LEGAL

Cookie Policy

Last updated: 23 June 2026

StarMatch uses a small number of strictly-necessary and functional cookies to deliver the service, plus optional analytics cookies that load only after you agree to them. Analytics is strictly opt-in: nothing analytics-related runs, and no analytics cookies are set, until you give consent through our cookie banner. This policy explains exactly what we store on your device, when we ask for your consent, and how you stay in control.

Who sets these cookies

The cookies described here are set by NRMConsulting Maciej Miernicki, a sole proprietorship (jednoosobowa działalność gospodarcza) entered in the Polish Central Registration and Information on Business (CEIDG) registered in the Polish CEIDG register, NIP 5871727423, correspondence address Wały Jagiellońskie 28/30 lok. 2, 80-853 Gdańsk, operating the StarMatch service at starmatch.pl.

If you have any question about cookies or local storage, write to us at kontakt@starmatch.pl. For matters concerning your personal data, you can also reach our data-protection contact at privacy@starmatch.pl.

Effective date: 2026-06-23.

What cookies and local storage are

Cookies are small text files that a website asks your browser to store on your device. On each later visit the browser can send them back, which lets the site recognise that a request comes from the same browser — for example, to keep you logged in or to remember a preference.

Local storage is a related browser technology. Like a cookie, it stores information on your device, but that information stays in your browser and is read by the StarMatch code running in the page — it is not automatically sent to our server with every request.

In legal terms, both cookies and local storage involve storing or accessing information on your terminal equipment. In Poland this is governed by the Act of 12 July 2024 — Electronic Communications Law (Prawo komunikacji elektronicznej, art. 399), which transposes the EU ePrivacy Directive (2002/58/EC, art. 5(3)). Where this information is also personal data, the GDPR (Regulation (EU) 2016/679) applies as well.

Categories of cookies we use

StarMatch uses first-party cookies — set by starmatch.pl itself — that fall into three categories:

  • Strictly necessary: required to deliver the service you asked for, such as keeping you logged in and remembering your cookie choices. These cannot be switched off.
  • Functional: remember a choice you actively made, such as your theme or language. These make the service nicer to use but are not essential.
  • Analytics: help us understand how the product is used so we can improve it. These are optional and load only after you consent.

We do NOT use advertising, marketing, or re-targeting cookies; we do NOT use cross-site tracking or profiling cookies that follow you around the web; and we do NOT embed social-media or third-party advertising cookies. Our analytics are first-party and privacy-preserving, as described below.

Do you need to consent?

It depends on the category of cookie.

Under art. 399(3) of the Polish Electronic Communications Law and art. 5(3) of the ePrivacy Directive, storing or reading information on your device does NOT require prior consent when it is necessary to provide the electronic service you have requested. Our strictly-necessary cookies (sm_session, sm_consent) fall within that exemption, and our functional cookies (sm_role, sm_theme, sm_locale) are written only when you actively use the service or change a preference.

Our analytics cookies are different. They are NOT necessary to provide the service, so the law requires your prior, freely given, informed and unambiguous consent before they are set (art. 399(1) of the Electronic Communications Law, and GDPR art. 4(11) and art. 7). That is why StarMatch shows a cookie-consent banner and keeps analytics switched off until you agree. You can give, refuse, change, or withdraw that consent at any time, and refusing is as easy as accepting.

Cookies we use

All cookies below are first-party (set by starmatch.pl). "Strictly necessary" means the service cannot work for you without it; "functional" means it remembers a preference you chose; "analytics" means it helps us measure product usage and is set only with your consent.

  • sm_session — Strictly necessary. Keeps you signed in. It is a signed token holding your username and role; it is httpOnly (not readable by page scripts), Secure in production, and SameSite=Lax. Duration: about 7 days.
  • sm_role — Functional. Set when you log in; holds your role label ("admin" or "tester") so the interface can show the right options. It is a UI hint only, not a security control. Duration: about 7 days.
  • sm_theme — Functional (preference). Remembers your light or dark theme. It is written only when you actively change the theme, never silently by default. Duration: about 1 year.
  • sm_locale — Functional (preference). Remembers your chosen language (Polish or English). It is written only when you actively switch the language. Duration: about 1 year.
  • sm_consent — Strictly necessary. Stores your cookie choices, together with the policy version they relate to and a timestamp, so we can honour your decision and know whether to ask again. Duration: about 180 days.
  • PostHog analytics cookies (names beginning with "ph_") — Analytics. Set ONLY after you consent to analytics; they let our analytics measure how the product is used. They are first-party: PostHog is served through our own EU "/ingest" proxy, so these cookies belong to starmatch.pl, not to a third-party domain. If you do not consent to analytics, these cookies are never created. Duration: typically up to about 1 year; cleared when you withdraw consent.

