Loading legal document
Moddingflow

Community, mods, and discussions for favorite games.

Project

NewsRatingAPIOAuthRules

Products

Moddingflow Premium

Site documents

Terms of UsePrivacy PolicyCookie PolicyLegal NoticeWithdrawal Information

Support

FAQ

© 2026 Moddingflow. All rights reserved.

Moddingflow
BETA

Games

All games (13)Recently added

My games

Oblivion RemasteredMinecraftStarfieldFallout 3The Witcher 3Oblivion
ForumNewsRating
Back to home

On this page

Summary1. Scope2. What we mean by cookies and similar technologies3. How this Cookie Policy differs from the Privacy PolicyServer-side active-audience measurement without browser storage4. Main categories5. Technology table6. When we request consent7. How to change or withdraw consent8. Third-party providers9. What the site does not use10. Policy changes and contact11. Reference sources

Moddingflow Cookie Policy

Последнее обновление: 14 August 2026

Section 1

Last updated: July 15, 2026

Summary

  • Moddingflow uses cookies, localStorage, sessionStorage, and IndexedDB for login, security, language, theme, forum drafts, view/download deduplication, manipulation protection, and stable counter operation.
  • The server-side heartbeat for the approximate DAU/WAU/MAU/YAU metric creates no new cookie, localStorage, or other browser storage. The former `mf_community_activity` cookie is no longer used and is deleted for remaining clients.
  • Technically necessary cookies and storage may be used without separate consent when they are needed for a requested function, security, login, or saving a user preference.
  • When "Remember me" is enabled during sign-in, the site stores the selected session mode in the `mf_auth_session_persistence` cookie; related auth cookies may keep the user signed in on that device for up to 30 days and survive a browser restart.
  • This Cookie Policy itself is not consent. If a particular technology requires consent, that consent is requested separately through a CMP, site settings, or an external-content load button.
  • Google AdSense and related advertising technologies are used only on allowed pages. For users in the EEA, the United Kingdom, and Switzerland, Google AdSense advertising cookies/local storage load only after consent through a Google-certified CMP if consent is required for the selected advertising type.
  • YouTube videos are first shown as a local placeholder; the external YouTube player loads only after user action or a saved permission.
  • Stripe cookies are used on Stripe Checkout or Stripe Customer Portal and are controlled by Stripe, not by the ordinary Moddingflow page.
  • As of this update, the site does not use Google Analytics, Meta Pixel, TikTok Pixel, Hotjar, Microsoft Clarity, or similar analytics/tracking tools unless they are expressly stated in this Cookie Policy.
  • 1. Scope

    This Cookie Policy explains which cookies and similar technologies the Moddingflow site at <https://moddingflow.com> uses, why they are needed, when consent is required, and how settings can be changed.

    The legal framework for Germany includes the GDPR/DSGVO and § 25 TDDDG. § 25 TDDDG regulates storing information on a user's device and accessing information already stored there, for example through cookies, localStorage, sessionStorage, IndexedDB, and similar technologies. Optional technologies, especially advertising, personalization, and external media players, are used only after consent or a separate user action where required by law.

    This policy applies to the Moddingflow site. It does not describe in detail local files, settings, or technical integrations of separate desktop applications if they exist separately from the site.

    2. What we mean by cookies and similar technologies

    In this policy, "cookies" is used broadly. It includes:

    • HTTP cookies that the browser stores and sends to the site or an external provider;
    • browser localStorage and sessionStorage;
    • IndexedDB, for example for local forum drafts;
    • consent strings, CMP signals, and records of user choices;
    • pixels, tags, and similar advertising or measurement calls;
    • third-party embeds, for example the external YouTube player;
    • Google AdSense and DoubleClick technologies if they load on allowed pages.

    These technologies may store or read information on the device. Some of them may also lead to processing of personal data, for example IP address, page URL, browser data, advertising identifiers, or interaction information. More detail about personal-data processing in general is provided in the Privacy Policy.

