← All documents

Cookie & Similar Technologies Policy

Website, PWA and analytics tools · version 0.9, 27 August 2026

Moru — website, PWA and related analytics/marketing tools

ControllerMORU-TECH Ltd., UIC 208895389
ProductMoru: web application/PWA and desktop widget
Version and date0.9 / 27 August 2026
StatusPublic document and UX text — working draft

Legal framework: Regulation (EU) 2016/679 (GDPR), the Bulgarian Personal Data Protection Act, applicable rules on electronic communications, and the national implementing legislation.

1. What this Policy covers

This Policy explains how Moru uses cookies, localStorage, sessionStorage, IndexedDB, SDKs, pixels, identifiers and other technologies that read or write information on a terminal device. The rules apply regardless of whether the technology is technically called a "cookie".

2. Categories of technologies

CategoryPurposeMode
Strictly necessaryLogin and session, security, abuse protection, remembering privacy choices, language, core PWA operation and a local buffer during temporary loss of network connectivity.Always active, but only to the extent genuinely necessary.
Analytics and diagnosticsGA4/GTM, PostHog, usage measurement, normalized errors and product funnels.Only after opt-in consent.
MarketingGoogle Ads and Meta Pixel for campaign measurement and remarketing, where used.Only after separate opt-in consent.
FunctionalOptional preferences that are not necessary for the core service.After the user chooses them, if introduced.

3. Strictly necessary technologies

TechnologyPurposeRetentionProvider
GoTrue/session JWT and related session keysMaintain login and protect the account.Session/until logout; refresh token according to configuration.First party
privacy/consent preferencesRemember analytics, marketing and health-consent choices.Up to 12 months or until changed/withdrawn.First party
language/localeSelected interface language.Up to 12 months.First party
country cacheCoarse country for access and localisation.Short period; recommended up to 24 hours.First party/Cloudflare
montu.offlineQueue.v1 or current keyTemporary buffering of failed first-party records.Until successful transmission, max. 7 days; delete on logout/withdrawal/deletion.First-party localStorage
Cloudflare Turnstile/security tokensProtection against automated abuse and security.Short-lived, according to the service.Cloudflare
PWA cache/service workerOffline functionality and delivery of static resources.Until update or user clears it.First party
The offline queue must not contain health-related payloads or free text in unencrypted localStorage. If it temporarily does, this is a blocking risk and encryption, minimisation and a short TTL must be implemented.

4. Analytics and diagnostics

ToolIdentifierData/purposeRetentionLegal basis
Google Analytics 4[GA4 Measurement ID — to be completed]Screens, sections, general clicks, onboarding and product funnels without health data.Up to 12 months; IP anonymisation/Google controls depending on configuration.Consent
PostHog EU Cloud[Project ID — to be completed]Product analytics and diagnostics; autocapture and session recording disabled; field allow-list.12 months.Consent
GTM consent state[Container ID — to be completed]Applies default denied and subsequent consent updates. The container itself must not send non-essential events before consent.Until the choice changes.Necessary only for consent management in a minimal configuration; everything else — consent

5. Marketing technologies

ToolIDPurpose and limitationLegal basis
Google AdsAW-18397389640Advertising campaign measurement and, only after a separate choice, audiences/remarketing. No health or camera-derived data are sent.Marketing consent
Meta Pixel1710901016659152Campaign measurement and, only after a separate choice, audiences. No health or camera-derived data are sent.Marketing consent

6. Data prohibited from being sent to third parties

The following categories are not sent to GA4, PostHog, Google Ads, Meta Pixel or other analytics/advertising platforms, even where the user has consented to analytics or marketing:

symptoms and onboarding options such as dry_eyes, headaches, blurred_focus and eye_tension;

fatigue score, eye-strain score, PERCLOS, blink rate, screen distance, head position and confidence;

calibration vectors, session_trace, gaze trajectories and health labels;

free text, email address, JWT, UUID in clear form, raw error messages or form content;

camera-permission information that allows sensitive inferences, except a minimal first-party technical event necessary for support.

Correction to the GA4 specificationThe GA4 specification contains events for symptoms, scores and camera/calibration errors. These events must be removed or transformed into non-sensitive aggregated markers before real deployment.

7. Banner text — first layer

Cookies and privacyWe use strictly necessary technologies so that login, security and Moru’s core functions work. With your consent, we separately use analytics/diagnostics and marketing technologies. They remain disabled until you make a choice. We do not send health indicators or camera data to analytics or advertising platforms. You can change your choice at any time in the Privacy Center.
ButtonText and action
Accept“Accept all” — enables analytics and marketing.
Reject“Reject optional” — leaves only strictly necessary technologies active.
Settings“Settings” — opens the second layer with separate toggles.
Link“Cookie Policy”

The accept and reject buttons must be equally visible, no option may be preselected, and the banner must be localised into all 12 service languages.

8. Settings — second layer

CategoryDefaultDescription
Strictly necessaryAlways activeNeeded for login, security, remembering privacy choices and core operation.
Analytics and diagnosticsOff by defaultGA4 and PostHog for product events without health data.
MarketingOff by defaultGoogle Ads and Meta Pixel for campaign measurement.
ButtonText
Save“Save choices”
All“Accept all”
Necessary only“Strictly necessary only”

9. Consent mode and technical criteria

On first load, consent state is denied for analytics_storage, ad_storage, ad_user_data and ad_personalization.

Non-essential scripts, pixels and SDKs do not send network requests before a positive choice.

The banner display/choice event is recorded first-party and is not sent to GA4 before consent.

On withdrawal, GA4/PostHog/Ads/Meta stop and the application deletes or resets the relevant first-party identifiers where technically possible.

The setting remains permanently accessible in the Privacy Center.

Every release includes an automated clean-browser test for decline and accept scenarios and a list of all external requests.

No cookie wall is used for the core service.

10. How the user changes their choice

Profile → Privacy Center → "Cookies and analytics". The new choice applies prospectively. Withdrawal does not affect the lawfulness of prior processing, but no new non-essential events are sent.

11. Updating the table

Before publication, the technical team performs an automated scan of the website/PWA and completes the exact names, domains, retention periods and identifiers. The Policy is updated when a new SDK, pixel, provider or purpose is introduced.

Sources and legal basis

Regulation (EU) 2016/679, in particular Articles 5, 6, 7, 9, 12–22, 24–25, 28, 30, 32–36 and 44–49.

EDPB Guidelines 05/2020 on consent.

EDPB Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive.

EDPB Cookie Banner Taskforce Report (2023).