Cookie Policy
This Policy explains the browser technologies Pulscam uses for authentication, security, age controls, preferences and future optional integrations.
1. Scope and relationship with the Privacy Policy
This Policy explains how Pulscam uses cookies, localStorage, sessionStorage and similar browser technologies for authentication, security, adult-access controls, preferences and platform operation.
It supplements the Privacy Policy. Where a browser identifier or stored value is linked to an account, device or identifiable person, the Privacy Policy also applies.
2. Storage categories
3. Current source-level inventory
A consolidated source scan identified browser-storage references used or contemplated for authentication, short-lived submission protection, account-setting tabs, broadcast-device preferences, dismissed safety notices, testing or debugging controls and related interface state.
The inventory includes both active keys and legacy or fallback references. Presence in source code does not prove that every item is written in every session. Pulscam must continue to reconcile source, browser runtime and provider documentation before public launch.
When Analytics is enabled, the browser-storage inventory also includes a random first-party analytics visitor identifier, a short analytics session identifier and the category-specific Analytics consent proof described below. These Analytics items are not used before the Analytics consent gate is satisfied.
4. Strictly necessary storage
Strictly necessary storage may operate without an optional-cookie choice where it is required to provide a feature requested by the user, maintain login or account security, remember an adult-access decision, preserve a consent selection, protect a form from repeated submission or prevent fraud and abuse.
Disabling or clearing necessary storage may sign the user out, reset age or consent choices, disable security controls or prevent requested functionality.
5. Preference storage
Preference storage may remember selected account tabs, interface state, device or broadcast choices and whether a safety notice was dismissed.
Preference storage that is not strictly necessary must remain subject to the applicable consent choice. A setting must not be classified as necessary merely because it is convenient.
6. First-party Analytics and marketing status
Pulscam may use its own first-party Analytics only after the user affirmatively enables the Analytics category. Analytics is optional, is not required for the core service and does not authorize marketing storage.
When enabled, first-party Analytics may measure page views, sessions, acquisition source and product engagement using a random browser analytics identifier and a short analytics session identifier. The server stores pseudonymous HMAC-derived values rather than the raw browser identifier. Marketing remains disabled unless it is separately activated, documented and subject to any required consent.
Rejecting Analytics or other optional storage does not block the core service. Closing or ignoring the consent interface does not activate an optional category.
7. Consent banner and choices
The consent interface may offer Accept all, Reject optional and Settings. Necessary storage remains available because it supports core security and requested functions.
Consent for optional storage must be a clear affirmative choice, must not be preselected and must be as easy to withdraw as to give. A refusal must be recorded without activating the refused category.
For server-side Analytics consent enforcement, the consent component uses the first-party cookie __Host-pulscam_analytics_consent_v1. It records the current consent version and whether the Analytics category is enabled or disabled. It is used to verify the Analytics choice before the server accepts Analytics events. The cookie uses Secure, Path=/ and SameSite=Lax.
8. Changing or withdrawing choices
Users may change optional-cookie choices through the available cookie settings. They may also clear browser storage through browser controls, although this can sign them out or reset preferences.
Withdrawal applies to future optional processing and does not make earlier lawful processing unlawful. Pulscam must stop or disable the relevant optional integration after the withdrawal is recorded, subject to reasonable technical propagation.
If Analytics consent is withdrawn, the Analytics consent proof is changed to the disabled state immediately, pending unsent Analytics events are discarded and the Analytics visitor and session identifiers are removed from browser storage. Resetting the consent record deletes the Analytics consent proof cookie. The general consent shadow cookie by itself does not authorize Analytics.
9. Duration and retention
Some browser values last only for a session. Others may remain until an expiry date, logout, account action, replacement by a newer value or manual clearing by the user.
Before production launch, Pulscam must maintain an approved inventory stating the name or category, provider, purpose, storage technology, first- or third-party status, duration, legal basis or consent category and removal trigger for each production item.
For first-party Analytics, raw Analytics events are retained for up to 30 days, Analytics sessions for up to 90 days, and pseudonymous visitor and visitor-day records for up to 395 days. The Analytics consent proof follows the consent-choice retention configured by the consent component and is deleted when consent is reset.
10. Third-party and provider storage
Security, streaming, communications, payment, payout or identity providers may introduce their own cookies or browser storage when their functionality is used. Payment-provider storage is provider-dependent and will be documented after each provider is selected and integrated.
Pulscam must not classify a provider's optional analytics or marketing technology as necessary merely because it is bundled with a provider product.
11. Anonymous-route scan and authenticated flows
The latest unauthenticated HTTP scan did not observe a Set-Cookie header on the sampled public routes. This does not prove that authenticated, checkout, streaming, security or provider flows never set cookies or other storage.
Production disclosure must be updated from browser and network evidence covering login, signup, viewer activity, creator activity, checkout, payout, support and consent-choice flows.
12. Security and prohibited uses
Pulscam may use necessary browser identifiers and device or network signals for authentication, account protection, fraud prevention and enforcement. Such information must not be repurposed for unrelated advertising without an appropriate legal basis and notice.
Pulscam does not authorize storage technologies for covert cross-site tracking, sale of sensitive adult-interest profiles or unrelated inference of sex life or sexual orientation.
13. Contacts and review status
Questions about cookie settings or browser-storage behavior may be sent to support@pulscam.com. Legal notices may be sent to legal@pulscam.com.
This Policy remains a pre-launch compliance version until the final operator identity, runtime inventory, provider list, durations, consent-browser tests and production integrations are verified.