Cookie Policy
Every cookie and storage item we set, and how to change your mind.
This policy lists the cookies and similar storage that Stremlix uses, what each one is for, and how long it lasts. It sits alongside the Privacy Policy, which explains the wider picture of what we do with personal data.
On this page
This is the full list. If it is not here, we do not set it.
| Name | Type | Purpose | Duration | Party | Essential |
|---|---|---|---|---|---|
| stremlix.session_token | Cookie (HTTP-only) | Keeps you signed in. This is the session itself. | 7 days | First party | Yes |
| stremlix.session_data | Cookie (HTTP-only) | A short-lived signed cache of your session so every page load does not hit the database. | 5 minutes | First party | Yes |
| stremlix.dont_remember | Cookie (HTTP-only) | Set only if you sign in without asking to be remembered, so the session ends with the browser. | Session | First party | Yes |
| stremlix_cid | Cookie | A random identifier that ties your cookie choices to this browser. It is not linked to you until you sign in, and carries no information about you. | 400 days | First party | Yes |
| stremlix_consent | Cookie | Records the choices you made in the banner and the policy version they were made against, so the page can honour them without waiting for a server round trip. | 400 days | First party | Yes |
| theme | Local storage | Remembers whether you chose light or dark mode. | Until you clear it | First party | No — set only with your Preferences consent |
| sentryReplaySession | Session storage | Groups the events of one visit together when an error report is sent. Text and media are masked before anything leaves your device. | Until the browser tab is closed | First party | Yes — error diagnostics |
We set no advertising cookies and no profiling cookies today, and nothing on this list is used to build a profile of you or to target advertising. stremlix_consent is our own format; it is not an IAB TC string and must not be read as one.
The banner asks per purpose, not as one switch. These are the purposes, in the order they appear, taken directly from the same definition the banner is built from — so this list and the banner cannot disagree.
| Purpose | What it covers | Default |
|---|---|---|
| Strictly necessary | Sign-in, session security, and remembering your cookie choice. The app cannot work without these. | Always on |
| Security and abuse prevention | Detecting suspicious sign-ins, rate-limiting abuse, and keeping accounts safe. | Always on |
| Preferences | Remembering choices like your theme so the app looks the same next visit. | Off until you turn it on |
| Analytics | Understanding which features are used so we can improve them. | Off until you turn it on |
| Store and access information on your device | Allowing cookies or similar storage to be read for the purposes below. | Off until you turn it on |
| Basic advertising | Showing ads that are not based on a profile of you. | Off until you turn it on |
| Build a profile for personalised advertising | Combining information about you to select ads that may be more relevant. | Off until you turn it on |
| Personalised advertising | Using that profile to choose which ads you see. | Off until you turn it on |
| Measure advertising performance | Reporting on whether ads were seen and whether they worked. | Off until you turn it on |
| Develop and improve services | Using aggregate insight to build and refine features. | Off until you turn it on |
Purposes marked "Always on" are either necessary to perform the contract you have with us or rest on our legitimate interest in keeping accounts secure; they are not consent-based and cannot be switched off while you use the Service. Everything else is off until you turn it on.
A choice you make lasts 12 months, after which we ask again. Publishing a new policy version also causes us to ask again.
Stremlix is not an IAB-registered Consent Management Platform, and nothing here is TCF-certified.
Our purpose list is deliberately shaped like the IAB TCF list so that a certified platform could be adopted later without discarding the consent already collected. That is a design choice about data portability. It is not a claim of certification, and we do not emit a TC string.
You can change or withdraw your cookie choices at any time, and withdrawing is as easy as giving. This control is also in the footer of every page.
Turning a purpose off stops the corresponding storage from being written from that point on, and the application keeps working. Nothing you pay for depends on saying yes.
Your browser can also block or delete cookies and site storage. Look for “Cookies and site data”, “Privacy and security”, or “Manage website data” in your browser's settings, and for the per-site controls in the address bar.
Blocking all cookies will sign you out and prevent you from signing back in, because the session cookie is how the Service knows who you are. Clearing site data also clears your recorded cookie choices, so we will ask again on your next visit.
On mobile, deleting the app removes its local storage. Data held in your account on our servers is unaffected until you delete the account.
We do not embed advertising networks, social widgets, or third-party analytics tags in the Service, so no third party sets a cookie through our pages today.
Some third parties are involved in the Service without setting cookies here: Stripe processes payments on its own pages, Sentry receives error reports, and Apple or Google handle sign-in when you choose those options. Their own policies govern what they do on their own surfaces.
When you play a stream, your device talks to your IPTV provider directly. Anything that provider stores on your device is theirs, is governed by their policy, and is outside our control — we do not host or transmit that content.
We treat a Global Privacy Control (GPC) signal as a refusal of all non-essential purposes. If your browser sends one, we do not need to ask, and we will not set non-essential storage.
We do not respond to the older Do Not Track header, which was never given an agreed meaning. It makes no practical difference here: we set no advertising or tracking cookies for it to disable.
We do not sell or share personal data for cross-context behavioural advertising, so there is no such sale for an opt-out signal to stop.
If we add a cookie, add a purpose, or change what an existing one does, we update this page, increase the version number shown at the top, and ask for your choices again before the new purpose takes effect.
| Version | Effective | What changed |
|---|---|---|
| 1 | 2026-08-18 | First published version. |
Questions about this policy can be sent to [TODO(owner): legal / notice email address]. MAFFEITECH INFORMATION TECHNOLOGY L.L.C, Dubai, United Arab Emirates.