• For Players
  • For Creators
  • About
  • Support

Cookie Policy

Version 1.0

  • Player Terms of Service
  • Creator Terms of Service
  • Acceptable Use Policy
  • Privacy Policy
  • Cookie Policy

Draft. Not in force. Not legal advice.

This policy explains what Klooz stores on your device, why, and what you can do about it. It covers cookies on our websites and the equivalent storage the mobile app uses.

The short version: Klooz uses no advertising cookies, no analytics cookies and no third-party tracking. Everything listed below is either required to sign you in and let you play, or remembers a preference you set. That is why you do not see a cookie banner.


1. What these technologies are

Cookies are small text files a website asks your browser to store and send back on later visits.

Local storage and session storage are browser stores a site can read and write. They hold more, and they are not sent with every request.

Secure storage on a phone is the operating system's protected keystore, used for things like login tokens.

The law treats all of these the same way: they are storage on your device, and the rules in Article 5(3) of the ePrivacy Directive apply to each of them. So does this policy.

2. Categories we use

Category Used by Klooz Needs your consent
Strictly necessary: sign-in, security, and the storage without which play does not work Yes No. Exempt under Article 5(3) ePrivacy Directive, because you cannot have the service you asked for without them
Preference: remembers a choice you made, like light or dark theme Yes, one item Treated as consent-based; you set it yourself by choosing the option
Analytics: measuring how the product is used No. None. N/A
Advertising / tracking: profiling, retargeting, ad measurement No. None. N/A

We do not share device storage data with advertisers, data brokers or social networks, because we do not collect it.

3. What is stored: website

3.1 Sign-in and security (strictly necessary)

Set by the Klooz player website, using Auth.js:

Name Type Purpose Lifetime
authjs.session-token (__Secure-authjs.session-token over HTTPS) Cookie Keeps you signed in Session or until sign-out
authjs.csrf-token (__Host-authjs.csrf-token) Cookie Protects against cross-site request forgery Session
authjs.callback-url Cookie Returns you to the page you were on after sign-in Session
authjs.pkce.code_verifier Cookie Secures the sign-in exchange (OAuth PKCE) A few minutes, during sign-in
authjs.state Cookie Ties a sign-in response to the request that started it A few minutes, during sign-in

Set by our identity service (Keycloak), on its own domain, when you sign in:

Name Type Purpose Lifetime
AUTH_SESSION_ID Cookie Identifies your authentication session Session
KEYCLOAK_IDENTITY Cookie Your signed-in identity for single sign-on Session, or the configured SSO lifetime
KEYCLOAK_SESSION Cookie Single sign-on session reference Session
KC_RESTART Cookie Recovers an interrupted sign-in A few minutes
KC_AUTH_STATE Cookie Sign-in flow state A few minutes

Some of these have a _LEGACY counterpart, sent for browsers that do not support the SameSite attribute. Same purpose, same lifetime.

These cannot be turned off. Blocking them means you cannot sign in.

3.2 The creator studio (strictly necessary)

The studio is a browser application. It uses local storage to hold your work, so that a reload or a lost connection does not lose it.

Name Store Purpose Lifetime
studio-draft-<experience id> Local storage An unsaved snapshot of the experience you are editing Until saved to the server or cleared
studio-seed-positions-<experience id> Local storage Positions of nodes on the editing canvas Until saved or cleared
klooz-studio-ui Local storage Studio layout state, which panels are open Until cleared
klooz-studio-right-panel-width Local storage Width you dragged the properties panel to Until cleared

None of these are sent to anyone. They stay in your browser and are readable only by the studio.

3.3 Preference

Name Store Purpose Lifetime
klooz-theme Local storage Whether you chose the light or dark theme Until cleared

If it is not set, we follow your operating system's setting and store nothing.

