HMU — Cookie Policy
Last updated: 2026-05-25 Operator: Romantic Lines LP Contact: [email protected]
1. What this Policy covers
This Cookie Policy explains what cookies and similar tracking technologies are used on hmu.com (the "Service"), what they do, who sets them, how long they last, and how you can control them. It supplements — and should be read together with — our Privacy Policy.
1.1 What is a cookie?
A cookie is a small text file that a website asks your browser to store on your device. The next time you visit, the browser sends the cookie back so the site can remember things about you, such as that you are logged in or which language you prefer. Cookies can be session cookies (deleted when you close the browser) or persistent cookies (with an expiry date weeks, months or years in the future).
A first-party cookie is set by the site you are visiting. A third-party cookie is set by a different domain (for example an analytics provider).
1.2 Other tracking technologies we use
The same rules apply to other ways of storing information on or reading information from your device. The technologies we use are:
| Technology | What it is | Where we use it |
|---|---|---|
| Cookies | Browser-stored text files | Authentication, preferences, consent state |
| Local storage / session storage | Larger data stores in your browser, not sent on every request | Age-gate confirmation (hmu_age_confirmed); UI preferences |
| Web beacons / pixels | Tiny images or scripts loaded from a third-party server, used to log a page view | Transactional and (with consent) marketing emails |
| Server-side identifiers | Tokens issued by our backend and stored in a cookie or local storage | Session continuity across page loads |
| Device fingerprinting | Not used for advertising. We collect a minimal hash of browser characteristics solely for fraud and bot detection, on the basis of legitimate interests. | Fraud and abuse prevention |
Throughout this Policy, when we say "cookie" we mean all of the technologies above, unless we say otherwise.
2. Cookie categories
We group the cookies we use into four categories. The first category is set automatically; the other three are loaded only after you have given consent (where consent is required by law — typically in the EEA, UK, Brazil and Australia) or only if you have not opted out (in jurisdictions that operate on an opt-out basis, such as California).
2.1 Strictly necessary (always on)
These cookies are essential for the Service to function. Without them you cannot log in, the page cannot remember which security checks you have passed, and basic features stop working. They are set on a "legitimate interests / necessary for the performance of a contract" basis and do not require your consent.
| Cookie / token | Purpose | Set by | Lifetime |
|---|---|---|---|
| Session access token | Identifies you to the Service so you stay signed in during a session | Us (first-party, on our domain) | Session, refreshed automatically |
| Session refresh token | Lets you stay signed in across visits without re-entering your password | Us (first-party, on our domain) | 30 days |
__Host-csrf | Cross-site request forgery protection | Us (first-party) | Session |
| Load-balancing cookie | Routes you to a consistent server so the Service responds reliably | Us (first-party) | Session |
Consent state cookie (hmu_cookie_consent) | Records your cookie preferences so we do not re-ask on every page | Us (first-party) | 12 months |
2.2 Functional (consent-gated in EEA/UK/BR/AU; opt-out in US)
These cookies improve the experience but are not strictly necessary. We will not set them until you indicate a preference in the consent banner (Section 3).
| Cookie / storage key | Purpose | Set by | Lifetime |
|---|---|---|---|
hmu_age_confirmed | Records that you have passed the age gate so you are not re-prompted on every visit. Note: this is a UX shortcut, not the authoritative age check; full age assurance is run separately as required by law in your jurisdiction. | HMU (first-party local storage) | Until you clear your browser storage |
hmu_theme | Remembers your UI theme preference | HMU (first-party) | 12 months |
hmu_locale | Remembers your language preference | HMU (first-party) | 12 months |
2.3 Analytics (consent-gated in EEA/UK/BR/AU)
We use analytics to understand which features are used, where users encounter friction, and how the Service performs. Analytics cookies are never set until you have actively consented in the EEA, UK, Brazil or Australia. In the United States, analytics are on by default; California residents may opt out at any time via the "Do Not Sell or Share My Personal Information" link.
| Cookie | Purpose | Set by | Lifetime |
|---|---|---|---|
| [ANALYTICS COOKIE NAME] | Distinguish unique users for aggregate analytics | Google Analytics | [N] months |
| [ANALYTICS SESSION COOKIE] | Distinguish unique sessions for funnel analysis | Google Analytics | 30 minutes |
We do not enable cross-site advertising IDs through our analytics provider. If we add such a feature in future, we will re-request your consent.
2.4 Marketing / advertising (consent-gated everywhere we use it)
We currently do not run third-party advertising on the Service and we do not load advertising-network cookies. If this changes — for example if we introduce a refer-a-friend incentive that requires conversion tracking — we will:
- Add a row to this table identifying the provider, purpose and lifetime;
- Treat the cookie as opt-in for all users in the EEA, UK, Brazil and Australia;
- Offer a CCPA "opt-out of sharing" link for California residents;
- Show a fresh consent prompt before the cookie is set.
Marketing emails we send may include a tracking pixel that records whether you opened the email. Email tracking pixels are tied to your marketing-email consent, which you give and may withdraw separately from your cookie preferences (see your account email-preferences screen).
3. Consent management
3.1 The consent banner
When you visit the Service for the first time (or after clearing your cookies, or after we make a material change to this Policy), you will see a consent banner with three options of equal visual prominence:
- Accept all — load every cookie category listed in Section 2;
- Reject all — load only the strictly necessary cookies in Section 2.1;
- Manage preferences — open a panel where you can toggle each non-essential category individually (functional, analytics, marketing) and review the cookies set in each.