    3. How this Cookie Policy differs from the Privacy Policy

    This Cookie Policy explains storage and reading of data on the user's device and similar technologies: which keys are used, what they are for, how long they may be stored, and when consent is required.

    The Privacy Policy explains personal-data processing in general: account, forum, publications, payments, providers, user rights, retention periods, and GDPR/DSGVO legal bases.

    This Cookie Policy does not replace consent and does not make optional technologies permitted. If a technology requires consent, consent must be obtained separately.

    Server-side active-audience measurement without browser storage

    After the feature is enabled, a visible, non-idle tab sends a one-minute heartbeat to the server on user pages outside `/admin`. It creates no cookie, localStorage, sessionStorage, IndexedDB, or other identifier on the device. The former `mf_community_activity` has been retired and expires; the separate `forum-anon-session-key` remains only for the existing deduplication of guest views and downloads and is not the identity for the new metric.

    The server accepts an IP only through the trusted proxy, normalizes it, and immediately converts it into an HMAC-SHA256 pseudonym. No raw IP is retained. One pseudonym counts as one approximate unique visitor in a rolling window, so a shared IP can merge several people and a changing IP can count one person more than once. Server-side sessions are retained for 731 days. This is processing of pseudonymised, not anonymous, personal data; the purposes, legal basis, and rights are described in the Privacy Policy.

    4. Main categories

    Strictly necessary. Needed for login, sessions, security, delivery of a requested function, saving required interface state, or carrying out a user choice. Separate consent is usually not requested.

    Functional / preferences. Save the selected language, theme, local interface state, drafts, and similar preferences. They are used without separate advertising consent where they are needed for a function or setting selected by the user.

    Security / anti-abuse. Help protect the MFA process, deduplicate views and downloads, prevent manipulation of statistics, abuse, and repeated actions.

    Optional advertising. Google AdSense, DoubleClick, Google CMP consent signals, advertising cookies, frequency capping, reporting, fraud prevention and similar ads technologies. For users in the EEA, the United Kingdom, and Switzerland, Google advertising cookies/local storage load only after consent through a Google-certified CMP if consent is required for the selected advertising type.

    External media. Embedded YouTube/Google materials do not load immediately. The site first shows a local placeholder and loads the external player only after user action or a saved permission.

    Payment-provider cookies outside the site. During payment or subscription management, the user goes to Stripe Checkout or Stripe Customer Portal. Cookies and similar technologies on those pages are controlled by Stripe.