3.4 Payments (applies once paid tickets go live)

When you pay for a ticket you are taken to Stripe Checkout, on checkout.stripe.com. Stripe sets its own cookies on its own domain to detect fraud and keep your checkout session:

Name Purpose Lifetime
__stripe_mid Fraud prevention, identifies the device across checkouts 1 year
__stripe_sid Fraud prevention, the current checkout session 30 minutes

These are set by Stripe as its own controller, and are necessary to take a payment safely. Stripe's cookie information: https://stripe.com/legal/cookies-policy.

Drafting note. If Stripe.js is ever embedded directly in a Klooz page rather than used via a redirect to Checkout, these cookies become first-party-context and the analysis has to be redone. Today the player app redirects.

4. What is stored: mobile app

The app does not use cookies. It stores the following on your device. All of it is necessary for the app to work, and none of it is shared with third parties for advertising.

What Where Purpose Lifetime
Sign-in tokens Secure storage (iOS Keychain / Android Keystore) Keeps you signed in Until you sign out
klooz_device_id Secure storage A random identifier for this installation, so offline play can be attributed to the right device and a session can be recovered Until you uninstall or sign out
Offline content packs, experience, media, offline map App storage Lets you play with no signal Until you delete the pack or uninstall
Event journal App storage Records what you did during offline play, uploaded when you reconnect Until uploaded and confirmed, then cleared
Theme preference App storage Light or dark Until cleared

Deleting the app removes all of it.

Device permissions (location, camera, notifications, storage) are separate from this and are covered in Player Terms §5 and the Privacy Policy.

5. Why there is no cookie banner

Under Article 5(3) of the ePrivacy Directive, storage that is strictly necessary to provide a service you explicitly asked for does not require consent. Sign-in, security and the studio's draft storage are exactly that: without them you cannot sign in or keep your work.

The one preference item, klooz-theme, is written only when you choose a theme yourself, holds no personal data, and is never sent anywhere.

Since we run no analytics, advertising or tracking technologies, there is nothing to ask you to consent to, so we publish this policy instead of interrupting you with a banner that has no real choice in it.

If that changes, this changes. Before we introduce any analytics, measurement or marketing technology we will publish an updated policy with a new policy_id and present a consent mechanism that lets you refuse as easily as accept, with nothing non-essential set before you choose.

Drafting note, for whoever adds the first analytics tag. This is the section that stops being true that day. The work is: a consent banner with equally prominent accept and reject, granular categories, no non-essential storage before a choice, a way to withdraw consent as easily as it was given, a consent log, and this table updated. The EDPB reads "strictly necessary" narrowly; product analytics does not qualify, and neither does a "we use cookies, OK" bar.

6. Managing storage yourself

In your browser you can view, block and delete cookies and local storage in the settings, see the help pages for Chrome, Safari, Firefox and Edge.

Be aware that blocking storage for klooz.io will sign you out, and will lose any unsaved work in the studio.

In the mobile app, sign out to clear tokens, delete downloaded packs from the app's storage settings, or uninstall the app to remove everything.

Do Not Track and Global Privacy Control signals: we do not track you, so there is nothing for these signals to change. We will honour them if that ever stops being true.

7. Personal data

Some of what is described here (a session token, a device identifier) is personal data under the GDPR. How we handle personal data, on what lawful basis, for how long, and how to exercise your rights of access, correction, deletion, objection and portability, is set out in the Privacy Policy.

Data controller: [FULL NAME], egyéni vállalkozó, [ADDRESS]. Contact: [PRIVACY EMAIL].

You may complain to the Hungarian supervisory authority, the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9-11, or to the authority where you live.

Full details: Privacy Policy.

8. Changes

We will update this policy when what we store changes. Material changes get a new policy_id, and (where the change introduces anything requiring consent) a consent prompt.

Last reviewed against the codebase: 2026-07-31.

Maintenance note. This inventory was taken from the source, not from a template. It goes stale the moment a dependency adds storage. Re-check it whenever the auth library, the payment flow, or the mobile storage layer changes, and before every release that adds a third-party script.

Klooz

  • Home
  • For Players
  • For Creators
  • About

Legal

  • Player Terms
  • Creator Terms
  • Acceptable Use
  • Privacy Policy
  • Cookie Policy

Support

  • Contact