Cookie and Tracking Technologies Policy
Last updated: 1 September 2026 · Effective: 1 September 2026 · Version 1.0
This Cookie and Tracking Technologies Policy explains how Opinyn uses cookies, software development kits, local storage, device and installation identifiers, analytics tools, push-notification tokens and similar technologies.
This Policy applies to the Opinyn mobile application, website and related services collectively referred to as the “Service”.
It forms part of the Opinyn Privacy Policy.
The Service is operated by:
Jan Nik Jesenovec – Manumed s.p.
Kokošnje 13
1233 Dob
Slovenia
Email: info@opinyn.com
What are cookies and tracking technologies?
Cookies are small text files stored on a user’s device when visiting a website.
Mobile applications do not always use traditional browser cookies. They may instead use similar technologies, including:
- software development kits or SDKs;
- local storage;
- session storage;
- device identifiers;
- application installation identifiers;
- authentication tokens;
- Firebase installation identifiers;
- analytics identifiers;
- push-notification tokens;
- pixels;
- tags;
- server logs;
- similar technologies.
In this Policy, “tracking technologies” refers collectively to these technologies.
Why Opinyn uses these technologies
Opinyn may use cookies and similar technologies to:
- allow users to create and access accounts;
- maintain secure sessions;
- remember user preferences;
- provide essential application functions;
- record privacy and consent choices;
- prevent fraud and unauthorised access;
- prevent duplicate or manipulated voting;
- maintain Service security;
- deliver push notifications;
- identify crashes and technical problems;
- measure how users interact with the Service;
- improve performance and usability;
- understand general dilemma and voting activity;
- measure feature engagement;
- provide optional marketing where separately permitted.
Categories of technologies
3.1 STRICTLY NECESSARY TECHNOLOGIES
These technologies are necessary for the Service to function securely and correctly.
They may be used to:
- authenticate users;
- maintain a login session;
- protect accounts;
- remember essential settings;
- process requests;
- prevent fraud;
- maintain voting integrity;
- prevent duplicate voting;
- detect malicious activity;
- store privacy choices;
- balance network traffic;
- provide essential security.
These technologies cannot generally be disabled through Opinyn’s consent settings because the Service may not function correctly without them.
Where required, users may prevent them through browser or device settings, but doing so may make the Service unavailable or unreliable.
Legal basis: performance of a contract, legitimate interests and compliance with legal obligations.
3.2 FUNCTIONAL TECHNOLOGIES
Functional technologies help Opinyn remember optional choices and provide enhanced features.
They may be used to remember:
- language;
- interface preferences;
- notification preferences;
- content preferences;
- accessibility settings;
- selected categories;
- other optional settings.
Depending on applicable law and the nature of the technology, functional technologies may be used based on consent or because they are necessary to provide a feature requested by the user.
3.3 ANALYTICS AND PERFORMANCE TECHNOLOGIES
Analytics technologies help Opinyn understand:
- how many people use the Service;
- which features are used;
- which application screens are visited;
- how users navigate the Service;
- how many dilemmas and votes are created;
- general participation and engagement rates;
- application performance;
- crashes and errors;
- whether features operate as intended;
- how the Service may be improved.
These technologies may process:
- pseudonymous user or installation identifiers;
- device and application information;
- screen views;
- feature events;
- session information;
- approximate location inferred from an IP address;
- general voting and dilemma events;
- crash and diagnostic information.
Where consent is required, non-essential analytics will remain disabled until the user provides consent.
Legal basis: consent where required or legitimate interests where the relevant processing is strictly necessary and lawfully permitted without consent.
3.4 PUSH-NOTIFICATION TECHNOLOGIES
Push-notification technologies allow Opinyn to send notifications about:
- votes and results;
- activity on dilemmas;
- comments and reactions;
- followers;
- account activity;
- content recommendations;
- reminders;
- security;
- moderation decisions;
- Service updates;
- promotional messages where separately permitted.
Push delivery may require:
- a device push token;
- application installation identifier;
- account identifier;
- device platform;
- notification preferences;
- delivery and interaction information.
Push notifications are delivered only after the user grants permission through the device or operating-system settings.
Users can disable push notifications at any time through Opinyn’s settings, where available, or the device’s notification settings.
3.5 MARKETING TECHNOLOGIES
Opinyn does not currently use personal data or sensitive voting inferences for targeted advertising.
If Opinyn introduces advertising or marketing tracking in the future, this Policy and the Privacy Policy will be updated.
Where legally required, marketing technologies will not be activated without prior consent.
Marketing consent will be separate from acceptance of the Terms of Use and will not be required to access essential Service features.
Technologies used by Opinyn
Depending on the platform, application version and enabled features, Opinyn may use the following services.
4.1 OPINYN ESSENTIAL TECHNOLOGIES
Provider: Opinyn
Purposes:
- account authentication;
- session security;
- essential preferences;
- consent records;
- voting integrity;
- fraud prevention;
- security;
- Service operation.
