Cookie Policy
Last updated: 25 August 2026
This Cookie Policy explains how Mammouth AI uses cookies and similar technologies to operate and secure mammouth.ai.
1. What cookies are
Cookies are small files that a website stores in your browser. They can keep you signed in, remember a language, or save a preference. Similar technologies include localStorage, the browser Cache API, scripts, embedded frames, and telemetry requests.
2. How we use cookies and similar technologies
At Mammouth AI, we use cookies and similar technologies to:
- keep you signed in and protect authenticated sessions;
- support features that you request, such as MCP connector authorization;
- remember your interface language and limited interface preferences;
- protect the service against automated or malicious traffic through Cloudflare; and
- support service monitoring and third-party features when you use them.
We also use localStorage, a browser storage area, for local application state. This includes keeping unfinished message drafts, remembering selected category lines and layout preferences, storing PWA installation status, preserving display preferences, and temporarily disabling the unique router after a recent failure. These values stay in your browser and are not used to track your browsing or create marketing profiles. A draft is sent to Mammouth only when you submit it.
Mammouth AI does not use tracking cookies for marketing or advertising. We do not use cookies to follow your activity across websites or build marketing profiles.
3. Cookie categories we use
Strictly necessary cookies
These cookies are needed to provide a service you request or to keep mammouth.ai secure and operational. They are set without consent because the service cannot work as intended without them.
| Cookie name | Provider | Purpose | Category | Duration | First/third party | Separate cookie preference |
|---|---|---|---|---|---|---|
| nuxt-session | Mammouth AI | Keeps you signed in and protects your authenticated session. | Strictly necessary | 30 days | First-party | No |
| gcp_token | Mammouth AI | Used to authenticate to our backend service to analyze documents when at least one document is added to a prompt. | Strictly necessary for the requested feature | Up to 30 days | First-party | No, when it is needed for the requested feature |
| cf_clearance | Cloudflare | Remembers a successful Cloudflare security check so you can access the service. | Strictly necessary | Controlled by Cloudflare; approximately one year | Mammouth cookie domain; Cloudflare provider | No, because it protects security and access |
| mcp_oauth_state | Mammouth AI | Links an MCP authorization request to your browser and protects that request. | Strictly necessary during MCP OAuth | Up to 10 minutes | First-party | No, because it is used only when you start this authorization flow |
Functional cookies
These cookies remember choices and support convenience features. They are functional cookies, not marketing or advertising cookies.
When you start organization SSO, Mammouth's Keycloak instance may set the following cookies on sso.mammouth.ai. They are strictly necessary for the SSO flow.
| Cookie name | Provider | Purpose | Category | Duration | First/third party | Separate cookie preference |
|---|---|---|---|---|---|---|
| i18n_redirected | Mammouth AI / nuxtjs/i18n | Remembers your interface language. | Functional | One year | First-party | No |
| g_state | Mammouth AI | Stores Google Identity Services sign-in state. | Functional during Google sign-in | 6 months | First-party | No |
| PWA_BANNER_DISMISSED | Mammouth AI | Remembers that you dismissed the PWA installation or help prompt. | Functional | Usually three to 120 days; up to one year from the account help link | First-party | No |
| PWA_BANNER_DISMISSED_COUNT | Mammouth AI | Counts PWA prompt dismissals so we can limit repeated prompts. | Functional | One year | First-party | No |
| QUOTA_BANNER_DISMISSED | Mammouth AI | Remembers that you dismissed a quota notification. | Functional | Two days | First-party | No |
| AUTH_SESSION_ID | Mammouth AI / Keycloak | Identifies your temporary SSO authentication session. | Strictly necessary during SSO | Session | First-party, Mammouth-operated SSO domain | No, because you requested SSO |
| KC_AUTH_SESSION_HASH | Mammouth AI / Keycloak | Protects your temporary SSO authentication session. | Strictly necessary during SSO | About 60 seconds | First-party, Mammouth-operated SSO domain | No, because you requested SSO |
| KC_RESTART | Mammouth AI / Keycloak | Preserves encrypted state if your SSO authentication needs to restart. | Strictly necessary during SSO | Session | First-party, Mammouth-operated SSO domain | No, because you requested SSO |
Analytics and service monitoring
Mammouth AI does not use analytics cookies. We use the following non-cookie technologies to understand whether the service is working and to diagnose errors and performance issues:
- Cloudflare Web Analytics beacon;
- Grafana Faro monitoring for errors, console warnings, requests, traces, browser data, and page data.
Some diagnostic events may be associated with your account or conversation after you sign in so that we can investigate service issues. We do not use this monitoring for marketing, only to improve our services.
Marketing and advertising cookies
Mammouth AI does not use marketing or advertising cookies, tracking pixels, or marketing scripts. We do not use cookies to track your browsing activity for marketing purposes.
External services
- Google Identity Services could optionally be used for web login. For that purpose, a g_state cookie is set on the Mammouth domain to manage Google sign-in state. During Google Sign-in, Google may set cookies on accounts.google.com, .google.com, .google.fr, and .youtube.com, including __Host-GAPS, OTZ, and other provider-controlled cookies. Be aware that Google documents that these cookies may support authentication, security, preferences, analytics, advertising, and personalization depending on the service and your settings.
- Our landing page displays thumbnails fetched from YouTube and open the video on YouTube in a new tab when you select it. Mammouth does not embed YouTube videos in an iframe. Consequently, no cookie from Youtube are set in your browser.
- Stripe Checkout is hosted externally. Mammouth redirects you to Stripe rather than loading a Stripe payment script on mammouth.ai.
4. Managing cookies, policy changes, and contact
Managing cookies
This Cookie Policy is the only cookie information we provide. We use only strictly necessary and functional cookies on mammouth.ai, and we do not use optional marketing or advertising cookies.
You can delete or block cookies through your browser settings, but doing so may sign you out, prevent requested OAuth or payment flows, affect security checks, or reset interface preferences. Cookies set by external providers on their own websites are managed by those providers.
Changes to this policy
We may update this Cookie Policy when our technologies, providers, or legal obligations change. The Last updated date identifies the latest version.
Contact details
For questions about this Cookie Policy or our use of cookies, contact Mammouth AI SAS at [email protected].