Cookie Policy

Effective date: 22 July 2026

1. Introduction

This Cookie Policy explains how MediaPuller.com ("MediaPuller," "we," "us," or "our") uses cookies and similar technologies when you visit or use the MediaPuller website, media downloader, anonymous story viewers, public media pages, administrative interfaces, and related web features (together, the "Service"). It should be read together with our Privacy Policy and Terms of Service.

This Policy is based on the technologies currently present in the Service. It distinguishes between storage used by ordinary public visitors, storage used only in restricted administrative functions, and storage that may be controlled by an external provider. It does not treat server-side platform sessions used to operate an integration as cookies placed on a visitor's device.

A cookie or browser-storage entry can contain an identifier or other information that qualifies as Personal Data when it relates to an identifiable person or device. Our Privacy Policy explains the broader processing of IP addresses, URLs, usernames, profile metadata, server logs, analytics data, and other information.

2. What Cookies Are

A cookie is a small text record that a website asks a browser to store on a computer, phone, tablet, or other device. The browser returns the cookie to the relevant domain on later requests while the cookie remains valid. Cookies can support security, authentication, user-interface continuity, preferences, analytics, or third-party functionality.

First-party cookies are associated with the MediaPuller domain shown in the browser. A third-party script can sometimes create a first-party cookie through code running on a MediaPuller page; Google Analytics cookies are an example. Third-party cookies are associated with another domain, such as an embedded service, source platform, or content-delivery provider.

A session cookie normally expires when the applicable browser session ends, although browser restore features can affect when a session is considered closed. A persistent cookie has an expiry or maximum age and can remain after the browser closes until it expires, is replaced, or is deleted.

3. What Similar Technologies Are

Cookie rules can also apply to technologies that store information on, or obtain information from, a user's device. Examples include local storage, session storage, IndexedDB, cache storage, service-worker caches, pixels, tags, software-development kits, embedded widgets, and device identifiers. This Policy describes those technologies where they are used by MediaPuller.

Normal browser caching is different from a cookie but can retain copies of pages, scripts, styles, images, fonts, thumbnails, audio, or video to improve performance. Downloads, browser history, operating-system recent-file lists, and copies saved by the user are controlled by the browser or device and are not MediaPuller cookies.

4. Why MediaPuller Uses Cookies

MediaPuller uses the cookies and similar technologies listed below for the following purposes:

  • to authenticate authorised administrators and preserve a requested administrator sign-in;
  • to protect selected forms against cross-site request forgery;
  • to carry a temporary success, warning, error, or interface action between page requests;
  • to apply language selections in restricted administrative functions;
  • to save an unsent administrator editing draft locally for a limited period;
  • to remember whether a visitor accepted or rejected optional cookie categories;
  • with consent, to measure visits, sessions, page use, and technical performance through Google Analytics 4;
  • with consent, to load optional comments supplied by an external provider; and
  • to maintain security, prevent abuse, and provide the feature a user or administrator requested.

The public downloader and anonymous story viewers currently do not require a consumer account, a consumer sign-in cookie, or a visitor's source-platform login cookie. Restricted administrator authentication is separate from the public workflow.

5. Cookie Categories

For this Policy, MediaPuller uses the following categories:

  • Strictly Necessary Cookies. Cookies needed to authenticate authorised personnel, secure protected forms, or deliver an essential operation specifically requested by the user. Disabling them can make the relevant protected function unavailable.
  • Functional Cookies and Storage. Technologies that support an interface message, language choice, editing draft, or other convenience. Some functional storage is used only in the administrator area.
  • Analytics Cookies. Technologies used to understand audiences, sessions, popular pages, interactions, and technical performance. They are not required for the downloader or story viewer to function.
  • Advertising Cookies. Technologies used to select, deliver, measure, or profile advertising. MediaPuller does not currently use active advertising cookies.
  • Third-Party Cookies or Storage. Technologies controlled by an external provider when its script, widget, media, or page is requested or embedded. A third-party technology may also fall within a functional, analytics, or advertising category according to its purpose.

6. Strictly Necessary Cookies

mediapuller_cookie_consent records the current policy version and whether the visitor allowed Analytics and External Content. It does not contain a name, email address, submitted media URL, or source-platform username. It is necessary to remember a rejection or withdrawal as well as an acceptance, so that optional technologies are not repeatedly activated or the same choice repeatedly requested.