Analytics: how it works

Our analytics provider is PostHog, hosted in the European Union. Analytics data is sent through a first-party reverse proxy on starmatch.pl (the "/ingest" path) and stays within the EU; it is not routed to a third-party tracking domain.

Analytics is opt-in only. No analytics code loads and no analytics cookies are set until you consent through the cookie banner. If you reject analytics, nothing analytics-related runs at all.

What we measure when you do consent: product-usage events (which features are used and how the app performs), tied to an opaque, irreversible per-account identifier and to your role ("admin" or "tester"). We do NOT collect your name, your birth data, your Oracle questions, or the free-text "what you are seeking" note. Autocapture masks all text on the page, so the content you type is not captured.

Session replay (the recording of an anonymised session) is OFF by default. It is enabled only if you separately opt in to it as its own category, and even then all inputs and text are masked so your typed content is never recorded.

Where this analytics data is personal data, our Privacy Policy explains the purposes, the legal basis (your consent), retention, and your rights.

The consent banner and how to manage or withdraw consent

On your first visit StarMatch shows a cookie-consent banner with three categories:

  • Strictly necessary — always on (these are exempt from consent and cannot be turned off);
  • Analytics — off by default, set only if you opt in;
  • Session replay — off by default, set only if you separately opt in.

"Accept all" and "Reject all" are offered with equal prominence, and you can also choose categories individually. There is no cookie wall: refusing analytics does not block your access to StarMatch, and refusing is just as easy as accepting.

You can reopen your preferences and change or withdraw your consent at any time using the "Manage cookies" control in the app. Withdrawing consent is as easy as giving it; when you withdraw analytics consent, analytics stops and the related cookies are cleared. Withdrawal does not affect the lawfulness of any processing carried out before you withdrew.

If we materially change this policy or how our cookies work, we update the policy version and ask for your consent again, so your earlier choice is never silently reused for new purposes.

Local storage we use

StarMatch stores some information in your browser's local storage (not cookies) so the app can work without sending that data to our server on its own. This data stays on your device and is fully under your control.

  • starmatch.profiles.v1 — your astrology profiles (a name, the relation such as self/partner/friend, the birth date, an optional birth time, and the birthplace with its coordinates and time zone). These profiles, including any you add for other people, are kept in your browser and are not uploaded by themselves. They are sent to our server only when you actively consult the Astral Oracle.
  • starmatch.oracle.v1 — your Oracle chat history (kept to roughly the last 100 messages).
  • starmatch.oracle.seeking — the free-text "what you are seeking" note you can give the Oracle.
  • starmatch.oracle.remember — your choice (on or off) about whether the Oracle may remember you between visits.

You can clear this local storage at any time from your browser settings (see below), and you can also manage this data through the tools described in our Privacy Policy. Clearing it removes your saved profiles and Oracle history from that browser.

How to control or delete cookies and local storage

You are always in control of what is stored on your device.

  • In the app: use the "Manage cookies" control to change or withdraw your analytics and session-replay consent at any time. You can also change the theme and language, switch off the Oracle's "remember me" option, and clear your saved profiles and Oracle history.
  • Browser settings: every major browser lets you view, block, or delete cookies and local storage, and clear stored site data. Look under Privacy/Security settings (for example: Chrome — Settings › Privacy and security › Cookies and other site data; Firefox — Settings › Privacy & Security; Safari — Settings › Privacy; Edge — Settings › Cookies and site permissions). You can also use your browser's "clear browsing data" function for starmatch.pl.

Please note that blocking or deleting the sm_session cookie will sign you out and prevent you from using the logged-in parts of StarMatch, because that cookie is essential to the service. Deleting the sm_consent cookie will cause the consent banner to appear again on your next visit. Clearing local storage will remove your locally saved profiles and chat history.

Relationship to our Privacy Policy

This Cookie Policy explains what is stored on your device and when we ask for your consent. Where cookies, analytics, or local storage involve your personal data, our Privacy Policy explains how we process it — including the purposes, legal bases (including your consent for analytics), the recipients of data (such as PostHog for analytics, and Google Cloud and Vertex AI for the Oracle), international transfers (including outside the EEA), retention periods, and your rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent.

For the rules governing your use of the service see our Terms of Service, and for our full company and registration details see the Legal & Company Information page.

You also have the right to lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa.

For anything related to your personal data, contact us at privacy@starmatch.pl.

Changes to this policy

We may update this Cookie Policy if our cookies, analytics, or local-storage usage changes, or to reflect changes in the law. When we do, we will revise the "effective date" shown at the top and, where the change is material, update the policy version recorded in your consent. If a change affects cookies that require your consent, we will ask for that consent again before the affected cookies are set.

We encourage you to review this page from time to time so you stay informed about how StarMatch uses cookies, analytics, and local storage.