//Legal

Cookies and local storage

Last updated: 21 August 2026

Everything Quiet Guard writes to your device, in full. No advertising tracker, no analytics, no cross-site tracking.

01 What this page covers

Article 82 of the French Data Protection Act does not only cover cookies: it covers any reading from or writing to your terminal. Your browser's local storage and session storage are included, so they are listed here alongside the cookies.

02 What we write to your device

  • Session cookie: keeps you signed in to the dashboard. Expires after two hours of inactivity.
  • XSRF-TOKEN cookie: protects your actions against request forgery. Expires with the session.
  • locale cookie, one year: remembers the language you picked. Set only when you click the language switcher, never automatically.
  • quiet-theme local storage: remembers the light or dark theme you picked on the site. Kept until you clear it.
  • theme local storage: the same preference inside the dashboard, written by the interface itself. Kept until you clear it.
  • _x_isOpen, _x_isOpenDesktop and _x_collapsedGroups local storage: whether the dashboard sidebar is open and which of its groups you folded away. Written by the interface, kept until you clear it.
  • monitor.enc.key session storage: when you unlock in the browser, holds the key derived from your passphrase for the lifetime of the tab. That key is never sent to us and disappears when the tab closes.

03 Why there is no consent banner

Everything above is either strictly necessary to the service you asked for, or a preference you explicitly chose. Both fall under the exemptions of article 82 III, as set out in CNIL deliberation 2020-091 of 17 September 2020. Your consent is not required, so we have no banner to put in your way.

If we ever added analytics, the exemption would only hold under strict conditions: our site alone, no cross-site matching, no transfer to a third party, aggregated results, a tracker capped at thirteen months and data at twenty-five. We would update this page before, not after.

04 Third-party resources

The public pages of this site load nothing from outside, with two exceptions: the contact form and the registration page load Cloudflare's anti-robot check, which receives your IP address, TLS fingerprint and user agent. Cloudflare states these are used only to tell a browser from a bot, and our integration sets no cookie. No other page contacts a third party.

The dashboard does load two typefaces from BunnyWay d.o.o. (Slovenia, European Union). They set no cookie but receive your browser's IP address in order to deliver the file.

05 Managing these

Your browser can block or clear cookies and local storage. Blocking the strictly necessary ones prevents signing in.

Questions: legal@quietsystems.dev.