Possible information:
- session token;
- account identifier;
- security token;
- privacy preference;
- language;
- device or installation information;
- voting-integrity indicators.
Typical duration:
- for the duration of a session;
- until logout;
- until expiry;
- until the account or relevant preference is deleted;
- for a limited security-retention period.
4.2 FIREBASE
Provider: Google
Opinyn uses or may use Firebase services for:
- authentication;
- application infrastructure;
- database and storage;
- push notifications;
- crash diagnostics;
- security;
- application analytics.
Firebase services may use:
- installation identifiers;
- application instance identifiers;
- device information;
- IP address;
- crash information;
- authentication tokens;
- push-notification tokens;
- analytics events;
- security information.
The exact information and duration depend on which Firebase services are enabled.
Essential Firebase functions may operate without optional analytics consent where necessary to provide account, security, database or notification functionality.
Google Analytics for Firebase or other non-essential analytics must be controlled separately where consent is legally required.
4.3 POSTHOG
Provider: PostHog
Opinyn uses or may use PostHog to understand:
- general Service usage;
- screen and feature engagement;
- general dilemma and voting activity;
- navigation;
- retention;
- technical performance;
- product errors;
- effectiveness of new features.
PostHog may process:
- pseudonymous distinct identifier;
- session identifier;
- device identifier;
- installation information;
- application events;
- feature flags;
- general usage information;
- consent configuration.
On the Opinyn website, PostHog may use a first-party cookie or local-storage entry with a name similar to:
ph_<project_api_key>_posthog
The exact name contains the relevant PostHog project key.
Depending on configuration, it may store:
- a distinct identifier;
- session identifier;
- device identifier;
- active feature flags;
- selected analytics properties;
- configuration information.
The default PostHog web-cookie duration may be up to 365 days, but Opinyn may configure a shorter duration or another storage method.
Where consent is required, PostHog must not store non-essential analytics cookies or identifiers before consent.
Opinyn should use PostHog’s European-hosted environment where available and appropriate.
4.4 APPLE PUSH NOTIFICATION SERVICE
Provider: Apple
Purpose:
- delivery of push notifications to Apple devices.
Possible information:
- device push token;
- application information;
- notification-delivery information;
- technical information necessary for delivery.
Duration:
- until the token expires, is replaced, notifications are disabled or the account is deleted.
4.5 FIREBASE CLOUD MESSAGING
Provider: Google
Purpose:
- delivery of push notifications, particularly to Android devices;
- notification routing and technical delivery.
Possible information:
- Firebase installation identifier;
- device push token;
- application information;
- notification-delivery information.
Duration:
- until the identifier or token expires, is deleted or is no longer needed.
4.6 APPLE AND GOOGLE SIGN-IN
When users choose Sign in with Apple or Google Sign-In, the selected provider may use cookies, tokens or similar technologies necessary to:
- authenticate the user;
- maintain provider security;
- allow the user to select an account;
- return authorised account information to Opinyn.
These technologies are controlled by Apple or Google according to their own terms and privacy policies.
Opinyn does not receive the user’s Apple or Google password.
Mobile device identifiers
The Opinyn application may process identifiers associated with:
- an application installation;
- Firebase services;
- push notifications;
- security;
- analytics;
- fraud prevention.
These identifiers do not necessarily directly reveal a user’s name, but they may constitute personal data when connected to an account, device or activity.
Opinyn will not use advertising identifiers for targeted advertising unless:
- the feature is introduced;
- this Policy is updated;
- applicable platform requirements are followed;
- any required user permission or consent is obtained.
Voting and security identifiers
Opinyn may use account, installation, device or security identifiers to:
- determine whether an eligible user already voted;
- prevent repeated or automated voting;
- detect suspicious voting patterns;
- identify fake or linked accounts;
- protect Aura, ranks, badges and statistics;
- investigate manipulation;
- correct affected voting results.
These technologies are considered essential where reasonably necessary to maintain the integrity and security of the Service.
Refusing optional analytics does not prevent Opinyn from processing information necessary to record votes or prevent manipulation.
Session replay
If Opinyn enables PostHog Session Replay or a similar feature, it must be configured to protect user privacy.
Session replay must not intentionally capture:
- passwords;
- authentication credentials;
- complete private text inputs;
- private support communications;
- sensitive reporting details;
- payment information;
- unmasked personal data;
- suspected child sexual abuse material;
- other information not necessary for product analysis.
Sensitive screens, fields, photographs and text should be masked or excluded.
Where required by law, session replay will remain disabled until the user provides consent.
If Session Replay is not enabled, Opinyn does not use it.
Consent
Where consent is required, Opinyn will request it before activating non-essential tracking technologies.
The consent request should provide choices such as:
- Accept All;
- Reject Non-Essential;
- Manage Preferences.
The consent interface must:
- use clear language;
- avoid preselected non-essential categories;
- make rejection reasonably as easy as acceptance;
- distinguish essential technologies from optional analytics;
- record the user’s choice;
- allow consent to be withdrawn.
A user’s decision to reject optional analytics will not prevent use of essential Opinyn features.
