Cookie Policy
What we store in your browser, why, for how long, and how to change your mind.
Version 1.0 In force since September 2, 2026 Updated September 2, 2026
This policy explains the cookies used by the Quathos Account at accounts.quathos.com, by the Quathos Auth console at auth.quathos.com, and by the hosted sign-in pages at auth.quathos.com or at a customer’s own domain. It is part of our Privacy Policy, and it describes what actually runs in your browser — not what a generic template assumes runs there.
1. What we do not do
It is shorter to start here, because the list of things absent from this product is longer than the list of cookies it sets:
- No advertising cookies, no ad networks, no retargeting pixels, and no conversion tags.
- No third-party analytics script. The pages you are reading load no script from any other host: the typeface is self-hosted and the Content Security Policy forbids external scripts outright, so reading a sign-in page does not tell anyone else who you are.
- No browser fingerprinting, no session replay, no heatmaps, and no cross-site tracking.
- No local storage and no session storage: the application keeps nothing in your browser beyond the cookies listed below.
- We do not sell or share personal information for cross-context behavioural advertising, as those terms are defined by California law. There is nothing to opt out of, because it does not happen.
2. Cookies we set
All seven are first-party cookies, set by the host you are visiting. With one exception explained below, they are host-only: a cookie set by one customer’s sign-in domain is not readable by another customer’s, and none of them is readable by any other website.
| Cookie | Purpose | Category | Lifetime |
|---|---|---|---|
| qid_session | Keeps you signed in after you log in. Marked HttpOnly, so no script on the page — ours or anyone else’s — can read it. The server ends the session after 24 hours without activity, whatever the cookie says. | Essential | Up to 14 days |
| qid_csrf | Proves that a form submission came from our own pages and not from a site pretending to be you. Without it, being logged in would be enough for another site to act in your name. | Essential | Up to 14 days |
| qid_signed_in | A flag with the value "1" and no secret in it, so that other Quathos pages can show "Account" instead of "Sign in" without calling the API. This is the one exception to host-only: on Quathos family hosts it is set for .quathos.com. On a customer’s tenant it stays host-only. | Essential | Up to 14 days |
| qid_mfa_challenge | Carries the state between the password step and the second-factor step of sign-in. HttpOnly, and gone in five minutes whether or not you finish. | Essential | 5 minutes |
| qid_consent | Records your cookie choice, the version of this policy you answered, and when. This is the cookie that stops us from asking again — and the record that proves what you chose. | Essential | 180 days |
| locale | The language you picked in the selector. Written only when you click it; before that, we read the language your browser announces and store nothing. | Preferences | 12 months |
| theme | Light or dark appearance. Written only when you click it; before that, the page follows your system setting. | Preferences | 12 months |
3. The three categories
- Essential — sign-in, CSRF protection, the second-factor step, the signed-in flag and the consent record itself. These are strictly necessary to deliver a service you asked for, so no consent is required for them and the preference panel does not pretend otherwise. Blocking them in your browser means you cannot log in.
- Preferences — language and appearance. They are written only by the act of choosing, which is the consent: the click is the request. Nothing is stored if you never touch the selectors.
- Analytics — measurement of product usage. None is in use today. The category exists, switched off, so that the day we adopt any measurement it is gated behind a choice you already control, instead of appearing first and asking later.
4. Third parties and other domains
Our pages embed no third-party content. Three flows, however, take you to — or are delivered by — someone else, and those parties set their own cookies under their own policies:
- After you sign in, we send you back to the application you came from — a Quathos product, or one of our customer’s applications. That application sets the cookies its own session requires, on its own domain, under its own notice.
- Checkout and billing management run on Stripe pages, on Stripe domains. We never receive your card number, and Stripe’s cookies are governed by Stripe.
- If a customer’s tenant lets you sign in with an external identity provider — a social login or your company’s single sign-on — that provider’s pages and cookies are theirs, not ours.
5. Your choices
- 1 The banner appears on your first visit and stays until you answer. It does not close by itself, it does not close when you scroll, and there is no hidden dismiss: continuing to browse is not consent here.
- 2 Accepting and refusing are one click each, side by side, with the same weight. Withdrawing later is as easy as giving it: the preference panel on this page is permanent and is linked from every page footer.
- 3 Your browser can block or delete cookies for this site at any time. Essential cookies are the ones you will miss: deleting them signs you out.
- 4 If your browser sends a Global Privacy Control signal, we treat it as a refusal of everything that is not essential, without asking. Honouring that signal is the whole point of it existing.
6. Changes to this policy
A new cookie, a new purpose or a new party means a new version of this policy and a new question: the consent record carries the version you answered, so when it changes materially the banner comes back and your earlier answer is not stretched to cover something you never saw.
7. Questions
Write to privacy@quathos.com and a person answers in writing.