Cookies and storage
Bullish Bear uses device storage for requested learning, security, identity and checkout functions—not for advertising or audience tracking.
Effective 27 August 2026 · Version 2026-08-27 · XXVIII Ltd, company no. 08184502Current tracking boundary
Bullish Bear does not currently install advertising cookies, behavioural trackers or analytics cookies. Because only requested or strictly necessary technology is active, there is no non-essential-cookie consent banner. If analytics or another non-essential technology is proposed later, it must remain disabled until this notice is updated and valid prior consent is available.
Auth0 identity and security
Auth0 uses strictly necessary session and security cookies when you choose to sign in with email/password or Google. They keep the authentication transaction secure, recognise the signed-in session and support sign-out. Their exact lifetime is controlled by the configured Auth0 session and security policy.
Guest Research continuity
The first-party bullish_bear_research_guest_v1 cookie is created when an unsigned learner uses a Research function that needs durable ownership. It contains a random token, not an email address or readable profile. It is HTTP-only, SameSite=Lax, Secure on HTTPS, available across the site and expires after one year. The server stores only its cryptographic hash when binding guest Research records.
Local storage
First-party local storage preserves requested course progress, chart preferences, practice and Quickfire summaries, Research continuity, free-sample state, sound choices and account-sync/conflict recovery. It remains on the device until Bullish Bear clears it through applicable sign-out or deletion behaviour, you clear site data, or a feature replaces it. Signed-in progress selected for synchronisation is also stored in the protected account database as explained in the Privacy notice.
Session storage
Session storage remembers short-lived interface state such as whether the brand introduction has been seen during the session, the narration mute choice and protection against counting the same sample twice in one session. The browser normally removes it when the tab or browsing session ends.
Paddle checkout
The Paddle checkout script is loaded only when a signed-in user requests checkout or subscription management. Paddle may then use storage required for checkout security, fraud prevention, transaction continuity and buyer-portal operation under its own notices. Bullish Bear keeps Paddle in Sandbox and the paywall off until the remaining launch gates are approved.
Your controls
You can clear Bullish Bear site data through browser settings. Doing so may remove unsigned progress, preferences and guest Research continuity from that device. Signed-in users can download or delete the application-held learner record from Your Account; an active subscription must first be cancelled through the Paddle portal.