Cookie Policy
1. What we use
Webmux uses strictly necessary cookies only. No analytics, no tracking, no advertising. The cookies below are required for the service to function and are exempt from prior-consent requirements under the ePrivacy Directive.
2. The cookies
| Name | Purpose | Lifetime | Scope |
|---|---|---|---|
__Secure-webmux_access | JWT carrying your authenticated session. Required for every authenticated API call. | 15 minutes (auto-refreshed via the refresh cookie below) | .webmux.app · HttpOnly · Secure · SameSite=Lax |
__Secure-webmux_refresh | Long-lived rotation token used to mint a fresh access token without re-auth. | 30 days | .webmux.app · HttpOnly · Secure · SameSite=Lax |
__Secure-webmux_session_marker | Non-HttpOnly signal so the SPA knows whether to render the signed-in UI without making an API call. No identity carried (value is always 1). | 30 days (mirrors refresh_token) | .webmux.app · Secure · SameSite=Lax |
__Secure-webmux_cid | Per-browser identity used to gate access to your local server (browser approval flow). | 1 year | .webmux.app · HttpOnly · Secure · SameSite=Lax |
__Host-webmux_demo_sid | Set on demo.webmux.app when you open the playable demo. Holds 128 random bits naming the temporary container allocated to you, plus the time it was issued, and nothing else — no account, no identifier we can link to a person. The timestamp is what ends the visit; it dates the cookie, never you. | 10 minutes | demo.webmux.app · HttpOnly · Secure · SameSite=Lax |
__Host-webmux_lan_session | Local HMAC cookie used when you reach Webmux over LAN with the LAN auth feature enabled. | 7 days | Your local server only · HttpOnly · SameSite=Lax · Secure and the __Host- prefix over HTTPS (a plain-HTTP LAN server sets webmux_lan_session without them, since a browser would reject the prefixed form) |
Your own Webmux server may set further cookies on its own address to authenticate you to itself. Those never reach us. The complete inventory, including the short-lived cookies used during a sign-in round-trip, is maintained alongside the code.
3. Analytics — what runs, and what it is not
We use Cloudflare Web Analytics on this site and on the dashboard. It measures page views and load performance in aggregate, and it is worth being precise about what that does and does not involve: it sets no cookie, assigns no persistent identifier, does not fingerprint your browser and does not follow you to any other website. That is why it appears in this section rather than in the table above — there is no cookie to list.
What we do not use:
- No advertising cookies.
- No third-party tracking cookies.
- No marketing pixels.
- No fingerprinting (cookie or otherwise) for cross-site tracking.
- No profiling and no automated decision-making about you.
4. Third-party cookies during checkout
If you start a Stripe checkout flow, Stripe may set cookies on its own domain (checkout.stripe.com) to process the transaction. These cookies are governed by Stripe's cookie policy, not this one.
5. How to control cookies
Strictly-necessary cookies cannot be disabled without breaking authentication. To stop them being set, sign out (which clears the session cookies) and refrain from signing back in. You can also clear all cookies for .webmux.app in your browser settings at any time.
6. Changes to this policy
If we ever introduce a non-strictly-necessary cookie, we will (a) update this page, (b) bump the version, and (c) prompt you for consent before setting it.