1. Only essential cookies
SCUTA Quant uses only cookies that are strictly necessary to provide the Service you ask for: keeping you signed in and protecting your account (authentication and CSRF protection). We do not use analytics, advertising or social-media cookies, and no third-party tracking scripts run on our pages.
Because these cookies are strictly necessary, they do not need your consent [CONFIRM UNDER APPLICABLE LAW]. We show a short notice so you know about them.
2. The cookies we set
| Cookie | Purpose | Expires |
|---|---|---|
| scuta_access | Keeps you signed in (short-lived session token, httpOnly) | 15 minutes |
| scuta_rt | Renews the session token; only sent to the sign-in endpoints (httpOnly) | 30 days |
| scuta_csrf | Protects forms and actions against cross-site request forgery (httpOnly) | 30 days |
| scuta_oauth_state | Protects a Google sign-in in progress; only if you use Google | 10 minutes |
| scuta_oauth_intent | Links Google or confirms it is you from Settings; only while you do that | 10 minutes |
All of them are first-party cookies set by our API, marked httpOnly (page scripts cannot read them), SameSite=Lax, and Secure in production.
3. Browser storage
The web app also stores a few values in your browser’s local storage. They are not sent to us and contain no tokens:
| Key | Purpose |
|---|---|
| scuta_signed_in | Remembers that this browser has signed in, so signed-out visits skip a session check |
| scuta_session_refreshes | Coordinates session renewal between open tabs |
| scuta.run-settings.v1.* | Your last run settings for each strategy |
| Workspace layout keys | Panel sizes and layout of the strategy workspace |
| scuta_cookie_notice | Remembers that you dismissed the cookie notice |
4. Pages run by others
Stripe Checkout and the Stripe billing portal, and Google’s sign-in page, are run by Stripe and Google on their own domains and set their own cookies there under their own policies.
5. If this changes
If we ever add analytics or other non-essential cookies, we will update this policy first and ask for your consent before setting them; you will be able to refuse without losing access to the Service.
6. Controlling cookies
You can delete or block cookies in your browser settings. Blocking the cookies above stops sign-in from working. Questions: [PRIVACY EMAIL].