Cookie Policy
Which cookies and similar device-storage technologies our sites use, what they do, how long they remain, and how choices work.
Version 1.4 · effective 28 July 2026
- Owner
- Obedience Global Ltd board
- Approved by
- Obedience Global Ltd board
- Approval date
- 28 July 2026
- Next review
- 28 October 2026
01What this policy covers
PECR applies to cookies and comparable technologies that store information on, or access information from, a device. This includes local storage, session storage, IndexedDB, Cache Storage, service workers, scripts and tags. Where personal data is involved, UK GDPR also applies.
We use as little device storage as practical. We ask for consent before PostHog analytics because our current implementation is not treated as exempt aggregate statistics. Authentication, account security and requested offline product functions use the strictly necessary exception. Appearance preferences can use the appearance exception and remain under the user's free control.
02Current inventory
| Cookie or technology | Site and purpose | Duration and control |
|---|---|---|
| __client, __client_uat, __session, __refresh, clerk_active_context and suffixed Clerk variants | Global, Cloud and Quantify authentication, satellite return, client freshness, active context and session security | Strictly necessary; client freshness up to about 400 days, session and refresh state up to about one year, and active context for the browser session. Sign-out, revocation and account actions control live access |
| __cf_bm and _cfuvid on Clerk authentication or image domains | Cloudflare bot and abuse protection for authentication and identity-image delivery | Strictly necessary security; __cf_bm about 30 minutes and _cfuvid for the browser session |
| __clerk_environment local storage | Global, Cloud and Quantify authentication environment and client configuration | Strictly necessary; persists until replaced or browser storage is cleared |
| obedience-loader-shown and obedience-cloud-loader-shown session storage | Prevents the Global or Cloud opening animation repeating during one browser session | Session only; requested interface function |
| obedience-theme and obedience-motion local storage | Global and Cloud appearance and motion preferences, written only when changed | Until changed or cleared; appearance exception with free controls |
| qqs-analytics-consent local storage | Quantify remembers Allow or Decline so it can honour the analytics choice | Until changed in Settings or browser storage is cleared; necessary consent record |
| PostHog ph_* identifiers and transient __ph_* SDK consent state | Quantify product-usage analytics through PostHog EU Cloud, only after Allow | Consent-based; cookie currently one year, local state until withdrawal or clearing, session state until the tab session ends, and SDK consent state cleared after the choice is applied |
| Quantify service worker and quantifyqs-v1 Cache Storage | Same-origin app shell and static assets for requested offline availability; API responses are excluded | Strictly necessary product function; kept until the cache version is replaced, the service worker is removed or browser data is cleared |
| quantifyqs-role and Quantify workspace local storage or IndexedDB | Caches the displayed role plus local-first projects, drafts, preferences and user-selected files when used. Server-side authorisation remains authoritative | Requested product function; retained on that device until the user deletes, resets or clears it |
03Production audit
A fresh anonymous browser audit on 28 July 2026 found no cookie on obedience.global and only its one-session loader marker. Cloud set the listed Clerk and Cloudflare security state and no analytics or advertising state. Quantify set Clerk state, its same-origin offline cache and no PostHog state before a choice.
Choosing Decline stored only the consent decision and produced no PostHog cookie, storage or analytics host request. Choosing Allow created the disclosed PostHog state and loaded its EU-hosted assets. No advertising, social-media tracking, device fingerprinting or session recording was observed.
Authenticated checks of Global admin, Cloud dashboard and admin, and Quantify dashboard found the listed Clerk session, refresh and active-context state. Global used no product storage and could use Clerk environment storage after client hydration. Cloud used Clerk environment storage. Quantify also used a role-display cache, a variations register and its same-origin offline cache. All four protected routes passed with no console or page errors.
04Managing choices and storage
Quantify presents Allow and Decline with equal prominence. Analytics can be changed in Settings; withdrawal stops capture and clears PostHog state. Browser controls can also clear or block storage. Authentication and requested product state may then be recreated when the corresponding service is used.
Clerk and Cloudflare may add a suffix to a cookie name or set a security cookie only when a risk or authentication flow requires it. We audit production at least quarterly and update this policy before a new non-exempt storage purpose is enabled.