Cookie Policy
Version 1.1.0—Last updated: 2026-10-02
Published
1. Our Approach to Cookies
Qpher is committed to respecting your privacy. Our marketing website (qpher.ai) uses Plausible Analytics, a privacy-focused analytics tool that does not use cookies, does not collect personally identifiable information, and does not track users across websites or devices. As a result, the marketing site does not set any analytics cookies. The User Portal (portal.qpher.ai) and our API (api.qpher.ai) use cookies only to sign you in to the User Portal. Qpher Vault on the web signs you in with a cookie set by its service, api.vault.qpher.ai; the web client itself (vault.qpher.ai) sets no cookies and stores nothing in your browser's storage. These are essential functional cookies required for the Service to operate and do not require consent under most cookie regulations.
2. Essential Cookies
The following essential cookies are used by the Qpher platform:
User Portal (set by portal.qpher.ai, and by api.qpher.ai when you sign in or your session is renewed):
-
qpher_access_token: HttpOnly, Secure, SameSite=Strict. Holds the access token for your session. Expires after 15 minutes.
- qpher_refresh_token: HttpOnly, Secure, SameSite=Strict. Holds the refresh token that renews your session. Expires 7 days after it was last renewed.
- qpher_logged_in: Secure, SameSite=Strict, not HttpOnly, so pages can read it. Holds only the value "true", to show that you are signed in. Expires 7 days after it was last set.
Each of these is set for the host that sets it (portal.qpher.ai or api.qpher.ai) and is not sent to our other sites.
Qpher Vault on the web (set by api.vault.qpher.ai; the __Host- prefix makes your browser keep them to that host):
- __Host-qv_refresh: HttpOnly, Secure, SameSite=Strict. Holds the refresh token that keeps you signed in. Renewed each time a signed-in page loads and about every 12 minutes while one is open; expires 7 days after it was last renewed, or when you sign out.
- __Host-qv_apple: HttpOnly, Secure, SameSite=None. Set only while you sign in with Apple, so that Apple's answer can be matched to the browser that started the sign-in. Expires after 10 minutes.
The Qpher Vault web client keeps its short-lived access token (15 minutes) in the page's memory only.
These cookies are strictly necessary for signing in to the User Portal and to Qpher Vault on the web, and are exempt from consent requirements under the ePrivacy Directive (2002/58/EC) and similar regulations. They are not used for tracking, advertising, or analytics purposes. Apart from qpher_logged_in, they hold session tokens, which carry identifiers such as your user ID, your organization and, for the User Portal, your email address.3. Third-Party Cookies
Qpher does not set third-party cookies on any of its domains. We do not use third-party advertising networks, social media tracking pixels, or cross-site analytics tools that set cookies. When you are redirected to Stripe for payment processing, Stripe may set its own cookies on the stripe.com domain in accordance with Stripe's own cookie policy. Qpher has no control over Stripe's cookies. Likewise, when you sign in with Apple, Apple may set its own cookies on apple.com. If you have questions about cookies set by Stripe or any other third-party service, please refer to their respective privacy and cookie policies.
4. Contact and Updates
If you have questions about our use of cookies, contact privacy@qpher.ai.
This Cookie Policy may be updated from time to time. The current version is always available at qpher.ai/legal/cookies.
Qpher LLC
Registered in the Commonwealth of Virginia, United States.
8401 Mayland Dr Ste A, Richmond, VA 23294, USA
Effective Date: February 16, 2026