Cookie Policy

This policy explains which cookies MovieFinder uses, on what legal basis, your rights, and how to manage your consent. It complies with the GDPR, the ePrivacy Directive (2002/58/EC as amended), EDPB Guidelines 05/2023 on deceptive design patterns, and the German TDDDG (2024).

Last updated: 15.04.2026. Applicable law: GDPR, ePrivacy Directive, TDDDG.

1. What Cookies Are

  • Cookies are small text files stored on your device when you visit a website. They hold information exchanged between your browser and the server.
  • Session cookies are deleted when you close your browser. Persistent cookies remain for the period defined by their expiry date.
  • You can manage or delete cookies at any time via browser settings — see section 9 below.

2. Our Principle: No Cookie Walls

  • MovieFinder does NOT make access to the service conditional on accepting non-essential cookies.
  • Refusing optional cookies is as easy as accepting them, in line with EDPB Guidelines 05/2023 on deceptive design patterns.
  • Only strictly necessary cookies are loaded by default — without your consent.

3. Strictly Necessary Cookies (no consent required)

  • auth-token — JWT authentication token; httpOnly, Secure, SameSite=Strict; expiry: 30 days (or until logout). Basis: GDPR Art. 6(1)(b) — performance of contract.
  • mf-cookie-consent — records your cookie consent preferences (accepted/rejected categories); expiry: 12 months. Basis: legitimate interest (GDPR Art. 6(1)(f)).
  • mf-locale — your chosen language (bg/en/es/de); expiry: 12 months. Basis: legitimate interest.
  • mf-theme — your chosen theme (light/dark); expiry: 12 months. Basis: legitimate interest.
  • These cookies cannot be disabled without breaking core functionality.

4. Functional Cookies (optional)

  • Saving preferences beyond the session (e.g. preferred genres, display mode). Basis: consent.
  • These cookies are only loaded if you have given explicit consent through our cookie banner.

5. Analytics Cookies (optional, consent-only)

  • We currently do not use third-party analytics platforms (e.g. Google Analytics). Should we introduce them, we will update this policy and request fresh consent.
  • All internal analytics are based on aggregated/anonymised data from server logs — no third-party cookies.

6. Third-Party Cookies — YouTube

  • When loading trailers, a YouTube player operated by Google LLC (USA) is embedded. Google may set its own cookies.
  • Trailers are loaded ONLY upon explicit user interaction (clicking the "Watch Trailer" button) — not automatically on page load.
  • We recommend reviewing Google's Privacy Policy: https://policies.google.com/privacy
  • Standard Contractual Clauses (SCCs) apply for data transfers to the USA via YouTube.

7. Third-Party Cookies — TMDB

  • We use the TMDB API (The Movie Database) for film data. Requests are made server-side — your browser does not connect directly to TMDB unless you click a link to tmdb.org.
  • TMDB images may load directly from image.tmdb.org — in that case their cookie terms apply.

8. IP Address Hashing for Login Security

  • During two-factor authentication and trusted-device management, we hash your IP address using SHA-256 + a secret key.
  • This is done for security purposes (preventing stolen sessions), not for tracking or advertising.
  • Legal basis: legitimate interest (GDPR Art. 6(1)(f)) — account security.
  • The hashes do NOT allow recovery of the original IP address and are not shared with third parties.

9. Managing Your Cookie Choices

  • First-visit banner: on your first visit a clear banner is shown with "Accept all", "Necessary only", and "Customise" options.
  • Withdraw consent: use the cookie settings button on this page below to change your preferences at any time.
  • Browser settings: Chrome в†’ Settings в†’ Privacy & Security в†’ Cookies; Firefox в†’ Options в†’ Privacy & Security; Safari в†’ Preferences в†’ Privacy.
  • Deleting all cookies: you can clear stored cookies in your browser settings, but this will sign you out of the service.

10. Policy Changes

  • For material changes we will notify you via a banner or email at least 14 days in advance.
  • Last updated: 15.04.2026.

Manage Cookies

Change your cookie preferences at any time.

You can change your cookie preferences at any time:

Change Cookie Settings