Bima

Bima · Read in Hebrew

Cookies Policy

Last updated: 19 August 2026

1. The cookies - complete list

  • bima_session - signed-in staff session. httpOnly, Secure, SameSite=Lax. 3 days, renewed on activity; expires after 2 hours idle.
  • bima-csrf - cross-site request forgery protection token. Readable by the browser on purpose so it can be echoed in a header. Secure, SameSite=Lax, 7 days.
  • bima_view - viewing session of a viewer who entered a code: session id, broadcast id, watermark reference. httpOnly, Secure, SameSite=Lax, 12 hours.
  • bima-goauth - temporary state for Sign in with Google, cleared when sign-in completes. httpOnly, Secure, 10 minutes, scoped to the sign-in path.
  • bima_consent - your choice about measurement cookies (accepted or declined), created only after you answer the banner on the public pages. Secure, SameSite=Lax; 12 months after accepting, 6 months after declining.

2. Browser storage

The player keeps in browser memory (not a cookie) a short-lived 120-second playback token that renews automatically. It is gone when the tab closes.

3. Measurement cookies - public pages only, only after consent

The public information pages (home, features, guides) show a banner. Only if you click Accept does Google Tag Manager load, and through it Google Analytics 4 (counting visits and paths on the site) and Google Ads conversion measurement (whether an enquiry came from a campaign). Ad personalization (remarketing) is switched off. Declining, or not answering, loads nothing. You can change your choice any time via the Cookie settings link at the bottom of the page.

  • _ga, _ga_<id> - Google Analytics 4: an anonymous browser identifier for counting visits. Up to two years (Google's default).
  • _gcl_au - Google Ads: links an ad click to your enquiry, for campaign measurement. 90 days.
  • doubleclick.net cookies (e.g. IDE, test_cookie) - may be set if Google needs them for conversion measurement; Google's privacy policy applies to them.

4. Third-party cookies

On viewer pages, the console and sign-in: none. Every file the site loads there, including the player library (hls.js), is served from our servers, and we load no Google scripts on them. Sign in with Google happens on Google's site under Google's privacy policy. On the public information pages only, and only after consent, Google scripts load for the measurement described in section 3.

5. Managing

You can delete cookies from your browser settings at any time; the effect is signing out of the account or the broadcast. Blocking cookies prevents entering the service, since they are our only way to recognize a session.