    5. Technology table

    Technology / keyTypeProviderPurposeCategoryPeriodConsent
    `sb-...-auth-token` and related Supabase Auth cookiescookieSupabase AuthLogin, maintaining the session, refresh token, and account protectionstrictly necessaryUntil logout, expiration, session/token revocation, or clearing cookiesNo separate consent requested
    `mf_auth_session_persistence`cookieModdingflowStores the selected session mode: ordinary browser session or "Remember me"; with the `remembered` value, related auth cookies may keep the user signed in after a browser restartstrictly necessary / user choiceUp to 30 days for `remembered`; for `session` - until the browser session closes, logout, session revocation, or clearing cookiesNo separate advertising consent requested; used only by user choice
    `mf_community_activity` (legacy, retired)cookieModdingflowFormer guest-activity key; the new HMAC-IP metric does not read it and site responses delete remaining copiesretiredExpires immediatelyNot used
    `site-lang`, legacy `forum-lang`cookieModdingflowSite language and compatibility with the old forum language cookiefunctional / preferenceUp to 12 months, language change, or clearing cookiesNo separate consent requested
    `whistle-theme`localStorageModdingflowInterface themefunctional / preferenceUntil theme change, settings reset, or clearing storageNo separate consent requested
    `whistle-privacy-lang`, `whistle-rules-lang`localStorageModdingflowLanguage of legal pages and related linksfunctional / preferenceUntil language change, settings reset, or clearing storageNo separate consent requested
    `forum-reply-draft:{topicId}` and IndexedDB `moddinghub-forum` / `replyDrafts`localStorage and IndexedDBModdingflowLocal forum reply draftsfunctionalUntil submission, draft deletion, removing the topic from storage, or clearing the browserNo separate consent requested
    `forum:viewed:{topicId}`sessionStorageModdingflowAvoid counting the same view again in one tabsecurity / functionalUntil the tab or browser session closesNo separate consent requested
    `forum-anon-session-key`localStorageModdingflowDeduplicating guest views/downloads and protecting statisticssecurity / functionalUntil browser localStorage is clearedNo separate consent requested
    `mfa-fail-count`localStorageModdingflowProtecting the MFA process against brute force and repeated failuressecurityUsually only the current MFA process; also until reset or clearing storageNo separate consent requested
    `moddingflow-header-auth-identity-v1`localStorageModdingflowLocal cache of account header state: login, nickname, avatar, status, and similar interface datafunctionalUntil logout, account change, site-cache clearing, or clearing storageNo separate consent requested
    `cookie-consent`, legacy `cookie_consent`, `cookies-accepted`cookie and/or localStorageModdingflowLegacy preference only: previous local cookie-preference or reset recordlegacy preferenceUntil settings reset or clearing the browserNot a source of Google AdSense consent
    `whistle-external-media-consent`localStorage + cookieModdingflowStoring the user's choice to allow external videos so the local placeholder is not shown every timeoptional external mediaUp to 12 months, until permission is withdrawn, or until browser storage is clearedRequires a user choice; can be reset
    Google CMP consent signals, including TCF/Google consent strings where applicablecookies, localStorage, and similar technologiesGoogle / Google-certified CMPManaging advertising consent, showing the CMP message, storing and transmitting the user's choiceoptional advertising consentAccording to Google CMP, message, browser, and Google account settingsThrough Google CMP for the EEA/United Kingdom/Switzerland, if applicable to the region and selected advertising mode
    Google AdSense / DoubleClick cookies, for example `__gads`, `__gpi`, `__eoi`, `FCNEC`, `IDE`, `NID`, or similarcookies, pixels/tags, local storage, and similar technologiesGoogleAds, frequency capping, reporting, fraud prevention, ad delivery and measurementoptional advertisingProvider-controlled; depends on Google, browser, region, and user choiceFor the EEA/United Kingdom/Switzerland - through a Google-certified CMP if consent is required for the selected advertising type
    YouTube/Google after an embed loadscookies, localStorage, network requests, and similar technologiesGoogle / YouTubeShowing video and operating the external playeroptional external mediaProvider-controlled; depends on Google/YouTube, browser, and Google accountOnly after user action or a saved setting
    Stripe cookies on Stripe Checkout / Stripe Customer Portalcookies and similar technologies on Stripe pagesStripePayment, fraud prevention, checkout, subscription management, customer portalpayment-provider cookies outside the siteControlled by Stripe, not by the Moddingflow siteManaged by Stripe and applicable Stripe settings

    6. When we request consent

    Moddingflow requests consent or a separate user action when a technology is not technically necessary and applicable law requires consent. This especially applies to Google AdSense, advertising personalization, advertising storage, Google/DoubleClick cookies, the external YouTube player, and saved permission for external media.

    For users in the EEA, the United Kingdom, and Switzerland, Google AdSense advertising cookies/local storage load only after consent through Google Privacy & messaging, a Google-certified CMP with support for the IAB Transparency & Consent Framework and, where applicable, Google consent signals, if consent is required for the selected advertising type. The CMP may offer consent, refusal, or settings.

    Even for non-personalized ads, Google may use cookies or similar storage for frequency capping, aggregated reporting, and fraud/abuse prevention. In countries where ePrivacy-style rules apply, consent may also be required for that storage.

