Cookie Policy
Ostatnia aktualizacja:
Ten dokument jest udostępniany w języku angielskim.
This page lists every cookie this site sets, without exception, and says plainly which of them depend on your permission.
The short version: everything in the first three tables is set whatever you choose, because the site cannot work, remember your language, or credit the right advert without it. Everything in the last two tables is set only if you clicked Accept on the banner - and if you did not, that code is never even downloaded, so there is nothing on the page that could set them.
Cookie settings, at the bottom of every page, changes the answer at any time.
The cookies we set
Strictly necessary
These make signing in, paying and staying protected from abuse possible. The site cannot work without them.
| Cookie | What it is for | Lifetime |
|---|---|---|
bpb_session | Keeps you signed in. Signed and readable only by the server. | 30 days |
bpb_ui | Tells the page, before it draws anything, whether to show the signed-in header and your balance. It is not a credential and grants no access - every request is still checked against bpb_session. | 30 days |
bpb_human | Records that you have passed the Cloudflare Turnstile check, so you are not asked again on every step. Signed and readable only by the server. | 45 minutes |
bpb_human_hint | Lets the upload form know a check has already been passed, so it does not draw a second one. | 45 minutes |
bpb_sender | Caps how many sign-in emails can be sent from one browser per day. This is what stops our address being used to send mail to strangers. | 30 days |
bpb_consent | Remembers your answer to the banner - accept or reject - so you are asked once and not on every page. Storing a refusal is what makes the refusal stick. | 12 months |
Functional
| Cookie | What it is for | Lifetime |
|---|---|---|
bpb_locale | Remembers the language you chose. We never redirect you by location - this only records your own choice. | 1 year |
Attribution
Both of these hold a label we ourselves put in a link, and nothing about you. They are first-party, are never passed to a third party, and are read exactly once - at the moment of a purchase, to work out which link earned it. They record the first link you arrived through and are not overwritten afterwards.
| Cookie | What it is for | Lifetime |
|---|---|---|
bpb_ref | If you arrived through a partner link, this records which one, so a later purchase can be credited to that partner. | 1 year |
bpb_utm | If you arrived from one of our own adverts, this records which campaign and which image - the utm_source, utm_medium, utm_campaign and utm_content values from the link you clicked. It is how we tell an advert that works from one that wastes money. | 1 year |
Analytics - only after Accept
| Cookie | What it is for | Lifetime |
|---|---|---|
ph_*_posthog | Set by PostHog, our EU-hosted product analytics, once you accept. It holds a random id that ties your page views together into one visit, so we can see where people give up. It is not linked to your name, and never to your photos. | 12 months |
bpb_did | A copy of that same random id, kept under our own domain so that a purchase - which is confirmed by Stripe on a page where our other cookies do not exist - can be joined to the visit it came from. Removed when you withdraw. | 12 months |
Advertising - only after Accept
| Cookie | What it is for | Lifetime |
|---|---|---|
_fbp | Set by the Meta pixel once you accept. It identifies this browser to Meta so that a visit or purchase can be matched to the advert that led to it. | 90 days |
_fbc | Set only if you arrived from a Meta advert. It holds the click id from that advert’s link, for the same matching. | 90 days |
That is the complete list. If you find a cookie under our domain that is not on this page, tell us at [email protected] - it is a bug.
What happens if you reject
Nothing about the site changes, and you are not asked again for 12 months. The two tables above stay empty: the PostHog bundle and the Meta pixel are never fetched, so no third-party code runs on the page at all.
We still count, on our own servers and without cookies. A small, fixed list of events - a page opened, a preview started, a purchase completed - is recorded under a code worked out fresh each day from your network address and browser. That code is never stored on your device, cannot be turned back into either input, and is a different code tomorrow. It tells us that 400 people opened the pricing page today. It cannot tell us who, and it cannot recognise any of them the next morning.
If your browser sends the Global Privacy Control signal, we read that as a rejection and do not show you the banner at all.
Cookies set by other companies
Only after you accept, and only the two named above - _fbp and _fbc, set
by Meta’s pixel. Reject, and there are none.
Three clarifications, because they are easy to mistake for ours:
- Payment. When you pay, you are on Stripe’s own checkout page. Stripe sets its own cookies there under its own domain, governed by Stripe’s privacy policy, not this one. We receive no cookie from that visit.
- Turnstile. The anti-bot check is served by Cloudflare inside a frame on
its own domain. Our
bpb_humancookie records only the result of the check. - PostHog. Its
ph_*cookie is set under our domain, not PostHog’s, because the script is served through our own address. That makes it a first-party cookie technically - but it exists to feed PostHog, so it is listed under Analytics above and gated on your consent like everything else there. Calling it “first-party” and leaving it out of the table would be true and dishonest at the same time.
Switching cookies off
The one-click way: Cookie settings at the bottom of any page. It clears your answer, removes the analytics and advertising cookies stored under it, and asks again. Nothing is remembered from before.
You can also block or delete cookies at any time in your browser. Every current browser offers this under Settings:
- Chrome - Settings, Privacy and security, Third-party cookies / Site data
- Safari - Settings, Privacy, Manage Website Data
- Firefox - Settings, Privacy & Security, Cookies and Site Data
- Edge - Settings, Cookies and site permissions
Deleting cookies from this site is safe: nothing of yours is stored in them. Your photos, your balance and your purchase history live in your account, and a sign-in link brings you back to all of it.
Be aware of what blocking them costs, since ours are not optional extras:
without bpb_session you cannot stay signed in, and without bpb_human you
will be asked to pass the anti-bot check again at every step.
Questions
Write to [email protected]. Our Privacy Policy covers everything else we hold.