NixoraTrade
DRAFT

This document is a draft and is not yet in force. It has not been reviewed by a lawyer and does not create a binding agreement. Amber boxes below are internal notes marking decisions still open. Published here for review only — please do not rely on it.

Nixora Systems Inc. · United States

Cookie & Local Storage Notice

Applies to NixoraTrade. See also Terms of Use, Privacy, Risk Disclosure.


Operator: Nixora Systems, Inc., a Delaware corporation Last updated: [to be set on publication]


1. Why this is a separate document

Most products bury cookies in a paragraph of the privacy policy. We give it its own page for a reason: NixoraTrade stores far more on your device than a normal web application does. The product is local-first — your annotations, journals, knowledge base and notes live in your browser, not on our servers.

That is a privacy advantage. It also means you should understand exactly what is on your device, and what happens if you clear it.

One exception exists: if the optional cloud backup feature is enabled for your account and you use it, copies of that data are also stored on our servers (Cloudflare R2 object storage) as backups — see the Privacy Policy §1.1. Nothing is uploaded unless the feature is enabled for your account and used by you.

2. The three kinds of storage we use

What it is Sent to our server?
Cookies Small values your browser sends back to us with each request Yes — that is their purpose
localStorage Key/value settings kept by the browser No — stays on your device
IndexedDB A full database inside your browser No — stays on your device

Only cookies travel to us. localStorage and IndexedDB stay on your machine unless you explicitly export them.

3. Cookies we set

All of the cookies we set are strictly necessary — the Service cannot work without them.

Cookie Purpose Type
Session authentication Keeps you signed in during a session Strictly necessary
Stay-signed-in Set only if you tick the box at sign-in; keeps you signed in between visits Strictly necessary (user-elected)

We set no advertising cookies, no behavioural-tracking cookies, and no cross-site trackers.

Internal note · VERIFYconfirm no analytics cookie is set in production. The benchmark competitor sets third-party analytics, support and feedback cookies; if we add any, this table and §6 both change.

4. What we store in your browser

This is not sent to us. It is listed so you know what is on your device.

IndexedDB — database MarketStructureDB:

localStorage — application settings and preferences (keys prefixed msa_), including feature flags, layout and chart preferences, and your sign-in preference.

Internal note · VERIFYproduce a full inventory of `msa_*` keys from the deployed build, and check whether any of them hold personal or account-identifying data. Note the known www-origin issue: values set on a non-www origin are in separate storage.

⚠️ If you clear this, it is gone

Clearing site data, using private/incognito mode, switching browser or device, or losing the device destroys this data permanently. We do not hold a copy and we cannot restore it. Use the export function to keep your own backups.

5. Third parties that load in the page

These are the requests that leave your browser to companies other than us. When they load, that third party receives your IP address, your browser and device information, and the page you were on.

Third party Origin Why it loads When
Google Fonts fonts.googleapis.com, fonts.gstatic.com Removed. The typefaces are now served from our own servers, so no request reaches Google at all Never
unpkg unpkg.com Removed. The charting library is served from our own page; the connection this CDN used to receive on every visit bought nothing and is gone Never
TradingView — Not loaded. No TradingView widget is embedded in the product today Never
YouTube youtube.com A link to a tutorial video. It is an ordinary link, not an embed — nothing reaches YouTube unless you click it Only if you click
Economic-calendar provider — Calendar data, fetched by our server Your browser never contacts them

Each of these operates under its own privacy policy, not ours.

Internal note · OWNERDONE — the web fonts are now self-hosted, which deleted the last third-party row above. There is no longer any third-party request on any page, so the consent question was replaced by a plain notice (§6). Nothing on this list loads today.

6. Notice, not consent

Nothing on our pages loads from a third party, so there is nothing for you to consent to.

We previously asked, because the interface typefaces were fetched from Google and that request revealed your IP address to them. Those font files are now served from our own servers. The result is that every visitor gets the same behaviour — no cookies, no trackers, no third-party requests — whether or not they click anything.

We still show a short notice on your first visit, because you should be told what is kept on your device before you start putting work into it. It has a single Got it button. We deliberately do not offer a "reject" option, because there is nothing to reject: the only things stored are your own work and your sign-in session, both of which are required to provide the service you asked for. A reject button that changed nothing would be theatre, and a consent record that means nothing is worse than no banner at all.

Your acknowledgement is stored in this browser's local storage — not in a cookie. Clearing your site data removes it and the notice appears once more.

If you are in the UK or the EU/EEA

Under the ePrivacy Directive (the "cookie law") and the UK PECR, consent is required to store or read information on your device unless that storage is strictly necessary to provide the service you requested. Everything we store falls in that exemption: your annotations, journals, knowledge base and notes are the service, and your session token is what keeps you signed in. We set no cookies at all, use no analytics or advertising technology, build no profiles, and share nothing with third parties — so there is no non-essential storage for which consent could be required.

Where the GDPR applies to us, the personal data we process is described in the Privacy Policy along with the rights you have over it. This notice covers device storage specifically; it is not the whole of our GDPR disclosure.

Internal note · COUNSELconfirm this position against current US state privacy laws. Some state laws grant opt-out rights for "targeted advertising" and "sale" of personal information — we do neither today, and if that ever changes, a consent or opt-out mechanism becomes necessary.

If the Service is ever offered in the EEA or UK, this position changes completely — prior, granular, freely-given consent would be required before the third parties in §5 may load. See Set B.

7. Controlling storage yourself

8. Changes

We will update this notice when our storage or third-party resources change, and update the "Last updated" date.

9. Contact

Questions about cookies or anything stored on your device: admin@nixorasys.com General support: support@nixorasys.com Telephone: +1 302 207 9414

Nixora Systems, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States