Cookie Policy

Effective 14 August 2026 · Version 3.0

This policy lists every cookie, local storage key and similar technology NovaBuild uses on novabuild.dev, explains why each one exists, and shows how to control them. It is a companion to the Privacy Policy.

Plain language summary

  • We use a small set of first party cookies. Most of them exist so you can stay signed in securely.
  • Preferences such as theme and sidebar state are kept in local storage on your own device.
  • Product analytics is aggregate and first party. We do not run advertising or cross site tracking cookies.
  • You can clear everything at any time from your browser, and you can opt out of analytics in the app.

The summary is for orientation only. The numbered sections below are the operative text.

1. What this policy covers

This policy covers the NovaBuild marketing site, the signed in application, the public project share pages and the documentation. It does not cover applications you build with NovaBuild and deploy yourself. Those are your sites, and you are responsible for publishing your own cookie notice and collecting consent where required.

2. What cookies and similar technologies are

A cookie is a small text file a site asks your browser to store and send back on later requests. Related technologies do similar jobs: local storage and session storage keep values on your device without sending them automatically, and pixels or beacons signal that a page or email was opened. We describe all of these together as cookies in this policy.

Cookies are first party when they are set by novabuild.dev, and third party when they are set by another domain loaded on the page. Session cookies disappear when you close the browser. Persistent cookies last until they expire or you delete them.

3. Categories we use

CategoryPurposeConsent neededCan you refuse
Strictly necessarySign in, session security, request integrity, abuse preventionNoNot while using the signed in app
PreferencesTheme, sidebar state, last workspace, editor layoutNo, stored locally on your deviceYes, clear site data
AnalyticsAggregate product measurement and error diagnosticsYes where required by lawYes, opt out in settings
AdvertisingNot usedNot applicableNot applicable

4. Strictly necessary cookies

NameTypePurposeLifetime
sb-access-tokenFirst party cookieCarries your short lived authentication token so server rendered pages know who you are1 hour
sb-refresh-tokenFirst party cookieRefreshes your session without forcing a new sign in30 days or until sign out
sb-<project>-auth-tokenLocal storageHolds the browser side session for the single page appUntil sign out or cleared
nb-csrfFirst party cookieProtects form and server function calls against cross site request forgerySession
nb-rlFirst party cookieTies a browser to a rate limit bucket so abuse controls work fairly24 hours

These cookies are set on the basis of necessity, not consent, because the signed in application cannot work without them. Blocking them will sign you out and break agent runs, previews and deploys.

5. Preference storage

KeyTypePurposeLifetime
nb-themeLocal storageRemembers Dark or Pearl so the app does not flash the wrong theme on loadUntil cleared
nb-workspaceLocal storageReopens the workspace you used lastUntil cleared
nb-sidebarLocal storageRemembers whether the sidebar is expandedUntil cleared
nb-editor-paneLocal storageRemembers the split between chat and previewUntil cleared
nb-cookie-choiceLocal storageRecords your analytics choice so we stop asking12 months

These values never leave your device automatically. Clearing site data resets them to the defaults.

6. Analytics and product measurement

We measure aggregate product usage so we can see which flows fail, which pages are slow and where agent runs break. Analytics events are first party, keyed to a rotating pseudonymous identifier rather than to your email, and never used to build advertising profiles or sold to anyone.

  • Events recorded include page views, prompt submissions, run outcomes, build failures and deploy outcomes.
  • We record coarse location derived from IP at country level, and we do not store the full IP alongside analytics events.
  • Public project share pages record anonymous view counts and referrer domains so project owners can see traffic.
  • You can opt out of product analytics in workspace settings, and the app then stops emitting these events for you.

Where the law requires consent for analytics, we ask before the first analytics event is sent, and we treat a refusal as a durable choice recorded in nb-cookie-choice.

7. Sandbox and preview frames

Project previews are served from an isolated sandbox domain inside an iframe. That domain may set its own technical cookies to route requests to the right container and to keep the hot reload channel open. Those cookies belong to the preview session, are cleared when the sandbox stops, and carry no profiling data.

Your app can set its own cookies

When you build authentication or analytics into a generated project, the preview will set whatever cookies your code sets. Those are yours to document and to obtain consent for.

8. What we do not use

  • No advertising or retargeting cookies, and no advertising network pixels.
  • No cross site tracking, no data broker enrichment, no fingerprinting scripts.
  • No session recording or keystroke capture of your prompts or code.
  • No social media share buttons that phone home before you click.

10. Browser and device controls

Every major browser lets you view, block and delete cookies, and clear local storage, from its privacy settings. Look for "Cookies and site data" in Chrome and Edge, "Cookies and Site Data" in Firefox, and "Privacy" in Safari. You can also use a private window to keep storage for one session only.

Trade offs to expect

  • Blocking all cookies signs you out of NovaBuild and prevents sign in.
  • Clearing local storage resets your theme, workspace and layout preferences.
  • Blocking third party frames prevents project previews from rendering.

11. Do Not Track and Global Privacy Control

We honour the Global Privacy Control signal as an opt out of non essential analytics. Browser Do Not Track headers have no agreed meaning, so we treat them the same way, which means we also stop non essential analytics when we see one.

12. Cookies in the apps you build

Generated projects can use cookies, local storage and third party scripts. When you deploy such a project you become the operator of that site. You are responsible for a cookie notice, for a lawful consent mechanism where required, and for keeping the inventory accurate. Ask an agent to scaffold a cookie banner and policy page for your project if you need one.

14. Changes to this policy

When we add or remove a cookie we update the tables above and the effective date. Material changes to non essential storage are announced in the app, and where consent is required we ask again rather than relying on an old choice.

15. Contact

Questions about this policy or a specific cookie: privacy@novabuild.dev. We are happy to confirm the current inventory in writing for procurement reviews.

This document is published by the NovaBuild team as general information about the service. It is not legal advice, and it is not a certification or an independent audit of NovaBuild or of any third party. If anything here is unclear, or you need a countersigned copy for procurement, email legal@novabuild.dev.