This policy explains cookies and similar technologies on mcstudio.io and app.mcstudio.io, including browser storage used for authentication, security, support, preferences and local work. Our Privacy Policy explains the associated processing of personal data.
MC Studio is a trade name of REVE Media, KVK 88874990, VAT identification number NL004665647B65, with business address Diamantdreef 16, 7828 AW Emmen, the Netherlands. Questions: privacy@mcstudio.io.
1. Cookies and similar technologies
Cookies are small records stored by a browser and sent with applicable requests. Local storage and IndexedDB can retain information on a device without being cookies. This policy covers those technologies too.
A first-party cookie is associated with the website domain you visit. It can still be supplied or used by an external provider. Its domain does not determine whether consent is required. A session cookie normally lasts for the browser session; browser session-restoration settings can affect how long it remains. A persistent cookie has an expiry, which may be renewed during use.
2. Current inventory and consent position
The inventory below reflects production observations on 14 September 2026, covering the homepage, waitlist, anonymous app login and an existing signed-in app session. Entries present in an existing browser may include data left by an earlier application version. The inventory is not represented as an exhaustive test of every registration, payment, Google Calendar connection, upload, sharing or preference journey.
The public website uses a session-based analytics mechanism; the signed-in app uses Intercom Messenger as well as authentication and local storage. The public website and the app have different storage behaviour.
Current consent controls: the check found the public analytics cookie being set before any consent interaction and found no visible cookie banner or settings control on the inspected public pages. Intercom was already loaded in the signed-in app before its support button was opened; that existing-session observation does not establish whether a choice was made on a previous visit. This policy does not represent that these uses have already obtained valid consent.
Where applicable law requires consent, you are entitled to a clear prior choice, to refuse optional technologies and to withdraw consent as easily as giving it. We must not treat silence, continued browsing, an account registration or acceptance of general Terms as cookie consent. Publishing this policy does not retrospectively authorise storage or tracking.
Strictly necessary technologies may be used without consent for the requested service where the legal conditions are satisfied. Under Dutch rules, certain analytics with no or little effect on privacy can also qualify for an exemption. No such exemption is asserted here for the unidentified public analytics operator. An operational or “functional” label alone does not establish an exemption.
3. Cookies on MC Studio domains
All eight cookies below were observed on MC Studio origins with path /. A leading dot indicates the cookie was scoped to the stated parent domain; “host-only” means the stated host. The table describes browser lifetimes, not how long a provider retains information on its servers.
3.1 Security and authentication
| Cookie and domain | Provider and purpose | Browser lifetime and consent position |
|---|---|---|
__cf_bm — .mcstudio.io | Cloudflare. Bot detection and protection against automated abuse. | 30 minutes of inactivity. Necessary-security use can be exempt from consent where the actual deployment meets the exemption. |
sb-pftgsjtscqbnymkrihlo-auth-token — app.mcstudio.io (host-only) | Supabase / MC Studio. Maintains the signed-in application session. | The observed expiry was consistent with a 400-day cookie lifetime in the installed authentication SDK. Token validity is separate and can end earlier. Requested authentication can be exempt where necessary. |
3.2 Website analytics and unidentified website delivery cookie
| Cookie and domain | Provider and purpose | Browser lifetime and consent position |
|---|---|---|
session-id — mcstudio.io (host-only) | Website analytics script /~flock.js, sending through /~api/analytics. Identifies a website visit/session. The underlying operator is not yet established. | 30 minutes, renewed on navigation. Prior consent is required unless a specific applicable analytics exemption is established; none is asserted here. |
__dpl — mcstudio.io (host-only) | Website delivery layer; underlying provider and exact purpose have not yet been established. Its name is not evidence of a deployment or routing function. | 24 hours observed, renewed during homepage/waitlist navigation. No necessity or consent exemption is asserted for an unidentified purpose. |
3.3 Application preferences and layout
| Cookie and domain | Provider and purpose | Browser lifetime and consent position |
|---|---|---|
mc-calendar-time-zone — app.mcstudio.io (host-only) | MC Studio. Remembers the browser time zone for calendar display. | Configured for 365 days in the reviewed source; the observed existing cookie is not a fresh measurement of that full period. A persistent-preference exemption depends on the requested function and necessity. |
mc.dashboard.loading-layout.v1 — app.mcstudio.io (host-only) | MC Studio. Stores dashboard dimensions to show matching loading placeholders. | Session. Short duration does not itself make a cookie necessary; use without consent requires an applicable exemption. |
3.4 In-app support
| Cookie and domain | Provider and purpose | Browser lifetime and consent position |
|---|---|---|
intercom-session-lyiceg3e — .mcstudio.io | Intercom. Maintains a Messenger session and access to conversations. | Seven days, with renewal observed during use. Automatically loading support is not treated as exempt merely because the service is called support; prior consent is needed unless the actual requested-service use qualifies for an exemption. |
intercom-device-id-lyiceg3e — .mcstudio.io | Intercom. Identifies a device interacting with Messenger for support and abuse prevention. | Approximately 270 days, with rolling expiry observed. Necessity must cover this device identification and its duration; no blanket exemption for all support identifiers is asserted. |
Cloudflare and Intercom publish descriptions of their cookie behaviour in their Cloudflare cookie documentation and Intercom Messenger cookie documentation. Those vendor descriptions do not establish MC Studio's consent configuration.
