Qua
MultiplayerWhy QuaHow it worksProofCompareSkillsDeployment
Login →
MultiplayerWhy QuaHow it worksProofCompareSkillsDeploymentLogin →
Legal

Cookie Policy

What Qua stores on your device, which consent category it belongs to, why it is there, and how to turn it off. Qua sets no advertising cookies and runs no cross-site trackers.

Last updated: August 25, 2026Applies to: qua.dev and the Qua application
  1. 1. Scope of this policy
  2. 2. Consent categories, explained
  3. 3. Strictly necessary
  4. 4. Security and abuse prevention
  5. 5. Functional and preferences
  6. 6. Analytics and performance
  7. 7. Advertising and cross-site tracking
  8. 8. Third parties that may set storage
  9. 9. How to control cookies and storage
  10. 10. Changes to this policy
  11. 11. Contact

1. Scope of this policy

This Cookie Policy explains how Qua uses cookies, browser local storage, session storage and similar technologies on the qua.dev website and in the Qua application. It supplements our Privacy Policy, which governs how we handle personal data more generally. Last updated August 25, 2026.

Qua relies more on browser storage than on classic cookies: your session token and interface preferences are kept in local storage on your own device, and a small number of cookies are set by our hosting, security and routing layers. We treat both the same way in this policy, because the privacy rules in the EU ePrivacy Directive, the UK PECR and the CCPA/CPRA apply to any technology that stores or reads information on your device — not just to cookies.

2. Consent categories, explained

Everything we store on your device falls into one of five categories. The category decides whether we need your consent before setting it, and what happens if you say no.

CategoryConsentWhat it meansIf you decline
Strictly necessaryAlways onSign-in, session continuity, request routing. Exempt from consent by law.Cannot be declined — the service will not function without them.
Security and abuse preventionAlways onBot mitigation and fair-use limits on public forms.Cannot be declined; treated as strictly necessary.
Functional and preferencesConsent requiredTheme, text size, dismissed tips, onboarding progress.Everything still works; the interface resets to defaults each visit.
Analytics and performanceConsent requiredAggregate, first-party measurement of usage and errors.No measurement is collected from your device. No feature is withheld.
Advertising and cross-site trackingConsent requiredAd targeting and cross-site profiling.Not applicable — Qua uses nothing in this category.

Consent is opt-in where it is required. Where the GDPR, UK PECR or a comparable law applies, non-essential categories stay off until you accept them, refusal is as easy as acceptance, and you can change your mind at any time. Consent is not a condition of using Qua.

3. Strictly necessary

Always on. Required to sign you in, keep you signed in, route your requests and protect the service. They cannot be switched off, because without them the product does not work. Under the GDPR/ePrivacy rules these are exempt from consent; we still list them here.

NameTechnologyPurposeRetention
Supabase auth sessionLocal storageHolds your authenticated session token so you stay signed in between page loads.Until sign-out or token expiry
Session routing / load balancingCookieSet by our hosting and CDN layer to route a request to the right region and edge node.Session
CSRF and request integrityCookieProtects form and server-function calls against cross-site request forgery.Session

4. Security and abuse prevention

Always on. Bot mitigation and rate limiting on public surfaces such as the demo and sign-in forms. These protect the service and other users, and are treated as strictly necessary.

NameTechnologyPurposeRetention
Cloudflare TurnstileCookieVerifies that a submission on the public demo form comes from a human, without behavioural profiling.Up to 30 minutes
Rate-limit markerLocal storageTracks demo quota consumption on the device to enforce fair-use limits.Up to 24 hours

5. Functional and preferences

Consent required. Remember how you like the product to look and behave. Declining them does not break anything — the interface simply returns to its defaults on every visit.

NameTechnologyPurposeRetention
qua-themeLocal storageStores your Auto / Light / Dark theme choice.Until cleared
Text size and display preferencesLocal storageStores the text-size and density controls on the marketing site and in the app.Until cleared
Onboarding and dismissal stateLocal storageRemembers which tours, checklists and prompts you have completed or dismissed.Until cleared
Install prompt stateLocal storageRemembers that you dismissed the install-as-an-app prompt.Until cleared

6. Analytics and performance

Consent required. Aggregate, first-party measurement of how pages and features are used, so we can find broken flows and slow pages. We do not use third-party advertising analytics, and product analytics inside the app measure outcomes — sessions, cost, resolution tier — never prompt content.

NameTechnologyPurposeRetention
First-party usage metricsLocal storageHolds an anonymous, rotating identifier used to de-duplicate page views. Not linked to advertising profiles.Up to 12 months
Error and performance tracesSession storageCorrelates client-side errors and slow renders within a single visit for debugging.Session

Product analytics inside the application measure outcomes, not content: session counts, cost, resolution tier and acceptance. We never record prompt or answer text for analytics purposes.

7. Advertising and cross-site tracking

Consent required. We do not use this category. Qua sets no advertising cookies, runs no ad-network pixels, and does not sell or share personal information for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA.

Nothing in this category is used on qua.dev or in the Qua application.

8. Third parties that may set storage

A small number of providers we use may set their own cookies when you interact with the relevant surface. Each is listed with its purpose and processing location on our Subprocessors page:

  • Cloudflare — routing, DDoS protection and Turnstile bot verification on public forms.
  • Supabase — authentication session handling for signed-in users.
  • Google — only if you choose to sign in with Google; the sign-in flow is handled on Google's own domain under Google's policies.

We do not embed advertising networks, social media pixels or data brokers on any Qua surface.

9. How to control cookies and storage

  • In your browser. Every major browser lets you block or delete cookies and site data for a specific site. Clearing Qua's site data removes your preferences and signs you out; strictly necessary items are recreated the next time you sign in.
  • Global Privacy Control. We honour the GPC signal as a valid opt-out of sale and sharing under the CCPA/CPRA — although, as noted above, Qua does not sell or share personal information for cross-context behavioural advertising.
  • Do Not Track. There is no common standard for responding to DNT, so we do not respond to it differently from GPC.
  • Organization-level controls. Administrators can restrict optional product features — including web retrieval and the Open Models tier — from the admin console. Those controls govern data flows, not device storage.

10. Changes to this policy

When we add or remove a technology that stores information on your device, we update this page in the same change and revise the date above. Material changes affecting a consent-required category are notified in-product before they take effect.

11. Contact

Questions about this policy or a request relating to cookies and tracking: privacy@qua.dev. Data protection contact: dpo@qua.dev. See also the Privacy Policy, the Data Processing Agreement and the Subprocessor list.

Qua
Pioneering enterprise-scale multiplayer AI.
QUA — Quantified · Unified · Autonomy.
Try Qua·Compare·Skills·Deployment·Open the app
Privacy Policy·Terms of Service·Cookie Policy·Data Processing Agreement·Subprocessors