NILLOW PRIVACY

A membrane around the person, not a profile of the person.

Nillow accepts account data and bounded project intent. OXA may organize what a project needs, but it does not decide who a person is, whether they are eligible, or what they can be persuaded to buy.

Controller and contact

This surface renders deployment configuration. Missing facts remain visibly missing instead of being inferred from the Nillow brand.

What crosses the membrane

Only information needed for the account, project, security, and explicitly initiated commercial path belongs here.

Account identity

Access, not behavioral identity

Email, username, password hash, active sessions, profile fields you choose, and bounded security audit events support account access and protection.

Project request

The work you ask us to understand

Your project summary, desired outcome, declared constraints, optional contact fields, permission receipts, and submission state are used to review and respond to the request.

Billing

Only after an explicit checkout

An immutable offer, its acceptance receipt, and bounded Paddle references are processed only when you deliberately start checkout. Paddle—not Nillow—collects payment-card details. A browser redirect never proves settlement and no payment grants enrollment, entitlement, or runtime authority.

Purpose and control boundaries

A permission receipt controls an application action. It does not, by itself, manufacture a legal basis for unrelated processing.

  • Project intake is recorded for steps taken at your request before a possible contract and for responding to that request.
  • Contact authorization permits a response about the submitted project. It does not subscribe you to marketing.
  • Optional marketing, if introduced, requires its own unchecked, versioned, withdrawable control.
  • Security evidence is kept separate from commercial persuasion and does not grant product or runtime authority.

Cookies and device storage

Optional audience measurement starts disabled. Rejecting it does not block the website, Portal account access, or project requests. The persistent Privacy Controls button reopens the choice and withdrawal removes the optional local identifier.

Essential

Secure sessions and requested actions

n0_session authenticates a Portal session for up to 12 hours, or 30 days only when Remember Me is selected. n0_passkey_pending binds a passkey ceremony for at most three minutes. Requested Portal and OXA handoffs may use short-lived session storage. These functions are not used for advertising and cannot be disabled while using the related service.

Optional analytics

First-party, bounded, off by default

When allowed, the HttpOnly n0_privacy_choice cookie presents an opaque choice token to the server, while __n0_funnel_sid_v1 groups the sequence of bounded route and interaction events within one tab. Each permitted event also carries the server-side identifier of the active consent receipt, so events made under the same receipt can be associated across tabs and visits for consent enforcement and retention. These fields do not directly name a person or contain visitor-authored project text. Withdrawal revokes the receipt, clears the cookie, and immediately disables and clears the optional tab identifier in every open same-origin tab.

Installed app

Explicit standalone mobile shell

The first-party service worker and nillow-mobile-brand-v2 cache are created only after the site has been installed and launched as a standalone web app. Ordinary browser visits do not register it.

  • Nillow currently deploys no advertising cookie, third-party analytics SDK, social pixel, or cross-site behavioral tracker.
  • The versioned consent choice itself is essential storage: it records what you accepted or refused for 180 days so the site can enforce that decision without asking on every page.
  • Explicit display and motion preferences are stored only after you use the corresponding control and serve that requested preference.

OXA project-intent assistance

OXA is allowed to map a project. It is not allowed to map a person into a persuasion target.

  • The report may organize stated needs, project constraints, possible capabilities, evidence, uncertainty, and open questions.
  • It must not infer personality, vulnerability, health, wealth, demographics, emotions, or presumed purchasing authority.
  • The project report remains reviewable and correctable by a person; an operator decides what happens next.

Retention and recipients

Retention review is a deletion decision point, not permission to keep every field indefinitely.

  • Expired sessions, abandoned handoffs, notification artifacts, analytics, and closed commercial records require separate, purpose-bounded schedules.
  • Limited billing, fraud, security, or claims evidence may need to be retained where a documented legal obligation or legal hold applies.
  • Commercial handling can create private operator notes, contact and follow-up evidence, internal quote drafts, and bounded processing receipts. These records follow the commercial retention review; won work requires a separate contract and claims review before disposal.
  • Deletion must cover the primary database, configured processors, and backup expiry—not only the visible account row.

Your controls

The authenticated export returns only commercial submissions linked to the signed-in account and their commercial state. It is not a complete Article 15 response: private operator notes, follow-up records, internal quote drafts, staff identities, and processing receipts require verified human review. It also excludes password, session, hash, webhook, and payment-provider internals.

  • Access and portability: use the authenticated submission export or request a broader verified copy from the configured privacy contact.
  • Correction, restriction, objection, and erasure: contact the configured controller. Identity must be verified before private data is disclosed or removed.
  • A processing-restricted commercial submission remains stored but is withheld from notification delivery and commercial operator handling. Restriction is not erasure.
  • Erasure may produce a disposition explaining which categories were deleted, anonymized, restricted, or retained under an applicable exception.
  • You may complain to the data-protection authority for your habitual residence, workplace, or the place of an alleged infringement.
Nillow
NILLOW://_
NILLOW OSENGINEERINGINTELLIGENCEPORTAL