COOKIE INVENTORY REQUIRED BEFORE PUBLICATION

This policy cannot be completed without a real technical inventory of the cookies, storage keys, SDKs, pixels and tokens actually used by www.mylol.com, app.mylol.com, app18.mylol.com and the registration, login, payment, age-assurance and chat flows. No cookie name, provider, domain or duration has been invented here. The cookie table below is intentionally empty until the inventory is supplied.

Legal · Cookies

Cookie and similar technologies policy

How MyLOL uses cookies, local storage and similar technologies across mylol.com and the app — what is strictly necessary, what is optional, and how to accept, reject or change your choices.

Last updated: [DATE]

What we can verify today

One thing has been checked directly rather than assumed, and it is recorded here so the difference between verified and unverified is visible.

www.mylol.com (current marketing build)
The marketing site as currently built sets no cookies, writes no localStorage or sessionStorage keys, loads no analytics script, no advertising pixel and no third-party SDK. Fonts are loaded from a third-party font host, which means that host receives a network request including your IP address and user agent — that is not device storage, but it is a third-party connection and must be disclosed. [PROVIDER TO CONFIRM in the inventory]
app.mylol.com and app18.mylol.com
[COOKIE INVENTORY REQUIRED] — the application, registration, login, payment, age-assurance and chat surfaces have not been inventoried. Nothing about them is asserted in this draft.

What are cookies?

A cookie is a small text file that a website asks your browser to store on your device. When you come back, your browser sends it again, so the site can recognise your session — for example, to keep you logged in rather than asking for your password on every page.

Some cookies are set by the site you are visiting (first-party). Others are set by another company whose service is embedded in the page, such as a payment or verification provider (third-party).

Some last only until you close your browser (session). Others stay for a defined period (persistent).

For teen members: Short version: a cookie is a little note your browser keeps for a website so the site remembers your visit. Some notes are needed for the site to work. Others are optional, and you get to say no to those.

Cookies and similar technologies

This policy is not only about cookies. It covers every technology that stores information on your device or reads information from it, including:

  • Local storage and session storage

    Browser storage a site can write to, often used for preferences or to hold a session token.

  • Software development kits (SDKs)

    Code from another company included in an app, which may create or read a device or installation identifier.

  • Pixels and tracking tags

    Tiny image or script requests used to record that a page or action occurred.

  • Authentication tokens

    Credentials issued after you log in, stored on your device so you stay logged in.

  • Device and fraud signals

    Information read from your browser or device to detect automation, account takeover and fraud.

  • Embedded media

    Players or content loaded from another service, which may set their own storage.

  • Cache and similar identifiers

    Other local mechanisms that can be used to store or retrieve an identifier.

Where the law treats access to, or storage on, your device as requiring consent, it generally does so regardless of whether the technology is technically a "cookie". That is why this policy is written around technologies, not just cookie files.

How MyLOL uses cookies and similar technologies

Categories below describe purposes, not confirmed technologies. A category stays in the published policy only if the inventory shows it actually exists.

Strictly necessary

Always active

Technologies without which the service you asked for cannot be delivered. Purposes in this category are expected to include:

  • Authentication — keeping you logged in and tied to the correct account
  • Session management — maintaining state as you move between pages
  • Security — protecting against account takeover, cross-site request forgery and abuse
  • Fraud prevention — detecting automated sign-ups, ban evasion and misuse
  • Load balancing and routing — sending your request to a working server
  • Recording your cookie choices, so we do not ask again on every page

Consent: Consent not generally required where the technology is strictly necessary to provide the service you requested — but the exemption is narrow and each item must be justified individually.

Actual names, domains, providers and durations: [COOKIE INVENTORY REQUIRED]. No entries are listed until confirmed.

[ATTORNEY REVIEW REQUIRED] — do not classify a technology as strictly necessary because it is convenient or commercially useful. Regulators read the exemption narrowly: analytics, fingerprinting for product insight, and most risk-scoring beyond genuine security fall outside it. Each item in this category needs an individual justification recorded in the inventory.

Preferences

Optional

Technologies that remember a choice you made, so the product behaves the way you set it. Possible purposes:

  • Language or region preference
  • Theme or display preference
  • Remembered interface settings, such as a collapsed panel

Consent: Consent required in jurisdictions with a consent rule for non-essential storage.

