Cookies Policy
Bima uses four cookies only, all strictly necessary. No analytics cookies, no advertising cookies, no cross-site tracking - hence no consent banner: under the law (ePrivacy Art. 5(3) and the Israeli Privacy Protection Law) strictly necessary cookies need no consent. If we ever add analytics we will add a consent mechanism first and update this document.
1. The cookies - complete list
- bima_session - signed-in staff session. httpOnly, Secure, SameSite=Lax. 3 days, renewed on activity; expires after 2 hours idle.
- bima-csrf - cross-site request forgery protection token. Readable by the browser on purpose so it can be echoed in a header. Secure, SameSite=Lax, 7 days.
- bima_view - viewing session of a viewer who entered a code: session id, broadcast id, watermark reference. httpOnly, Secure, SameSite=Lax, 12 hours.
- bima-goauth - temporary state for Sign in with Google, cleared when sign-in completes. httpOnly, Secure, 10 minutes, scoped to the sign-in path.
2. Browser storage
The player keeps in browser memory (not a cookie) a short-lived 120-second playback token that renews automatically. It is gone when the tab closes.
3. Third-party cookies
None. Every file the site loads, including the player library (hls.js), is served from our servers. Sign in with Google happens on Google's site under Google's privacy policy; we load no Google scripts on our pages.
4. Managing
You can delete cookies from your browser settings at any time; the effect is signing out of the account or the broadcast. Blocking cookies prevents entering the service, since they are our only way to recognize a session.