Skip to content

Privacy

Privacy at Quotum (English translation)

This translation is provided for information. The reference text is the French document at quotum.app/PRIVACY.md, which prevails.

Dated October 2, 2026. The French original of this document is a file versioned with the application's code, in a repository that is not public: each change to it has a commit, an author and a date, but that history is not open to you. What follows applies to the first version of the application made available for download and to the following ones, until a new dated version of that file says otherwise.

What has changed since the previous version, dated September 25, 2026, and why. This version once again modifies a commitment of part II, the one on identifiers. It too does so before the first release of the application: no copy has yet been made available for download or sold, and so no one has obtained it under the previous commitment.

The reason: erasing two items from your Mac was still enough to restart the trial. The mark that prevents it had to live somewhere other than on that Mac. The version of September 25, 2026, had, for its part, introduced activation once per Mac, the trial marker in the Keychain and the list of refused keys, described below.

This document has two halves, and they are not read in the same way. The first describes what the application does today — verifiable, and contradicted by the code on the day it became false. The second is a commitment about what the product will not become: it cannot be verified, it is kept.

I. What the application does today

What it reads

Quotum asks you for no password and opens no session. It reads the credentials that the command-line tools have already placed on the machine — and only for the tools you have chosen to track. None is tracked on installation: on a fresh installation, none of these sources is opened.

ToolWhere the credential is read
Claude

Keychain, item Claude Code-credentials, through /usr/bin/security

Warp

Keychain, items dev.warp.Warp-Stable and dev.warp.Warp-Stable.tui

Codex

~/.codex/auth.json, or $CODEX_HOME/auth.json

Windsurf

~/.local/share/devin/credentials.toml, and the state.vscdb database of Windsurf or of Devin

Cursor

Cursor's state.vscdb database, key cursorAuth/accessToken

Codebuff

~/.config/manicode/credentials.json

Augment

~/.augment/session.json

opencode

~/.local/share/opencode/auth.json, entry opencode-go

Grok

~/.grok/auth.json, or the file designated by $GROK_AUTH_PATH / $GROK_HOME; the GROK_DEPLOYMENT_KEY variable is used only when the file holds no session

A check that opens nothing, before any tracking. To tell you whether a tool has left its sign-in on this Mac, the “Add an account” sheet only checks that these files exist, without opening them, before you even turn tracking on: ~/.local/share/devin/credentials.toml, ~/Library/Application Support/Windsurf/User/globalStorage/state.vscdb, ~/Library/Application Support/Devin/User/globalStorage/state.vscdb, ~/Library/Application Support/Cursor/User/globalStorage/state.vscdb, ~/.config/manicode/credentials.json, ~/.augment/session.json, ~/.local/share/opencode/auth.json and ~/.grok/auth.json — or wherever $XDG_DATA_HOME, $GROK_AUTH_PATH and $GROK_HOME move them. It also looks at whether the GROK_DEPLOYMENT_KEY variable is set, without keeping or sending its value. No content is read, the Keychain is not queried, and nothing goes out over the network. A file being there therefore does not mean the sign-in is still valid: only a measurement, once the tool is tracked, lets Quotum call an account signed in.

And six other sources, which do not depend on this choice: they are read at each measurement, whether a tool is tracked or not, including on a fresh installation. None of them is used to query a provider. They are ~/.claude.json (the oauthAccount object, which names the connected account without carrying any token); the address and secret files of the local proxies — the secret is one, a credential: it is placed in the path of the address queried, and travels only over the local loopback; ~/Applications and Chrome's Local State; ps -axo command, to know which applications are running; the usage history that Claude Code writes itself (plan-usage-history.json); and the Codex CLI session logs (<CODEX_HOME>/sessions/…/rollout-*.jsonl), of which only the end is read, in search of the quota headers that the server left there.

These session logs are the transcripts of your conversations. We open them to look for a percentage, nothing from them leaves the machine — and we prefer to write this here rather than keep quiet about it on the grounds that no token is found in them.

