Effective date: 2026-09-10
Version: cookies-ohio-2026-09-10-v1
1. What this notice covers
Real Nova World Corporation uses cookies and related browser technologies to operate Bondora. A cookie is a small value stored by your browser and sent with appropriate requests. Session storage, local storage, and network events can also be used by a website. A technology does not become anonymous or exempt from privacy requirements simply because it is not called a cookie.
Read this notice together with the Privacy Notice. You can review your optional choices through Privacy Choices or the Privacy Settings control available on the site.
2. Necessary technologies
A reading-specific cookie with a name beginning bondora_reading_ is used to authorize access to an individual private reading. It contains signed session information rather than the report text. The current expiry is 30 days after the session is issued. The cookie is configured to prevent ordinary page scripts from reading it and to use secure transmission in production. It should be treated as a private credential.
Session expiry is not a data-deletion schedule. It does not establish the paid access period or remove consumer rights attached to a purchase. A transaction or reading reference is not a substitute for the session credential.
We also use necessary mechanisms for security and for remembering your privacy choices. These purposes are separate from optional product analytics. Administrator-only session technologies are used for restricted operational interfaces, not to create a public customer profile.
3. Optional analytics and draft preferences
Optional analytics measure limited product interactions and are disabled unless you choose to allow them. Rejecting optional analytics does not block access to a preview, purchase, or paid reading. We do not permit reading questions, birth details, report text, or private credentials in analytics event properties.
Where the interface offers to save a draft or remember an optional preference, it explains what is saved and the duration. Do not use a persistent saved draft on a shared device unless you understand who else can access that browser. You can use the interface’s clear-draft control where available, or clear the relevant browser storage. Your legal agreement and consent checkboxes must not be silently reselected from a saved draft.
The current storage inventory, including any enabled draft or preference storage, is shown here:
- bondora_followup_pending:[reading ID] — Tab session storage. Non-authorizing request number for checking an uncertain follow-up; no question or answer is stored here. Until the answer is retrieved, the customer explicitly starts a different failed question, or the browser discards the tab session. Session restoration may preserve it; private reading authorization is always required.
- bondora_reading_[reading ID] — HttpOnly cookie. Private reading authorization. 30 days from issuance or authorized renewal; renewal does not extend purchased access.
- bondora_market_v1 — HttpOnly cookie. Signed state, adult/capacity and no-minors declaration for approved new service. 10 minutes. Issued only after an approved eligibility declaration; all regions currently remain closed.
- bondora_requests_session — HttpOnly cookie. Private review and recovery of website request acknowledgements. 30 days from issuance when website intake is enabled. This is not proof of reading ownership.
- bondora_recovery_flow — HttpOnly cookie. Private recovery request browser, separate from report authorization. Maximum seven-day signed lifetime; issued only when independently approved recovery is enabled. It cannot restore a report by itself.
- bondora_recovery_proof — HttpOnly cookie. Verified mailbox proof bound to the same recovery request and browser. Maximum seven-day signed lifetime from verification. A separate manual approval lasts one hour; a completed claim can repeat its identical result for ten minutes without extending purchased access.
- bondora_analytics_off — Browser-readable session cookie. Current privacy-choice marker; it cannot authorize analytics alone. Browser session. A rejection takes effect immediately; browser session restoration may preserve cookies.
- bondora_privacy_choice_v1_[random choice ID] — HttpOnly session cookie. Server-signed optional-analytics permission after an explicit Allow choice. Browser session and a maximum 24-hour signature age, bound to the current choice and legal artifact. Withdrawal or GPC stops optional transmission without waiting for cookie expiry.
- bondora-reflection-draft-v2 — Tab session storage. Bounded situation, question, step and a non-authorizing reading reference for retry. Until cleared, a completed preview removes the draft, or the browser discards the tab session. Session restoration can preserve it. Agreement choices and birth profiles are not saved.
- bondora-reading-draft-v1 — Legacy tab session storage. Earlier form draft. The current form removes this key when it reads the draft, carrying forward only bounded relationship context. Use Clear saved draft on a shared device.
- bondora_admin_session — Administrator-only HttpOnly cookie. Signed authorization for restricted administration. 8 hours, limited to the /admin path. It is not a customer analytics identifier.
These are the first-party mechanisms implemented in this candidate. Actual enabled functions determine which are issued; their technical lifetimes are not data-deletion promises. PayPal may use its own payment, security and fraud-prevention technologies after checkout is deliberately started. Its exact browser keys, purposes and durations, and deployed provider behavior, still require verification. No optional third-party analytics SDK is included in the current application..
4. PayPal and other providers
When you choose to use PayPal, its checkout may load provider resources and use its own technologies for payment, security, and fraud prevention. PayPal has its own privacy and cookie information and may act independently for those activities. Choosing PayPal is not a general permission for unrelated advertising tracking by Bondora.
The active provider and purpose information appears in the storage inventory. We do not label all provider activity “necessary” merely because a provider supplies a payment or analytics tool. Where a particular activity requires a separate choice, the service must obtain that choice or avoid the activity.
5. Your controls
You can accept or reject optional analytics, change your choice later, or withdraw an earlier permission through Privacy Settings. Withdrawing permission stops future optional collection; it does not retroactively make earlier permitted processing unlawful. You may also request deletion where applicable.
A recognized Global Privacy Control signal is respected for any covered sale or sharing activity. Bondora additionally treats that signal as a reason to leave optional analytics off. We do not silently override the signal with an older saved preference. A legacy Do Not Track header is not the same mechanism.
Your browser can delete or block cookies and other storage. Blocking necessary reading-session storage may prevent private reading access. Clearing storage does not automatically delete database records or cancel a purchase. Contact real@realnova.world for an access problem or real@realnova.world for a privacy request.
6. Updates
We update this notice and the inventory when the active technology or purpose changes. We seek a new choice when a new purpose requires it rather than treating an old choice as unlimited permission.