[CONFIRM BEFORE PUBLISHING] whether any preference storage exists. If none exists, delete this category rather than keeping it as boilerplate. [COOKIE INVENTORY REQUIRED]

Analytics

Optional

Technologies used to understand how the product is used and where it fails. Possible purposes:

  • Page and feature usage counts
  • Interaction and funnel measurement, such as where registration is abandoned
  • Error and performance measurement

Consent: Consent required in the UK and EU/EEA before any analytics storage is set or read. Also relevant to opt-out rights in some US states.

Provider: [PROVIDER TO CONFIRM]. We will not describe analytics as "anonymous" or "anonymised" unless that is technically accurate. If the tool receives an IP address, a device identifier or an account identifier — even briefly, even hashed — the data is personal information and this policy will say so. [COOKIE INVENTORY REQUIRED]

[CONFIRM BEFORE PUBLISHING] which analytics tool is deployed, whether IP truncation is enabled, whether an account identifier is sent, whether cross-site or cross-device linking occurs, and whether analytics is disabled entirely for teen accounts.

Functional

Optional

Optional enhancements that are not required for the service to work. Where these exist they may include embedded media players, support chat widgets, or content loaded from another service.

  • Embedded media or player storage — [CONFIRM whether any embedded player is used, including for profile music]
  • Support or help widget — [CONFIRM whether one is deployed]

Consent: Consent required where the function is not strictly necessary.

[CONFIRM BEFORE PUBLISHING] the contents of this category, or delete it. [COOKIE INVENTORY REQUIRED]

Advertising and tracking

Not asserted either way

MyLOL is intended to operate primarily through subscriptions rather than advertising. This draft deliberately does not include an advertising section, and equally does not yet claim that no advertising technologies exist.

  • [CONFIRM NO ADVERTISING/TRACKING TECHNOLOGIES] — required before any statement that MyLOL uses none
  • The confirmation must cover: advertising pixels, conversion tags, retargeting tags, social share/embed scripts that set identifiers, affiliate or attribution SDKs, and any marketing-platform script on the marketing site

Consent: Consent required where such technologies exist. Additional restrictions apply where users are minors.

If the confirmation comes back clean, this category is replaced by a single plain statement that MyLOL uses no advertising or cross-site tracking technologies. If anything is found, it must be disclosed in full, and its use on teen surfaces reviewed separately before launch.

[ATTORNEY REVIEW REQUIRED] — profiling-based advertising to minors is prohibited or restricted in several markets, including under the EU Digital Services Act and several US state laws. No advertising technology may be enabled on teen surfaces without a specific legal determination.

Age assurance and security technologies

Assessment required

Age and identity checks are typically performed by a specialist provider whose code or hosted flow runs during registration. That provider may set its own storage or read device signals — for example to keep the state of a check, to detect a repeated attempt, or to detect spoofing.

  • Verification session state during a check — [PROVIDER TO CONFIRM]
  • Anti-spoofing and repeat-attempt signals — [PROVIDER TO CONFIRM]
  • Whether the provider sets a persistent identifier that survives the check — [CONFIRM]
  • Whether the provider's storage is set before or after a consent decision — [CONFIRM]

Consent: Depends on the specific technology and the market.

How verification data itself is processed and retained is set out in the Privacy Policy, Section 5. This policy only addresses what is stored on, or read from, your device.

[ATTORNEY REVIEW REQUIRED] — do not blanket-classify age-assurance and fraud technologies as strictly necessary. Some elements may qualify (completing a check the user initiated); others, such as persistent device identifiers used for cross-session risk scoring, may not. Each requires a separate assessment, and the classification must be recorded per item in the inventory.[CONFIRM BEFORE PUBLISHING] the payment flow separately: [PAYMENT PROCESSOR] scripts and iframes commonly set their own storage for fraud prevention, and their classification must be justified rather than assumed.

Cookie and technology table

This table is published with the policy. It is empty because the inventory has not been supplied, and it will not be populated with placeholder or example entries.

NameProviderPurposeCategoryDurationFirst / third party
[COOKIE INVENTORY REQUIRED] — no verified entries. Inventing entries here would misstate what MyLOL does on members' devices, which is exactly the harm this policy exists to prevent.

Required technical cookie inventory

Engineering must complete one row per technology, per surface, before this policy can be published. A technology may not be described in the policy until every field is answered.

