BernuviaBernuvia

Cookie Policy

Last updated: October 3, 2026 · Bernuvia

The binding version of this document is the English one. The Spanish version is drafted by us; the versions in the remaining languages are automatic courtesy translations generated by the platform.

1. What this policy covers

1.1. This policy lists every cookie and every item we keep in your browser, what each one is for, how long it lasts and how to remove it. It develops section 6 of our Privacy Notice, which summarises it; for everything else we do with personal data, the Privacy Notice governs.

1.2. It is written from the code of the site: every item listed here is one the site really sets. If an item is not listed, we do not set it.

1.3. It applies to the website in all its languages. The API, the MCP server and the webhooks set no cookies: they authenticate with a token sent in each request.

2. What cookies and browser storage are

2.1. A cookie is a small piece of text that a site asks your browser to keep and to send back with each request to that site. Every cookie in this policy is our own (first-party): it is set and read only by our domain. All of them carry `SameSite=Lax`, so they are not sent with requests started by other sites, except when you follow a link to us, and all of them carry `Secure` in production, so they only travel over an encrypted connection.

2.2. Some cookies are not readable by the page's own code (`HttpOnly`): only our server sees them, which protects them if a script on the page were ever compromised. The tables say which ones.

2.3. Local storage and session storage are areas of your browser where the page's own code keeps data. Nothing in them travels to our servers by itself. Session storage is erased when you close the tab; local storage stays until it is deleted. Some wallet components also use a small database in your browser (IndexedDB).

2.4. The rules on storing information on your device apply to all of these, not only to cookies, so this policy covers all of them.

3. Cookies we set

We use four categories: strictly necessary (something you asked for cannot work without it), security (it protects your account or our forms against abuse), preference (it remembers a choice you made) and referral (section 3.4).

3.1 Signing in and your wallet

NameWhat it is forDurationReadable by the pageCategory
codingpro_sessionKeeps you signed in. It holds a random token; our database keeps only a fingerprint of it.30 days from sign-in; it stops working sooner if you do not use it for 14 days, and it is deleted when you sign outNoStrictly necessary
oauth_stateProtects sign-in with Google or GitHub against forged requests (anti-CSRF).Deleted when sign-in finishes; 10 minutes at most if you abandon itNoSecurity
oauth_nextThe page to take you back to after signing in with Google or GitHub.Deleted when sign-in finishes; 10 minutes at most if you abandon itNoStrictly necessary
bv_pending_2faThe two-step verification ticket between your first sign-in step and the code from your authenticator app.5 minutesNoSecurity
bv_2fa_correoYour email address, so the two-step dialog knows which account the code is for. Only when you sign in with Google or GitHub to an account with two-step verification turned on.5 minutes; the dialog deletes it as soon as it reads itYesStrictly necessary
bv_wallet_bootA signed token, redeemable once, that opens your wallet (or creates it, the first time) right after you sign in.5 minutes; deleted when redeemedNoStrictly necessary
bv_wallet_boot_flagTells the page that there is a wallet token waiting to be redeemed. It holds only the value 1.5 minutes; deleted with the previous oneYesStrictly necessary
bv_traspaso_unlockAdministrators only: unlocks an administrative screen after a second-factor check.Until you close the browser; it stops working after 8 hours at mostNoSecurity

3.2 Your preferences

NameWhat it is forDurationReadable by the pageCategory
bv-langThe language you chose in the language selector or in your profile or, when you are signed in, the language saved in your account.1 yearYesPreference
bv-themeThe light or dark theme, once you change it. Until then the site follows your device setting and sets nothing.1 yearYesPreference
bv-sidebarWhether you keep the side menu of your dashboard collapsed. It is set only when you collapse or expand that menu.1 yearYesPreference

3.3 Forms and ratings

NameWhat it is forDurationReadable by the pageCategory
bv-contactA random marker, set when you send the contact form without being signed in, so the daily message limit applies to the same browser.400 daysNoSecurity
bv-vidA random number that records the vote you cast on a help centre or documentation article ("was this useful?") without being signed in, so you can change it and one browser does not count ten times. It is set only when you vote, never when you read.1 yearYesStrictly necessary

3.4 Invitations (referral programme)

NameWhat it is forDurationReadable by the pageCategory
bv-refThe handle of the person whose invitation link you opened (a link to any page of the site carrying the ref parameter), so that, if you then create an account, the invitation applies to it: the benefits of the referral programme for you and the commission for whoever invited you, where the programme is active.90 daysNoReferral

The invitation cookie is set when you open the link, whether or not you then create an account. It holds only the inviter's handle and no identifier of you, and it is read only at the moment an account is created: it does nothing for an account that already exists.