The token only passes through. It is read, placed in the header of a request, and nothing else: it is copied into no file, written to no log, kept in no cache. The network session is declared ephemeral, its cache is set to nil, and its policy ignores any local cache.

Where it connects

To the quota interfaces of the nine providers, to two ports on the local loopback of your own machine, and to the publisher, for the only three reasons described below: updates, opening the trial and activating the license. The complete list of addresses, line of code by line of code, is on the site's “What Quotum reads on your Mac” page.

Each reader first looks for its credential on the machine and only goes onto the network if it has found it. On a computer where a tool is not installed, no request goes out to that provider.

What goes nowhere

None of your measurements, none of your account names, none of your tokens is sent to the publisher. There is no account to create, no audience measurement, no automatic incident report. Two identifiers specific to your Mac go to the publisher, each once: at first launch, the token that Apple issues to this Mac for the trial, which the publisher passes on to Apple without keeping it; on activation of your license, the fingerprint of a key created by its chip. They are described in the next two sections, and named as such.

Three exceptions, and they are real. Quotum queries the publisher's update feed to find out whether a more recent version exists; nothing else goes back up there: no account, no measurement, no statistics. It opens the trial at first launch, through a request that the license service has verified by Apple. And it activates your license, once per Mac. Writing “there is no publisher server” would be false, and we do not write it.

The trial, opened by Apple

The trial opens through a request that Quotum sends at first launch, to licences.quotum.app/essai: a 32-byte code drawn at random on this Mac, and a token that Apple issues to this Mac through DeviceCheck, an Apple service — ephemeral, single-use, and readable only by Apple. Nothing else: no serial number, no machine name, no measurement. The request carries no cookie and follows no redirect. Before it goes out, the 32-byte code is written to your preferences and to the “Quotum — trial” item of your Keychain: a lost response is asked for again with it, and the service then returns the same response.

The license service passes this token on to Apple, without keeping it. Apple keeps, for each device and for each developer, two bits and the date of their last modification; the service sets one, once, and never erases it: it is what says that the trial has already been used on this Mac. It survives erasing the Mac as well as reinstalling Quotum. If it is already set, the trial does not open: a second-hand Mac whose previous owner tried Quotum has no trial left — write to us then at contact@quotum.app; a purchase remains refundable in any case on simple request for thirty days. Otherwise, the service returns a signed ticket, which Quotum then verifies on this Mac, offline: no further request for the trial.

If the service does not respond, the same request goes out again by itself one minute later, then at doubling intervals, six hours at most, as long as trial time remains; in the meantime, no account is measured, and the fourteen days of the trial count from the first launch. Without Apple's response, no trial: a trial opened for lack of a response could be obtained by blocking an address. In a virtual machine, where DeviceCheck does not exist, the trial is not available, and nothing goes out.

The license service keeps the SHA-256 fingerprint of the code, never the code itself, with the date of the first request and the date on which the mark was set at Apple: thirty days, after which they are erased at the next trial request, whichever Mac makes it. Your IP address is used to route the request and, for one minute at most, to limit the number of requests; it is not kept.

This processing is based on the legitimate interest in offering the trial only once per Mac: without it, the trial could be restarted at will. Its controller is the publisher, named below. Apple receives the token and keeps the mark: for people in the European Economic Area, its privacy policy designates Apple Distribution International Limited, in Ireland, as the controller, states that this data is generally stored by Apple Inc. in the United States, and governs its transfers outside the Union by standard contractual clauses. Its policy: https://www.apple.com/legal/privacy/. You may object to this processing; without it, the trial simply cannot open, and a purchased license works without it.

Activation, once per Mac

The key you enter is first verified on your machine, by its signature. Then, when you choose “Activate This Mac”, Quotum sends a single request, to licences.quotum.app/activer: your license key, the public half of a key that this Mac's security chip creates for the occasion, and a signature proving that the request comes from this Mac. Nothing else: no serial number, no machine name, no measurement. It carries no cookie and follows no redirect. The response is an activation certificate, which Quotum then verifies on this Mac, offline, at each launch: no further request for the license on this Mac, neither to verify it again nor to renew it.