4. Local storage and IndexedDB
The following entries were present in the inspected signed-in app browser. {workshopId} and {projectId} represent identifiers, not literal values or extra cookie names. Local storage and IndexedDB have no automatic browser expiry. Where application cleanup has not been established, we do not promise a fixed deletion time for a local entry.
4.1 Local work and application state
| Key or database | Function | Storage and retention information |
|---|---|---|
mc.dashboard.project-notes:{workshopId}:{projectId} | Project-note drafts. | Local storage. No automatic application expiry was found in the reviewed source. |
mc.scos | Local workspace data, including legacy data where retained. | Local storage. No automatic expiry was found; contents may require careful workspace-specific recovery. |
mc-designs, version 1 | Local design documents. | IndexedDB. No automatic expiry was found in the reviewed source. |
mc.onboarding.v1 | Onboarding progress or dismissal. | Local storage. No automatic expiry was found. |
Storage strictly needed to retain work or provide a function you request may qualify for a necessary-function exemption. That does not exempt unrelated tracking, every field in a legacy store or unlimited retention merely because information is stored locally.
4.2 Interface preferences
These first-party local-storage keys remember the following interface choices. No automatic expiry was found in the reviewed source; their necessity and retention depend on the actual requested preference.
| Key | Remembered preference |
|---|---|
mc.scos.scheduleOpen.v1 | Calendar schedule-card visibility. |
mc.openDesign | Last open design. |
mc.scos.navCollapsed.v2 | Collapsed navigation groups. |
mc.projTab | Project tab. |
mc.toolModes | Designer tool modes. |
mc.side | Application side. |
mc.stage | Application stage. |
mc.scos.nav | Navigation location. |
4.3 Support and potentially historical storage
| Key | What is established | What is not established |
|---|---|---|
intercom.intercom-state-lyiceg3e | Intercom local-storage state associated with Messenger. | Its detailed contents and provider cleanup period were not inspected. It has no browser-set expiry and must be assessed with the support cookies. |
mc.workshop.tab | An existing workshop-tab preference key. | The unversioned key differs from the current source's versioned key; an active writer was not established. |
sb-pftgsjtscqbnymkrihlo-auth-token in local storage | An authentication-related key was present in addition to the cookie. | Whether this local copy is still written or required was not established. Token validity is separate from local-storage persistence. |
ably-transport-preference | A connection-preference key was present in the app storage context. | The importing service, active writer, exact purpose and application expiry were not confirmed. It is not evidence, by itself, that MC Studio directly engages Ably. |
No session-storage entries were present in the inspected app tab. That observation does not exclude conditional session storage in journeys not covered by the check.
5. Scope limits and other services
Browser extensions and other websites can create storage that is visible in development tools. Unattributed extension or Google-domain observations are not listed as established MC Studio tracking technologies. Conversely, a limited scan is not proof that every third-party interaction is absent.
Payment, registration, recovery, calendar connection, uploads and public customer-card journeys can involve conditional storage not captured in the listed navigation check. The inventory must be updated to reflect any additional technology actually used. We do not invent cookie names, durations or recipients for those unverified journeys.
Google Calendar API access is separate from permission to place cookies. Calendar information and information derived from it remain subject to the specific Limited Use and no-AI/ML restrictions in section 6.1 of the Privacy Policy. No Google-domain cookie is attributed to that integration merely because Google Calendar is supported.
6. Your choices and browser data
You can use your browser's privacy controls to block or remove cookies and other site data. Blocking required authentication or security storage may prevent login or affect the requested service. Browser settings are not a substitute for any prior consent MC Studio must obtain.
Preserve local work before clearing site data. Removing local storage or IndexedDB can permanently erase designs, workspace information or drafts that have not synchronised to MC Studio. Contact support@mcstudio.io if you need help preserving local work. Clearing browser data does not delete the corresponding cloud account or all server-side records. Server-side account deletion does not guarantee that local data on every device is remotely erased.
Contact privacy@mcstudio.io to exercise privacy rights, object to relevant processing or withdraw consent you previously gave. You can contact support by email without opening Intercom Messenger. The inspected public deployment did not provide a verified “Cookie Settings” control, and this policy does not direct you to a control that has not been made available.
Where a consent interface is provided, it must offer meaningful acceptance, refusal and withdrawal controls, avoid pre-selected optional purposes and explain the relevant providers and uses. Optional processing requiring consent must not begin before that consent. Refusal of optional tracking must not be used as a penalty that makes ordinary website access unavailable.
7. Retention, security and provider processing
Cookie expiry is separate from the validity of a login token and from server-side retention of analytics or support records. Cookies may be refreshed; local storage may remain until removed by the application, browser or user. We do not represent the 30-minute analytics cookie as a 30-minute retention period for all analytics data.
Provider roles, personal-data retention, international transfers and privacy rights are addressed in the Privacy Policy and applicable subprocessor information. Secure or HttpOnly attributes concern security, not consent classification; a Secure cookie is not automatically lawful to use without consent.
8. Changes and contact
We update this policy and the inventory as relevant technologies or their purposes change. A policy update does not replace a required consent request, withdrawal control or subprocessor notice.
Cookie and privacy questions: privacy@mcstudio.io. Technical help preserving local work: support@mcstudio.io. You retain the right to complain to a competent supervisory authority, including the Dutch Autoriteit Persoonsgegevens, without first contacting us.