Fields required per technology

  • Name / storage key
  • Domain
  • Provider
  • Purpose
  • Category
  • First or third party
  • Data accessed
  • Duration
  • Session or persistent
  • Necessary or optional
  • Countries where used
  • Consent requirement

Surfaces to inventory

  • www.mylol.com — marketing site, including any font, media or embed host
  • app.mylol.com — teen application
  • app18.mylol.com — adult application
  • Registration flow, including age assurance and any parental-authorisation step
  • Login, session refresh and account recovery
  • Payment and subscription flows, including any processor iframe or hosted page
  • Chat and real-time social features, including websocket or presence identifiers
  • Photo and media upload, including any CDN or transformation service
  • Email and notification links, including any open- or click-tracking pixel
  • Support and help surfaces, if any widget is embedded
  • Native or mobile app SDKs and any installation identifier, if apps exist

Additional questions per technology

  • Whether the technology is set before or after a consent decision — anything non-essential set before consent is a compliance defect, not a documentation gap
  • Whether it is present on teen surfaces, adult surfaces, or both
  • Whether it can be disabled without breaking the service, and what degrades if it is
  • Whether it is read cross-site or cross-device
  • Whether the data reaches a third party, and in which country
  • Whether the value is or contains an identifier that can be linked to an account
  • The legal justification if it is claimed to be strictly necessary

Your choices

Where consent is required, we ask for it through a consent banner the first time you visit, and no optional technology is set or read until you make a choice. Strictly necessary technologies are always active because the service cannot work without them.

You can accept optional technologies, reject them, or open the preference centre and choose category by category. Rejecting optional technologies keeps MyLOL working — you may lose optional conveniences, not access.

You can change or withdraw your choice at any time from Cookie settings, which is available in the footer of every page and in account settings. Withdrawing consent stops future use and, where technically possible, clears the storage already set. [CONFIRM the clear-on-withdrawal behaviour once implemented.]

You can also control cookies in your browser settings, including deleting existing cookies and blocking new ones. Blocking strictly necessary cookies will prevent login from working.

No dark patterns

  • "Reject optional cookies" appears at the same level as "Accept optional cookies", with the same size, prominence and styling.
  • Rejecting takes one click, exactly like accepting. Rejection is never buried behind an extra screen.
  • No pre-ticked optional categories, no "legitimate interest" toggles switched on by default, no confirm-shaming language.
  • No cookie wall: content is not withheld from members who reject optional technologies.
  • The banner does not reappear on every page to pressure a change of mind.
[ATTORNEY REVIEW REQUIRED] — confirm the banner design against ICO guidance on consent and on the equivalence of reject and accept, EDPB guidance on deceptive design, and CNIL's rules on refusal being as easy as acceptance.

Teen members and cookie choices

The teen community is designed to a higher privacy standard, and that extends to what runs on a teen member's device.

Optional technologies on teen surfaces are treated with more caution than on adult surfaces. Where a consent-based technology cannot be explained clearly enough for a young member to make a real choice, the correct answer is not to run it.

[CONFIRM which optional categories, if any, are offered at all on teen surfaces. The defensible position is that teen surfaces run strictly necessary technologies only, but that must be confirmed against what is actually deployed rather than asserted here.]

No claim about behavioural advertising or profiling of teen members appears in this draft, in either direction, until the confirmation in the advertising category above is complete.

For teen members: Plain version: on the teen side we try to run only what the site genuinely needs. If we ever offer optional extras, we'll ask you first, in words that actually make sense.

[ATTORNEY REVIEW REQUIRED] — ICO Children's Code expectations on the validity of a child's consent, on high-privacy defaults, and on transparency written for the age of the audience. Where consent from a minor cannot be relied upon, the technology should not be deployed on teen surfaces.

Changing your consent

Open Cookie settings from the footer of any page, or from account settings when you are logged in, and change any category. Your choice takes effect immediately and is remembered on that browser.

Because your choice is stored on the device, you may need to set it again on a different browser or device, or if you clear your browser storage.

[CONFIRM the exact location and label of the settings entry point once the consent tool is deployed, and confirm that a record of consent — what was agreed, when, and to which version — is retained as evidence.]

Cookie banner copy

Proposed copy. The bracketed purpose list must be replaced with the categories that actually exist after the inventory, and any category that does not exist must be removed from both the banner and the preference centre.

Preview

Cookies on MyLOL

MyLOL uses necessary technologies to keep the site secure and working. With your permission, we may also use optional technologies for [ACTUAL PURPOSES — e.g. analytics]. You can change your mind at any time in Cookie settings.

Accept optional cookies Reject optional cookies Manage choices

Links: Cookie Policy · Privacy Policy

Banner rules

  • Show before any optional technology is set or read.
  • Do not include a category in the banner text that does not exist in the inventory.
  • If, after the inventory, the only technologies used are strictly necessary, do not show a consent banner at all — show a short notice in the footer instead. A consent banner that asks permission for nothing is its own form of dark pattern.
  • Teen surfaces: [CONFIRM whether any banner is shown, and if so, that the wording is readable by a 13-year-old.]

