01
Scope
This notice explains cookies and browser storage used by the MUTA Portal for login, language settings, editor recovery, and consent-based guest game sessions.
MUTA does not use personalized-advertising cookies or advertising fingerprints.
02
Essential authentication cookies
- accessToken: authenticates signed-in requests. It is HTTP-only, unavailable to page JavaScript, and normally expires after 15 minutes.
- refreshToken: securely renews a signed-in session. It is HTTP-only and normally expires after 14 days.
In production these cookies use Secure, SameSite=Lax, and the Portal-wide path. Blocking them prevents sign-in.
03
Language and feature settings
- NEXT_LOCALE: remembers Korean or English for up to one year.
- NEXT_LOCALE_SOURCE: records that the language was chosen manually.
- Local storage: may hold search history, editor view preferences, selected AI model, job-recovery details, and game-creation plans in that browser.
- Session storage: may hold SSO request-verification values and unsaved editor drafts while the current tab remains open.
04
Optional guest game session
- mutaGuestId: distinguishes a consenting guest using a random identifier for up to 30 days.
- mutaGuestToken: authenticates the current game session and real-time lobby for up to 6 hours.
- mutaGuestConsent: records the accepted notice version for up to 30 days.
Guest sessions process game and room identifiers, entry path, lobby joins/leaves, game start/end, active play time, and coarse device class. MUTA does not collect an email, real name, or advertising fingerprint for this profile.
05
Deletion and controls
You can refuse guest tracking on the game entry screen. After consenting, clear site data or use the withdrawal control to remove guest cookies and end active sessions.
Signing out removes member authentication cookies. Use your browser's site-data controls to remove language cookies and local or session storage.
06
Security and contact
Authentication tokens are kept out of browser local storage and handled with HTTP-only cookies. SSO verification values are removed from session storage after the request completes.
On a shared device, sign out and clear site data when finished. Contact muta@emotionwave.com with cookie or storage questions.