Privacy Policy

Privacy, explained clearly.

QuotaHalo is a Mac utility for viewing Codex quota and optional Local Token Activity. This policy explains what the app processes, what stays on your Mac, and when your authorized Codex executable may communicate with OpenAI services.

01 / At a Glance

Privacy at a Glance

Prompts
Not read or collected by QuotaHalo
Responses
Not read or collected by QuotaHalo
Source code
Not read or collected by QuotaHalo
Project content
Not read or collected by QuotaHalo
Quota
Requested through your authorized Codex executable
Local Token Activity
Optional, read-only local processing
Activity history
Optional local 30-day aggregates
Raw thread IDs
Memory-only; not persisted or sent to the UI
Runtime observability
Local, bounded, latest snapshot only

02 / Separate Data Paths

Separate by design.

Quota authorization and Local Token Activity do not use the same data source. Authorizing one does not automatically authorize or enable the other.

Quota authorization via CodexOptional Local Token Activity source

03 / Policy

QuotaHalo Privacy Policy

About QuotaHalo

QuotaHalo helps you view Codex quota, keep a compact Mac HUD nearby, and optionally view locally observed Token Activity. This policy applies to the QuotaHalo Mac app and the QuotaHalo website.

Information QuotaHalo Does Not Read or Collect

QuotaHalo does not read or collect your prompts, responses, source code, project content, project names, or project paths for its quota or Local Token Activity features.

QuotaHalo does not read, copy, parse, or log the credentials from your existing Codex configuration. It does not bundle, download, install, update, or modify Codex.

Codex Executable Authorization

You explicitly choose the Codex executable that QuotaHalo may run. macOS stores a security-scoped authorization so the app can validate and use that selected executable. If the executable changes, QuotaHalo can require you to choose it again rather than trust an outdated authorization.

Quota and Account Access

For quota, QuotaHalo starts the authorized Codex executable as a managed local app-server process. It uses a separate writable authentication home inside QuotaHalo's sandbox and asks Codex for structural account status and rate-limit information.

QuotaHalo does not inspect the contents of Codex credential files. Signing in is an explicit user action. If the account is signed out, QuotaHalo does not silently begin a Device Code login.

Local Token Activity

Local Token Activity is optional, off until you enable it, and uses a local Codex data directory that you choose separately. QuotaHalo opens the supported local database in a read-only mode and reads only the fields required to calculate activity changes.

Raw thread identifiers may be held briefly in app memory to calculate per-thread changes and anonymous aggregates. They are not persisted in activity history, sent to the UI, or written to diagnostics. QuotaHalo does not read thread titles, prompts, responses, source code, project names, or project paths for this feature.

Local Token Activity is based on activity observed locally by QuotaHalo. It is not official OpenAI billing usage or official token consumption.

Why does QuotaHalo ask me to choose a Codex data directory?

The directory is the separately authorized, read-only source for Local Token Activity. Choosing it does not enable Token Activity, authorize quota access, or grant access to unrelated folders.

Local Storage and Preferences

QuotaHalo stores app settings, window and Edge preferences, a last-known quota cache, optional aggregate activity history, personal activity profiles, security-scoped authorizations, and local operational state in its macOS sandbox.

Optional activity history contains daily aggregates for up to 30 days and does not store raw thread identifiers. Personal Activity Baseline data is stored separately and can be reset separately. A cached quota remains last-known data until a validated refresh replaces it or you clear the quota cache.

Security-Scoped Authorizations

macOS security-scoped bookmarks let QuotaHalo reopen only the Codex executable and local data directory you selected. These bookmarks are local app data. Selecting a different source replaces the corresponding authorization; turning a feature off does not by itself erase its saved authorization.

Runtime Observability and Diagnostics

The Mac App Store build maintains a privacy-safe local runtime snapshot to verify launch, activation, marker, quota, and scheduler state. It stores only counters, state labels, booleans, timestamps, and a one-way marker correlation hash. The snapshot is local-only, latest-only, bounded to 16 KiB, and atomically replaced.

It contains no credentials, account identifiers, raw quota values, prompt or response content, bookmark bytes, or home-directory path. QuotaHalo has no remote diagnostics backend and does not upload this snapshot. Failure to write it does not change app behavior.

Login Launch Marker

When you enable Launch at Login, the sandboxed Login Helper places a small one-time marker in the shared App Group before opening QuotaHalo without activation. The marker contains a schema version, the background-login intent, a creation time, and a random nonce. It does not contain account, quota, credential, bookmark, or user-content data.

QuotaHalo atomically claims and removes the marker. Stale, malformed, or unsupported markers are not treated as background-login authority. The App Group is not used for quota, authentication, settings, history, profiles, bookmarks, or runtime observability.

Network Communication and External Services

QuotaHalo itself does not operate an analytics server, telemetry service, advertising network, tracking SDK, remote logging service, or cloud user database. The website does not load analytics or tracking scripts.

The external Codex executable you authorize may communicate with OpenAI services for login, account status, and rate-limit information. Those communications are performed by Codex and are subject to the terms and privacy practices that apply to Codex and OpenAI. QuotaHalo does not make privacy promises on OpenAI's behalf.

QuotaHalo also uses Apple system services for sandboxing, security-scoped access, Launch at Login, notifications when you enable them, and standard Mac App Store distribution.

Retention

In-memory working data lasts only for the running process. The last-known quota cache and latest runtime snapshot remain until replaced or local app data is removed. Settings and security-scoped authorizations remain until changed, replaced, or local app data is removed. Optional activity history is retained for up to 30 days. Personal activity profiles remain until reset or local app data is removed.

Your Controls, Revocation, and Deletion

In QuotaHalo Settings you can turn Token Activity off, pause or clear 30-day activity history, reset Personal Activity Baseline data, choose a different Token Activity source, choose Codex again, clear the quota cache, sign out of QuotaHalo's separate ChatGPT login, and turn Launch at Login off.

Signing out of QuotaHalo does not sign you out of ChatGPT.app and does not change the Token Activity source. Uninstalling QuotaHalo removes the app but macOS may retain sandboxed app data. QuotaHalo 1.0.0 does not provide one Erase All Data control, so this policy does not claim that uninstalling automatically removes every local file.

Security

QuotaHalo uses the macOS App Sandbox, read-only security-scoped access where applicable, private local file permissions, bounded file formats, atomic replacement, and validated external executable identity. No software can guarantee absolute security, but these controls limit access and reduce the effect of malformed or unavailable local data.

Children

QuotaHalo is a general-purpose developer utility and is not directed to children. It does not provide its own cloud account system or advertising profile.

Changes to This Policy

This policy may be updated when QuotaHalo's features, distribution, or privacy practices change. Material changes will be reflected on this page before they are represented as current product behavior.

Contact

For privacy questions, email support@quotahalo.comor visit the QuotaHalo Support page.