysFirst-partyNo, when it is needed for the requested feature
cf_clearanceCloudflareRemembers a successful Cloudflare security check so you can access the service.Strictly necessaryControlled by Cloudflare; approximately one yearMammouth cookie domain; Cloudflare providerNo, because it protects security and access
mcp_oauth_stateMammouth AILinks an MCP authorization request to your browser and protects that request.Strictly necessary during MCP OAuthUp to 10 minutesFirst-partyNo, because it is used only when you start this authorization flow

Functional cookies

These cookies remember choices and support convenience features. They are functional cookies, not marketing or advertising cookies.

When you start organization SSO, Mammouth's Keycloak instance may set the following cookies on sso.mammouth.ai. They are strictly necessary for the SSO flow.

Cookie nameProviderPurposeCategoryDurationFirst/third partySeparate cookie preference
i18n_redirectedMammouth AI / nuxtjs/i18nRemembers your interface language.FunctionalOne yearFirst-partyNo
g_stateMammouth AIStores Google Identity Services sign-in state.Functional during Google sign-in6 monthsFirst-partyNo
PWA_BANNER_DISMISSEDMammouth AIRemembers that you dismissed the PWA installation or help prompt.FunctionalUsually three to 120 days; up to one year from the account help linkFirst-partyNo
PWA_BANNER_DISMISSED_COUNTMammouth AICounts PWA prompt dismissals so we can limit repeated prompts.FunctionalOne yearFirst-partyNo
QUOTA_BANNER_DISMISSEDMammouth AIRemembers that you dismissed a quota notification.FunctionalTwo daysFirst-partyNo
AUTH_SESSION_IDMammouth AI / KeycloakIdentifies your temporary SSO authentication session.Strictly necessary during SSOSessionFirst-party, Mammouth-operated SSO domainNo, because you requested SSO
KC_AUTH_SESSION_HASHMammouth AI / KeycloakProtects your temporary SSO authentication session.Strictly necessary during SSOAbout 60 secondsFirst-party, Mammouth-operated SSO domainNo, because you requested SSO
KC_RESTARTMammouth AI / KeycloakPreserves encrypted state if your SSO authentication needs to restart.Strictly necessary during SSOSessionFirst-party, Mammouth-operated SSO domainNo, because you requested SSO

Analytics and service monitoring

Mammouth AI does not use analytics cookies. We use the following non-cookie technologies to understand whether the service is working and to diagnose errors and performance issues:

  • Cloudflare Web Analytics beacon;
  • Grafana Faro monitoring for errors, console warnings, requests, traces, browser data, and page data.

Some diagnostic events may be associated with your account or conversation after you sign in so that we can investigate service issues. We do not use this monitoring for marketing, only to improve our services.

Marketing and advertising cookies

Mammouth AI does not use marketing or advertising cookies, tracking pixels, or marketing scripts. We do not use cookies to track your browsing activity for marketing purposes.

External services

  • Google Identity Services could optionally be used for web login. For that purpose, a g_state cookie is set on the Mammouth domain to manage Google sign-in state. During Google Sign-in, Google may set cookies on accounts.google.com, .google.com, .google.fr, and .youtube.com, including __Host-GAPS, OTZ, and other provider-controlled cookies. Be aware that Google documents that these cookies may support authentication, security, preferences, analytics, advertising, and personalization depending on the service and your settings.
  • Our landing page displays thumbnails fetched from YouTube and open the video on YouTube in a new tab when you select it. Mammouth does not embed YouTube videos in an iframe. Consequently, no cookie from Youtube are set in your browser.
  • Stripe Checkout is hosted externally. Mammouth redirects you to Stripe rather than loading a Stripe payment script on mammouth.ai.

4. Managing cookies, policy changes, and contact

Managing cookies

This Cookie Policy is the only cookie information we provide. We use only strictly necessary and functional cookies on mammouth.ai, and we do not use optional marketing or advertising cookies.

You can delete or block cookies through your browser settings, but doing so may sign you out, prevent requested OAuth or payment flows, affect security checks, or reset interface preferences. Cookies set by external providers on their own websites are managed by those providers.

Changes to this policy

We may update this Cookie Policy when our technologies, providers, or legal obligations change. The Last updated date identifies the latest version.

Contact details

For questions about this Cookie Policy or our use of cookies, contact Mammouth AI SAS at [email protected].

© 2026 Mammouth AI. All rights reserved.

version 38c24ed