4. Items we keep in your browser storage

4.1 Local storage (stays until it is deleted)

NameWhat it is forWhen it is deletedCategory
bv-cartThe templates in your cart (their catalogue identifiers). Only with a session.When you sign out (it stays saved in your account); emptying the cart leaves the key with an empty listStrictly necessary
bv-cart-ownerThe identifier of the account the cart belongs to, so that another account signing in on the same browser does not inherit it.When you sign outStrictly necessary
bv-sell-draft and bv-sell-draft-edit:(template)The draft of a listing you are publishing or editing, so you do not lose it if you leave the page. When you choose to save and exit, a copy is also kept in your account so you can continue on another device.When you publish or discard the draftStrictly necessary
bv-wallet-duenoYour email address, written when you connect your wallet, to detect whether the wallet open in this browser belongs to another account.It is replaced the next time a wallet is connected; it is not deleted when you sign outSecurity
bv-otp-last-sentYour email address and the time of the last wallet code we sent, so that opening several dialogs does not send several codes.It is replaced with each new code; it is not deleted when you sign outStrictly necessary
bv-wallet-epochA marker (the value 2), written the first time you use the wallet in this browser, recording that the one-time cleanup of wallet sessions from an earlier version of the wallet sign-in has already run.It is not deletedStrictly necessary
bv-admin-nav-plegadasAdministrators only: which groups of the administration menu you collapsed.It is not deletedPreference

4.2 Session storage (erased when you close the tab)

NameWhat it is forCategory
bv-cart-pendingThe templates you tried to add to the cart before signing in; they go into your cart as soon as you sign in.Strictly necessary
bv-cash-order:(template)The order in progress when you pay by card or transfer through a payment provider, so the page can carry on when you come back from the provider's window.Strictly necessary
bv-cash-session:(template)The payment provider's session in progress, with the wallet that opened it and its balance before paying, so the waiting screen resumes if you reload. It is ignored after 2 hours if nobody started paying, and after 48 hours in any case.Strictly necessary
bv-lang-cuenta:(language):(page)A one-off lock that stops the site from redirecting you in a loop when it switches to the language saved in your account.Strictly necessary

4.3 Keys written by the wallet components

The wallet component of thirdweb runs inside our pages and keeps its own keys in local storage, so that your wallet stays connected from one page to the next: keys beginning with thirdweb (the active wallet, the connected wallets, the last chain used and the details of the wallet's signed-in user), walletToken, passkey-credential-id and a-, and keys beginning with tw.wc. When you sign out we delete the keys that hold your wallet's authentication (those beginning with thirdweb, walletToken and passkey-credential-id, and the a- key of our application); the tw.wc. keys, which only remember chain preferences for WalletConnect, stay until you delete them.

If you connect an external wallet through WalletConnect, its component keeps the connection session in your browser (keys beginning with wc@2, in IndexedDB or, if that is not available, in local storage). It stays until you disconnect the wallet or delete it; we do not delete it when you sign out.

If you connect Coinbase Wallet, its component keeps its own keys in local storage (keys beginning with -CBWSDK: and -walletlink:); thirdweb also records the parameters of a WalletConnect connection under tw:connected-wallet-params. They stay until you disconnect the wallet or delete them; we do not delete them when you sign out.

These keys follow the rules of thirdweb, WalletConnect and Coinbase Wallet, which may change their names between versions. Their processing of data is described in sections 5.1 and 5.7 of the Privacy Notice.

5. Third parties and what we do not control

5.1 Signing in with Google or GitHub

When you choose one of them, your browser goes to their site to sign in. There they set and read their own cookies under their own policies; we neither see nor control them. When you come back, only the cookies in section 3.1 are ours.

5.2 Wallets

Apart from the keys in section 4.3, signing in to the thirdweb wallet may open a frame from thirdweb's own domain, and WalletConnect may load a verification frame from its domain. What those frames keep is stored under their domain and is governed by their policies. An external wallet you install in your browser (an extension or a mobile app) keeps its own data, which we never see.

