The short version
1What cookies are
Cookies are small text files that a website stores in your browser so it can remember information between visits, such as whether you are signed in. Similar technologies include your browser’s local storage and tracking pixels in email. This policy explains which of these Mailivy uses and why.
2Cookies on mailivy.com
Our website at mailivy.com sets no cookies of its own and loads no third-party analytics, advertising or social media scripts. Fonts and images are served from our own domain.
The website is delivered through Cloudflare, our hosting and security provider. If Cloudflare detects traffic that looks automated, it may set a strictly necessary security cookie called __cf_bm to tell people and bots apart. It doesn’t identify you and expires after 30 minutes.
3Cookies in the Mailivy apps
When you sign in to Mailivy in a browser, we use the cookies below. All of them are strictly necessary for the Service to work, so they don’t require your consent.
| Name | Set by | Purpose | Duration |
|---|---|---|---|
| mailivy_session | Mailivy (first party) | Keeps you signed in and links your requests to your session | Until you sign out, or 30 days if you choose “Stay signed in” |
| mailivy_csrf | Mailivy (first party) | Protects forms against cross-site request forgery | Until you close your browser |
| __cf_bm | Cloudflare, on our behalf | Tells people apart from automated bot traffic | 30 minutes |
4Local storage in our apps
Our web and desktop apps keep some settings in your browser’s local storage, such as your theme, reading layout and keyboard shortcut preferences, along with an encrypted cache of recent mail so it opens faster. This data stays on your device, is never used for tracking, and is cleared when you sign out.
5What we don’t use
- No advertising or retargeting cookies.
- No social media cookies or share buttons that follow you around.
- No third-party analytics cookies, on the website or in the apps.
- No cross-site tracking of any kind.
We also strip tracking pixels from the mail you receive, so senders can’t use them to see whether, when or where you opened a message.
6Why there’s no cookie banner
Under the Swedish Electronic Communications Act, which implements the EU ePrivacy Directive, consent is needed only for cookies that aren’t strictly necessary. Because we only use cookies that are essential to provide a service you have asked for, there is nothing to consent to and no banner to click through. If that ever changes, we’ll ask for your consent before setting any optional cookie.
7Managing cookies
You can view, delete and block cookies in your browser settings. If you block strictly necessary cookies, you won’t be able to stay signed in to Mailivy in that browser, but the website will keep working normally.
8Changes and contact
If we change the cookies we use, we’ll update this policy and the “Last updated” date at the top. Questions about cookies? Write to privacy@mailivy.com.