Bond checking runs in this browser. Entered serials and saved holdings are not sent by this checker to our server, included in URLs, or sent to usage counting. Optional usage counts are explained below; hosting and other WordPress components need a separate release privacy inspection.
When you switch language with an unfinished checker entry, this tab temporarily keeps the entry in session storage and removes it after restoring it. Closing the tab clears this temporary storage. The entry is never put in the language link or sent to our server.
Optional usage counts require both site-operator activation and your explicit permission. If enabled and allowed, the theme sends only a broad page family, language, and a page-view or check-started/finished/unavailable event. It does not send the number, denomination, draw date, match outcome, URL, query, referrer, saved list, or a visitor identifier. No session replay is installed.
Permission lasts up to 30 days in this browser and can be withdrawn with the footer control. Withdrawal stops future requests and cancels pending ones; already combined counts cannot be separated by person. The server stores daily totals by broad event, page family and language for the current UTC date and 29 previous dates. These counts measure opted-in activity, not unique people or personal return visits.
The usage endpoint receives a normal network request. It uses a separate five-minute rotating keyed IP hash to limit requests; it does not store the raw IP in its aggregate tables. Actual deletion depends on the host scheduler and cleanup. Hosting logs, backups and other WordPress components require a separate retention and privacy check before this optional collection is activated.
My Bonds uses local browser storage. It is not encrypted. Other people using the same browser profile may see the list. You can export, import or delete it; browser clearing and private browsing can remove or restrict it. The beta and production origins have separate storage.
Feedback is submitted only when you choose to send the form. It is stored as a private WordPress record for the site operator; no email is sent. Obvious long digit strings, links and email addresses are redacted, but please do not enter private information. Records are scheduled for deletion after 30 days; the hosting scheduler and backup retention require release verification.
The feedback limit uses a short-lived keyed hash of the request IP, not a stored raw IP. Ordinary hosting logs may still record web requests. The final hosting retention policy is pending owner verification before audience release.