Cookie policy
Last updated: 13 August 2026
What a cookie is, and what other technologies Nalucam uses
A cookie is a small text file that a website stores in your browser when you visit it and that the browser sends back with every later request. It exists to remember something from one page to the next: the language you chose, whether you have already answered a notice, or how the site is used. Without that memory, every page would be a first visit.
The Spanish Data Protection Agency groups cookies and «similar technologies» under the same term, so we also tell you about the ones that are not cookies. And there is one distinction this document must not blur: the record of your decision about audience measurement is browser local storage, not a cookie. The difference is not just the name: a cookie travels to the server with every request, and that record travels with none. It stays in your browser and is only read by the site itself, once loaded, to find out whether it has to ask you again.
Nalucam uses no advertising cookies, no social network cookies, and no third-party cookies that build a profile of you across other sites. The table below lists every device the site may use on your terminal, with no exceptions.
Storage devices that Nalucam uses
All of them are ours: none belongs to a third party. Audience measurement will run on Matomo installed on our own server, so the data will never leave it and no outside company will receive it.
| Name | Storage type | Owner | Purpose | Duration | Legal basis |
|---|---|---|---|---|---|
nalucam_lang | Cookie | First-party | Remember the language you picked by hand in the footer switcher, so that it overrides the one your browser proposes on its own | 1 year | Exempt from consent: it is a preference you expressly request by clicking the language switcher |
nalucam_consent | Browser local storage. NOT a cookie: it never travels in any request to the server | First-party | Store your decision about audience measurement so we do not ask you again on every page | 24 months, counted from the timestamp the record itself stores. Once that period is over, you are asked again | Exempt from consent: it is the record of the consent itself |
nalucam_confirm | Cookie | First-party | Carry the confirmation link for your sign-up from the email through to the button that confirms it, taking the identifier out of the address bar: it never lands in your history nor travels when you share the page | 48 hours, the same as the email link lasts, and less if you confirm sooner: it is withdrawn in the very hop in which the confirmation completes | Exempt from consent: it is strictly necessary for the service you have just requested —confirming your own sign-up— and does NOT depend on your decision about audience measurement, which is a separate decision. It only exists if you sign up, and only while that step lasts |
_pk_id | Cookie | First-party (Matomo installed on our server) | Audience measurement: telling one visit apart from another without identifying you | Committed cap: 13 months, the period set by the Spanish Data Protection Agency’s audience-measurement guidance, which we apply. The effective duration is 393 days, below that cap: we measured it on 31 August 2026 on our own installation, in a real browser. We are not stating it from memory | Consent |
_pk_ses | Cookie | First-party (Matomo installed on our server) | Audience measurement: grouping the pages you view in a row into a single session | 30 minutes: we measured it on 31 August 2026 on our own installation, in a real browser. We are not stating it from memory | Consent |
| Our own interaction beacon | None: it stores absolutely nothing on your terminal | First-party | Click heatmap and scroll depth, with no data that identifies you | It leaves nothing on your device. The data it sends is kept on our server for at most 25 months | Consent |
The two durations the table leaves marked as pending are those of the measurement cookies, and they are there on purpose: the measurement system is not deployed yet, so their real values cannot be checked today. They will be published as measured before either of those two cookies is ever written to anyone’s browser. We would rather declare the gap than publish a figure nobody has verified.
How to accept, reject and change your decision
The first time you come in you will see a notice with two buttons of the same size and the same visual weight: accept and reject, side by side and in the same layer. There is no box ticked in advance, there is no button hidden behind a second step, and carrying on browsing without touching anything does not count as accepting.
You can change your mind whenever you like and with no paperwork: in the footer of every page there is a permanent control called «Cookie preferences» that reopens the decision and lets you withdraw whatever you had accepted. Withdrawing is exactly as easy as accepting, which is what the rules require.
When you reject, or withdraw an earlier acceptance, three things happen straight away on the same page, without reloading: the site stops sending any new measurement request, the measurement system’s cookies are deleted, and the mechanisms that fed them are disconnected. What we cannot undo is that a file already downloaded stays in your browser cache until the cache is cleared: it sends nothing, but it is there, and we say so instead of promising that it disappears.
How long your decision lasts
Your decision is stored for 24 months. That is the maximum period the Spanish Data Protection Agency points to as good practice, and while it is valid you are not asked again on every visit: it would be annoying, and the rules expressly say it is not needed.
Once those 24 months are up the notice comes back and the question is asked again, without assuming the earlier answer. An expired decision is neither an acceptance nor a rejection: it is the absence of a decision, and in the absence of a decision nothing is switched on.
If your browser has local storage blocked — in some private browsing modes, for example — your decision will still govern the page you are looking at, but it cannot be saved, so you will be asked again on your next visit. We would rather ask too often than treat as consented something we cannot read.
How to delete cookies and local storage from your browser
Besides the footer control, your browser lets you see and delete on your own everything sites store in it, including our cookies and our decision record. The path varies by browser, but it is always inside the privacy settings:
- Google Chrome: Settings → Privacy and security → Third-party cookies → See all site data and permissions.
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data → Manage Data.
- Safari: Settings → Privacy → Manage Website Data.
- Microsoft Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data.
Bear in mind two consequences, neither of them serious: if you delete the language cookie, the site will go back to proposing your browser’s language; and if you delete the record of your decision, the notice will come back on your next visit, because as far as we know you will be someone who has not decided yet.
Changes to this policy
This policy will be updated whenever the devices we use, their purpose or how long they last change. The date of the last update is at the top of the document, and it is what lets you check at a glance which version you are reading.
When a change affects the purposes or brings in a third party, we will not treat the decision you made earlier as valid: the notice will come back and you will have to decide again about what is being asked of you now. That is why the record of your decision also stores the version of the processing you decided on.