Poliogo

Cookie Policy

Effective date: August 7, 2026

Last updated: August 7, 2026

1. Scope

This policy explains how Poliogo uses cookies and similar technologies on poliogo.com and any views embedded in them (together, the "Services"). It applies to everyone who uses them, wherever you are, and it sits alongside our Privacy Policy. Region-specific rights are in section 8.

2. What we mean by "cookies"

"Cookies" here covers every technology that stores or reads data on your device:

  • HTTP cookies — small text files set by us (first-party) or by a provider (third-party).
  • Web storagelocalStorage and sessionStorage entries that stay in your browser until they are cleared.

We do not use browser or canvas fingerprinting or CNAME cloaking to disguise third-party tracking as first-party.

3. Our legal basis for using them

Strictly necessary items are set because you asked for a service that cannot work without them (ePrivacy Directive Art. 5(3) exemption; GDPR Art. 6(1)(f)). Everything else is set only after you opt in, and you can withdraw that consent at any time (GDPR Art. 6(1)(a)). In the United States we treat your choices, including the Global Privacy Control signal, as an opt-out of sale and sharing under the CCPA/CPRA and comparable state laws.

We never pre-tick consent boxes, and "Reject all" is always as easy and as prominent as "Accept all".

4. The four categories

CategoryConsentWhat it does
Strictly necessaryNot requiredSign-in, session security, load balancing, remembering your consent choices
Functional and preferencesOpt-inLanguage, region, theme, layout and other choices you have made
Performance and analyticsOpt-inHow many people visit, which features they use, where errors happen
Marketing and targetingOpt-inBuilding interest profiles, retargeting ads, measuring campaign results

Today we use strictly necessary items only.

5. What we actually set

Set by us

NameProviderCategoryPurposeLifespan
__sessionPoliogoStrictly NecessaryCarries the signed token that keeps you signed inUntil you sign out or it expires

We also keep entries in your browser's own storage. The ones that keep you signed in or record your consent are strictly necessary; anything else follows the category it belongs to and is written only after you opt in.

Set by the services we use

NameProviderCategoryPurposeLifespan
__cf_bmCloudflareStrictly NecessaryBot management and abuse prevention30 minutes
firebase:authUser:*FirebaseStrictly NecessaryKeeps you signed in (browser storage, not a cookie)Until you sign out

This schedule is regenerated whenever the services in our product change, so it matches what actually runs.

6. Third parties and where the data goes

The technologies below are set by providers acting on our behalf, and they may combine what they collect here with data they already hold about you:

  • Cloudflare (Cloudflare, Inc.) — CDN, DNS, security filtering and edge compute. Processing location: Edge locations worldwide. Privacy policy: https://www.cloudflare.com/privacypolicy/
  • Firebase (Google LLC) — Sign-in, app data storage and push messaging. Processing location: United States. Privacy policy: https://firebase.google.com/support/privacy

Some of them process data outside your country — processing locations include Edge locations worldwide and United States. Where that means a transfer out of the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the provider's certification under the EU–US Data Privacy Framework.

7. Managing and withdrawing consent

  • Ask us — write to [email protected] and we will apply your choice to every non-essential technology listed above.
  • Your browser — Chrome, Safari, Firefox and Edge all let you block or delete cookies. Blocking strictly necessary items will break sign-in.
  • Global Privacy Control — GPC is a signal your browser or an extension can send to ask us not to sell or share your data. We do not read it automatically yet, so please use the controls above.

Whenever we add a technology in a category that needs your permission, we ask before it loads and re-ask at least every 12 months.

8. United States disclosures

Under the CCPA as amended by the CPRA, and comparable laws in Virginia, Colorado, Connecticut, Utah, Texas and Florida:

  • We do not sell personal information for money.
  • We use no analytics or advertising technologies, so no "sale" or "sharing" takes place.
  • We do not knowingly sell or share the personal information of anyone under 16.

9. Retention and security

Lifespans are listed in section 5; none of our own non-essential items lasts longer than 12 months. Consent records are kept for 24 months as proof that consent was given, and are stored encrypted with access limited to the people who need it.

10. Changes

We update this policy when the technologies we use change. The date at the top shows the current version, and we ask for consent again when a change materially affects a category you had turned off.

11. Contact

Questions about this policy, or about any item listed above:


Generated by Poliogo from the services detected in this product. Poliogo is a compliance management platform, not a law firm, and this document is not legal advice.