Cookie Policy
1. Introduction
This Cookie Policy explains how Oh My Lore! (“we”, “us”, “our”) uses cookies and similar technologies on our websites (ohmylore.app, ohmylore.eu, ohmylore.quest) and in the Oh My Lore! mobile application.
It should be read together with our Privacy Policy, which explains how we handle personal data more broadly.
This Policy is governed by:
- The GDPR (Regulation (EU) 2016/679)
- The ePrivacy Directive (Directive 2002/58/EC)
- Czech Act No. 127/2005 Sb. (Electronic Communications Act), which requires prior opt-in consent for non-essential cookies.
2. What Are Cookies and Similar Technologies?
Cookies are small text files placed on your device by a website. They let the site remember things about your visit.
Similar technologies include localStorage, sessionStorage, IndexedDB, and tracking pixels. For simplicity, we refer to all of them collectively as “cookies” in this Policy.
First-party cookies are set by Oh My Lore! itself.
Third-party cookies are set by services we use (e.g. Google, Polar).
3. Cookies We Use
The exact cookies set can change as we update the Service. We maintain this table as accurately as possible and review it regularly. The categories and purposes below are always current.
| Name | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
Firebase Auth session (IndexedDB firebaseLocalStorage) |
Oh My Lore! / Google Firebase | Keeps you logged in across page loads | Strictly necessary | Session / up to 1 year |
| Firestore offline cache (IndexedDB) | Oh My Lore! / Google Firebase | Makes the Service usable briefly when offline | Strictly necessary | Until cache is cleared |
| CSRF protection token | Oh My Lore! | Prevents cross-site request forgery | Strictly necessary | Session |
| Theme / language preferences (localStorage) | Oh My Lore! | Remembers your display preferences | Functional | Until you clear storage |
Consent preferences (localStorage oml.consent) |
Oh My Lore! / Klaro consent manager | Remembers your cookie consent decisions | Strictly necessary | 12 months (then re-asked) |
| Polar checkout session | Polar Software, Inc. | Secure checkout session and fraud prevention on Polar-hosted checkout pages | Strictly necessary (checkout only) | Session |
| Loops email pixel | Loops, Inc. | Newsletter / wishlist sign-up and delivery of transactional email you request | Functional | Varies |
| Google reCAPTCHA | Google Ireland Ltd. | Bot and abuse protection on forms (e.g. sign-up, wishlist) | Functional / security | Up to 6 months |
We will update this table as we audit production and change our stack.
4. Categories We Use
Strictly Necessary
These are essential for the Service to function. They do not require your consent, but we list them for transparency. Without them, you cannot log in, stay logged in, complete payments, or use core features.
Functional
These remember your preferences (theme, language) to improve your experience. Under Czech law, these generally require consent unless the user clearly initiated the preference.
Analytics
We do not use analytics cookies. Google Analytics / Firebase Analytics has been removed from the Service. If this changes, we will update this Policy and request fresh consent before setting any analytics cookie.
Advertising / Targeting
We do not use advertising or targeting cookies. If this changes, we will update this Policy and request fresh consent.
5. Third-Party Cookies
Some cookies are set by services we embed:
- Firebase (Google Ireland Ltd. / Google LLC) — authentication, storage. See above.
- Polar Software, Inc. — Merchant of Record / payments. Polar Privacy Policy. Polar checkout pages may set session cookies for fraud prevention.
- Loops, Inc. — transactional and wishlist email. Loops Privacy Policy. May include a delivery/open pixel in emails you receive.
- Google reCAPTCHA (Google Ireland Ltd.) — bot and abuse protection on forms. Google Privacy Policy.
Web fonts are self-hosted on our own servers — loading our pages sends no font request to Google or any other third-party CDN.
6. How to Manage Your Preferences
In-App
- At launch: Oh My Lore does not show a cookie banner. Only strictly necessary services run when you open the app, so there is nothing to consent to up front. Optional services (payments, wishlist email, form protection) ask in context, at the moment you actually use them.
- Any time: Open the consent dialog at https://ohmylore.app/?cookie-settings=1, or via the “Cookie & consent preferences” link on the sign-in screen and in the user menu, to review or change your choices service-by-service.
Changing your choice is as easy as giving the original consent. You will not lose access to the Service by declining optional cookies.
Browser Level
You can also manage cookies in your browser settings. Instructions:
7. Withdrawing Consent
You can withdraw consent at any time by reopening the consent dialog at https://ohmylore.app/?cookie-settings=1. Withdrawal takes effect immediately for future visits and does not affect the lawfulness of processing based on consent before withdrawal.
8. What Happens If You Block Cookies
- Blocking strictly necessary cookies: The Service will not work — you cannot log in or make payments.
- Blocking functional cookies: Preferences like theme and language will reset on each visit.
- Blocking optional cookies: No impact on core features. Some conveniences — such as spam protection on forms or newsletter sign-up — may not work.
9. Changes to This Cookie Policy
We may update this Cookie Policy when we change the cookies we use. If we add new categories requiring consent, we will ask for your consent again before activating them. The “Last updated” date at the top will always reflect the most recent version.
10. Contact
If you have questions about this Cookie Policy, please email support@ohmylore.app.
For complaints about our handling of cookies, you can contact the Czech supervisory authority, Úřad pro ochranu osobních údajů (ÚOOÚ), at https://www.uoou.cz/.