What is the mf_user cookie?
mf_user is a cookie placed by the Mouseflow script, a behavioral analytics platform providing heatmaps, session replay, and form analytics. The cookie is set by the third-party provider Mouseflow ApS, but appears on the visited site's domain (a first-party cookie from the browser's perspective) since the script runs in the page's context.
It typically appears as soon as the Mouseflow script loads on a page, if the site owner has installed the service to track visitor behavior.
What data it stores
mf_user stores a unique identifier associated with the visitor, used by Mouseflow to recognize the same user on return visits and link browsing sessions together. The exact value format may vary and is not publicly documented in detail.
Data collected through this identifier (browsing behavior, mouse movements, clicks, form data) is sent to Mouseflow's servers for processing and display in the client's dashboard.
What it is used for
The cookie's purpose is statistical: it allows Mouseflow to distinguish unique visitors from repeat sessions of the same user, so that heatmap reports, session recordings, and behavioral statistics remain accurate and don't count the same person multiple times.
For the site owner, this data helps understand how visitors interact with the page (where they click, where they abandon a form, how much time they spend on sections), for the purpose of UX and conversion optimization.
Does it require consent?
CookieFix classifies mf_user under the statistics (behavioral analytics) category. It is not strictly necessary for the site to function, so under GDPR and the ePrivacy Directive (transposed in Romania via Law 506/2004), setting it requires the visitor's prior consent.
- The Mouseflow script must be blocked until explicit consent for the statistics category is obtained.
- The cookie must be listed in the site's cookie policy, with purpose, provider, and duration.
- Visitors must be able to refuse or withdraw consent as easily as they grant it.
How to block or delete mf_user
A visitor can delete or block mf_user from browser settings (Chrome, Firefox, Safari, Edge – site-specific cookie management), or use tracking-script blocking extensions.
For site owners, the most practical solution is using a consent management platform (CMP) like CookieFix, which automatically blocks the Mouseflow script before consent for the statistics category is given, and only activates it after the visitor explicitly accepts.
Frequently asked questions
It's a cookie set by Mouseflow to recognize a visitor as unique across multiple visits, used for heatmaps and session replay.
Its typical lifespan is 90 days, after which it expires and is reset on the next visit.
Yes, as a statistics/analytics cookie it requires prior consent under GDPR and Law 506/2004, since it is not strictly necessary for the site to function.
You can use a consent management platform that automatically blocks the Mouseflow script until the visitor accepts the statistics category.