Skip to content
Back to home

Legal document

Cookie Policy

Version 2026-10-06.2Published on 6 October 2026

Last updated: 6 October 2026 (version 2026-10-06.2)

This Cookie Policy explains which cookies and similar tools the website https://quantum-mind.mgquantumsystems.com uses and what the Quantum Mind mobile app does on your device. It complements the Privacy Policy.

1. In short

  • We use only technical cookies that are strictly necessary for the operation and security of sign-in.
  • We use no profiling, advertising, statistical analytics or third-party cookies, nor cross-site tracking tools.
  • For this reason we show no consent banner: it is not required.
  • The public pages of the website set no cookies and do not use the browser’s local storage.
  • The mobile app does not use cookies: it keeps a few items in the device’s secure storage (section 7).

2. Controller

The controller is Allinners LLC, a company registered in Sharjah Media City, United Arab Emirates (Office 10, Level 1, Sharjah Media City, Sharjah, UAE — PO Box 487177). Contact: support@mgquantumsystems.com.

3. What cookies are

Cookies are small text files that a website saves in the browser. By “similar tools” we mean other technologies that store or read information on the device, such as the browser’s local storage. Technical cookies are needed to make the site work or to provide a service you asked for, for example keeping you signed in; they are not used to track you.

4. Public pages

The home page, the Privacy Policy, the Cookie Policy, the Terms and Conditions, the account deletion page and the support page set no cookies, do not use local storage, load no third-party resources and contain no analytics tools. Even the fonts are served from the same domain as the site.

5. Technical cookies of the sign-in pages and the panel

The following cookies are set only when you open the sign-in pages (sign-in, forgotten password, password reset, invitation) or the management panel reserved for staff. Students use the mobile app and normally do not need these pages, except to open an invitation or password reset link. In production the name of each cookie is preceded by the prefix __Host-, which binds it to our domain and to the HTTPS protocol.

  • qm_csrf: protection against forged requests (CSRF), that is, unwanted actions carried out in your name. Readable by the page; SameSite Strict. Duration: session (deleted when the browser is closed).
  • qm_did: random device key, used to recognise an already authorised device and apply the device limit; on the server we keep only a hash of it. HttpOnly; SameSite Lax. Duration: 400 days. It is set at the first sign-in attempt from that browser, even if it fails.
  • qm_mfa: temporary challenge of two-step verification. HttpOnly; SameSite Strict. Duration: 5 minutes.
  • qm_at: access token that keeps the session authenticated. HttpOnly; SameSite Lax. Duration: about 15 minutes, renewed as long as the session is active.
  • qm_rt: refresh token that allows the session to be kept. HttpOnly; SameSite Lax. Duration: normally 12 hours and in any case no longer than 7 days.

All these cookies have the Secure flag. When you sign out of the panel qm_at, qm_rt and qm_mfa are deleted; qm_did remains until it expires and qm_csrf until the browser is closed. None of these cookies is used to track you or for advertising or statistical purposes.

6. Browser local storage

The panel reserved for staff saves in the browser’s local storage the preference qm.sidebar.collapsed (side menu closed or open). It is an interface preference, it stays on your device, it is not sent to our servers and it contains no personal data. The public pages do not use it.

7. Mobile app

The app does not use cookies and contains no advertising or third-party analytics tools. On your device it saves, in the system’s secure storage (Keychain on iOS, Keystore on Android, accessible only while the device is unlocked), only the data needed to work:

  • the session refresh token, until you sign out of the app;
  • a random device key, used to recognise an already authorised device;
  • the indication that you completed the initial introduction;
  • the push notification token, only if you turned notifications on, until you turn them off or sign out of the app;
  • the email address of the last sign-in, only if you chose “Remember me”, until you sign in again without that option or delete the account.

The app update service (EAS Update, by Expo) also saves on the device a random installation identifier, used to distribute updates; it is not linked to your account (see the Privacy Policy, section 3.5). This data is strictly necessary to provide the service you asked for or is saved at your choice.

8. What we do not do

  • No profiling or advertising cookies.
  • No analytics or audience measurement tools on the website, ours or third-party; no third-party analytics tools in the app.
  • No embedded social network buttons or content, videos or maps.
  • No cross-site or cross-app tracking and no disclosure of data to advertising networks.

If in the future we wanted to introduce tools that are not strictly necessary, we would update this policy and ask for your consent before using them.

Technical cookies and similar tools that are strictly necessary do not require consent (Art. 122 of the Italian Personal Data Protection Code, Legislative Decree 196/2003; Art. 5(3) of Directive 2002/58/EC; the Italian Data Protection Authority’s Guidelines on cookies and other tracking tools of 10 June 2021), but they require this notice. Any personal data processed through them is processed for our legitimate interest in running and protecting the service (Art. 6(1)(f) GDPR) and to provide the service you requested (point (b)).

10. How to manage or delete cookies

You can view, block or delete cookies from your browser settings. If you block the technical sign-in cookies you will not be able to sign in to the panel or use the sign-in pages, because the session cannot be kept; the public pages keep working. To remove what the app saves on the device, delete the app. Signing out of the app removes the session token and the notification token (the latter also when you turn reminders off in Profile, Notifications); the remembered email stays until the next sign-in without “Remember me” or until the account is deleted. On iOS some data saved in the secure storage (for example the random device key) may remain after uninstalling: to remove the credentials, sign out of the account first.

The website and the app contain links that you open voluntarily (for example the link to a live session on Zoom, a WhatsApp message to support, the stores). When you open them you leave our site: the cookies of those services are governed by their own notices.

12. Changes

If we change the tools we use we update this policy, with date and version number.

13. Contacts

For questions write to support@mgquantumsystems.com.