What is the c_user cookie?
c_user is an HTTP cookie set by Facebook (owned by Meta Platforms Inc.) on the .facebook.com domain. It appears on a third-party site whenever that site loads a Facebook element, such as a Like button, comments plugin, conversion pixel, or social login widget.
The cookie is automatically set by Facebook when a user logs into their Facebook account, and it is later read by any page, including third-party sites, that loads Facebook scripts or iframes.
What data it stores
According to publicly available Meta information, c_user stores the numeric account ID of the logged-in Facebook user. The exact value differs per user, and Meta does not publicly document its precise format in detail.
Data associated with this cookie is transmitted to Facebook/Meta servers and used to correlate user activity between Facebook and third-party sites that embed Meta tools (pixel, social plugin, advertising).
What it is used for
For Facebook/Meta, c_user helps quickly recognize a logged-in user on any page loading Facebook resources, enabling features like showing a name/avatar in social widgets or pre-filling login forms.
From a marketing standpoint, this cookie feeds into the user profile used for ad targeting and conversion measurement via Meta Pixel, even when the visitor is browsing a site unrelated to Facebook.
Does it require consent?
CookieFix classifies c_user under the marketing category, since it is tied to cross-site tracking and Meta advertising rather than being strictly necessary for the host site's operation.
- Under GDPR and Romania's Law 506/2004 (implementing the ePrivacy Directive), this cookie requires explicit, prior consent from the visitor before being set.
- Site owners must disclose it in their cookie policy, including provider, purpose, and duration.
- Consent must be collected through a compliant banner, and the Facebook script that triggers this cookie should be blocked until acceptance.
How to block or delete c_user
Visitors can delete or block c_user manually via browser settings (Chrome, Firefox, Edge, Safari) by clearing browsing data for facebook.com, or by enabling third-party cookie blocking/tracking prevention.
Site owners cannot disable the cookie itself since it is set by Facebook, but the script that triggers it (social plugin, pixel) can be blocked until consent is given. A consent management platform like CookieFix automatically blocks Facebook scripts and only loads them after a visitor accepts the marketing category.
Frequently asked questions
It is a cookie set by Facebook on the .facebook.com domain that identifies a logged-in user and is read by Facebook plugins or scripts embedded on third-party sites.
Yes, since it is classified as marketing and used for cross-site tracking, it requires prior consent under GDPR and Romania's ePrivacy-based legislation.
Its typical duration is about 1 year from being set, after which it expires automatically unless renewed through a new login.
It cannot be edited directly since it belongs to Facebook, but the script that triggers it (pixel, social plugin) can be blocked until consent using a CMP like CookieFix.