Updated 28 August 2026
This is a translation provided for convenience. Only the French version is legally binding.
Cookie policy
Version applicable during the private beta.
Quiet Metrics is built without any identification or tracking cookie. This page describes, exhaustively, what is stored on your device and what is not.
On the public pages of quietmetrics.dev
No analytics cookies. The home page, the documentation and the legal pages use only two preferences stored in the browser's local storage:
| Key | Purpose | Duration |
|---|---|---|
quiet-theme |
Remember the light or dark theme chosen by the user | Until the user clears the site's data |
quiet-cookie-note |
Remember that this information notice was dismissed | Until the user clears the site's data |
These values contain no identifier, are never sent to the server and are not used to measure browsing. They are stored after an explicit action by the user. No consent banner is therefore displayed on these pages alone, as long as this configuration remains unchanged.
Protecting the public forms
The contact and registration pages load the Cloudflare Turnstile security widget, strictly necessary to prevent automated submissions and account creation. It is loaded on no other page. It analyses technical signals from the browser and the connection, then issues a single-use token verified by our server. Turnstile is used neither for analytics nor for advertising. Pre-clearance mode, which could place a cf_clearance cookie on our domain, is not enabled. Details are in the privacy policy and in Cloudflare's Turnstile addendum.
On sites measured by Quiet Metrics
No identification or tracking cookie. The measurement script (qm.js), the pixel and the server SDKs store on the devices of visitors to customer sites no identifier and no value allowing them to be recognised from one visit to the next. Counting relies on an ephemeral fingerprint recomputed on every page view and destroyed every night: the method is described in how we count.
Two entries, and only two, may be written on the device of a visitor to a measured site. They have neither the same origin nor the same legal regime, and are described separately below for that reason: the opt-out marker, which the person requests themselves in order to stop the measurement, and the visit continuity cookie, which the measurement stores so as not to count the same visit twice. Neither of the two contains an identifier: their content is the same for everyone, and that content is transmitted to Quiet Metrics in neither case.
The absence of an identification or tracking cookie does not automatically exempt the measured site from consent or information duties. The applicable regime depends on the features enabled, the purposes pursued and the other tools on the site. Campaign and UTM tracking, conversions and custom events may in particular require the visitors' prior consent. It is for the operator of the measured site, as controller, to determine and apply the appropriate regime.
The opt-out marker, written at the person's request
The first of the two entries only takes place if the visitor asks for it, and serves only to stop the measurement:
| Key | Purpose | Duration |
|---|---|---|
qm_ignore |
Record the refusal to be measured, so that the script, the pixel and the server SDKs stop counting visits | 5 years, or until the visitor removes it |
Visitors set it and remove it themselves. By loading a page of the measured site with the ?qm_ignore=1 parameter, a visitor asks no longer to be counted; with ?qm_ignore=0, they revoke that request. Nothing else writes it.
It takes two complementary forms, so that a single action covers both tracking modes: a first-party cookie of the measured site (path=/, samesite=lax, and secure where the site is served over HTTPS), the only form the server SDKs can read, and an entry of the same name in the browser's local storage, which takes over where the cookie is refused or has expired.
This marker contains no identifier: its only value is 1. It is never transmitted to Quiet Metrics, allows neither recognising nor following the person, and has no effect other than stopping the measurement. It therefore belongs to the trackers intended to record the choice expressed by the person as to the storing of trackers, which the French data protection authority's guidelines exempt from consent: making the recording of a refusal conditional on consent would deprive it of its purpose.
The visit continuity cookie, written by the measurement
The second entry follows from no request by the visitor: it is stored by the measurement itself, and therefore falls under the regime of audience measurement rather than that of a refusal. This is why it is dealt with in a section separate from the previous one.
| Key | Purpose | Duration |
|---|---|---|
qm_visit |
Signal that a visit is already under way in this browser, so that a network change occurring during the visit does not cause the same person to be counted twice | 10 sliding minutes, extended on every page view; the cookie expires on its own as soon as browsing stops |
What it corrects. The fingerprint that tells visitors apart is recomputed on every page view from the subscriber network and the browser. When that network changes during a visit, for instance when moving from a mobile network to a wireless one, the fingerprint changes with it and one and the same person would be counted as two distinct visitors on the same day. This cookie merely signals that a visit is already open in this browser, which makes it possible not to open a second one.
It contains no identifier. Its value is 1, the same for everyone: it tells nobody apart, allows no visit to be linked to any other, and does not outlive the visit it accompanies. Only its presence is signalled to the collection service, never its content, since it has none.
It is never stored on the device of a person who has opted out. The opt-out marker described above stops the measurement before any write: a visitor carrying qm_ignore does not receive this cookie.
It takes the form of a first-party cookie of the measured site (path=/, samesite=lax, and secure where the site is served over HTTPS), with no local storage counterpart. Serving audience measurement rather than the recording of a refusal, it does not benefit from the exemption specific to the opt-out marker: the regime applicable to it is the one recalled above, which the operator of the measured site determines in the light of its purposes and configuration.
In the member area (application)
The application uses only cookies strictly necessary to its operation, exempt from consent under the French data protection authority's guidelines:
| Cookie | Purpose | Duration |
|---|---|---|
quiet_metrics_session |
Session of the signed-in user | 2 hours (end of session) |
XSRF-TOKEN |
Protecting forms against CSRF attacks | 2 hours |
remember_web_* |
"Stay signed in", only if you tick the option | 400 days maximum |
These cookies serve only the operation of your account: they do not track your browsing, serve no advertising and are shared with no third party.
Payment
Payment takes place on Stripe's pages (checkout and billing portal, stripe.com domain): any cookies stored in that context fall under Stripe's policy.
In summary
| Context | Cookies stored | Banner required |
|---|---|---|
| Public pages of quietmetrics.dev | No analytics cookies; two functional local preferences, and Turnstile on the contact and registration pages only | No |
| Sites measured by Quiet Metrics | No identification or tracking cookie; two entries only, the opt-out marker qm_ignore requested by the visitor and the visit continuity cookie qm_visit lasting 10 sliding minutes |
To be determined by the site operator, based on its configuration and purposes; the opt-out marker is for its part exempt |
| Member area (signed in) | Strictly necessary only | No (exempt) |
Any questions: Protected contact detail: enable JavaScript to reveal it.