Preference-centre categories

Only categories confirmed by the inventory may appear. Each category lists the technologies in it, their provider, purpose and duration, drawn from the same inventory that feeds the cookie table.

CategoryDefaultStatus
Strictly necessaryAlways on, no toggleExplain why each item qualifies; do not use this category as a dumping ground
PreferencesOff by default[CONFIRM the category exists]
AnalyticsOff by default[CONFIRM provider and configuration]
FunctionalOff by default[CONFIRM the category exists]
Advertising / trackingCategory omitted unless the inventory finds any[CONFIRM NO ADVERTISING/TRACKING TECHNOLOGIES]

Developer implementation requirements

What must be true in the codebase before this policy is accurate.

Consent gating

  • No optional script, pixel, SDK or storage write executes before a consent decision exists. Scripts must be loaded conditionally, not merely told not to report.
  • Strictly necessary technologies are enumerated in code, not assumed by omission.
  • A single consent state is the source of truth, read by every surface (marketing site and both apps).
  • On withdrawal, stop the technology and clear the storage it set where technically possible.
  • Server-side equivalents count: any server-set non-essential cookie must respect the same gate.

Consent records

  • Store what was consented to, the timestamp, the policy/banner version, and the categories accepted.
  • Make the record retrievable for a regulator or a member request.
  • Re-ask when categories or providers materially change.

Teen surfaces

  • Ability to disable optional categories entirely for teen accounts, enforced server-side and not only in the UI.
  • Verify no third-party script on teen surfaces sets storage or identifiers.
  • Confirm teen pages are excluded from any marketing or attribution tooling.

Verification and maintenance

  • Automated scan of each surface listing every cookie and storage key set, before and after consent, run in CI and reviewed on each release.
  • Include third-party embeds, font hosts, CDNs, media players and payment iframes in the scan.
  • Regenerate the published cookie table from the inventory rather than editing it by hand, so the page cannot drift from reality.
  • Re-scan after adding any dependency that loads remote code.

Jurisdictional legal-review issues

Consent rules for device storage differ from general privacy rules and must be reviewed separately per launch market.

United Kingdom

  • PECR regulation 6 — consent required for storage or access unless strictly necessary for a service the user requested; confirm which items genuinely qualify.
  • ICO guidance on cookies and on consent-or-pay/consent design, including that rejecting must be as easy as accepting.
  • Any changes to the strictly-necessary exemption introduced by the Data (Use and Access) Act — confirm what is in force.
  • ICO Children's Code implications for consent obtained from teen members.

EU / EEA

  • ePrivacy Directive Article 5(3) as implemented in each Member State — national variations are real and material.
  • GDPR standard of consent: freely given, specific, informed, unambiguous, withdrawable, and no legitimate-interest fallback for storage consent.
  • EDPB guidance on deceptive design patterns in consent interfaces.
  • DSA restrictions on advertising based on profiling of minors.
  • Whether any national authority requires a specific refusal mechanism or banner behaviour.

France

  • CNIL cookie guidelines — refusal as easy as acceptance, consent validity period and re-asking cadence, and documentation of consent.
  • CNIL position on analytics exemptions: confirm whether the specific tool and configuration can qualify, rather than assuming it does.
  • French-language presentation of the banner and policy.

Canada

  • PIPEDA meaningful-consent guidance, including express consent for sensitive purposes.
  • Quebec Law 25 — privacy by default, transparency for technologies that identify or locate a person, and French-language requirements.
  • Whether any provincial rule affects tracking technologies used with minors.

United States

  • State privacy laws in each state of operation — opt-out of sale/sharing and targeted advertising, and whether analytics or embeds fall within those definitions.
  • Recognition of universal opt-out signals such as Global Privacy Control, where required.
  • COPPA implications of any third-party technology present on surfaces where under-13 attempts occur.
  • Restrictions on targeted advertising to known minors.

Australia

  • Privacy Act obligations relevant to online identifiers and tracking, and any reform provisions in force.
  • Whether tracking technologies are permissible on surfaces subject to social-media age restrictions.

All other markets

  • [COUNTRY LEGAL REVIEW REQUIRED] — do not assume the UK/EU consent model satisfies, or is required by, other markets. Each launch market needs its own determination.

Contact

Questions about cookies, storage or your consent choices:

[PRIVACY EMAIL]

See also our Privacy Policy at /legal/privacy and our Terms of Service at /legal/terms.