Skip to content

Cookies are off until you say otherwise

Non-essential cookies stay off unless you accept them, and rejecting them leaves the site fully usable. What runs either way is only what the site cannot work without: the anti-abuse check on our forms, the record of the choice you make here, and the access cookie on internal routes. Site analytics is cookieless and loads only after you accept. Cookie policy

DRAFT — pending legal review

This page is a draft written by the team; it takes effect only when a lawyer releases it, and nothing on it is investment advice.

Cookie Policy

Every cookie this build sets, who sets it, why, and how long it lasts. Non-essential cookies are refused by default until you say otherwise.

Version
1.1.0
Effective
Not yet in effect
Applies to
quant24.io and beta.quant24.io during pre-launch
Last updated
2026-09-07

Cookies are small files a site asks your browser to keep. This page lists every one this build sets, who sets it, what it is for and how long it lasts. It is written against the code that exists today, not against a template.

Two things are true of this build and worth saying first. Non-essential cookies are refused by default: nothing beyond what the Service needs to work is set until you accept it, and refusing is a click, not a form. And there is no public sign-in and no paid plan yet, so the cookies that depend on them are listed as planned: they appear when the feature that needs them ships.

This Policy forms part of our Terms of Service and is read together with the Privacy Policy, which explains what we do with personal data once we have it.

Categories we use

  • Strictly necessary. Without them the Service does not work: telling a person from a script on our forms, remembering what you chose in the cookie banner, holding an internal review key and, once sign-in exists, keeping you signed in. These are set without asking, because asking to be allowed to remember your refusal is a loop.
  • Analytics. Counting how a page is used. Off by default; only after you accept; and not configured in this build at all, as the section below explains.
  • Advertising. We set none, and there are no advertising or cross-site tracking cookies in this build.

What this build sets today

NameSet byPurposeCategoryLifetimeStatus
q24_consentQuant24Records what you chose in the cookie banner: whether analytics is on or off, the date, a random identifier that is tied to no name, email or account, and the version of this Policy in force when you chose. Secure, SameSite=Lax, sent on every path of the site. It is written only when you press a button in the banner or in the settings dialog; reading a page sets nothingStrictly necessaryOne yearIn this build
Cloudflare TurnstileCloudflare, on our behalfThe human check on our forms. It loads when a form comes into view and runs between your browser and Cloudflare, which receives your IP address and browser signals (user-agent, TLS fingerprint) and also uses them to improve Turnstile, as Cloudflare's Turnstile privacy addendum describes; we then pass Cloudflare the token and your IP address once, to verify it. While it runs, Cloudflare may set its challenge cookies — cf_clearance and the cf_chl_rc_* family — on its own domain, with names and lifetimes that are Cloudflare's, listed in Cloudflare's cookie policyStrictly necessarySet by CloudflareIn this build
q24_internalQuant24Proves the reader holds the internal key for the design and content review route. HttpOnly, Secure, SameSite=Lax, Path=/design, so it is not sent anywhere else on the siteStrictly necessary30 daysIn this build

That is the whole list, and each entry is set only when something happens: you decide in the banner, a form comes into view, or you hold an internal key. A page without a form, read and left, asks your browser to store nothing. The internal route is not linked from anywhere public, and the production deployment does not serve it at all.

Your banner choice is also written to our database, under the same random identifier the cookie carries and with the version of this Policy — no name, no email, no account. It is how we can show that a choice was made if we are ever asked to, and the Privacy Policy describes it.

What is planned, and when it appears

These are not set yet. Each appears when the feature that needs it ships, and this page is updated in the same commit.

NameSet byPurposeCategoryLifetimeAppears when
authjs.session-tokenQuant24 (Auth.js)Keeps you signed in. A signed token; it holds no passwordStrictly necessarySession, up to 30 daysWhen you sign in
authjs.csrf-tokenQuant24 (Auth.js)Protects the sign-in flow against cross-site forgeryStrictly necessarySessionWhen you sign in
authjs.callback-urlQuant24 (Auth.js)Returns you to the page you came from after signing inStrictly necessarySessionWhen you sign in
Stripe Checkout and billing portalStripe, on Stripe's own pagesPayment session and fraud prevention while you pay. These are set on Stripe's domain, not ours, and are described in Stripe's privacy noticeStrictly necessarySet by StripeWhen paid plans open

Analytics

Analytics in this build is not active. The code is written to load Cloudflare Web Analytics — a script that sets no cookies and builds no cross-site profile — and to load it only after you accept analytics in the banner. Loading it also needs a Cloudflare Web Analytics key, and no key is configured in this build: today, accepting analytics changes what the cookie records and loads nothing. When the key exists, the beacon will load after consent and only then, and this page will say so in the same commit.

Two things hold either way. Gating a cookieless beacon behind consent is stricter than the law requires, and it is the position we chose: one switch, not a technicality. And the product events the App will record in our own database in a later phase sit behind the same switch; nothing records them in this build.

We do not sell personal data, we do not share it for cross-context advertising, and we run no advertising pixels.

Your choices

  • The banner. On your first visit the banner offers three buttons: Accept all, Reject non-essential and Cookie settings. Refusing is one click, in a button of the same size as accepting, and nothing optional loads while the banner is waiting for you.
  • Cookie settings. The settings dialog has a single switch, Analytics, because analytics is the only optional thing there is. Save choice records what the switch says; Cancel leaves everything as it was. If you turn analytics off after having it on, the page reloads, so that nothing already loaded keeps running.
  • Changing your mind. The same dialog reopens from the Cookie settings link in the footer of every page, and withdrawing is as easy as giving.
  • Your browser. You can block or delete cookies in your browser settings for this site or for every site. Without q24_consent we cannot remember your choice, so the banner asks again on your next visit; once sign-in exists, blocking strictly-necessary cookies will break it.
  • Do Not Track and Global Privacy Control. We do not currently detect either signal. If we start honouring one, it will be said here.

Changes to this Policy

When a cookie is added, removed or changes purpose, this page changes with it, its version is bumped and the date at the top moves. q24_consent carries the version of this Policy it was given under: when the version changes, a choice made under the old one no longer counts, and the banner asks you again before anything optional loads.

Questions: b.caldera@quant24.io, with "cookies" in the subject.