Cookie Policy
What Qua stores on your device, which consent category it belongs to, why it is there, and how to turn it off. Qua sets no advertising cookies and runs no cross-site trackers.
1. Scope of this policy
This Cookie Policy explains how Qua uses cookies, browser local storage, session storage and similar technologies on the qua.dev website and in the Qua application. It supplements our Privacy Policy, which governs how we handle personal data more generally. Last updated August 25, 2026.
Qua relies more on browser storage than on classic cookies: your session token and interface preferences are kept in local storage on your own device, and a small number of cookies are set by our hosting, security and routing layers. We treat both the same way in this policy, because the privacy rules in the EU ePrivacy Directive, the UK PECR and the CCPA/CPRA apply to any technology that stores or reads information on your device — not just to cookies.
2. Consent categories, explained
Everything we store on your device falls into one of five categories. The category decides whether we need your consent before setting it, and what happens if you say no.
| Category | Consent | What it means | If you decline |
|---|---|---|---|
| Strictly necessary | Always on | Sign-in, session continuity, request routing. Exempt from consent by law. | Cannot be declined — the service will not function without them. |
| Security and abuse prevention | Always on | Bot mitigation and fair-use limits on public forms. | Cannot be declined; treated as strictly necessary. |
| Functional and preferences | Consent required | Theme, text size, dismissed tips, onboarding progress. | Everything still works; the interface resets to defaults each visit. |
| Analytics and performance | Consent required | Aggregate, first-party measurement of usage and errors. | No measurement is collected from your device. No feature is withheld. |
| Advertising and cross-site tracking | Consent required | Ad targeting and cross-site profiling. | Not applicable — Qua uses nothing in this category. |
Consent is opt-in where it is required. Where the GDPR, UK PECR or a comparable law applies, non-essential categories stay off until you accept them, refusal is as easy as acceptance, and you can change your mind at any time. Consent is not a condition of using Qua.
3. Strictly necessary
Always on. Required to sign you in, keep you signed in, route your requests and protect the service. They cannot be switched off, because without them the product does not work. Under the GDPR/ePrivacy rules these are exempt from consent; we still list them here.
| Name | Technology | Purpose | Retention |
|---|---|---|---|
| Supabase auth session | Local storage | Holds your authenticated session token so you stay signed in between page loads. | Until sign-out or token expiry |
| Session routing / load balancing | Cookie | Set by our hosting and CDN layer to route a request to the right region and edge node. | Session |
| CSRF and request integrity | Cookie | Protects form and server-function calls against cross-site request forgery. | Session |
4. Security and abuse prevention
Always on. Bot mitigation and rate limiting on public surfaces such as the demo and sign-in forms. These protect the service and other users, and are treated as strictly necessary.
| Name | Technology | Purpose | Retention |
|---|---|---|---|
| Cloudflare Turnstile | Cookie | Verifies that a submission on the public demo form comes from a human, without behavioural profiling. | Up to 30 minutes |
| Rate-limit marker | Local storage | Tracks demo quota consumption on the device to enforce fair-use limits. | Up to 24 hours |
5. Functional and preferences
Consent required. Remember how you like the product to look and behave. Declining them does not break anything — the interface simply returns to its defaults on every visit.
| Name | Technology | Purpose | Retention |
|---|---|---|---|
| qua-theme | Local storage | Stores your Auto / Light / Dark theme choice. | Until cleared |
| Text size and display preferences | Local storage | Stores the text-size and density controls on the marketing site and in the app. | Until cleared |
| Onboarding and dismissal state | Local storage | Remembers which tours, checklists and prompts you have completed or dismissed. | Until cleared |
| Install prompt state | Local storage | Remembers that you dismissed the install-as-an-app prompt. | Until cleared |
6. Analytics and performance
Consent required. Aggregate, first-party measurement of how pages and features are used, so we can find broken flows and slow pages. We do not use third-party advertising analytics, and product analytics inside the app measure outcomes — sessions, cost, resolution tier — never prompt content.
| Name | Technology | Purpose | Retention |
|---|---|---|---|
| First-party usage metrics | Local storage | Holds an anonymous, rotating identifier used to de-duplicate page views. Not linked to advertising profiles. | Up to 12 months |
| Error and performance traces | Session storage | Correlates client-side errors and slow renders within a single visit for debugging. | Session |
Product analytics inside the application measure outcomes, not content: session counts, cost, resolution tier and acceptance. We never record prompt or answer text for analytics purposes.
7. Advertising and cross-site tracking
Consent required. We do not use this category. Qua sets no advertising cookies, runs no ad-network pixels, and does not sell or share personal information for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA.
Nothing in this category is used on qua.dev or in the Qua application.
8. Third parties that may set storage
A small number of providers we use may set their own cookies when you interact with the relevant surface. Each is listed with its purpose and processing location on our Subprocessors page:
- Cloudflare — routing, DDoS protection and Turnstile bot verification on public forms.
- Supabase — authentication session handling for signed-in users.
- Google — only if you choose to sign in with Google; the sign-in flow is handled on Google's own domain under Google's policies.
We do not embed advertising networks, social media pixels or data brokers on any Qua surface.
9. How to control cookies and storage
- In your browser. Every major browser lets you block or delete cookies and site data for a specific site. Clearing Qua's site data removes your preferences and signs you out; strictly necessary items are recreated the next time you sign in.
- Global Privacy Control. We honour the GPC signal as a valid opt-out of sale and sharing under the CCPA/CPRA — although, as noted above, Qua does not sell or share personal information for cross-context behavioural advertising.
- Do Not Track. There is no common standard for responding to DNT, so we do not respond to it differently from GPC.
- Organization-level controls. Administrators can restrict optional product features — including web retrieval and the Open Models tier — from the admin console. Those controls govern data flows, not device storage.
10. Changes to this policy
When we add or remove a technology that stores information on your device, we update this page in the same change and revise the date above. Material changes affecting a consent-required category are notified in-product before they take effect.
11. Contact
Questions about this policy or a request relating to cookies and tracking: privacy@qua.dev. Data protection contact: dpo@qua.dev. See also the Privacy Policy, the Data Processing Agreement and the Subprocessor list.