Restricted administrator authentication and ASP.NET Core antiforgery cookies are described separately below. They are used only when an authorised administrator accesses a restricted interface; they are not placed on an ordinary public visitor merely because the visitor uses the downloader, story viewer, or a public result page.

These cookies are not used for behavioural advertising. The consent cookie may be placed without Analytics consent where applicable law recognises the strictly-necessary exception because it remembers and enforces the visitor's privacy choice. Restricted administrator security cookies are similarly used only for the protected functions that require them.

7. Functional Cookies

SiteScriptMessage temporarily carries encoded interface messages or actions between requests. It is a session cookie and the site-side script removes it after processing. It can be used in public and administrator interfaces after an operation redirects to another page so that the destination can display the correct success, warning, or error message.

sitelang and adminlang are set when an authorised administrator saves language settings. They do not have an application-configured expiry and therefore follow session-cookie behaviour. Public language navigation is primarily expressed through the selected language in the page address rather than through these administrator cookies.

TinyMCE autosave storage is restricted to pages that load the administrator editor. It stores a draft and a timestamp in local storage so that an authorised editor can restore recent unsaved work. It is not used by the public downloader or story-viewer forms.

8. Analytics Cookies

MediaPuller uses Google Analytics 4 only after the visitor enables Analytics. The Google tag is not requested before that choice. When enabled, the standard configuration can create the first-party cookies _ga and a property-specific _ga_E71HGNX8E5 cookie. Google describes these cookies as distinguishing users and preserving session state. Their retention is up to two years by default, subject to MediaPuller's Google Analytics configuration, browser restrictions, renewal behaviour, deletion, or withdrawal of consent.

Google Analytics may receive the page address, referrer, timestamps, interaction and campaign information, browser and device information, language, analytics identifiers, and location information inferred from the network connection. Google may process this information outside the country in which the visitor is located. Further details are available in Google's own privacy and data-transfer materials.

Analytics cookies are not necessary to submit a media URL, search for available stories, view a result, or download media. MediaPuller therefore keeps Analytics disabled unless the visitor affirmatively enables it through the banner or Cookie Settings.

9. Advertising Cookies

MediaPuller does not currently use an active advertising integration, Google Ads destination, or advertising cookie. Advertising placeholders that do not load an active advertising service do not create an advertising-cookie inventory by themselves. The consent implementation keeps Google advertising storage, advertising user-data, and advertising-personalisation signals denied.

If MediaPuller later activates an advertising provider, remarketing feature, or advertising measurement destination, we will update this Policy and the cookie inventory and, where required, obtain consent before loading the relevant technology.

10. Public Visitor Cookie Inventory

The following table lists cookies that can be placed in an ordinary public visitor's browser when using the downloader, story viewer, public pages, or consent controls. SiteScriptMessage can also be used in a restricted administrator interface. "Can User Disable It?" describes the available choice and the likely effect.

Cookie Name Provider Category Purpose First-party or Third-party Session or Persistent Retention Period Legal Basis: Device Access / Personal Data Processing Can User Disable It?
mediapuller_cookie_consent MediaPuller Strictly Necessary Stores the policy version and the visitor's Analytics and External Content choices. First-party Persistent 180 days from the most recent saved choice Device access: Strictly necessary to remember and enforce the visitor's privacy choice.
Personal Data processing: Legitimate interests in consent administration and legal compliance.
Yes, but the choice will be forgotten and the banner will appear again.
SiteScriptMessage MediaPuller Functional Carries a temporary interface message or action across a redirect and is removed after processing. First-party Session Browser session or earlier removal after the message is processed Device access: Strictly necessary where the cookie is essential to complete an expressly requested operation; otherwise used only where permitted by applicable law.
Personal Data processing: Legitimate interests in interface continuity.
Yes, but status messages or follow-up interface actions may not appear.
_ga Google Analytics Analytics Distinguishes browser instances for audience and usage measurement. First-party cookie created by third-party analytics code Persistent Up to 2 years by default, subject to configuration, browser restrictions, renewal, deletion, or withdrawal Device access: Consent.
Personal Data processing: Consent.
Yes. Disabling it does not prevent core downloader or story-viewer functions.
_ga_E71HGNX8E5 Google Analytics Analytics Preserves session state for the configured Google Analytics property. First-party cookie created by third-party analytics code Persistent Up to 2 years by default, subject to configuration, browser restrictions, renewal, deletion, or withdrawal Device access: Consent.
Personal Data processing: Consent.
Yes. Disabling it does not prevent core downloader or story-viewer functions.