If the service does not respond, the same request goes out again by itself one minute later, then at doubling intervals, six hours at most, for seven days at most after you choose “Activate This Mac”; after that, nothing more goes out without a new action on your part. If the connection is impossible, Quotum displays a request code, QUOTUM-DEMANDE-…, which carries only the identifier of your license and the fingerprint of this Mac's key: sent to contact@quotum.app from the purchase address, it gets you an activation code, within the same cap.

The chip's key is drawn at random, never leaves the chip in the clear, and says nothing about your hardware. But its public half is specific to this Mac, and the license service keeps a fingerprint of it with your license: it is an identifier, and we call it that. It is used only to count the Macs activated — three new Macs at most per period of 365 rolling days, more on a reasoned request — and to recognize a Mac already activated, which is reactivated without counting during the 400 days its activation is kept; beyond that, reactivating it counts as one activation. Erasing Quotum's preferences, erasing the Mac or changing Macs counts as one activation: the chip's key, once lost, must be created again. On a machine without a security chip — a virtual machine, in practice —, a software key takes its place; it is refused on a Mac that has a chip.

A key that has circulated is replaced free of charge: the old one no longer activates any new Mac, and the Macs already activated keep working. A key whose purchase was refunded in full, or whose payment dispute was lost, no longer activates any Mac, and stops working in the versions of the application published afterwards: each of them carries an 8-byte fingerprint of every key refused in this way, computed over the entire key, and a fingerprint published in a released version can no longer be removed from it. A dispute that is still open suspends the activation of new Macs until it is closed; a withdrawal that has only been declared suspends nothing.

What the application writes

On your Mac, the application writes to its preferences; to the “Quotum — trial” item of your Keychain; to its folder ~/Library/Application Support/Quotum/, where an empty file, licence.verrou, prevents two copies open at the same time from each creating a key for this Mac, and where the quota resets already requested are noted; and, only on your actions, the account applications you create, their folders, the script used to pin a terminal, which erases itself at the end, and the open-at-login file, if you turn that option on. At the publisher, opening the trial and activating a Mac each record one line, described above and below; at Apple, opening the trial sets the mark described above. On your provider accounts, a single function writes: spending a Codex quota reset credit of a ChatGPT account. It cannot be reversed.

It has two paths, and neither goes off on its own for a tool you do not track: without consent to measuring, no quota is measured, and nothing can conclude that an account has run dry.

Where your settings live

In the application's preferences, on your machine. They are synchronized nowhere and do not leave the computer.

The license key is stored there too, with what activation produced: the chip's key, in the form that the chip itself encrypted and that only works on this Mac, and the activation certificate. The trial keeps there its start date, the time already elapsed, the last time the clock showed, the code drawn at random and the ticket received. Its start date and its code are also written to your Keychain, in an item named “Quotum — trial” (service app.quotum.mac.essai), not synchronized with iCloud. It contains only this date and this code, and it remains after the application is deleted: it is what prevents erasing the preferences, or reinstalling the application, from restarting the trial. To erase every trace of Quotum from your Mac, also delete this item in Keychain Access; the trial would not start again for all that, since the mark Apple keeps for this Mac prevents it. None of this is sent anywhere, apart from what the trial and activation requests carry.

The site, which is not the application

Everything above describes the application. The site quotum.app is a different thing, and it does include audience measurement.

It is hosted by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, United States), which counts its visits with Cloudflare Web Analytics, on our behalf:

Like any host, Cloudflare also receives the visitor's IP address in order to serve the pages. Apart from Cloudflare's measurement script, the site loads nothing from a third party: no font, no script, no image.

The purchase, which is not the application

What follows describes everything that a purchase puts into circulation. The controller of this processing is the publisher: Régis Jehl, sole proprietor, MASH MEDIA, 20 rue du Tabac, 67600 Ebersheim, France, contact@quotum.app.