    Technically necessary cookies and storage, for example auth cookies, the "Remember me" setting, language, theme, security keys, local drafts, or anti-abuse keys, are used without separate consent when they are needed for a requested function, security, login, or saving a user preference.

    7. How to change or withdraw consent

    You can change or withdraw choices in several ways:

    • through the Google CMP / Privacy & messaging link or settings element if it is shown on the site for your region;
    • through Moddingflow account privacy settings if the corresponding setting is available;
    • through the "Reset external videos" / "Reset videos" action in the "Privacy" section of the Moddingflow account: it removes the permanent permission, reloads the page, and after reload embedded YouTube/Google materials require another click;
    • through browser settings, where cookies, localStorage, sessionStorage, and IndexedDB for `moddingflow.com` can be deleted;
    • through Google account, browser, or device settings for Google advertising preferences where applicable;
    • through Stripe settings on Stripe pages if you are on Stripe Checkout, Stripe Customer Portal, or another Stripe service.

    If you delete technically necessary cookies/storage, some functions may stop working correctly: login may be reset, the selected language or theme may return to default, local forum drafts may disappear, and external videos may require user action again.

    8. Third-party providers

    Google AdSense / DoubleClick / Google CMP. On allowed pages, the site may load the Google AdSense script. For advertising, Google may use cookies, tags, local storage, consent signals and similar technologies for ad delivery, frequency capping, reporting, fraud prevention and, where allowed, personalization. For users in the EEA, the United Kingdom, and Switzerland, Google AdSense advertising cookies/local storage load only after consent through a Google-certified CMP if consent is required for the selected advertising type.

    YouTube / Google external media. The site uses privacy-enhanced / no-cookie embeds through `youtube-nocookie.com`, but this does not fully exclude data processing. The external YouTube player loads only after user action or a saved permission. Before the user presses the video-load button, the user's browser should not contact YouTube/Google domains for that embed. If a preview is used, it is loaded locally from Moddingflow or shown as a local placeholder. After loading, Google/YouTube may receive the IP address, page URL, browser data, and information about interaction with the video.

    Stripe. During payment, the user goes to Stripe Checkout or Stripe Customer Portal, where cookies and similar technologies are controlled by Stripe. Stripe may use those technologies for payment, fraud prevention, security, checkout, customer portal and subscription management. Moddingflow does not control the duration of Stripe cookies on Stripe pages.

    Supabase Auth. Supabase Auth is used for login and sessions. Related auth cookies are needed for the requested account function and security.

    9. What the site does not use

    As of this update, Moddingflow site code does not use Google Analytics, Meta Pixel, TikTok Pixel, Hotjar, Microsoft Clarity, or similar analytics/tracking tools unless they are expressly stated in this Cookie Policy.

    This does not mean that the site uses no optional technologies at all. Google AdSense may be used on allowed pages, YouTube videos may load after user action or saved permission, and payment or subscription management may happen on Stripe pages.

    If such analytics/tracking tools are added in the future, this Cookie Policy will be updated, and consent will be requested where required by law.

    10. Policy changes and contact

    Moddingflow may update this Cookie Policy if technologies, providers, consent settings, legal requirements, or site functions change. Material changes may be shown on the site or in the account where applicable.

    Contact for cookies and privacy questions:

    Valerii Semenov
    Email: <moddingflow@gmail.com>
    Postal address:
    c/o Autorenglück #61208
    Albert-Einstein-Straße 47
    02977 Hoyerswerda
    Germany

    11. Reference sources

    This policy was prepared with reference to § 25 TDDDG, the GDPR/DSGVO, including Recital 30 and Articles 5 and 13, the EDPB explanation of pseudonymisation, EDPB Guidelines 05/2020 on consent, Google AdSense EU user consent policy and Privacy & messaging guidance, Google consent revocation guidance, YouTube privacy-enhanced embed documentation, and Stripe Cookie Policy.