Blackwing
TermsPrivacyCookiesSovereignty

Cookie Policy

Effective date: August 9, 2026 · Last updated: August 9, 2026

Plain-English summary: Blackwing sets three cookies, all of them strictly necessary — one keeps you signed in, two protect the sign-in flow itself. We run no analytics, no advertising, no third-party trackers, no fingerprinting, and no cross-site tracking of any kind. We do not sell or share personal information. If we ever add privacy-preserving, aggregate usage measurement, it will be off until you turn it on.

This Cookie Policy explains how Blackwing (“we,” “us,” “our”) uses cookies and similar technologies, including browser local storage, on blackwing.software (the “Service”). It should be read together with our Privacy Policy and Terms of Service.

1. What Cookies and Similar Technologies Are

A cookie is a small text file a website asks your browser to store. “Similar technologies” covers anything else that reads from or writes to your device, including localStorage, sessionStorage, and tracking pixels. Privacy law in most jurisdictions treats all of these the same way, so this policy does too: everything below is disclosed regardless of the technical mechanism used.

We group them into two categories.

Strictly necessary. Required to deliver a service you have explicitly asked for — signing in, staying signed in, and protecting that process from attack. These cannot be switched off, because without them the Service cannot function. Under the EU ePrivacy Directive, the UK PECR, and equivalent rules elsewhere, these do not require consent.

Optional. Everything else. As of the effective date above, we use none. Optional storage is off by default in every country and stays off until you affirmatively enable it.

2. Cookies We Set

All three are first-party (set by blackwing.software, readable by nobody else), HttpOnly (unreadable by JavaScript, including any script an attacker manages to inject), Secure in production (only ever sent over HTTPS), and SameSite=Lax — meaning they are not attached to background requests made by other websites. They are still sent when you follow a top-level link into the site, which is what allows the return leg of the DigitalOcean sign-in to work.

NamePurposeCategoryLifetime
rf_sessionKeeps you signed in after authentication. Contains a signed token identifying your account and session generation — no wallet material of any kind.Strictly necessary24 hours
rf_oauth_stateA single-use random value that ties your DigitalOcean sign-in request to the response, preventing cross-site request forgery during login.Strictly necessary10 minutes
rf_oauth_pkce_verifierThe PKCE verifier for the DigitalOcean OAuth exchange, which stops an intercepted authorisation code from being redeemed by anyone else.Strictly necessary10 minutes

We set no other cookies. There are no advertising cookies, no analytics cookies, no social-media cookies, and no third-party cookies. The Service loads no third-party scripts, tag managers, or tracking pixels.

3. Data Your Browser Stores Locally

The application also stores information in your browser’s localStorage. This data never leaves your device — it is not transmitted to us, it is not readable by any other site, and it is not used to identify, profile, or track you. It exists so the interface behaves sensibly across page reloads.

What is storedWhy
Your selected node and interface preferencesSo the app shows the node you were last working with, and remembers small UI choices such as whether an explainer panel is open.
Your address book and saved distribution programsThese are deliberately local-only features. Your contacts and followed programs are stored on your device rather than on our servers, so that we never hold them.
Onboarding and wallet-setup progress markersFlags recording that you confirmed a recovery-phrase backup or that a node has begun syncing, so reloading the page does not lose your place. No seed phrase, passphrase, or private key is ever stored, in local storage or anywhere else.
Mining display stateRecent hashrate samples and rate-calculation anchors, so charts stay continuous between polls.
Your privacy choicesThe record of the choice you made in the cookie banner, including the date and how it was made, kept under the key blackwing.consent.v1.
Kaspa chat and collection recordsLocally cached conversation peer details and records of KRC-721 collections you deployed.

Because this data is local, you can erase all of it at any time by clearing site data in your browser. Doing so signs you out and resets these preferences; it does not affect your node, your wallet, or anything on-chain.

4. Your Choices, by Jurisdiction

We apply one standard everywhere: optional storage is off unless you opt in. Some jurisdictions permit a weaker opt-out standard; we do not use it. The differences below therefore concern the rights and controls available to you, not the amount of data we collect.

4.1 European Economic Area, United Kingdom and Switzerland

Under the ePrivacy Directive and GDPR (and the UK PECR and Swiss revFADP), we must obtain your consent before storing anything non-essential. We do not store anything non-essential at all, and no optional storage is written before consent is given. You can refuse in one click, refusing is exactly as easy as accepting, and you can withdraw consent at any time from the link in the footer of every page. Refusing costs you nothing: the Service works identically either way. We re-ask for consent at least every six months so that a stale choice cannot stand in indefinitely.

4.2 California

Under the CCPA as amended by the CPRA: we do not sell your personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the statute. There is accordingly no “Do Not Sell or Share My Personal Information” process to complete — there is nothing to opt out of. We honour the Global Privacy Control signal automatically. Your rights to know, delete, correct, and to be free from retaliation are described in the Privacy Policy.

4.3 Other United States states

Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Delaware, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland and other states with comprehensive privacy laws grant a right to opt out of targeted advertising, sale, and certain profiling. We do none of these things. Where the law requires recognition of a universal opt-out mechanism, we honour the Global Privacy Control signal.

4.4 Canada, Brazil and elsewhere

Quebec’s Law 25, Canada’s PIPEDA, and Brazil’s LGPD impose consent requirements comparable to the EEA standard. We apply the same opt-in default to visitors from these jurisdictions, and to any visitor whose location we cannot determine.

4.5 Global Privacy Control

If your browser or an extension sends a Global Privacy Control signal — or the older Do Not Track header — we treat it as a refusal of all optional storage, record that refusal, and do not interrupt you with a banner. You can still open at any time to review or change that: if you make an affirmative choice there yourself, that later explicit choice governs, because the dialog tells you the signal was detected before you decide.

5. How We Determine Which Rules Apply

To show you the correct notice, we make a rough guess at your region from one signal only: the timezone your browser already reports.

We deliberately do not use an IP geolocation service to do this. Sending every visitor’s IP address to a third-party lookup provider in order to display a privacy notice would create precisely the kind of data flow this notice exists to avoid.

The trade-off is that the guess is imperfect — a VPN or an unusual timezone will get it wrong. This does not affect your privacy, because the strict opt-in default applies to everyone regardless of detected location, and any region we cannot identify is treated as the strictest. Detection only changes wording.

6. Future Use of Aggregate Usage Measurement

We may later add privacy-preserving measurement of how the site is used — for example, which pages are visited and how long they are read — to help us improve it. If we do:

  • it will be counted in aggregate and will not be used to build a profile of you or to identify you;
  • it will remain off until you opt in, in every jurisdiction, through the controls described above;
  • it will never be used for advertising, and personal information will never be sold or shared;
  • this policy will be updated and the effective date changed before any such measurement is enabled, and everyone will be asked again rather than having a previous choice reinterpreted as agreement.

7. Changes to This Policy

If we change how we use cookies or similar technologies, we will update this page and change the “Last updated” date. Where the change means we would collect more than you previously agreed to, we will ask for your consent again rather than relying on the old choice.

8. Contact

Questions about this policy, or a request to exercise your rights, can be sent through the contact route listed in the Privacy Policy.

Blackwing is a non-custodial software interface. By using it you agree to the Terms of Service and Privacy Policy. You can change your at any time.