Ximly Cookie Policy
Β§ 1. What this document covers
1.1. This document describes all cookies and similar technologies (browser-memory entries in localStorage/sessionStorage, third-party scripts) used by the Ximly application (app.ximly.app) β and the rules for giving and withdrawing consent.
1.2. It is published as a standalone, publicly available page β you can read it without an account and without accepting anything. The rules of personal data processing are described in the Privacy Policy (Document D3); there you will also find the register of data recipients and information on transfers.
1.3. The marketing site (www.ximly.app) uses no analytics cookies and no tracking scripts.
1.4. Definitions. Cookies β small files saved by the browser and sent back with subsequent requests (e.g. keeping you logged in). localStorage/sessionStorage β browser memory for local settings (not sent to the server automatically; sessionStorage disappears when the tab is closed). Third-party scripts β code loaded from other companies' servers; the mere loading discloses to them your IP address and browser data, and the script may save its own cookies. The saving and reading of information on a device is governed by Article 399 of the Polish Electronic Communications Law (Prawo komunikacji elektronicznej, "PKE"), and the obligation to inform you about the processing of data β by Articles 12β13 GDPR; hence this policy and the consent banner.
Β§ 2. A correction and general rules
2.1. Cookies may contain personal data. In particular, the login cookie app_token contains an encrypted authentication token linked to your account β it is personal data within the meaning of Article 4(1) GDPR. The earlier claim that "cookies contain no personal data" was incorrect and is withdrawn.
2.2. Lifetime of the login credential. The app_token cookie is valid for 90 days; the access token stored in it expires on the server side approximately 3 months after issue, and earlier it is invalidated by logging out or removing the session from the list. Your control over this is the list of active sessions in your account settings (Document D3 Β§ 12.3).
2.3. Browser settings are not a consent mechanism. You may use them to additionally restrict cookies, but you express consent to categories other than the necessary ones exclusively in the banner/consent settings described in Β§ 3. Continued use of the service is not consent.
Β§ 3. Categories and the consent mechanism
3.1. We use exactly two categories:
- necessary β required for the service to operate (login, security, remembering your decisions); they require no consent (Article 399(3) PKE);
- analytics β they help us understand how the product is used; they also include session recording (a replayable record of the interface β Β§ 3.7a); they operate exclusively upon your consent.
We use no marketing or advertising cookies β that category does not exist in our system. We also count purely technical entries as necessary (settings such as language/theme, features launched at your request) β Article 399(3) PKE requires no consent for them.
3.2. Consent via the banner. On your first visit the banner asks for your decision. You may: accept all, reject all categories other than the necessary ones (with a single action, as easily as accepting), or set each category separately. The analytics category is off by default β only your active decision switches it on.
3.3. The server-side consent register. We record every decision in an immutable register: the scope, the policy version, the source of the decision (banner / settings / synchronization at login), the time, the IP address and the browser; a decision made before an account was created is re-sent to us by your browser at login and we then record it as a decision linked to your account, while the earlier record remains in the register as anonymous, because we create no identifier for visitors that would allow it to be linked to you. The register is the proof of consent (Article 7(1) GDPR), goes into the data export and survives account deletion (Article 17(3) GDPR); the retention period of these proofs is indicated in the Privacy Policy (Document D3 Β§ 9.2) β the same as for all proofs of consent and proofs of delivery of documents. A technical copy of the decision lives in the browser (ximly_cookie_consent), so that the banner does not return on every visit.
3.4. Withdrawal of consent is possible at any time and is as easy as giving it: in the consent settings you change your decision with a single action; withdrawal switches analytics off from that moment (it does not affect the lawfulness of the earlier processing).
3.5. Until you give consent, the analytics tool does not start at all and collects nothing.
3.6. Consequences of no consent. Refusing analytics consent restricts no feature of the service. We use no "cookie wall": access is never conditional on consent to categories other than the necessary ones.
3.7. What analytics records after consent: pseudonymous events (a random identifier, not the account) β clicks, screens visited, error data; without its own cookies, with loss of continuity after a page refresh. Screen addresses may contain technical identifiers (e.g. of a Learning Space β definition: Document D1 Β§ 1.2). The provider and region β Document D3 Β§ 7.
3.7a. Session recording. The same analytics consent starts session recording: the tool saves a replayable course of your session in the application interface β mouse movements and clicks, scrolling, screen changes and changes of the visible page content. The recording does not include camera image, audio or lesson video; the content of chat messages, the lesson chat and text fields is masked in the recording (Document D3 Β§ 19.4). Recording does not operate before you log in or on accounts of persons under 18 or of unknown age (Β§ 5) and stops immediately after consent is withdrawn (Β§ 3.4). Recordings are pseudonymous, stored for no longer than 90 days and deleted automatically (Document D3 Β§ 19.4).
