Moby
Cookies and browser storage
Last updated 6 August 2026
Moby sets no profiling or session-recording storage, and uses no tag manager. The two measurement tools are Google Analytics and the Meta Pixel, on this site and the web app, and neither loads until you allow it — one question, one answer for both. What follows is everything the app puts in your browser.
| Name | Type | Set by | Purpose | Kept for | Category |
|---|---|---|---|---|---|
| session | Cookie | First party | Identifies the signed-in session. The session contents are held server-side; the cookie carries only a signed identifier | 24 hours from last activity | essential |
| session (CSRF token) | Cookie | First party | Carries the token that proves a form submission came from a page this site served | Life of the session | essential |
| cookie_consent | Local storage | First party | Records whether the Meta Pixel on this site and address lookup were allowed, so the question is asked once. Storing the answer to a consent question is itself exempt | Until cleared by the visitor | essential |
| scrollPosition | Session storage | First party | Returns a long list to where it was when you left it | Until the browser tab is closed | functional |
| moby.browser.role_selection | Session storage | First party | Temporarily holds the signed proof needed to choose between roles on one account during sign-in | Until role choice, sign-out, expiry, or browser-tab close | essential |
| moby.browser.role_choices | Session storage | First party | Temporarily holds the roles available to the signed-in account so the sign-in page can present a choice | Until role choice, sign-out, expiry, or browser-tab close | essential |
| moby.browser.role_accounts | Session storage | First party | Temporarily holds the names of the accounts your password matched so the sign-in page can present a choice between them | Until role choice, sign-out, expiry, or browser-tab close | essential |
| moby.org.partial_2fa | Session storage | First party | Temporarily carries the organisation sign-in proof to the second-factor screen | Until verification, expiry, or browser-tab close | essential |
| moby.platform.partial_2fa | Session storage | First party | Temporarily carries the platform sign-in proof to the second-factor screen | Until verification, expiry, or browser-tab close | essential |
| a2hs_dismissed_* | Local storage | First party | Remembers that the “install this app” prompt was dismissed | Until cleared by the visitor | functional |
| Google Maps (NID and related) | Cookie and local storage | Set by Google when address lookup is used. Nothing is loaded from Google, and nothing is set, until address lookup is switched on | Set by Google — see Google's own cookie notice | ||
| moby.consent | Local storage | First party | Records whether the Meta Pixel was allowed on the web app, so the question is asked once. Storing the answer to a consent question is itself exempt | Until cleared by the visitor | essential |
| _fbp | Cookie | Meta Platforms | Set by the Meta Pixel on this site or the web app to tell one browser from another when measuring whether an advert led to a sign-up. Nothing is loaded from Meta, and nothing is set, until you allow it | 90 days | |
| _fbc | Cookie | Meta Platforms | Set by the Meta Pixel on this site or the web app when you arrive from a Meta advert, carrying the click identifier that advert was served with. Only after you allow it | 90 days | |
| _ga and _ga_* | Cookie | Set by Google Analytics on this site to tell one browser from another when counting visits and the pages they reach. Nothing is loaded from Google, and nothing is set, until you allow it | 2 years |
What asks first
Two third parties can set something in your browser, and each is switched off until you switch it on. Google, through the address lookup that suggests addresses as you type one: until then the address field works as an ordinary text box, nothing is requested from Google, and no Google storage is set. And Meta, through the pixel that measures whether one of our adverts led to a sign-up: this site asks with a bar on your first visit, the web app asks on its own, and until you allow it nothing is loaded from Meta and nothing is set. On this site that one answer also switches on address lookup. Each choice is recorded so you are not asked again on that device.
Changing your mind
Clearing this site's data in your browser clears the record of those choices, and each will ask again the next time it comes up. Every other item above is either essential to a signed-in session or a small convenience — a scroll position, a dismissed prompt — that carries no identifier and follows you nowhere.
Connections that set nothing
Some pages load fonts and icon files from Google Fonts, jsDelivr and Cloudflare, and the push-notification pages load Firebase's messaging library from Google. None of these set a cookie or store anything, but each one does disclose your IP address to that provider in order to serve the file. We list them here because a page that only lists cookies is not an honest list of who sees you.
Full detail on who processes what is in the privacy notice and the sub-processor register.