StepWhat is processedBy whomWhy
Order page (licences.quotum.app)

The date, the time and the version of the texts of the three agreements you give before paying — immediate delivery of the key, loss of the right of withdrawal, acceptance of the terms of sale and of the license

A publisher service hosted at Cloudflare, which passes them on to Stripe with the order

To prove these agreements, the first two of which the law requires in order to deliver the key straight away

Payment

Your email address, the payment details entered at Stripe, the country, the amount

Stripe

To collect the payment. We never receive the full card number: only the email, the name and the country entered, the amount, the card brand and the last four digits of the card

Issuing the key

The identifier of the payment session, the key issued, its date, its status (paid, withdrawn, refunded, disputed) with the date of any withdrawal and that of any full refund, each payment dispute (its identifier at Stripe, its outcome and its dates), and a fingerprint of your email address — not the address itself

The same publisher service, and its database, at Cloudflare

To deliver the key only once, to send it to you again if you lose it, and not to send again a key that has been refunded

Activating a Mac

The identifier of your license, the SHA-256 fingerprint of the public key created by this Mac's chip, and the date; for an activation granted by hand, the fact that it was manual and, beyond the cap, the reason for the exception — a reason, never a name or an address. Your IP address is used to route the request and, for one minute at most, to limit the number of requests; the service does not keep it: its logs are switched off. The identifier of your license is also used, for one minute at most, to limit the number of requests made for the same license

The publisher's license service, at Cloudflare

To count the Macs activated per license, recognize a Mac already activated, and refuse a key that has been refunded, disputed or replaced

Cap reached

The identifier of the license, the date of the refused request and that of the next free slot. Your address is not read

The same service, which alerts the publisher by an email to its own address, sent by Brevo, at most once every thirty days for the same key

To spot a key that is circulating, in order to replace it

Replacing a key

The new key, its link with your purchase and the reason for the replacement; your address, read again at Stripe in order to send it to you

The publisher's service, Stripe, Brevo

To give you a new key if yours has circulated

Keys refused by the application

An 8-byte fingerprint of each key whose purchase was refunded in full, or whose payment dispute was lost. No name, no address, no purchase reference

Published in each version of the application

So that such a key stops working in the versions published afterwards

Emails

Your email address, and the content of the message: the purchase confirmation, with your key and, attached as PDF files, the full text of the terms of sale and of the license agreement in the versions you accepted; the acknowledgment of receipt of a withdrawal or of a refund request

Brevo

To give you the confirmation of the contract and the acknowledgment of receipt on a durable medium, as the law requires

“Renoncer au contrat ici” (Withdraw from contract here)

Your first and last name, the email address of the purchase, the purchase reference if you give it, the address at which to receive the acknowledgment. The service keeps only the date of the withdrawal: the rest exists only in the acknowledgment

The publisher's service, then Brevo for the acknowledgment, sent to the address you give, with a copy to the purchase address if it differs, and to the publisher

To receive your withdrawal or your refund request, acknowledge receipt of it, and refund you

What this processing is based on. The performance of the contract, for the payment, the key and its delivery; our legal obligations, for the proof of the two agreements, the confirmation of the contract, withdrawal and accounting; and the legitimate interest in preventing fraud, for what Stripe does with it.

For activation, its cap, the cap alert and the list of refused keys: the legitimate interest in enforcing a license intended for its holder, and in stopping its use when the contract has ended. This data is the fingerprint of a key drawn at random and the identifier of your license: it reveals nothing about your hardware and is used for no profiling. Replacing a key falls under the performance of the contract. The chip's key, the activation certificate, the “Quotum — trial” item, and the trial's code and ticket, written and read on your Mac, are strictly necessary for what you ask for — the activation you choose, the trial you start —: they do not require your consent, only this information.

The fingerprint of your address. The service that issues the keys does not keep your address in the clear. It keeps a fingerprint of it, computed with a secret key: enough to recognize the address you will one day enter to retrieve your key or to withdraw, without the fingerprint being enough to reconstruct it. Your address itself exists in the clear only at Stripe and at Brevo.

