What we use
The only cookie we set on the QuickAsk web service is a single HttpOnly, Secure session cookie issued after you sign in with Google. It is required to maintain your login state and is removed when you sign out or when the session expires.
| Cookie | Purpose & lifetime |
|---|---|
access_token |
Short-lived JWT bound to your active session. HttpOnly, Secure, SameSite=Lax. Lifetime: 15 minutes; refreshed automatically while you are active. |
refresh_token |
Long-lived rotation token used to obtain a new access token. HttpOnly, Secure, SameSite=Lax. Lifetime: up to 30 days; revoked when you sign out or revoke the session. |
Both cookies are strictly necessary for the service to function. Without them you cannot stay signed in.