Withdrawing or changing consent
Users may change their tracking preferences at any time through:
Settings → Privacy → Analytics Preferences
or another clearly labelled privacy-settings interface.
Website users should be able to reopen the cookie-preference interface through a persistent link such as:
Cookie Settings
Withdrawing consent:
- stops future optional collection;
- does not affect processing performed before withdrawal;
- does not automatically delete information already lawfully collected;
- does not disable strictly necessary technologies.
Users may separately request deletion of previously collected personal data according to the Privacy Policy and Account and Data Deletion Policy.
Push-notification controls
Push notifications may be managed through:
- Opinyn’s notification settings;
- Apple iOS notification settings;
- Android notification settings;
- other applicable device settings.
Disabling push notifications does not:
- delete the Opinyn account;
- withdraw consent for unrelated analytics;
- delete previously processed data;
- prevent essential information from being displayed inside the application;
- prevent legally necessary communications by email or another appropriate method.
Browser controls
Website users may use browser settings to:
- view cookies;
- delete cookies;
- block cookies;
- restrict local storage;
- clear website data;
- block third-party technologies.
Blocking strictly necessary cookies may prevent:
- login;
- secure sessions;
- saved preferences;
- proper website operation.
Browser settings may not control SDKs or identifiers used by the mobile application.
Device controls
Mobile-device settings may allow users to:
- disable notifications;
- reset certain identifiers;
- restrict tracking permission;
- limit advertising personalisation;
- delete application storage;
- uninstall the application.
Uninstalling the application does not delete the Opinyn account or server-side personal data.
Do not track and similar signals
Some browsers or devices provide privacy signals such as “Do Not Track”.
Because technical standards and legal requirements concerning these signals vary, Opinyn may not respond uniformly to all signals.
Where legally required and technically supported, Opinyn will recognise applicable consent or opt-out signals.
Data collected before login
The Opinyn website or application may process limited technical data before a user signs in where necessary for:
- security;
- fraud prevention;
- loading the Service;
- remembering privacy choices;
- preventing technical abuse.
Non-essential analytics for logged-out users will be used only where an appropriate legal basis exists and consent will be requested where required.
Retention
Cookies and tracking information are retained only for as long as reasonably necessary.
Typical retention periods include:
- session technologies: until logout, expiry or the end of the session;
- consent records: while relevant and for up to five years where necessary to demonstrate compliance;
- essential security identifiers: for the period necessary to provide security, normally no longer than 12 months unless a longer period is justified;
- push tokens: until expiry, replacement, withdrawal of permission or account deletion;
- analytics identifiers and events: normally no longer than 24 months;
- PostHog web cookie: up to 365 days unless configured for a shorter period;
- crash and diagnostic information: normally no longer than necessary to identify and resolve technical problems;
- anonymised statistics: may be retained indefinitely where they no longer identify a person.
Specific retention may differ where required by law, security or legal claims.
International transfers
Providers of tracking technologies may process information outside Slovenia or the European Economic Area.
Where legally required, Opinyn will use appropriate safeguards such as:
- adequacy decisions;
- European Commission standard contractual clauses;
- supplementary security measures;
- another lawful transfer mechanism.
Where available and appropriate, Opinyn will use European hosting regions.
Third-party responsibility
Third-party providers may independently process information according to their own privacy policies.
Users should review the privacy information provided by:
- Google and Firebase;
- Apple;
- PostHog;
- other providers identified in the Service.
Opinyn remains responsible for selecting and configuring processors as required by applicable data-protection law.
Children and young users
Opinyn does not use minors’ personal data or sensitive voting inferences for targeted advertising.
Non-essential analytics involving young users must be subject to applicable age and consent requirements.
Opinyn may use essential security and safety technologies to:
- protect young users;
- enforce minimum-age requirements;
- prevent grooming or exploitation;
- investigate child-safety reports;
- prevent banned users from returning.
Changes to the technologies used
The exact cookies, SDKs and identifiers may change as Opinyn:
- updates the Service;
- adds or removes providers;
- improves security;
- introduces new functionality;
- changes technical configuration.
Where a change materially affects user privacy or requires consent, Opinyn will update this Policy and request consent before activating the new non-essential technology.
The active consent-preference interface should reflect the technologies actually enabled in the relevant application or website version.
Changes to this policy
Opinyn may update this Policy to reflect:
- changes to tracking technologies;
- changes in providers;
- new features;
- legal or regulatory requirements;
- security developments.
The latest version will be available through the Service.
Contact
Questions or requests concerning cookies and tracking technologies may be sent to:
Jan Nik Jesenovec – Manumed s.p.
Kokošnje 13
1233 Dob
Slovenia
Email: info@opinyn.com
Service provider and data controller: Jan Nik Jesenovec – Manumed s.p., Kokošnje 13, 1233 Dob, Slovenia · info@opinyn.com
Terms of Use Privacy Policy Community Guidelines Moderation & Appeals Child Safety Account & Data Deletion Copyright & IP Sign-Up Agreement Delete Your Account