Quillspy privacy notice
Your writing stays in your browser
Quillspy reads supported text files in your browser, selects phrase anchors and calculates SHA-256 fingerprints. File contents, filenames and selected phrases are not sent to the Quillspy server by this workflow. Choosing a file does not upload a manuscript. The app keeps this working information in the page while you use it. Your original file is not changed.
If you choose Save fingerprint, the server receives two digests (the original-file fingerprint and the anchor-set fingerprint), the original byte count, anchor count and extraction-version label. It stores these with a sequence number, server-clock date, previous-event digest and event digest. These are fingerprints and metadata, not encrypted documents or stored manuscript text. Digests can still reveal a match to someone who already has a candidate file; they should not be treated as anonymous information.
If you download a fingerprint record, that file contains your local filename, selected phrase excerpts, offsets and fingerprint metadata. It is saved to the destination your browser uses. Keep it private if those excerpts are sensitive. Quillspy does not control copies you download or share.
Google sign-in
Signing in sends you to Google. Quillspy requests only basic sign-in identity access (openid and email), not Gmail, Drive, contacts or files. Quillspy validates Google's response and stores your Google account identifier and verified email with a generated app identifier to recognize your account. Google handles its own sign-in process under its own policies. Quillspy does not receive your Google password and does not keep Google access or ID tokens after validating sign-in.
Saving a fingerprint requires a valid signed-in session. New fingerprint records are assigned to the account identifier from the server-validated session and kept in a separate per-account hash chain. Another account cannot read those records or obtain their count or chain head through the ledger API. Five older ownerless prototype records are archived outside user-facing routes and are not assigned to any account by guess. Quillspy still does not upload or store manuscripts.
Cookies and session records
Quillspy uses a short-lived browser cookie to bind a Google sign-in attempt to that browser (up to ten minutes) and a session cookie for app sign-in (up to eight hours). Cookies are Secure, HttpOnly and SameSite=Lax. The server stores a hash of the session token, your app identifier and expiry, and temporary sign-in state/nonce/PKCE data. Signing out removes the current app session; it does not sign you out of Google or delete your identity or fingerprint records.
Expiry limits whether a sign-in flow or session can be used. Expired server rows are cleaned during later sign-in activity, not necessarily at the exact expiry time. The app has no analytics, advertising cookies or third-party tracking scripts in its current implementation.
Why this information is used
Fingerprint metadata supports saving a record and checking the prototype ledger's hash chain. Sign-in identity and session records support authentication and sign-out. The current app does not search the web, send alerts, operate a document vault, invite recipients, monitor document viewing, use your camera or run museum-mode capture detection. Those features require separate implementation and updated disclosures before they can use your data.
Access, service providers and security
The application operator and authorized server administrators can access the stored identity and fingerprint metadata. Server records are not end-to-end encrypted, and a hash chain is not an independent notarization or proof of authorship. Quillspy uses HTTPS, session protections and an isolated application container. These measures do not guarantee absolute security.
Google processes sign-in, and the hosting infrastructure carries network requests and stores the server databases. Connecting to a website necessarily sends network information such as your IP address and browser request headers to the infrastructure. The application suppresses its own request logging; that is not a promise that hosting or network providers keep no operational records. The current Quillspy application does not sell data, serve targeted ads or send identity/ledger data to an analytics service.
Retention, deletion and your choices
Quillspy keeps your Google account identifier, verified email and saved fingerprint records until you ask for them to be deleted. There is no automatic expiry and no self-service delete button yet. To request deletion, email hi@quillspy.com from the Google account email you signed in with. Brandon Gatz reviews the request and removes your identity, sign-in sessions and fingerprint records from the live databases.
The hosting provider may keep backup copies of the server. Those copies are kept and expire on the provider's own schedule. Quillspy does not promise a date by which backup copies are gone. Deletion from the live databases does not remove anything you downloaded or copies on your own devices.
Signing out ends the current session; it does not delete your records. You can also process a file locally without saving a fingerprint, choose not to sign in, and remove Quillspy's access in your Google Account connection settings. Revoking Google access does not itself delete Quillspy's stored records.
Changes that add storage, sharing, monitoring or camera use will need clear updated disclosures and any required permission before those features use your information.
Contact
Quillspy is operated by Brandon Gatz personally. Email hi@quillspy.com for privacy and deletion requests. Messages are forwarded to Brandon Gatz's Gmail, and those mail systems process what you send. No response deadline is promised, and a reply may land in a spam folder.