5.3 Card and conversion providers

If you pay by card or transfer, the provider you choose inside the payment component opens on its own domain, in a new window or tab. It sets its own cookies there and may ask you to verify your identity, under its own contract and its own policies. We do not control them.

5.4 Images from other servers

Some images are loaded directly from other servers: the avatars of accounts created with Google or GitHub, and some logos inside the payment component. Those servers see the IP address of whoever loads the page. We set nothing for them and we do not control what they do.

5.5 Audience and speed measurement

The pages load Vercel's audience analytics and speed measurement (Vercel Analytics and Speed Insights) from our own domain. They set no cookies, write nothing to your browser storage and use no identifier that stays in your browser: they count visits and measure load times without storing anything on your device to recognise you later. Section 5.4 of the Privacy Notice describes them.

5.6 What we do not use

There are no advertising, profiling or cross-site tracking cookies. We do not use Google Analytics or Tag Manager, advertising networks, social network buttons or plugins, heatmap or session-recording tools, third-party video players, third-party captchas or externally hosted fonts.

6. Why there is no cookie banner

6.1. The rules on storing information on your device (Article 5(3) of the European ePrivacy Directive and the national laws that implement it) require your consent before a site stores or reads anything on your device, except where it is strictly necessary to provide a service you have expressly asked for, or solely to transmit a communication.

6.2. Apart from the invitation cookie, which section 6.3 deals with, everything in sections 3 and 4 is set because you asked for something that cannot work without it (signing in, two-step verification, opening your wallet, paying, keeping your cart or your draft, recording the vote you cast), to protect your account and our forms against abuse, or to remember a choice you made (language, theme, menus). None of it is used for advertising or profiling, or to follow you across other sites.

6.3. The invitation cookie (section 3.4) is set only when you open a link that carries an invitation, and its only use is to apply that invitation if you create an account. We treat it as part of the invitation you chose to follow, not as tracking: it holds no identifier of you and it is read only when an account is created.

6.4. Our audience and speed measurement stores nothing in your browser (section 5.5).

6.5. If we ever want to use something that does need your consent, we will ask for it before setting it, and we will update this policy first. The one thing that needs your consent today, campaign emails, is asked for separately and has nothing to do with cookies (see the Privacy Notice).

7. How to delete or block them, and what happens if you do

7.1. Every major browser (Chrome, Edge, Firefox, Safari and their mobile versions) lets you, from its privacy settings, usually under "cookies and site data" or "website data", delete the data of our site alone or of every site, and block cookies for a site. Deleting a site's data removes its cookies and its local and session storage at once. In a private window, all of it is erased when you close the window. The exact steps are in your browser's help pages.

7.2. What stops working if you delete or block them:

  • Session: you are signed out. If you block cookies on our site, you cannot sign in, buy, sell or publish; you can still browse the catalogue and read the help centre and the documentation.
  • Sign-in with Google or GitHub and two-step verification: they cannot be completed while those cookies are blocked.
  • Wallet: the thirdweb keys are deleted and you will have to open your wallet again. Your wallet and your funds do not depend on your browser: the same email always opens the same wallet.
  • Language and theme: the site chooses the language again from the address you open, your browser's settings and, failing that, the country of your connection, and the theme from your device. With a session, the language and theme saved in your account still apply.
  • Vote on articles: your anonymous vote stops being recognised and you can vote again as a new visitor.
  • Invitation: if you delete the invitation cookie before creating your account, the invitation does not apply.
  • Cart and drafts: the cart is saved in your account and comes back when you sign in; a draft comes back only if you used save and exit.
  • A card or transfer payment under way: the page forgets that it was waiting, and nothing is charged because of that. If the money arrives, it stays in your wallet and you can use it to pay with the normal button.
  • Contact form: the daily limit still applies through your email address and your connection.

7.3. Deleting all this from your browser does not delete what we hold on our servers. For that, see your rights in the Privacy Notice.

8. Changes to this policy

We update this policy whenever we add, remove or change an item, so that it always matches what the site sets. The date of the last update is shown at the top of this page. If a change would need your consent, we will ask for it before setting anything.

9. Contact

For any question about this policy, write to us through the contact form with the data protection category. That category is not subject to the one-message-per-day limit and we tell you the outcome by email.