Which cookies, why, and how to control them.
At a glance
Cookies are small text files that websites store on your device. They help sites remember who you are, keep you logged in, and understand how people use the product. Nothing sinister — just plumbing that makes the web work.
This policy explains exactly which cookies Dyva, Inc. ("Dyva," "we," "us") uses, what each one does, and how you can control them. We keep it simple because you should not need a law degree to understand what is happening on your device.
Here is the full inventory — the complete list of cookies this site sets. Six in total, and none of them is set unconditionally: each appears only once the thing it records has happened to you. Local storage is covered separately in Section 7.
| Category | Cookie | Purpose | Duration |
|---|---|---|---|
| Strictly Necessary | dyva_auth | A flag — the single value "1" — that tells the server you are signed in, so a protected page renders instead of bouncing you to the login screen. It is not your session token and carries no personal data. Cleared the moment you sign out. | 30 days |
| Strictly Necessary | dyva_age_verified | A signed token recording that an age check passed, used to gate age-restricted areas. Set only if you complete a verification. | 1 year |
| Strictly Necessary | dyva_gpc | Records that your browser sent a Global Privacy Control (or legacy Do Not Track) signal, so the app can act on it and show you that it did without another round trip. Removed automatically as soon as your browser stops sending the signal. | 1 year, or until the signal stops |
| Strictly Necessary | dyva_geo_bypass | Staff-only. Set exclusively when a staff access key is used to reach the site from outside a served region. Never set for ordinary visits. | 90 days |
| Functional | NEXT_LOCALE | Stores the language you chose, so pages render in it on the server. | 1 year |
| Functional | dyva_mobile | Set when you arrive on the mobile site (m.dyva.ai), so the app serves mobile-native behavior. | 1 year |
dyva_authStrictly NecessaryA flag — the single value "1" — that tells the server you are signed in, so a protected page renders instead of bouncing you to the login screen. It is not your session token and carries no personal data. Cleared the moment you sign out.
dyva_age_verifiedStrictly NecessaryA signed token recording that an age check passed, used to gate age-restricted areas. Set only if you complete a verification.
dyva_gpcStrictly NecessaryRecords that your browser sent a Global Privacy Control (or legacy Do Not Track) signal, so the app can act on it and show you that it did without another round trip. Removed automatically as soon as your browser stops sending the signal.
dyva_geo_bypassStrictly NecessaryStaff-only. Set exclusively when a staff access key is used to reach the site from outside a served region. Never set for ordinary visits.
NEXT_LOCALEFunctionalStores the language you chose, so pages render in it on the server.
dyva_mobileFunctionalSet when you arrive on the mobile site (m.dyva.ai), so the app serves mobile-native behavior.
These carry the state the server has to know before it can render a page correctly: that you are signed in, that an age check passed, that your browser asked us to stop, and — for staff only — that a regional access key was used. They hold flags and signed tokens, not content and not identifiers we can profile you with.
Your session token itself is not in a cookie. It lives in your browser's local storage (Section 7); the dyva_auth cookie only tells the server that a signed-in session exists.
Because they are what makes the Service work, you cannot opt out of strictly necessary cookies. Blocking them in your browser will break sign-in and age-gated areas.
Two things, and only two. NEXT_LOCALE holds the language you picked, in a cookie rather than local storage because the server has to know it before it renders the page. dyva_mobile records that you arrived on the mobile site, so the app keeps serving mobile-native behavior.
Your other display choices — theme, colour, text size, density — are not cookies. They are stored on your device in local storage and never sent to us. See Section 7.
These cookies stay on your device and are not shared with anyone. If you block them, the site still works; your language will reset to your browser's default each visit.
Dyva does not set an analytics cookie. There is no visitor identifier, no session identifier for measurement, and nothing in the inventory above that exists to count you.
What does exist is the "non-essential" category the consent banner asks you about, and it is two things, both first-party and both sent to our own servers rather than stored on your device:
Both are checked against your consent choice at the moment they would send — not once at page load — so choosing "Essential Only", or withdrawing consent afterwards, stops them on the very next event without a reload.
Separately, when someone opens a publicly shared character page we record that a view happened, its type, and the referring site. No visitor identifier is stored, and nothing is recorded at all for a request carrying a privacy signal (Section 9).
We do not use Google Analytics, Facebook Pixel, or any other third-party tracking service. Your activity on Dyva stays on Dyva.
There are none on dyva.ai. We do not embed a third-party tag, pixel, or script that could set one — including Stripe's. Payment happens by sending you to Stripe's own hosted checkout page, where Stripe sets its own cookies on its own domain for payment processing, fraud prevention, and financial compliance, governed by Stripe's Privacy Policy. Nothing from that transaction is written back onto ours.
No ad networks, no social media trackers, no retargeting pixels, no data brokers. We have zero interest in selling your attention to the highest bidder.
Most of what Dyva keeps on your device is in local storage, not cookies. Unlike a cookie, it is not attached to every request — it stays on the device unless the app deliberately sends it. The significant items:
dyva_token, dyva_refresh_token) — what actually keeps you signed in.dyva_cookie_consent) and when you made it — so we can show you the decision on record and honor it. Withdrawing consent deletes both.Some short-lived state uses session storage and is gone when you close the tab. We do not use IndexedDB. All the same principles in this policy apply here — these are for functionality, not tracking. Clearing site data in your browser removes all of it and signs you out.
You do not have to go into your browser settings to change your mind, and you are not stuck with the answer you gave the banner. The control is below — it shows the choice currently recorded on this device and when you made it, and it changes that choice immediately.
The same control is in four places: this page, its own page at /legal/cookies if you want to link straight to it, the link in the site footer, and Settings → Data Controls. All four read and write the same stored choice.
Your browser settings still work too, and you are welcome to use them: every major browser lets you view and delete individual cookies, block them per site, or clear them on exit. Fair warning — blocking the strictly necessary cookies in Section 3 will prevent you from signing in and from reaching age-gated areas.
Earlier versions of this policy promised we honored Do Not Track. We did not — nothing in the product read the header. That has been fixed, and the standard has moved on: browsers have removed the DNT toggle and the working group behind it disbanded. Its successor is Global Privacy Control (Sec-GPC: 1), which, unlike DNT, is a legally binding opt-out under California's CCPA/CPRA.
We honor GPC across the platform. Every API request is checked, not just the page you happen to land on. When the signal is present:
DNT: 1 is accepted as a legacy equivalent and treated identically, for the browsers that still send it.
Two limits, stated plainly. If you are not signed in we honor the signal for the life of the request and then forget it — we will not create an identifier for someone whose browser just asked us to stop. And this is the complete list of what changes: we run no advertising technology, so there is nothing further to switch off.
We may update this Cookie Policy when our practices change or when the law requires it. The effective date at the top of this page reflects the last revision. If we make material changes — like adding a new category of cookies or a new third-party provider — we will notify you through the Service.
Questions about cookies or how we use them? Reach us at [email protected].