Skip to content

Mutually

Cookie Policy

Last updated 29 September 2026 · Version cookies-2026-09-29-draft

Draft — pending legal review. This page describes how Mutually works today. It isn’t final, and it isn’t yet a binding document.

We keep cookies to a minimum: a few that make Mutually work, and one for analytics that’s off unless you allow it. This draft has not yet been reviewed by counsel. For how we handle personal information more generally, see the Privacy Policy.

What cookies are

Cookies are small files a website stores in your browser. We also use your browser’s local storage in a few places; this policy covers both.

Strictly necessary

These keep Mutually working and secure, so they can’t be switched off. They’re never used for advertising or to follow you to other websites.

  • Signing in (authjs.session-token, or __Secure-authjs.session-token on our secure site) — keeps you signed in. Lasts up to 30 days, or until you sign out.
  • Device recognition (mutually.device) — recognises a browser you’ve used before, so we can show you your signed-in devices and warn you about a sign-in from somewhere new. Lasts up to 13 months.
  • Accepting an invitation (mut_invite) — remembers the invitation you’re accepting while you sign up. Lasts 1 hour.
  • Your place on the waitlist (mutually_waitlist) — after you confirm your place, lets this browser update where you’re based. Only sent to waitlist pages. Lasts 30 days.
  • Bot protection — when you use a form such as “Request an invitation” or “Find my link”, our form-protection provider (Cloudflare Turnstile) runs a check that may use a short-lived cookie or similar storage.
  • Your cookie choice (local storage mutually.analytics.consent) — remembers whether you allowed analytics, so we don’t ask again.
  • Offline page (a service worker in the member app) — lets the app show a friendly page instead of an error when your connection drops. It stores no personal information.
  • Unsent drafts (local storage) — the member app and private Connector links keep an unfinished message or answer on this device, so it isn’t lost if the page closes. Cleared once it’s sent.
  • Notifications (a service worker) — if you turn on notifications, delivers them to this device. You can turn them off in Settings or in your browser.

Analytics — only if you allow it

  • What: PostHog, a product analytics service, hosted in the European Union. It sets a cookie named ph_…_posthog (lasting up to 1 year) to count visits and learn which pages help.
  • What we don’t do: we don’t record your screen or keystrokes, we don’t collect your IP address, we don’t capture what you type into forms, and links that contain private codes are masked before anything is recorded.
  • Your choice: analytics stays off until you choose “Allow” on the banner. You can change your mind at any time below, and from Settings in the member app.

Third-party content

We don’t use advertising, social-media or tracking pixels. Our pages don’t embed content from other sites that sets its own cookies.

Managing cookies in your browser

You can also clear or block cookies in your browser’s settings. If you block the strictly necessary ones, you won’t be able to sign in.

Changes

If we add or change a cookie, we’ll update this page and its version number, and ask again where your consent is needed.

Questions: support@mutually.lol.

Analytics

…

We’d rather introduce you well than introduce you often.

Mutually is invite-only while the network grows, one circle at a time.

The list isn’t open yet.

We’re inviting a few people at a time. If someone invited you, open the link in their message.

Already a member? Sign in