Stripe. To collect the payment, Stripe acts on our behalf. According to its own privacy policy, it also processes this data for its own purposes — notably fraud prevention and its legal obligations to combat money laundering —, and provides Link directly to those who choose to use it, under its own terms. Its transfers outside the European Union rely, according to that same policy, on standard contractual clauses and, for Stripe, Inc., on its certification under the EU–US Data Privacy Framework. Its policy: https://stripe.com/fr/privacy.

Cloudflare, already the site's host, also hosts, on our behalf, the service that issues keys, activates Macs and opens trials, and its database. This service's logs are switched off in production: Cloudflare keeps neither your IP address nor the address of any request there. The transfer conditions are those described above, for the site.

Brevo (Sendinblue SAS, 17 rue Salneuve, 75017 Paris, France) sends the emails on our behalf. We write our emails in HTML and in plain text, without any image or link: the logo is drawn in colored cells, and nothing is loaded from a server. Brevo still adds an open-tracking pixel to them, as well as an unsubscribe link in their headers, which it does not allow us to remove: Brevo does not allow open and click tracking to be switched off (observed on September 24, 2026, on a test email). We have enabled anonymous tracking there: an open is counted without being associated with your address. For it not to be counted at all, it is enough that your email client does not load remote images. The addresses that our emails cite, such as quotum.app/cgv.html, are written out in full there, without “https://”: Brevo does not turn them into redirect links (observed the same day), and nothing you click there is counted.

How long.

Your rights. You may request access to the data concerning you, its rectification, its erasure when no legal obligation requires it to be kept, the restriction of its processing, its portability, and object to processing based on our legitimate interest. Write to contact@quotum.app. You may also refer the matter to the CNIL, the French data protection authority (www.cnil.fr).

For activation, we will examine your objection bearing in mind that, without this record, the activation cap cannot be enforced.

II. What the product will not become

These four commitments have no end date.

Never a subscription

Quotum is sold once. The price paid opens the right to use the application with no time limit. There will be no switch to a subscription, nor any feature already bought that would one day be put behind a recurring payment.

What this commitment does not say: a later major version, if one ever exists, may be a separate paid product. What is promised here is that what you bought remains yours, not that everything written afterwards comes to you free of charge.

Never audience measurement added after the fact

No telemetry, no audience measurement, no usage report, neither today nor in a later version that would introduce it discreetly.

Two identifiers, and never another, both described above: the token that Apple issues to a Mac for the trial, sent at first launch and passed on to Apple without being kept; and, on activation of your license, the fingerprint of a key that this Mac's chip draws at random, sent once. Quotum neither reads nor sends any hardware identifier (serial number, platform identifier, hardware address of a network card): Apple's token, which only Apple can read, is the only one that designates this Mac to Apple. In the legal sense, the “Quotum — trial” item of your Keychain and the key that the chip creates on activation are trackers, even though they measure nothing: we call them that.

This commitment changed twice, on September 25, 2026, and then on September 26, 2026, before the first release of the application: until then it excluded any tracker and any machine identifier, then admitted only the activation identifier. It will not change again through an update of what you bought. Should it have to change again, it would only be in a product sold separately — a new major version, paid, with its own key pair —, announced by a new dated version of this document.

If the product is sold or discontinued

The last published version remains downloadable and usable. A Mac already activated depends on no publisher service: it works offline, with no time limit, and the absence of a response from the update feed blocks nothing. Activating a new Mac, however, depends on the license service. Before any shutdown of this service, we would publish a release token: entered in the application, it makes the key alone sufficient on any Mac, as before activation — except for a key refused because of a refund or a lost dispute. This token is signed as soon as activations are put into service, and the publisher is the only one who holds it. This promise therefore assumes a publisher still able to publish it: if the publisher disappeared without having done so, the Macs already activated would keep working, but no new Mac could be activated any more.

What we will never ask for

A token, an API key, the content of a credentials file. No problem with Quotum is diagnosed with them. If a support reply asked you for one, it would not come from us.

Contact

For any question about this document: contact@quotum.app.