Cookies are small files a site asks your browser to keep. This page lists every one this build sets, who sets it, what it is for and how long it lasts. It is written against the code that exists today, not against a template.
Two things are true of this build and worth saying first. Non-essential cookies are refused by default: nothing beyond what the Service needs to work is set until you accept it, and refusing is a click, not a form. And there is no public sign-in and no paid plan yet, so the cookies that depend on them are listed as planned: they appear when the feature that needs them ships.
This Policy forms part of our Terms of Service and is read together with the Privacy Policy, which explains what we do with personal data once we have it.
Categories we use
- Strictly necessary. Without them the Service does not work: telling a person from a script on our forms, remembering what you chose in the cookie banner, holding an internal review key and, once sign-in exists, keeping you signed in. These are set without asking, because asking to be allowed to remember your refusal is a loop.
- Analytics. Counting how a page is used. Off by default; only after you accept; and not configured in this build at all, as the section below explains.
- Advertising. We set none, and there are no advertising or cross-site tracking cookies in this build.
What this build sets today
| Name | Set by | Purpose | Category | Lifetime | Status |
|---|---|---|---|---|---|
q24_consent | Quant24 | Records what you chose in the cookie banner: whether analytics is on or off, the date, a random identifier that is tied to no name, email or account, and the version of this Policy in force when you chose. Secure, SameSite=Lax, sent on every path of the site. It is written only when you press a button in the banner or in the settings dialog; reading a page sets nothing | Strictly necessary | One year | In this build |
| Cloudflare Turnstile | Cloudflare, on our behalf | The human check on our forms. It loads when a form comes into view and runs between your browser and Cloudflare, which receives your IP address and browser signals (user-agent, TLS fingerprint) and also uses them to improve Turnstile, as Cloudflare's Turnstile privacy addendum describes; we then pass Cloudflare the token and your IP address once, to verify it. While it runs, Cloudflare may set its challenge cookies — cf_clearance and the cf_chl_rc_* family — on its own domain, with names and lifetimes that are Cloudflare's, listed in Cloudflare's cookie policy | Strictly necessary | Set by Cloudflare | In this build |
q24_internal | Quant24 | Proves the reader holds the internal key for the design and content review route. HttpOnly, Secure, SameSite=Lax, Path=/design, so it is not sent anywhere else on the site | Strictly necessary | 30 days | In this build |
That is the whole list, and each entry is set only when something happens: you decide in the banner, a form comes into view, or you hold an internal key. A page without a form, read and left, asks your browser to store nothing. The internal route is not linked from anywhere public, and the production deployment does not serve it at all.
Your banner choice is also written to our database, under the same random identifier the cookie carries and with the version of this Policy — no name, no email, no account. It is how we can show that a choice was made if we are ever asked to, and the Privacy Policy describes it.
What is planned, and when it appears
These are not set yet. Each appears when the feature that needs it ships, and this page is updated in the same commit.
| Name | Set by | Purpose | Category | Lifetime | Appears when |
|---|---|---|---|---|---|
authjs.session-token | Quant24 (Auth.js) | Keeps you signed in. A signed token; it holds no password | Strictly necessary | Session, up to 30 days | When you sign in |
authjs.csrf-token | Quant24 (Auth.js) | Protects the sign-in flow against cross-site forgery | Strictly necessary | Session | When you sign in |
authjs.callback-url | Quant24 (Auth.js) | Returns you to the page you came from after signing in | Strictly necessary | Session | When you sign in |
| Stripe Checkout and billing portal | Stripe, on Stripe's own pages | Payment session and fraud prevention while you pay. These are set on Stripe's domain, not ours, and are described in Stripe's privacy notice | Strictly necessary | Set by Stripe | When paid plans open |
Analytics
Analytics in this build is not active. The code is written to load Cloudflare Web Analytics — a script that sets no cookies and builds no cross-site profile — and to load it only after you accept analytics in the banner. Loading it also needs a Cloudflare Web Analytics key, and no key is configured in this build: today, accepting analytics changes what the cookie records and loads nothing. When the key exists, the beacon will load after consent and only then, and this page will say so in the same commit.
Two things hold either way. Gating a cookieless beacon behind consent is stricter than the law requires, and it is the position we chose: one switch, not a technicality. And the product events the App will record in our own database in a later phase sit behind the same switch; nothing records them in this build.
We do not sell personal data, we do not share it for cross-context advertising, and we run no advertising pixels.
Your choices
- The banner. On your first visit the banner offers three buttons: Accept all, Reject non-essential and Cookie settings. Refusing is one click, in a button of the same size as accepting, and nothing optional loads while the banner is waiting for you.
- Cookie settings. The settings dialog has a single switch, Analytics, because analytics is the only optional thing there is. Save choice records what the switch says; Cancel leaves everything as it was. If you turn analytics off after having it on, the page reloads, so that nothing already loaded keeps running.
- Changing your mind. The same dialog reopens from the Cookie settings link in the footer of every page, and withdrawing is as easy as giving.
- Your browser. You can block or delete cookies in your browser settings for this site or for
every site. Without
q24_consentwe cannot remember your choice, so the banner asks again on your next visit; once sign-in exists, blocking strictly-necessary cookies will break it. - Do Not Track and Global Privacy Control. We do not currently detect either signal. If we start honouring one, it will be said here.
Changes to this Policy
When a cookie is added, removed or changes purpose, this page changes with it, its version is
bumped and the date at the top moves. q24_consent carries the version of this Policy it was given
under: when the version changes, a choice made under the old one no longer counts, and the banner
asks you again before anything optional loads.
Questions: b.caldera@quant24.io, with "cookies" in the subject.