11. Restricted Administrator Cookies and Storage

The following cookies and browser-storage technologies are used only when an authorised administrator accesses a restricted administration interface. They are not placed on ordinary public visitors merely because they use the downloader, story viewer, or public result pages.

11.1 Administrator Cookies

Cookie Name Provider Category Purpose First-party or Third-party Session or Persistent Retention Period Legal Basis: Device Access / Personal Data Processing Can User Disable It?
.BaseApp.Web-Core-AUTH MediaPuller Strictly Necessary Authenticates authorised administrators and supports an administrator's remember-me choice. First-party Session unless remember-me is selected; persistent when selected Browser session, or up to 60 days for a persistent administrator sign-in Device access: Strictly necessary exception under applicable ePrivacy or PECR rules.
Personal Data processing: Performance of requested authentication and legitimate interests in authentication and security.
Yes, through browser controls, but administrator sign-in will fail or not persist.
.AspNetCore.Antiforgery.[runtime-generated suffix] MediaPuller through ASP.NET Core Strictly Necessary Pairs with a protected form token to help prevent cross-site request forgery. First-party Session Browser session; the exact suffix is generated by the framework and is not fixed in the application. Device access: Strictly necessary exception under applicable ePrivacy or PECR rules.
Personal Data processing: Legitimate interests in form security and prevention of fraudulent submissions.
Yes, but protected form submissions can fail.
sitelang MediaPuller Functional Applies an authorised administrator's saved site-language selection. First-party Session Browser session; no explicit application expiry is configured Device access: Applicable preference, appearance, or strictly necessary exception where available, because the authorised administrator explicitly requests the language setting.
Personal Data processing: Legitimate interests in applying the selected interface preference.
Yes, but the selected administrator language may not be retained during the session.
adminlang MediaPuller Functional Applies an authorised administrator's saved administration-language selection. First-party Session Browser session; no explicit application expiry is configured Device access: Applicable preference, appearance, or strictly necessary exception where available, because the authorised administrator explicitly requests the language setting.
Personal Data processing: Legitimate interests in applying the selected interface preference.
Yes, but the selected administration language may not be retained during the session.

11.2 Administrator Local Storage

Storage Name Provider and Scope Category Purpose Retention Can User Disable It?
tinymce-autosave-{path}{query}-{id}-draft MediaPuller administrator editor through TinyMCE; local storage Functional Stores the current unsaved editor draft. The placeholders are replaced with the administrator page path, query, and editor identifier. The draft is treated as expired after approximately 20 minutes under the current editor configuration. It may be removed when the draft is saved, cleared, replaced, found to be expired, or deleted through browser controls. Yes, but administrator draft recovery will not work.
tinymce-autosave-{path}{query}-{id}-time MediaPuller administrator editor through TinyMCE; local storage Functional Stores the timestamp used to determine whether an administrator autosave draft is still current. The related draft is treated as expired after approximately 20 minutes. The timestamp may be removed when the draft is saved, cleared, replaced, found to be expired, or deleted through browser controls. Yes, but administrator draft recovery will not work correctly.

MediaPuller does not currently use sessionStorage, IndexedDB, the Cache Storage API, or a service worker for its own application functions.

12. Third-Party Cookies and Embedded Content

A third party can receive a visitor's IP address, User-Agent, requested resource, referrer, and cookies already associated with that third party when the browser loads its script, iframe, image, font, audio, video, or other resource. MediaPuller cannot read every third-party cookie, control its retention, or guarantee that an external provider will not change its storage practices.

News detail pages offer a HyperComments comments widget as optional External Content. MediaPuller displays a local placeholder and does not request the HyperComments runtime until the visitor enables External Content in Cookie Settings or affirmatively selects Load comments. Loading the widget can allow the provider to use cookies or similar technologies and receive information necessary to deliver comments. Exact HyperComments cookie names and retention periods are controlled by the provider and are not listed in the named-cookie tables above.

