Cookie Policy
XSTARME uses the smallest possible amount of browser storage: one session cookie to keep you signed in, and one flag to remember that you confirmed your age. There are no advertising, analytics, or tracking cookies on this Site.
1. What this covers
“Cookies” here means cookies and equivalent technologies such as browser local storage. This policy explains what is stored on your device, by whom, and for how long. It sits alongside our Privacy Policy.
2. What we store
| Name | Type | Set by | Purpose | Lifetime |
|---|---|---|---|---|
PHPSESSID |
Cookie — strictly necessary | Us (first party) | Identifies your browsing session so you stay signed in and your subscription access works as you move between pages. Marked HttpOnly and SameSite=Lax, so it cannot be read by scripts or sent from other sites. |
Deleted when you close your browser |
xstarme_age_ok |
Local storage — strictly necessary | Us (first party) | Records that you confirmed you are 18 or older, so the age notice is not shown on every page. It is a single flag, stays on your device, and is never transmitted to our servers. | Until you clear your browser data |
| Paddle checkout cookies | Cookies and storage — necessary for payment | Paddle (third party) | Set only when you open the checkout to subscribe. Paddle uses them to run the payment flow, remember checkout state, apply the right tax, and detect payment fraud. Governed by Paddle’s own privacy and cookie notices, shown at checkout. | Set by Paddle |
3. What we do not use
There are no advertising cookies, retargeting pixels, social-media buttons, session recorders, A/B-testing tools, or analytics services (including Google Analytics) on this Site. We do not track you across other websites and we do not sell or share any browsing information.
4. Third-party requests without cookies
Two resources are loaded from outside our servers. Neither sets a cookie, but both mean your IP address and browser details are visible to that provider:
- Google Fonts — the “Inter” typeface used across the Site is fetched from Google’s font servers on every page load.
- Paddle — the checkout script is loaded from Paddle’s servers, but only on pages where a subscription can actually be purchased.
5. Why we do not show a cookie banner
Under the ePrivacy Directive and the UK PECR, consent is not required for storage that is strictly necessary to provide a service the user has requested. Everything we set falls into that category: a session cookie needed to sign you in, and an age flag needed to comply with our obligations around adult content. There is nothing optional to consent to. If we ever add analytics or advertising, we will ask for your consent first and update this policy before doing so.
6. Controlling cookies
You can delete or block cookies and clear local storage in your browser settings. Note that blocking the session cookie will prevent you from signing in or watching anything you have subscribed to, and clearing local storage means the age confirmation will be shown again.
Browser instructions: Chrome, Firefox, Safari, Edge.
7. Changes and contact
If what we store changes, we will update this page and the “last updated” date above. Questions: privacy@xstarme.com.