Cookie Policy
Effective date: August 7, 2026
Last updated: August 7, 2026
1. Scope
This policy explains how Poliogo uses cookies and similar technologies on poliogo.com and any views embedded in them (together, the "Services"). It applies to everyone who uses them, wherever you are, and it sits alongside our Privacy Policy. Region-specific rights are in section 8.
2. What we mean by "cookies"
"Cookies" here covers every technology that stores or reads data on your device:
- HTTP cookies — small text files set by us (first-party) or by a provider (third-party).
- Web storage —
localStorageandsessionStorageentries that stay in your browser until they are cleared.
We do not use browser or canvas fingerprinting or CNAME cloaking to disguise third-party tracking as first-party.
3. Our legal basis for using them
Strictly necessary items are set because you asked for a service that cannot work without them (ePrivacy Directive Art. 5(3) exemption; GDPR Art. 6(1)(f)). Everything else is set only after you opt in, and you can withdraw that consent at any time (GDPR Art. 6(1)(a)). In the United States we treat your choices, including the Global Privacy Control signal, as an opt-out of sale and sharing under the CCPA/CPRA and comparable state laws.
We never pre-tick consent boxes, and "Reject all" is always as easy and as prominent as "Accept all".
4. The four categories
| Category | Consent | What it does |
|---|---|---|
| Strictly necessary | Not required | Sign-in, session security, load balancing, remembering your consent choices |
| Functional and preferences | Opt-in | Language, region, theme, layout and other choices you have made |
| Performance and analytics | Opt-in | How many people visit, which features they use, where errors happen |
| Marketing and targeting | Opt-in | Building interest profiles, retargeting ads, measuring campaign results |
Today we use strictly necessary items only.
5. What we actually set
Set by us
| Name | Provider | Category | Purpose | Lifespan |
|---|---|---|---|---|
__session | Poliogo | Strictly Necessary | Carries the signed token that keeps you signed in | Until you sign out or it expires |
We also keep entries in your browser's own storage. The ones that keep you signed in or record your consent are strictly necessary; anything else follows the category it belongs to and is written only after you opt in.
Set by the services we use
| Name | Provider | Category | Purpose | Lifespan |
|---|---|---|---|---|
__cf_bm | Cloudflare | Strictly Necessary | Bot management and abuse prevention | 30 minutes |
firebase:authUser:* | Firebase | Strictly Necessary | Keeps you signed in (browser storage, not a cookie) | Until you sign out |
This schedule is regenerated whenever the services in our product change, so it matches what actually runs.
6. Third parties and where the data goes
The technologies below are set by providers acting on our behalf, and they may combine what they collect here with data they already hold about you:
- Cloudflare (Cloudflare, Inc.) — CDN, DNS, security filtering and edge compute. Processing location: Edge locations worldwide. Privacy policy: https://www.cloudflare.com/privacypolicy/
- Firebase (Google LLC) — Sign-in, app data storage and push messaging. Processing location: United States. Privacy policy: https://firebase.google.com/support/privacy
Some of them process data outside your country — processing locations include Edge locations worldwide and United States. Where that means a transfer out of the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the provider's certification under the EU–US Data Privacy Framework.
7. Managing and withdrawing consent
- Ask us — write to [email protected] and we will apply your choice to every non-essential technology listed above.
- Your browser — Chrome, Safari, Firefox and Edge all let you block or delete cookies. Blocking strictly necessary items will break sign-in.
- Global Privacy Control — GPC is a signal your browser or an extension can send to ask us not to sell or share your data. We do not read it automatically yet, so please use the controls above.
Whenever we add a technology in a category that needs your permission, we ask before it loads and re-ask at least every 12 months.
8. United States disclosures
Under the CCPA as amended by the CPRA, and comparable laws in Virginia, Colorado, Connecticut, Utah, Texas and Florida:
- We do not sell personal information for money.
- We use no analytics or advertising technologies, so no "sale" or "sharing" takes place.
- We do not knowingly sell or share the personal information of anyone under 16.
9. Retention and security
Lifespans are listed in section 5; none of our own non-essential items lasts longer than 12 months. Consent records are kept for 24 months as proof that consent was given, and are stored encrypted with access limited to the people who need it.
10. Changes
We update this policy when the technologies we use change. The date at the top shows the current version, and we ask for consent again when a change materially affects a category you had turned off.
11. Contact
Questions about this policy, or about any item listed above:
- Email: [email protected]
- Entity: Poliogo, Israel
- Website: poliogo.com
Generated by Poliogo from the services detected in this product. Poliogo is a compliance management platform, not a law firm, and this document is not legal advice.