Privacy Policy
Privacy, explained clearly.
QuotaHalo is a Mac utility for viewing Codex quota and optional Local Token Activity. This policy explains what the app processes, what stays on your Mac, and when your authorized Codex executable may communicate with OpenAI services.
01 / At a Glance
Privacy at a Glance
- Prompts
- Not read or collected by QuotaHalo
- Responses
- Not read or collected by QuotaHalo
- Source code
- Not read or collected by QuotaHalo
- Project content
- Not read or collected by QuotaHalo
- Quota
- Requested through your authorized Codex executable
- Local Token Activity
- Optional, read-only local processing
- Activity history
- Optional local 30-day aggregates
- Raw thread IDs
- Memory-only; not persisted or sent to the UI
- Runtime observability
- Local, bounded, latest snapshot only
02 / Separate Data Paths
Separate by design.
Quota authorization and Local Token Activity do not use the same data source. Authorizing one does not automatically authorize or enable the other.
03 / Policy
QuotaHalo Privacy Policy
About QuotaHalo
QuotaHalo helps you view Codex quota, keep a compact Mac HUD nearby, and optionally view locally observed Token Activity. This policy applies to the QuotaHalo Mac app and the QuotaHalo website.
Information QuotaHalo Does Not Read or Collect
QuotaHalo does not read or collect your prompts, responses, source code, project content, project names, or project paths for its quota or Local Token Activity features.
QuotaHalo does not read, copy, parse, or log the credentials from your existing Codex configuration. It does not bundle, download, install, update, or modify Codex.
Codex Executable Authorization
You explicitly choose the Codex executable that QuotaHalo may run. macOS stores a security-scoped authorization so the app can validate and use that selected executable. If the executable changes, QuotaHalo can require you to choose it again rather than trust an outdated authorization.
Quota and Account Access
For quota, QuotaHalo starts the authorized Codex executable as a managed local app-server process. It uses a separate writable authentication home inside QuotaHalo's sandbox and asks Codex for structural account status and rate-limit information.
QuotaHalo does not inspect the contents of Codex credential files. Signing in is an explicit user action. If the account is signed out, QuotaHalo does not silently begin a Device Code login.
Local Token Activity
Local Token Activity is optional, off until you enable it, and uses a local Codex data directory that you choose separately. QuotaHalo opens the supported local database in a read-only mode and reads only the fields required to calculate activity changes.
Raw thread identifiers may be held briefly in app memory to calculate per-thread changes and anonymous aggregates. They are not persisted in activity history, sent to the UI, or written to diagnostics. QuotaHalo does not read thread titles, prompts, responses, source code, project names, or project paths for this feature.
Local Token Activity is based on activity observed locally by QuotaHalo. It is not official OpenAI billing usage or official token consumption.
Why does QuotaHalo ask me to choose a Codex data directory?
The directory is the separately authorized, read-only source for Local Token Activity. Choosing it does not enable Token Activity, authorize quota access, or grant access to unrelated folders.
Local Storage and Preferences
QuotaHalo stores app settings, window and Edge preferences, a last-known quota cache, optional aggregate activity history, personal activity profiles, security-scoped authorizations, and local operational state in its macOS sandbox.
Optional activity history contains daily aggregates for up to 30 days and does not store raw thread identifiers. Personal Activity Baseline data is stored separately and can be reset separately. A cached quota remains last-known data until a validated refresh replaces it or you clear the quota cache.
Security-Scoped Authorizations
macOS security-scoped bookmarks let QuotaHalo reopen only the Codex executable and local data directory you selected. These bookmarks are local app data. Selecting a different source replaces the corresponding authorization; turning a feature off does not by itself erase its saved authorization.
Runtime Observability and Diagnostics
The Mac App Store build maintains a privacy-safe local runtime snapshot to verify launch, activation, marker, quota, and scheduler state. It stores only counters, state labels, booleans, timestamps, and a one-way marker correlation hash. The snapshot is local-only, latest-only, bounded to 16 KiB, and atomically replaced.
It contains no credentials, account identifiers, raw quota values, prompt or response content, bookmark bytes, or home-directory path. QuotaHalo has no remote diagnostics backend and does not upload this snapshot. Failure to write it does not change app behavior.
Login Launch Marker
When you enable Launch at Login, the sandboxed Login Helper places a small one-time marker in the shared App Group before opening QuotaHalo without activation. The marker contains a schema version, the background-login intent, a creation time, and a random nonce. It does not contain account, quota, credential, bookmark, or user-content data.
QuotaHalo atomically claims and removes the marker. Stale, malformed, or unsupported markers are not treated as background-login authority. The App Group is not used for quota, authentication, settings, history, profiles, bookmarks, or runtime observability.
Network Communication and External Services
QuotaHalo itself does not operate an analytics server, telemetry service, advertising network, tracking SDK, remote logging service, or cloud user database. The website does not load analytics or tracking scripts.
The external Codex executable you authorize may communicate with OpenAI services for login, account status, and rate-limit information. Those communications are performed by Codex and are subject to the terms and privacy practices that apply to Codex and OpenAI. QuotaHalo does not make privacy promises on OpenAI's behalf.
QuotaHalo also uses Apple system services for sandboxing, security-scoped access, Launch at Login, notifications when you enable them, and standard Mac App Store distribution.
Retention
In-memory working data lasts only for the running process. The last-known quota cache and latest runtime snapshot remain until replaced or local app data is removed. Settings and security-scoped authorizations remain until changed, replaced, or local app data is removed. Optional activity history is retained for up to 30 days. Personal activity profiles remain until reset or local app data is removed.
Your Controls, Revocation, and Deletion
In QuotaHalo Settings you can turn Token Activity off, pause or clear 30-day activity history, reset Personal Activity Baseline data, choose a different Token Activity source, choose Codex again, clear the quota cache, sign out of QuotaHalo's separate ChatGPT login, and turn Launch at Login off.
Signing out of QuotaHalo does not sign you out of ChatGPT.app and does not change the Token Activity source. Uninstalling QuotaHalo removes the app but macOS may retain sandboxed app data. QuotaHalo 1.0.0 does not provide one Erase All Data control, so this policy does not claim that uninstalling automatically removes every local file.
Security
QuotaHalo uses the macOS App Sandbox, read-only security-scoped access where applicable, private local file permissions, bounded file formats, atomic replacement, and validated external executable identity. No software can guarantee absolute security, but these controls limit access and reduce the effect of malformed or unavailable local data.
Children
QuotaHalo is a general-purpose developer utility and is not directed to children. It does not provide its own cloud account system or advertising profile.
Changes to This Policy
This policy may be updated when QuotaHalo's features, distribution, or privacy practices change. Material changes will be reflected on this page before they are represented as current product behavior.
Contact
For privacy questions, email support@quotahalo.comor visit the QuotaHalo Support page.