Last updated: August 2026
This policy sets out every cookie and storage technology used by bimi.tv, the panel and the embedded player, with its exact name, purpose and lifetime.
A cookie is a small text file a site stores in your browser to remember something between pages or visits: that you are signed in, for example. Alongside them sit equivalent technologies such as local storage, which keeps data in the browser without sending it automatically with every request. This policy covers both.
Every cookie we set on bimi.tv and app.bimi.tv is strictly functional: required to deliver the service and to keep the session secure. Under art. 22.2 of the Spanish LSSI these do not require prior consent.
| Cookie | Purpose | Duration | Attributes |
|---|---|---|---|
PHPSESSID |
PHP session. On the public site it carries the CSRF token that protects forms against request forgery. | 7 days | Secure |
bimitv_session |
Identifies your active session in the panel. | Until the browser closes, or 90 days with "remember me" | HttpOnly, Secure, SameSite=Strict |
bimitv_device |
Device token. Lets us recognise already-known machines and detect anomalous access to the account. | 365 days | HttpOnly, Secure, SameSite=Strict |
When a client embeds a BIMI.TV video on their website, our player sets no first-party cookies on that site. It does use the browser's local storage for two technical purposes:
IABTCF_TCString, euconsent-v2 or euconsent) from that site's local storage or cookies, so it can honour it when requesting advertising. The player only reads it; it never writes or modifies it.Playback statistics are produced from events sent to our API, not from tracking cookies. What those events contain, and the legal basis for processing them, is described in the Privacy Policy.
Monetisation is off unless the publisher of the video turns it on. When it is on, the player requests ads from Google (Ad Manager, via the IMA SDK), and the request is made in personalised advertising mode by default. That means Google may set its own cookies and advertising identifiers in the viewer's browser and use them to select and measure ads. These are Google's cookies, not BIMI.TV's, and they are governed by its privacy policy.
The applicable consent is the one collected by the site hosting the player. The player reads that site's IAB TCF consent string and Google's SDK applies it to the request, so if you have not accepted personalised advertising, that decision limits the processing. Requests are also flagged as not directed to children.
If the publisher does not enable monetisation, the player requests no ads and no advertising cookie is involved.
BIMI.TV sets no first-party advertising cookies, no tracking pixels and no third-party analytics cookies (we do not use Google Analytics or equivalents). We build no advertising profiles of our own, do not follow viewers across different sites, and do not sell or share browsing information for commercial purposes. The only advertising cookies that may be set are those of the ad provider described in section 5, and only when the publisher enables monetisation.
You can inspect, block or delete cookies and local storage from your browser settings. The usual paths are:
Note that our cookies are functional: blocking or deleting them will stop you signing in and using the panel normally. Blocking local storage does not prevent videos from playing.
To withdraw or change advertising consent, do so in the consent manager of the site where you are watching the video, since that site, not BIMI.TV, is what collects it.
We may update this policy to reflect technical or legal changes. The current version will be published on this page with its corresponding date.