We follow the guidance issued by the French CNIL, the Italian Garante and the European Data Protection Board: "Reject all" is presented with the same emphasis as "Accept all", and refusal is as easy as acceptance. Closing or scrolling past the banner is not treated as consent.
3.2 Withdrawing or changing consent
You can change your preferences at any time by clicking the Cookie settings link in the footer of every page, which re-opens the preferences panel. You can also access the panel directly at hmu.com/cookie-settings.
Withdrawing consent does not affect the lawfulness of any processing carried out before the withdrawal. After you withdraw, the cookies in the de-selected category are deleted on your next page load.
Browser-level controls (e.g. clearing cookies or blocking third-party cookies) override any choice you have made in our banner; if you do this we will treat your next visit as a new visit and re-show the banner.
3.3 Do Not Track and Global Privacy Control signals
We honour the Global Privacy Control (GPC) signal as a valid opt-out of "sale" and "sharing" for California (CCPA / CPRA), Colorado (CPA), Connecticut (CTDPA) and other US state privacy laws that treat it as such. If your browser sends a GPC signal we will not set marketing cookies in those jurisdictions and will record the signal alongside your account.
We currently do not act on the older "Do Not Track" header because there is no industry consensus on how it should be interpreted.
4. Cookies set by third parties
A small number of cookies are set by third parties whose code runs on the Service or on their own domain. The third party, not HMU, is the entity that places these cookies; we list them here for transparency. Where the provider has its own cookie notice, we link to it.
| Third party | Purpose | Cookie names (illustrative) | Provider's cookie notice |
|---|---|---|---|
| Google Analytics | Aggregate analytics (loaded only with consent) | [List of cookie names] | [Provider URL] |
| Our payment processor | Fraud detection on the payment iframe / redirect | [Set on the processor's own domain, not ours] | [Provider URL] |
| Our age-verification provider | Liveness and anti-spoofing during age verification | [Set on the provider's own domain] | [Provider URL] |
We also send marketing emails that may include an email-open tracking pixel — loaded only by your email client when you open a marketing email, not on the website. This is tied to your marketing-email consent, not your cookie preferences (see Section 2.4).
The lifetimes, exact names and purposes of third-party cookies are determined by the third party and may change. We review this list whenever a third party whose cookies appear on the Service is added, removed or changed.
5. How to manage cookies in your browser
In addition to the in-product Cookie settings panel described in Section 3, you can manage cookies directly in your browser:
- Chrome: Settings > Privacy and security > Cookies and other site data
- Firefox: Settings > Privacy & Security > Cookies and Site Data
- Safari: Settings > Privacy
- Edge: Settings > Cookies and site permissions
- Brave: Settings > Shields and Privacy and security
You can also use industry tools such as the European Interactive Digital Advertising Alliance opt-out (https://www.youronlinechoices.eu) and the Digital Advertising Alliance opt-out (https://optout.aboutads.info), though these are aimed at the advertising ecosystem and have limited relevance to the Service today because we do not run third-party advertising.
Be aware: if you block strictly necessary cookies (Section 2.1) the Service will not work — you will not be able to log in, payments will fail, and the age gate may loop. There is no way for us to deliver a 18+ chat product without those minimal cookies.
6. Withdrawing consent — quick reference
| You want to… | Do this |
|---|---|
| Withdraw analytics consent | Footer > Cookie settings > toggle Analytics off |
| Withdraw functional-cookie consent | Footer > Cookie settings > toggle Functional off |
| Withdraw marketing-email consent | Account settings > Email preferences > Unsubscribe |
| Opt out of "sale" / "sharing" (California) | Footer > Do Not Sell or Share My Personal Information |
| Limit use of Sensitive Personal Information (California) | Footer > Limit the Use of My Sensitive Personal Information |
| Delete all cookies set by HMU | Use your browser's "Clear site data" for hmu.com |
| Delete your account and everything we hold | Profile > Delete account, or email [email protected] |
7. Children
The Service is restricted to users aged 18 and over. We do not knowingly load cookies for, or collect Personal Data from, anyone under 18. See Section 11 of the Privacy Policy.
8. Changes to this Policy
We will update this Cookie Policy when we add, remove or change a category of cookie, when we add a new subprocessor whose cookies appear on the Service, or when applicable law changes. For material changes we will:
- Show an in-app notice the next time you visit;
- Re-prompt the consent banner so you can refresh your choice;
- Update the "Last updated" date at the top.
A version history is kept at hmu.com/cookie-policy/changelog.
9. Contact
Questions about cookies, this Policy, or how to control tracking:
- Email: [email protected]
- Data Protection Officer: [email protected]
- Postal: Romantic Lines LP, 5 South Charlotte Street, Edinburgh, EH2 4AN, Scotland
- EU representative: [EU REPRESENTATIVE]
- UK representative: [UK REPRESENTATIVE]
- Brazil representative / DPO: [BRAZIL DPO/REPRESENTATIVE]
You may also lodge a complaint with your local supervisory authority — see Section 18 of the Privacy Policy for contact details.
This document is part of the HMU legal pack. See also: Privacy Policy, Terms of Service.