Some pages can embed a third-party site or load Google-hosted fonts. Downloader and story-viewer results can also display or link to media, avatars, thumbnails, or previews supplied by a source platform, CDN, media-delivery provider, or intermediary. If the browser contacts those domains directly, their cookies and storage are governed by their own policies. Dynamic source-platform cookie names cannot be reliably listed because the provider and requested media vary by result.

Merely storing a technical source-platform session on MediaPuller's server does not place that platform's session cookie on the visitor's device. Such server-side integration credentials are operational data addressed by the Privacy Policy, not visitor cookies in this inventory.

13. Third-Party Providers

Google Analytics. Google provides audience and usage measurement. After Analytics consent, Google's tag can create the analytics cookies listed above and transmit analytics events to Google. Google's policies, service settings, and international-transfer arrangements govern its independent or processor activities as applicable.

HyperComments. HyperComments provides the optional comments widget on applicable news pages. The remote runtime is blocked until External Content consent. Once loaded, the provider may operate its own authentication, comment, preference, security, or measurement storage. MediaPuller does not assign those remote cookie names in its application.

Source platforms, CDNs, and media-delivery services. These providers deliver media or metadata selected by the user. A direct browser request may expose ordinary connection data and provider-domain cookies. A server-side request normally exposes MediaPuller's server connection instead, unless data is deliberately forwarded.

Edge, reverse-proxy, hosting, and security providers. If MediaPuller uses such a provider, it may process connection information and may set a security or load-balancing cookie under its own configuration. MediaPuller does not currently use a specific reverse-proxy, CDN-security, CAPTCHA, or load-balancing cookie identified in this Policy.

14. Local Storage

The only MediaPuller application use of local storage is TinyMCE autosave in the restricted administrator editor. The public downloader and story-viewer interfaces do not intentionally write submitted URLs, usernames, profile identifiers, or results to MediaPuller local-storage keys.

Local storage normally persists beyond a browser session until the application removes the value, the browser clears site data, or the user deletes it. Under the current editor configuration, an autosave draft is treated as expired after approximately 20 minutes; physical removal occurs when the editor's draft logic checks, saves, clears, replaces, or removes that value. Private-browsing modes and browser policies can behave differently.

15. Session Storage, IndexedDB, and Service Workers

MediaPuller does not currently use session storage, IndexedDB, service workers, or a MediaPuller-managed offline cache through the Cache Storage API for its own application functions. Third-party scripts or embedded pages can use technologies within their own origin and under their own rules. We will review and update this Policy if those technologies or integrations change.

16. Browser Cache and Downloads

A browser may cache MediaPuller HTML, CSS, JavaScript, images, fonts, and other static resources according to response headers, browser settings, available storage, and normal cache rules. When a result uses a direct third-party media address, the browser or source CDN controls the applicable media-cache behaviour. The exact browser-cache retention period cannot be determined from the application because browsers, providers, headers, private mode, and user settings differ.

If a user downloads or opens media, the device may retain the file, a partial file, a thumbnail, playback state, download history, or a recently-used record. Those device-side copies are not cookies and cannot be removed by deleting MediaPuller cookies alone.

17. Cookie Retention

Retention is stated in the inventory where it can be determined. A session cookie generally lasts until the relevant browser session ends. A persistent cookie remains until its expiry, replacement, or deletion. An analytics expiry can be renewed when the tag sends another event. Browser restore, privacy protection, storage partitioning, automatic deletion, private mode, and user action may shorten or alter practical retention.

Third-party retention is controlled by the provider unless MediaPuller configures it. If the application cannot verify a provider-controlled duration, this Policy says so rather than guessing. We review and update this inventory whenever our providers, tags, authentication settings, embedded widgets, or browser-storage technologies change.

18. Legal Basis

18.1 Storing or accessing information on a device

EU ePrivacy rules and UK PECR govern whether information may be stored on or accessed from a user's device. MediaPuller relies on the applicable strictly-necessary exception for technologies required to authenticate an authorised administrator, protect a requested form, remember and enforce a cookie choice, or provide another expressly requested essential operation. This exception is limited to technologies genuinely necessary for that purpose.

Analytics and optional External Content are not treated as strictly necessary. MediaPuller requests consent before activating Google Analytics or the HyperComments runtime. Legitimate interests alone are not used as permission to place or access non-essential analytics storage.

