Cookie Policy
Effective date: 2026-09-24 · Policy version: v2
OpenLLM is operated by Quantide LLC, a Delaware (USA) limited liability company. Privacy questions and rights requests: [email protected].
1. What this Policy covers
This Cookie Policy explains how Quantide LLC ("we", "us") uses cookies and similar browser storage on the OpenLLM service (the "Service"). It supplements our Privacy Policy and Terms of Service. Capitalised terms not defined here have the meaning given there.
A "cookie" is a small text file a site stores in your browser. We use cookies for three purposes: to run the Service (strictly necessary), to understand and improve it (analytics) and, only if you Accept, to measure our own ads on Meta (Facebook and Instagram). We do not sell personal information.
2. Your choices
When you first visit, we show a consent banner. You can Accept or Decline analytics cookies:
- Strictly necessary cookies are always on — the Service cannot function without them, and they store no analytics data.
- Analytics and advertising cookies are set only if you Accept. If you Decline, we instruct our analytics provider to stop capturing, the Meta pixel is never loaded, and no analytics or advertising cookies are used.
Accepting the current policy also enables limited daemon diagnostic reports by default for your signed-in account, unless you have opted out. These reports are not cookies. You can turn them off separately in Settings → Legal → Diagnostics, or on a machine with openllm doctor opt-out. Accepting cookies again does not override an account or machine opt-out. Declining or withdrawing consent blocks future reports.
We remember your choice so we only ask once per policy version: it is cached in a first-party cookie and, if you are signed in, on your account record so it follows you across devices. We will ask again only when this Policy's version changes (shown at the top of this page). You can also change your mind at any time by clearing the openllm_cookie_consent cookie in your browser, which brings the banner back.
3. Cookies we use
3.1 Strictly necessary
- Session cookie (set by Neon Auth / Better Auth) — keeps you signed in. Required for any authenticated page.
openllm_cookie_consent— stores your consent choice and the policy version you agreed to, so we don't re-prompt. First-party,SameSite=Lax, retained up to 12 months.openllm_marketing_consent— mirrors the marketing-emails box on the sign-in page (on by default; untick to opt out), so your answer survives the sign-in redirect and can be recorded on your account. First-party,SameSite=Lax, retained up to 7 days.- Short-lived helper cookies set by Google during the OAuth sign-in redirect, governed by Google's own notice.
Your zero-knowledge vault session (the unwrapped Data Encryption Key) is held in memory only — it is never written to a cookie. See the Privacy Policy §3.4.
3.2 Analytics (consent required)
- PostHog (
ph_*_posthog) — first-party product analytics and error monitoring: which pages and features are used, anonymous-then-identified usage, and session replay (with all form inputs masked and secret screens excluded). Set only after you Accept; retained up to 12 months. We send these events to PostHog, Inc. via a first-party reverse proxy (/ingest). We do not use this data for advertising.
3.3 Advertising measurement (consent required)
- Meta Pixel (
_fbp,_fbc) — loaded only on our public marketing pages and only after you Accept. It tells Meta Platforms, Inc. that a visitor viewed a page after seeing one of our ads. Retained up to 90 days. - Meta Conversions API — if you Accepted, our server tells Meta when you sign up, start a trial or subscribe, with your email and account id hashed (never in plain text), plus your IP address, browser user agent and the Meta cookies above, so Meta can match the conversion to the ad you saw. Never your prompts, responses, credentials or any vault data. Meta uses this to measure and optimise our ads.
Daemon diagnostic reports are processed by PostHog and retained for 30 days after submission. They contain daemon version, platform, error codes and timing information, not prompts, responses, credentials or raw log files. See the Privacy Policy for details.
We instruct PostHog to mask all keyboard input and to never record the recovery-phrase or API-key screens, and our server strips any credential material before it reaches PostHog.
4. Third parties
The analytics cookies above are operated with PostHog, Inc. as our processor. Advertising measurement (§3.3) is shared with Meta Platforms, Inc. under Meta's Business Tools Terms, only with your consent. Sign-in uses Google LLC as the identity provider. Our hosting (Vercel) and database (Neon) providers may also set technical cookies necessary to serve the site. Each third party's own privacy notice governs its processing; see our Privacy Policy §6 for the full sub-processor list.
5. Managing cookies in your browser
Beyond our banner, you can block or delete cookies through your browser settings. Blocking strictly-necessary cookies will break sign-in and other core features. Most browsers also offer a "Do Not Track" or global privacy control signal; where required by applicable law we honour recognised opt-out signals.
6. Changes to this Policy
We may update this Policy from time to time. When we make a material change we bump the policy version (shown at the top of this page), which re-triggers the consent banner so you can review and choose again. Your continued use after the effective date constitutes acceptance of the non-analytics, strictly-necessary cookies.
7. Contact
Quantide LLC · Delaware, U.S.A.
- Privacy questions and rights requests: [email protected]
- General: [email protected]