Β§ 4. Inventory of cookies and similar technologies
4.1. Cookies:
| Name | Provider | Category | Purpose | Lifetime | Type |
|---|---|---|---|---|---|
app_token | Ximly | necessary | session authentication (an encrypted token; attributes blocking read-out by scripts and enforcing an encrypted connection) | 90 days | cookie |
ximly_session | Ximly | necessary | the technical session (maintaining continuity between requests) | approx. 2 hours (a persistent cookie β it does not expire when the browser is closed) | cookie |
XSRF-TOKEN | Ximly | necessary | protection against CSRF attacks (impersonation of your logged-in requests from another site) | approx. 2 hours (like ximly_session β persistent) | cookie |
__cf_bm | Cloudflare | necessary (security) | bot filtering at the infrastructure level | approx. 30 minutes | cookie |
_cfuvid | Cloudflare | necessary (security) | request rate limiting at the infrastructure level; may be set on some requests | session (until the browser is closed) | cookie |
| the Turnstile challenge cookie | Cloudflare | necessary (security) | may be set by the anti-bot mechanism on the registration, login and password-reset forms when the mechanism is enabled for the given action (Document D3 Β§ 7) | only for the duration of the check | cookie |
sidebar:state | Ximly | necessary (an interface setting saved upon your action β Article 399(3) PKE) | remembering that the side panel is collapsed | 7 days | cookie (JS) |
4.2. Browser-memory entries (localStorage / sessionStorage) β all belong to the necessary category (the operation and convenience of the service, Β§ 3.1), are saved locally and are not automatically passed to us:
| Key | Purpose | Type |
|---|---|---|
ximly_cookie_consent | the record of your consent decision (a local copy of the register of Β§ 3.3) | localStorage |
ximly_cookie_consent.analytics | the on/off marker for analytics used by the analytics tool β subordinate to your decision under Β§ 3.3 (an outdated marker will never itself start analytics) | localStorage |
i18nextLng | remembering the interface language | localStorage |
current-workspace-storage | the most recently opened Learning Space β identifier and name (definition of a Learning Space: Document D1 Β§ 1.2) | localStorage |
theme | the light/dark theme | localStorage |
selectedWebcam, selectedMic, selectedSpeaker, webcamOn, micOn, extensionInfo | device preferences in the virtual classroom | localStorage |
hint and tutorial keys (among others should_show_invite_help, product tour keys, dismissed informational banners) | remembering dismissed hints | localStorage |
| chat throttling keys | limiting the frequency of sending messages | localStorage |
mobilePromptDismissed | dismissal of the mobile prompt | sessionStorage |
ximly.pending-registration-email | the e-mail address provided at registration β keeping the registration steps continuous until registration is completed | sessionStorage |
ximly.confirmed-date-of-birth | the date of birth confirmed at the age-establishing step, together with the account identifier β carrying it over to the registration summary; the entry disappears when the tab is closed and for a different account | sessionStorage |
ximly.confirmed-parent-email | the Parent's/Guardian's e-mail address indicated at the age-establishing step, together with the account identifier β carrying it over to the subsequent activation steps; the entry disappears when the tab is closed and for a different account | sessionStorage |
parent_invitation_handed_off:{token} | a marker that the Guardian invitation link has already been used in this tab β protects against a repeated attempt with a spent invitation | sessionStorage |
4.3. Third-party scripts and resources (they may save their own cookies/localStorage β recipient details: Document D3 Β§ 7):
| Technology | Provider | Category | When it starts |
|---|---|---|---|
| PostHog (analytics and session recording β Β§ 3.7a) | PostHog (EU instance) | analytics | exclusively after analytics consent; without its own cookies β in browser memory it saves only the marker of your consent (ximly_cookie_consent.analytics, Β§ 4.2), and its working data is kept only in the tab's memory and disappears after a page refresh; without account identification |
| The Featurebase help widget | Featurebase | necessary (help β a feature launched at your request) | the widget script is loaded only on the first use of the help feature (clicking "Help & Support"); we then pass to the provider a signed token of your account containing the identifier, e-mail address, first and last name, role, time zone and interface language (the recipient and basis β Document D3 Β§ 7) |
| Turnstile (anti-bot) | Cloudflare | necessary (security) | on the registration, login and password-reset forms β when the mechanism is enabled for the given action (Document D3 Β§ 7) |
| Stripe.js | Stripe | necessary (payments) | on the payment paths |
| The real-time channel (Pusher) | Pusher | necessary | after logging in (chat, notifications) |
| Lesson video (Cloudflare RealtimeKit) | Cloudflare | necessary | in the virtual classroom |
| Embedded YouTube video | necessary for the feature you request (playing the video) β launched only at your request | only after clicking play (a profile with video, watching together) | |
| The whiteboard (the tldraw synchronization worker) | the worker operator (Document D3 Β§ 7) | necessary | in the virtual classroom |
4.4. The inventory contains no advertising cookies, no tracking pixels and no attribution SDKs β their absence has been verified (GA/GTM, Meta, Hotjar, Clarity, Sentry, Segment, Mixpanel and others).
Β§ 5. Minors
5.1. We do not switch analytics β including session recording β on for persons under 16 β even with consent in the banner. For a logged-in account with an age under 16 or unknown, analytics is suppressed on the server side (the banner decision remains recorded, but is marked as blocked due to age); turning 16 lifts the block. We do not switch session recording on for persons under 18: on the account of a person aged 16β17 analytics consent starts the remaining analytics, but not session recording; turning 18 lifts that block (Β§ 3.7a).
5.2. Before you log in, we do not know your age β which is why, until you log in, analytics remains off regardless of the decision in the banner. Analytics consent expressed before logging in takes effect only after logging in to the account of a person who is 16 or older; until then we treat it as not given.
Β§ 6. Changes to this policy
6.1. The cookie policy carries a version designation; the current version is designated "1". After a new version is published, we will ask you for a new decision (reconsent): a consent record given for the old version ceases to be current, and analytics remains off until you make a new decision.
6.2. We update the inventory of Β§ 4 with every change to the set of technologies β more often than the Privacy Policy; that is why this is a separate document.