18.2 Processing Personal Data obtained through those technologies

After the storage or access question is addressed, the GDPR or UK GDPR legal basis for processing related Personal Data is assessed separately. Depending on the purpose, MediaPuller relies on:

  • performance of a requested service or steps requested by the user for protected operations and authentication where applicable;
  • legitimate interests in securing the Service, authenticating authorised administrators, preventing fraudulent submissions, preserving interface continuity, and operating requested preferences, provided those interests are not overridden by the person's rights; and
  • consent for Google Analytics and optional External Content processing activated by the visitor.

19. Consent and Cookie Banner

MediaPuller does not activate Google Analytics or the HyperComments runtime until the visitor has provided the corresponding consent. On a first visit without a saved choice, the cookie banner offers Accept all, Reject all, and Cookie settings as directly available first-layer actions. Optional categories are off unless the visitor enables them.

Accept all enables Analytics and External Content. Reject all keeps both optional categories disabled. Cookie settings allows the visitor to select either category separately. Necessary cookies remain available because they operate security, protected functions, and the saved privacy choice. Silence, continued browsing, or scrolling is not treated as consent.

The choice and policy version are stored in mediapuller_cookie_consent for 180 days. Selecting Load comments is a specific affirmative choice to enable External Content without enabling Analytics. Advertising-related Google storage and personalisation signals remain denied because MediaPuller does not currently use an advertising integration.

20. Withdrawal of Consent and Browser Controls

Where processing is based on consent, a user may withdraw it at any time without affecting processing lawfully carried out before withdrawal. A permanent Cookie settings link is available in the public footer. Saving Analytics as disabled sends a denied consent state, prevents further MediaPuller analytics use on the page, and attempts to remove the known MediaPuller-domain Google Analytics cookies. Disabling External Content prevents optional widgets from loading on later page views. A third-party script already loaded on the current page cannot always be unloaded completely, so reloading the page after withdrawal provides the cleanest state.

Most browsers allow users to view cookies and site data, block all cookies, block third-party cookies, delete selected cookies, clear data when the browser closes, or create site-specific exceptions. Blocking all cookies can prevent administrator authentication, protected forms, temporary messages, or language features from working. Deleting local storage removes an administrator's unsaved autosave draft.

Google also provides browser and account-level tools that may affect analytics collection. A browser's Do Not Track signal is not implemented as a specific MediaPuller cookie control. Where applicable law requires MediaPuller to recognise a legally valid opt-out signal for the relevant processing, MediaPuller will honour that signal.

21. International Transfers

Google, HyperComments, source platforms, CDNs, hosting providers, and other external services may process information in countries different from the visitor's country. Those countries may have different data-protection laws. The provider's published privacy and transfer materials describe the mechanisms it applies to its processing. Where MediaPuller is responsible for a restricted international transfer, the applicable safeguards depend on the provider, destination, contractual terms, and law in force at the time of transfer. Information about safeguards applicable to a particular MediaPuller-controlled transfer may be requested through the contact details below.

A visitor who affirmatively enables or directly requests a third-party resource also establishes a connection to that provider. The provider's privacy and cookie materials contain further information about its locations, recipients, retention, and transfer arrangements. This Policy does not itself create or replace a required transfer mechanism.

22. Children

The Service is not directed to children who are below the age at which they may independently consent to relevant online processing in their jurisdiction. MediaPuller does not knowingly use analytics cookies to profile a child as such. A parent or guardian who believes that a child has supplied cookie-related Personal Data may contact us and request review or deletion, subject to legal and technical limitations.

23. Policy Updates

We may update this Cookie Policy when cookies, storage technologies, providers, legal requirements, consent controls, or Service features change. The revised version will show a new effective date. A material change may also be presented through an appropriate notice or renewed consent request where required.

Adding a new analytics, advertising, embedded, security, or preference technology requires a review before deployment so that the cookie inventory, consent categories, retention information, and provider disclosures remain accurate.

24. Contact Information

Questions about this Cookie Policy, the cookie inventory, consent choices, or cookie-related Personal Data may be sent to mediapuller@gmail.com. Please use "Cookie Policy Request" in the subject line and identify the browser, page, cookie name, or provider concerned where possible. Do not send passwords, authentication cookies, source-platform session files, or other secrets.

For information about broader data practices and data-subject rights, please review the MediaPuller Privacy Policy.