Legal & privacy

Privacy

This policy covers the Quill Terminal software and service, operated under the registered business name Quill Terminal. The Quill Terminal Privacy Lead can be reached through the support form or at support@quillterminal.app. This policy explains what Quill Terminal collects, why it is used, who processes it, and the choices available to you.

Prompts stay local by default

Quill Terminal keeps prompts, drafts, templates, prompt history, and local settings on your computer. Quill Terminal does not upload that document content to the Quill Terminal website. When you deliberately send content to an AI provider, the provider receives it as described below.

Account and license data

The account service stores your sign-in email and, when supplied by Google or GitHub, display name and avatar; authentication-provider identifiers; access or private-evaluation status; license key; download history; and activated-device metadata. A private invitation stores only a hash of the raw one-time link, its optional email lock, owner-selected source and campaign labels, claim deadline, open/claim times, and the account that accepts it. Native browser activation stores hashes of separate short-lived browser and polling secrets, request status and expiry, the approving account, and the same device metadata used for normal license activation. The raw poll secret remains only in the native process, while the raw browser code is exchanged on its first website request for a short-lived HttpOnly same-site cookie; neither raw secret is stored in the account database. After you sign in, Quill Terminal also records when an otherwise pseudonymous public-website session was authenticated and which sign-in provider was used. This supports private visit-to-account-to-download reporting and customer support; anonymous sessions are not assigned an identity. Device metadata consists of a normally random installation identifier, a hostname-based label, operating system, processor architecture, installed Quill Terminal version, and first- and last-seen times. If local state cannot save a new random identifier before first activation, Quill Terminal uses a stable app-scoped fallback derived locally from coarse host, user, home, app-path, and architecture values so retries do not consume new device seats; those raw values are not sent as the identifier. Quill Terminal derives a shortened one-way support ID from the installation ID and records a blocked attempt if that same ID later reports a different operating system, including the claimed operating system, architecture, app version, time, and attempt count. This evidence helps resolve device-seat disputes; it is not a hardware serial or location. To prevent repeated evaluations, Quill Terminal also keeps one-way, app-scoped claims for the verified account identity and computer. Raw machine properties are combined locally and are not sent to the service. These claims are used only for license and evaluation-abuse prevention, not advertising. Prompt and document content is not included.

Purchases and billing

Paddle acts as merchant of record and handles checkout, payment details, tax, receipts, subscription billing, and payment recovery. Quill Terminal does not receive or store complete card or bank details. Quill Terminal loads Paddle.js on its pricing page for checkout, on the signed-in Account page for an associated Paddle customer, and on the public homepage only when the URL contains Paddle's payment-recovery parameter. Ordinary anonymous homepage visits do not initialize Retain. Paddle Retain is bundled with Paddle.js and loads its runtime from Paddle's ProfitWell service. When a recovery widget is shown, that runtime may also load supporting fonts, browser compatibility code, images, and error monitoring through Google, Cloudflare's public CDN, and Sentry as part of Paddle's delivery infrastructure. Retain may use its own browser identifier and receive the current page, referring page, and browser or network information needed to deliver and measure the requested payment-recovery intervention. On Account, Quill Terminal supplies the associated Paddle customer ID only when that Paddle customer record exists. Paddle processes this information under its own privacy terms; Quill Terminal does not use Paddle.js or Retain for advertising. To operate licenses and customer support, Quill Terminal stores Paddle customer, subscription, transaction, invoice, refund, credit, chargeback, currency, tax, fee, and earnings references associated with your account.

After your first completed purchase, Quill Terminal uses a transactional email provider to send your verified account email a welcome message containing your plan, amount paid, receipt reference, and license key. Quill Terminal stores the provider message identifier and a sanitized delivery status so the message is not sent repeatedly; the email body is not copied into Quill Terminal's database.

