Cookie Policy
QuestKeep is in beta. We wrote this page ourselves and no lawyer has reviewed it. It lists the cookies QuestKeep actually sets today, and it will change as the product does.
Last updated Aug 25, 2026
QuestKeep sets 13 first-party cookies, and not one of them is for advertising or analytics. Every one is there to sign someone in, to keep a session going, or to remember a choice you made.
What cookies we use
A cookie is a small piece of text a site asks your browser to keep and send back on the next request. QuestKeep uses them for exactly three things: signing a guardian in, keeping a family device and a child's session going, and remembering a choice such as your language.
Every cookie below is first-party, set by QuestKeep on QuestKeep's own domain. There are none from anybody else.
Why there is no cookie banner
You will not see a cookie banner here, and that is a decision rather than an omission. Consent is required for cookies that are not necessary: advertising, tracking, analytics. QuestKeep sets none of those. All 13 cookies below are strictly necessary to provide the service you asked for, which is the one case where the law does not require consent.
The day we want a cookie that is not strictly necessary, we will ask you first.
The full list
Here is every cookie QuestKeep sets, what it is for, and how long it lasts. The names are the ones used over HTTPS in production; see the note on prefixes below.
| Cookie | What it is for | How long it lasts |
|---|---|---|
| __Secure-authjs.session-token | Keeps a guardian signed in after they authenticate. | 30 days |
| __Secure-authjs.callback-url | Remembers which page to return to after sign-in. | Until you close the browser |
| __Host-authjs.csrf-token | Protects the sign-in endpoints against cross-site request forgery. | Until you close the browser |
| __Secure-authjs.pkce.code_verifier | Proves the sign-in request and its reply belong together (PKCE). | 15 minutes |
| __Secure-authjs.state | One-time value tying the sign-in redirect back to the request that started it. | 15 minutes |
| __Secure-authjs.nonce | One-time value that stops a sign-in reply being replayed. | Until you close the browser |
| __Host-qk_device | Marks this device as your family's shared screen, so the home screen shows the adventurer grid. | 400 days |
| __Host-qk_kid | Keeps an adventurer signed in on the family device. Internal identifiers only — no name, avatar, or PIN. | 30 minutes |
| __Host-qk_invite | Carries a guardian invitation across the sign-in round-trip so the invited grown-up joins the right family. | 30 minutes |
| qk_onb | Remembers that the setup wizard was finished or dismissed. | 365 days |
| locale | Remembers the interface language you chose. | 365 days |
| qk_tz | Short-lived hint of your browser's timezone, used to guess the family's timezone at signup. | 10 minutes |
| qk_loc | Short-lived hint of your browser's language, used to guess the family's currency at signup. | 10 minutes |
Guardian sign-in
Six cookies belong to our sign-in library and are set while a guardian signs in with Microsoft Entra External ID. They carry the signed-in session plus the one-time values that make the sign-in round-trip safe — the state, nonce, and PKCE values that stop somebody replaying or hijacking it.
Their names come from that library rather than from us, so an upgrade could rename them, and the session cookie may be split across more than one cookie if it grows.
Family device and adventurer sessions
Three cookies are ours and are signed by us. One marks a device as belonging to your family, which is what turns the home screen into the avatar grid. One is the signed-in adventurer's session, and it carries internal identifiers only — never a child's name, avatar, or PIN. One carries a guardian invitation across the sign-in round-trip so the invited grown-up joins the right family.
All three are HTTP-only, so no script on the page can read them, and a guardian can log every device out from the family settings.
Preferences and short-lived hints
Four small cookies remember choices: whether the setup wizard was finished, which language you picked, and two short-lived hints — your browser's timezone and language — that let us guess your family's timezone and currency when the account is created. The two hints expire in ten minutes.
Names in production and in local development
Over HTTPS our cookie names carry a __Host- or __Secure- prefix, which tells the browser to refuse the cookie unless it was set securely. On plain HTTP — only ever local development on a home network — the prefix is dropped, because a browser would reject the cookie otherwise. Same cookie, same purpose; the name in the table above is the production one.
Managing cookies
You can delete or block cookies in your browser settings. Blocking the ones above means QuestKeep stops working: a guardian cannot stay signed in, a family device cannot be recognised, and a child cannot start a session. There is nothing here to opt out of for privacy reasons, because none of it tracks you.
No third-party cookies
No third party sets a cookie on QuestKeep. There is no advertising network, no analytics, no social widget, no embedded video, and no chat bubble. When paid plans start, checkout will happen on the payment provider's own pages rather than on ours, so no payment cookie will be set on our domain either.