Cookie Policy

QuestKeep is in beta. We wrote this page ourselves and no lawyer has reviewed it. It lists the cookies QuestKeep actually sets today, and it will change as the product does.

Last updated Aug 25, 2026

QuestKeep sets 13 first-party cookies, and not one of them is for advertising or analytics. Every one is there to sign someone in, to keep a session going, or to remember a choice you made.

What cookies we use

A cookie is a small piece of text a site asks your browser to keep and send back on the next request. QuestKeep uses them for exactly three things: signing a guardian in, keeping a family device and a child's session going, and remembering a choice such as your language.

Every cookie below is first-party, set by QuestKeep on QuestKeep's own domain. There are none from anybody else.

Why there is no cookie banner

You will not see a cookie banner here, and that is a decision rather than an omission. Consent is required for cookies that are not necessary: advertising, tracking, analytics. QuestKeep sets none of those. All 13 cookies below are strictly necessary to provide the service you asked for, which is the one case where the law does not require consent.

The day we want a cookie that is not strictly necessary, we will ask you first.

The full list

Here is every cookie QuestKeep sets, what it is for, and how long it lasts. The names are the ones used over HTTPS in production; see the note on prefixes below.

CookieWhat it is forHow long it lasts
__Secure-authjs.session-tokenKeeps a guardian signed in after they authenticate.30 days
__Secure-authjs.callback-urlRemembers which page to return to after sign-in.Until you close the browser
__Host-authjs.csrf-tokenProtects the sign-in endpoints against cross-site request forgery.Until you close the browser
__Secure-authjs.pkce.code_verifierProves the sign-in request and its reply belong together (PKCE).15 minutes
__Secure-authjs.stateOne-time value tying the sign-in redirect back to the request that started it.15 minutes
__Secure-authjs.nonceOne-time value that stops a sign-in reply being replayed.Until you close the browser
__Host-qk_deviceMarks this device as your family's shared screen, so the home screen shows the adventurer grid.400 days
__Host-qk_kidKeeps an adventurer signed in on the family device. Internal identifiers only — no name, avatar, or PIN.30 minutes
__Host-qk_inviteCarries a guardian invitation across the sign-in round-trip so the invited grown-up joins the right family.30 minutes
qk_onbRemembers that the setup wizard was finished or dismissed.365 days
localeRemembers the interface language you chose.365 days
qk_tzShort-lived hint of your browser's timezone, used to guess the family's timezone at signup.10 minutes
qk_locShort-lived hint of your browser's language, used to guess the family's currency at signup.10 minutes

Guardian sign-in

Six cookies belong to our sign-in library and are set while a guardian signs in with Microsoft Entra External ID. They carry the signed-in session plus the one-time values that make the sign-in round-trip safe — the state, nonce, and PKCE values that stop somebody replaying or hijacking it.

Their names come from that library rather than from us, so an upgrade could rename them, and the session cookie may be split across more than one cookie if it grows.

Family device and adventurer sessions

Three cookies are ours and are signed by us. One marks a device as belonging to your family, which is what turns the home screen into the avatar grid. One is the signed-in adventurer's session, and it carries internal identifiers only — never a child's name, avatar, or PIN. One carries a guardian invitation across the sign-in round-trip so the invited grown-up joins the right family.

All three are HTTP-only, so no script on the page can read them, and a guardian can log every device out from the family settings.

Preferences and short-lived hints

Four small cookies remember choices: whether the setup wizard was finished, which language you picked, and two short-lived hints — your browser's timezone and language — that let us guess your family's timezone and currency when the account is created. The two hints expire in ten minutes.

Names in production and in local development

Over HTTPS our cookie names carry a __Host- or __Secure- prefix, which tells the browser to refuse the cookie unless it was set securely. On plain HTTP — only ever local development on a home network — the prefix is dropped, because a browser would reject the cookie otherwise. Same cookie, same purpose; the name in the table above is the production one.

Managing cookies

You can delete or block cookies in your browser settings. Blocking the ones above means QuestKeep stops working: a guardian cannot stay signed in, a family device cannot be recognised, and a child cannot start a session. There is nothing here to opt out of for privacy reasons, because none of it tracks you.

No third-party cookies

No third party sets a cookie on QuestKeep. There is no advertising network, no analytics, no social widget, no embedded video, and no chat bubble. When paid plans start, checkout will happen on the payment provider's own pages rather than on ours, so no payment cookie will be set on our domain either.