quodeq / privacy
Last updated 7 October 2026

Privacy

What quodeq does with your code and data: nothing. Every network connection the software and this website make, listed.

quodeq is open source software that runs on your machine. There is no quodeq account, no quodeq server, and no telemetry. We never see your code, your results, or who you are. This page lists every network connection the software and this website make, so you can check each claim against the source.

The software

Your code stays local. quodeq reads your source files on your machine and writes results to ~/.quodeq as plain JSON. API keys you enter are stored in your operating system keychain, or in environment variables you set yourself. Nothing is uploaded to us. We have no servers to upload it to.

The AI provider you choose. To evaluate code, quodeq sends it to the model provider you configure, using your own API key or CLI account. With a local provider (Ollama or llama.cpp) nothing leaves the machine. With a cloud provider, your code goes to that provider and their privacy policy and data processing terms apply to that traffic: Anthropic (Claude), Google (Gemini), OpenAI (Codex), GitHub (Copilot), OpenRouter. quodeq adds no identifiers of its own to those requests.

Version check. Once a day quodeq makes one unauthenticated request to find out whether a newer release exists: the PyPI JSON endpoint for pip, pipx and uv installs, or the GitHub Releases API for the desktop apps. It sends nothing beyond what any HTTP request carries. Turn it off with QUODEQ_NO_UPDATE_NOTIFIER=1 or under Settings, Updates.

Dashboard fonts. The local dashboard loads its fonts from Google Fonts, so your browser contacts fonts.googleapis.com and fonts.gstatic.com when you open it. Google sees your IP address for that request. No page content or code is involved.

Features that connect out only if you turn them on. The assistant's web search is off by default and only available with local providers. When you enable it, searches go to DuckDuckGo and the assistant fetches the pages it finds. Connecting a GitHub account uses GitHub's device login and stores the token locally. The CI reporter posts results to the GitHub API using a token you provide in your pipeline.

This website

quodeq.ai is a static site served by GitHub Pages. It uses Cloudflare Web Analytics to count page views. That script sets no cookies, does not fingerprint your browser, and reports aggregate numbers such as page, referrer and country. It is covered by the Cloudflare privacy policy. The site loads fonts from Google Fonts. It stores one key in your browser's local storage, quodeq-theme, to remember light or dark mode, and that value never leaves your browser. The demo video on the home page loads from youtube-nocookie.com only when you press play, and the share buttons on blog posts open the social network only when you click them. GitHub may log requests to the site under the GitHub Privacy Statement.

Data processing agreement

quodeq does not process personal data or source code on anyone's behalf. It has no server, no account and no telemetry, so there is no processor relationship with the project and no data processing agreement to sign. This section is the only DPA statement quodeq can truthfully offer.

The agreement that governs your code is the one you already have with the model provider you configure. For GitHub Copilot that is the GitHub Data Protection Agreement in the GitHub customer terms, including any data residency option your enterprise has enabled. For the other cloud providers, use the DPA published by that provider. If you use a local model, no data leaves your device and no agreement is needed.

Changes and contact

This page lives in the website repository, so every change is visible in its history. Questions go to quodeq.ai@gmail.com.