Cookie & Similar Technologies Policy
Website, PWA and analytics tools · version 0.9, 27 August 2026
Moru — website, PWA and related analytics/marketing tools
| Controller | MORU-TECH Ltd., UIC 208895389 |
|---|---|
| Product | Moru: web application/PWA and desktop widget |
| Version and date | 0.9 / 27 August 2026 |
| Status | Public document and UX text — working draft |
Legal framework: Regulation (EU) 2016/679 (GDPR), the Bulgarian Personal Data Protection Act, applicable rules on electronic communications, and the national implementing legislation.
1. What this Policy covers
This Policy explains how Moru uses cookies, localStorage, sessionStorage, IndexedDB, SDKs, pixels, identifiers and other technologies that read or write information on a terminal device. The rules apply regardless of whether the technology is technically called a "cookie".
2. Categories of technologies
| Category | Purpose | Mode |
|---|---|---|
| Strictly necessary | Login and session, security, abuse protection, remembering privacy choices, language, core PWA operation and a local buffer during temporary loss of network connectivity. | Always active, but only to the extent genuinely necessary. |
| Analytics and diagnostics | GA4/GTM, PostHog, usage measurement, normalized errors and product funnels. | Only after opt-in consent. |
| Marketing | Google Ads and Meta Pixel for campaign measurement and remarketing, where used. | Only after separate opt-in consent. |
| Functional | Optional preferences that are not necessary for the core service. | After the user chooses them, if introduced. |
3. Strictly necessary technologies
| Technology | Purpose | Retention | Provider |
|---|---|---|---|
| GoTrue/session JWT and related session keys | Maintain login and protect the account. | Session/until logout; refresh token according to configuration. | First party |
| privacy/consent preferences | Remember analytics, marketing and health-consent choices. | Up to 12 months or until changed/withdrawn. | First party |
| language/locale | Selected interface language. | Up to 12 months. | First party |
| country cache | Coarse country for access and localisation. | Short period; recommended up to 24 hours. | First party/Cloudflare |
| montu.offlineQueue.v1 or current key | Temporary buffering of failed first-party records. | Until successful transmission, max. 7 days; delete on logout/withdrawal/deletion. | First-party localStorage |
| Cloudflare Turnstile/security tokens | Protection against automated abuse and security. | Short-lived, according to the service. | Cloudflare |
| PWA cache/service worker | Offline functionality and delivery of static resources. | Until update or user clears it. | First party |
| The offline queue must not contain health-related payloads or free text in unencrypted localStorage. If it temporarily does, this is a blocking risk and encryption, minimisation and a short TTL must be implemented. |
|---|
4. Analytics and diagnostics
| Tool | Identifier | Data/purpose | Retention | Legal basis |
|---|---|---|---|---|
| Google Analytics 4 | [GA4 Measurement ID — to be completed] | Screens, sections, general clicks, onboarding and product funnels without health data. | Up to 12 months; IP anonymisation/Google controls depending on configuration. | Consent |
| PostHog EU Cloud | [Project ID — to be completed] | Product analytics and diagnostics; autocapture and session recording disabled; field allow-list. | 12 months. | Consent |
| GTM consent state | [Container ID — to be completed] | Applies default denied and subsequent consent updates. The container itself must not send non-essential events before consent. | Until the choice changes. | Necessary only for consent management in a minimal configuration; everything else — consent |
5. Marketing technologies
| Tool | ID | Purpose and limitation | Legal basis |
|---|---|---|---|
| Google Ads | AW-18397389640 | Advertising campaign measurement and, only after a separate choice, audiences/remarketing. No health or camera-derived data are sent. | Marketing consent |
| Meta Pixel | 1710901016659152 | Campaign measurement and, only after a separate choice, audiences. No health or camera-derived data are sent. | Marketing consent |
6. Data prohibited from being sent to third parties
The following categories are not sent to GA4, PostHog, Google Ads, Meta Pixel or other analytics/advertising platforms, even where the user has consented to analytics or marketing:
symptoms and onboarding options such as dry_eyes, headaches, blurred_focus and eye_tension;
fatigue score, eye-strain score, PERCLOS, blink rate, screen distance, head position and confidence;
calibration vectors, session_trace, gaze trajectories and health labels;
free text, email address, JWT, UUID in clear form, raw error messages or form content;
camera-permission information that allows sensitive inferences, except a minimal first-party technical event necessary for support.
| Correction to the GA4 specificationThe GA4 specification contains events for symptoms, scores and camera/calibration errors. These events must be removed or transformed into non-sensitive aggregated markers before real deployment. |
|---|
7. Banner text — first layer
| Cookies and privacyWe use strictly necessary technologies so that login, security and Moru’s core functions work. With your consent, we separately use analytics/diagnostics and marketing technologies. They remain disabled until you make a choice. We do not send health indicators or camera data to analytics or advertising platforms. You can change your choice at any time in the Privacy Center. |
|---|
| Button | Text and action |
|---|---|
| Accept | “Accept all” — enables analytics and marketing. |
| Reject | “Reject optional” — leaves only strictly necessary technologies active. |
| Settings | “Settings” — opens the second layer with separate toggles. |
| Link | “Cookie Policy” |
The accept and reject buttons must be equally visible, no option may be preselected, and the banner must be localised into all 12 service languages.
8. Settings — second layer
| Category | Default | Description |
|---|---|---|
| Strictly necessary | Always active | Needed for login, security, remembering privacy choices and core operation. |
| Analytics and diagnostics | Off by default | GA4 and PostHog for product events without health data. |
| Marketing | Off by default | Google Ads and Meta Pixel for campaign measurement. |
| Button | Text |
|---|---|
| Save | “Save choices” |
| All | “Accept all” |
| Necessary only | “Strictly necessary only” |
9. Consent mode and technical criteria
On first load, consent state is denied for analytics_storage, ad_storage, ad_user_data and ad_personalization.
Non-essential scripts, pixels and SDKs do not send network requests before a positive choice.
The banner display/choice event is recorded first-party and is not sent to GA4 before consent.
On withdrawal, GA4/PostHog/Ads/Meta stop and the application deletes or resets the relevant first-party identifiers where technically possible.
The setting remains permanently accessible in the Privacy Center.
Every release includes an automated clean-browser test for decline and accept scenarios and a list of all external requests.
No cookie wall is used for the core service.
10. How the user changes their choice
Profile → Privacy Center → "Cookies and analytics". The new choice applies prospectively. Withdrawal does not affect the lawfulness of prior processing, but no new non-essential events are sent.
11. Updating the table
Before publication, the technical team performs an automated scan of the website/PWA and completes the exact names, domains, retention periods and identifiers. The Policy is updated when a new SDK, pixel, provider or purpose is introduced.
Sources and legal basis
Regulation (EU) 2016/679, in particular Articles 5, 6, 7, 9, 12–22, 24–25, 28, 30, 32–36 and 44–49.
EDPB Guidelines 05/2020 on consent.
EDPB Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive.
EDPB Cookie Banner Taskforce Report (2023).