Provider requests

When you deliberately send a prompt through an Anthropic or OpenAI API target, Quill Terminal sends that content directly to the selected provider using the credential you configured. Provider CLI targets make their own connections under their own terms.

Service providers and international processing

Quill Terminal uses service providers to operate the account service: Vercel for website hosting, Neon for the account database, Cloudflare R2 for release downloads, Resend for transactional email, Paddle as merchant of record, and Google or GitHub when you choose their sign-in option. These providers process information under their own terms and security programs. Information may be processed outside Ontario or Canada and may be subject to the laws of the place where it is processed.

Anonymous website activity

Quill Terminal counts anonymous browser journeys so the administrator can understand whether people are finding the website and which launch channels produce sign-ins, private-evaluation starts, downloads, and purchases. A random identifier is kept in first-party browser storage for at most 24 hours so an email sign-in link opened in another tab can remain connected to the same coarse first touch; it is sent only to Quill Terminal. The server stores a keyed one-way hash plus first- and last-seen times. First-touch attribution is limited to an allowlisted launch-source label or sanitized UTM source, medium, and campaign labels, the referring hostname without its URL or path, and a broad landing category such as home, pricing, or docs. It does not store an IP address, exact visited path, full referrer URL, user agent, or browser profile. Separate devices or journeys may count separately, so these totals are not presented as unique people. Browsers that send Global Privacy Control or Do Not Track are excluded.

Feedback and support

Information you deliberately submit through the Feedback page or app feedback form is relayed to the Quill Terminal support inbox for support and product improvement. App feedback also includes the Quill Terminal version and operating-system platform so the report can be diagnosed. An optional email address is used so support can reply. Do not include API keys, passwords, license keys, or confidential prompt content in feedback.

Browser storage and authentication

Quill Terminal uses essential authentication cookies to keep signed-in website sessions secure. During native browser activation, the website session proves the account to the server and is never copied into the native app. After explicit approval, the app receives a signed device-bound license lease and a display-only summary of the verified email, access type, plan cycle, dates, and renewal state. That summary, a signed-out marker, and the lease are stored together in the operating system credential vault. The public-website activity counter uses first-party browser storage containing a random identifier with a maximum 24-hour lifetime. If you authenticate, the server can associate that pseudonymous journey and its coarse first-touch attribution with your Quill Terminal account. Quill Terminal does not use this counter for advertising, behavioral profiling, or cross-site tracking.

Retention

Account, entitlement, billing, security-audit, activation, invitation, and download records are retained while needed to provide Quill Terminal, meet financial and legal obligations, investigate abuse, resolve disputes, or handle support requests. One-way evaluation identity and device claims may be retained after account deletion where necessary to prevent repeated evaluation abuse; they cannot be used to recover the underlying email or raw machine properties without Quill Terminal's separate server secret. Public visitor-session hashes, coarse acquisition fields, and any account association added after sign-in expire after approximately 75 days so the private administration dashboard can report a rolling 60-day window. Paddle and other providers may retain transaction or security records under their own legal obligations.

Safeguards

Quill Terminal uses access controls, encrypted transport, restricted administrator access, signed license tokens, provider-managed encryption, secret separation, rate limits, and audit records appropriate to the information handled. No system can guarantee absolute security; report a suspected account or license compromise promptly.

Your choices and privacy requests

You may request access to or correction of personal information associated with your account, withdraw optional consent, or request deletion of eligible information. Some records may be retained where required for transactions, fraud prevention, security, legal obligations, or dispute resolution. Use the support form or email support@quillterminal.app. You may also raise an unresolved privacy concern with the Office of the Privacy Commissioner of Canada.

Children

Quill Terminal is not directed to children and paid accounts require the age of majority. If you believe a child provided personal information, contact support so it can be reviewed and removed where appropriate.

Changes

This policy may be updated as Quill Terminal or its providers change. Material changes will be posted with a new effective date and communicated through the account service when reasonably required.

Effective September 2, 2026.