Cookie Policy
Last updated: August 5, 2026
This Cookie Policy explains how MyNovelty uses cookies, browser local storage, session storage, and similar technologies when you use the Service. It should be read with our Privacy Policy.
We do not use optional advertising cookies or optional third-party behavioral analytics. The technologies described below support authentication, security, payments, privacy choices, and features or preferences you request.
If you want to change product privacy settings, use Settings > Privacy; this page explains what is stored and why.
Cookie Set by MyNovelty
| Cookie | Purpose | Duration |
|---|---|---|
product_mode | Remembers whether you selected the full application or the engine-focused experience after you allow functional preferences on this device. | Session (no expiration is set) |
This preference cookie is set when you explicitly choose a product mode. It is a session cookie, so it does not persist once your browser session ends. Authentication is not stored in a MyNovelty cookie.
Browser Storage
Browser storage is data saved by the web application on your device. It is not automatically included with every web request as a cookie is.
| Storage | Purpose | Typical duration |
|---|---|---|
cd:privacy-consent:v1 | Stores your browser privacy choice, when you made it, and whether functional preferences are allowed on this device so we do not keep prompting you. | Until you reset browser data or MyNovelty asks for a new choice version |
chess_access_token / chess_refresh_token | Authenticates your account and refreshes your session. Access tokens expire after a short period; refresh sessions last up to 30 days. | Until sign-out, account deletion, revocation, expiry, or browser-data clearing |
chess_user | Keeps a limited local copy of your account ID, email, display name, plan, and role for the signed-in interface. | Until sign-out, account deletion, or browser-data clearing |
auth_return_url / auth_return_url_ts | Necessary sign-in storage. Remembers the page you were on (and when) so we can send you back there after you finish signing in through email/password or an OAuth provider (Google or Facebook). | Removed as soon as sign-in completes or you sign out; a stored value older than about 10 minutes is ignored |
cd:workspace:* / repertoire workspace data | Restores open boards, PGNs, FENs, annotations, repertoire tabs, and layout state on the same device. | Until sign-out for account-scoped data, or browser-data clearing |
Engine and interface preferences | Remembers board appearance, engine source and tier, threads, hash, MultiPV, evaluation display, and similar choices only after you allow functional preferences on this device. | Until changed or browser-data clearing |
cd:engineIntent | Session storage used to recover an in-progress engine-start action after a navigation or sign-in redirect. | Current browser tab/session |
cd:analyze-handoff:* (if present) | Current-tab session storage used for one-time private analyze handoffs when unsaved content is opened without a durable server ID. | Current browser tab/session; consumed once or cleared within 10 minutes |
Key names can change as the product evolves. We group related preference keys above because they have the same function and retention behavior.
Functional preference storage is browser-scoped and off until you enable it. Necessary sign-in, security, checkout, and consent-record storage remains active because the service cannot operate without it.
Browser-local consent choices, current-tab analyze handoff state, and similar device-only data are not part of the server-side export. Account deletion also does not remotely wipe local or offline copies already on your device, including mobile caches, sync-folder copies, or GUI files outside MyNovelty systems.
Public Lichess tablebase fallback is an account choice stored by MyNovelty, not a browser cookie or functional-preference record. It is off until you allow it and remains reversible in Settings > Privacy.
Third-Party Technologies
Stripe
Stripe may use cookies and similar technologies on embedded payment elements, Checkout, and its billing portal for payment processing, fraud prevention, authentication, and session continuity. See Stripe's Privacy Policy.
Cloudflare Turnstile
MyNovelty may load Cloudflare Turnstile as a bot-protection check on account-security flows: account registration, requesting a password reset, and the sign-in challenge shown after repeated failed login attempts. Turnstile may use cookies or device signals needed for that security check. See Cloudflare's Privacy Policy.
Sign-in providers
If you choose Google or Facebook sign-in, the provider may use its own cookies during the top-level authorization flow. Those cookies are controlled by the provider, not MyNovelty.
Google Fonts
MyNovelty self-hosts its Google Fonts (Open Sans, Questrial, and IBM Plex Mono) at build time. The font files are bundled with the site and served from MyNovelty's own servers, so loading a MyNovelty page does not send a request to Google Fonts and Google does not receive your IP address, user agent, or any other request information for font loading.
Your Controls
- Open Settings > Privacy or a supported “Privacy choices” entry point to revisit your browser privacy choice when that shared dialog is available.
- Use your browser controls to view, block, or delete cookies and site data.
- Rejecting non-essential preferences prevents future optional preference writes and clears the MyNovelty functional-preference data that the current privacy harness owns.
- Sign out to remove authentication and account-scoped workspace data from that browser.
- Use a private-browsing window if you do not want preferences retained after the window closes.
Blocking the product-mode cookie only prevents that preference from being remembered. Blocking browser storage prevents account sign-in and some workspace or preference features from working. Third-party cookie controls may also prevent checkout, bot detection, or social sign-in.
Consent
MyNovelty stores a necessary browser record of your privacy choice so we can honor it on later visits. Today, the only optional category in the web app is functional preference storage on this device. No optional analytics or advertising technologies are active. If we add another optional processor later, we will update this policy and the Privacy Center before enabling it where consent is required.
Changes to This Policy
We may update this policy when our technologies or legal obligations change. We will post the updated version here and revise the “Last updated” date.
Contact
Questions about cookies or browser storage can be sent to privacy@mynovelty.io.