Browsing without signing in
If you only read public pages and do not sign in, we do not set an authentication cookie. Anonymous video previews are served through our API; playback position is not saved between visits.
We use privacy-oriented, cookieless pageview analytics (Umami Cloud, EU data region) to measure audience size. Umami does not set marketing cookies or cross-site identifiers in its default configuration. We rely on legitimate interest for this limited statistical purpose and you can object (see Your rights).
When you interact with the site
Certain features only work if the browser stores a small amount of data. These are strictly necessary for the feature you request — not for advertising or profiling.
By signing in, subscribing, enabling notifications, installing the web app, or changing playback speed, you use features that require the storage listed in the table below. You can avoid most of this storage by not using those features (for example, stay logged out and do not change player settings).
We do not use your interaction as consent to unrelated marketing trackers. If we ever add optional analytics or marketing tools that are not strictly necessary, we will ask for consent first.
Cookies and browser storage we use
The application code below is under our control. Third-party payment pages (Stripe) may set their own cookies when you start checkout on their surfaces.
| Name / key | Mechanism | Purpose | Lifetime | Strictly necessary? |
|---|---|---|---|---|
| refresh_token | HttpOnly cookie (first-party API) | Keeps you signed in between visits; rotated on refresh | Up to 30 days, or until logout | Yes — authentication |
| playbackRate | localStorage | Remembers your chosen video playback speed | Until you clear site data | Functional — only after you change speed |
| nuxt-color-mode | localStorage | Applies light/dark display matching your system preference | Until you clear site data | Functional — display preference |
| vmp_pwa_device_token | localStorage | Links push-login handoff to your browser on installed iOS PWA | Persistent until cleared | Yes — only when you use PWA push sign-in |
| vmp_pwa_login_email | localStorage | Prefills email during PWA sign-in wizard | Until cleared or push disabled | Functional — PWA login UX |
| vmp-pwa-auth (IndexedDB) | IndexedDB | Temporary handoff code between Safari and installed PWA | Short-lived; cleared after redeem | Yes — iOS PWA authentication |
| Service worker caches | Cache API (PWA) | Offline shell and faster repeat loads for installed app | While PWA installed / until cache purge | Yes — PWA functionality |
| Session handoff keys | sessionStorage | Short-lived auth and UI state during a single tab session | Until tab closes | Yes — security during login flows |
| vmp_personal_data_notice_ack | localStorage | Remembers that you dismissed the personal data notice banner | Until you clear site data | Functional — only after you acknowledge the notice |
Who processes data on our behalf
Primary hosting uses Cloudflare (API Worker, D1 database, R2 media, Pages frontend). Traffic is served from Cloudflare’s global network; we cannot guarantee that every byte stays inside the EU, but we minimise personal data and use EU-based analytics where possible.
Backup infrastructure may run on Deno Deploy (API) and Vercel (frontend).
Other processors include: Umami Cloud (EU) for anonymous statistics; Stripe for payments; Brevo for transactional email; Sentry for error monitoring on the frontend and API. Payment and email processing happen only when you use those features.
Cloudflare — hosting, CDN, security (global edge)
Umami Cloud (EU region) — cookieless pageview statistics
Stripe — payment processing when you subscribe
Brevo — magic-link and account email
Sentry — error and stability monitoring (technical logs)
Deno Deploy / Vercel — backup API and frontend deployments
Server-side processing (no browser cookie)
When video streams are delivered, our API logs anonymised technical events (for example hashed IP, country from network headers, and viewing session buckets) to operate the service, prevent abuse, and show aggregate statistics to administrators. These logs are not used to advertise to you and are not shared with ad networks.
Your rights (EU / UK visitors)
Under the GDPR you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interest. You may withdraw consent where processing is consent-based (we use little consent-based processing today).
To exercise rights, contact us using the support channel published on this site. You may also lodge a complaint with your supervisory authority:
Czechia — Úřad pro ochranu osobních údajů (ÚOOÚ), uoou.cz
Slovakia — Úrad na ochranu osobných údajov SR (ÚOO SR), dataprotection.gov.sk
Updates
We may update this notice when the service or law changes. The latest version is always published at this URL. Material changes will be reflected in the on-site notice banner when appropriate.