Privacy policy
Your catalogue stays on your own disk unless you choose a feature that shares selected data with another service.
The short version
The application has no accounts, no usage analytics and no automatic crash reporting. Your project stays on your device. If you export to Google Sheets, submit feedback with details, use a plugin, or use the optional AI agent, the information you choose to share may go to another provider. qrate also checks release and plugin catalog metadata, and downloads components when you request them. Those network requests contain no project records. This website counts page views without cookies; that is the one difference between the website and the application.
What qrate collects
The application does not automatically send your catalogue, file paths, settings or usage data to the qrate team. It makes requests to qrate's release and plugin catalog services; those services receive ordinary connection information such as your IP address and user agent, but not your project contents. qrate writes a session log on your own machine to help you diagnose problems. When you open the feedback form, qrate gives your browser a short log preview. The form sends that preview to us only if you choose to include it.
This website
This site serves pages, images, and an optional feedback form, without accounts. Cloudflare serves it, and records standard request information for delivery and abuse prevention. That information includes your IP address, your user agent and the page you asked for. We do not use it to build profiles, and we run no advertising scripts. GitHub serves the application downloads. Their own privacy policy applies once you follow a download link.
The site does run Cloudflare Web Analytics, which counts page views so we can tell whether the download instructions are reaching anyone. It sets no cookie, stores no identifier in your browser, and assigns you no visitor ID that would follow you between sessions or to any other site. It reports the page you viewed, the referrer, and coarse details such as country, browser and device type. It has no access to your catalogue, and it runs only on this website. Cloudflare discards the IP address at the edge rather than storing it with the measurement. The feedback page does not load this analytics script. To opt out, block static.cloudflareinsights.com; any content blocker will do it, and the site works exactly the same without the script.
One address on this site answers qrate rather than a browser. It hands the application its own Google API credentials, so we can rotate them without shipping a new release. It carries no personal data in either direction. Your Google sign-in never passes through it. That happens between your browser, Google, and your own computer.
Optional feedback reports
The Feedback button opens a browser form with app version, commit, operating system, architecture, project dimensions, plugin counts, and a short current-session log preview. qrate removes your home-directory path from the log preview. The URL fragment holds this data locally in your browser, where browser extensions can access it. The page removes the fragment before it loads third-party scripts. It lets you edit or exclude the summary and does not show the log preview until you choose to include it.
Only submitting the form sends its contents to us. Reports can include your description, optional contact email, diagnostic summary, and files you explicitly attach. Inspect logs and screenshots for private information before attaching them. Cloudflare processes the submission and uses Turnstile and request information to prevent abuse. Linear stores reports and attachments for the qrate team. Reports are not public GitHub issues.
We use reports to investigate issues, improve qrate, and reply if you provide an email. Reports remain in Linear while needed for investigation and follow-up. To request deletion, email qrate@dvnl.work with your report ID. Provider backup and security retention policies may apply after deletion.
The browser converter reads your .qrate file on your device. It sends no project data to us. If you choose Google Sheets export, the page asks you to sign in to Google and sends the selected rows and columns to Google for that export.
Google user data
qrate can export a project to a Google Sheet. That is the only feature that touches a Google account, and it is optional. Nothing happens until you start the export and consent in your browser.
- Scope requested:
drive.fileonly. This scope reaches only the files qrate itself creates and the ones you hand it by name through Google's own file chooser. It gives qrate no access to the rest of your Drive: not your other documents, not your folders, not your file list. - Choosing an existing sheet: qrate opens Google's file chooser in your browser. Google shows you your own files and tells qrate about the one you pick, and nothing else. The chooser page on this site never sees the list. It passes your selection back to qrate on your own machine.
- What is sent: the rows and columns of the project you chose to export, sent directly from your computer to Google's API in order to create the sheet you asked for.
- Where it goes: straight to Google. The data does not pass through any server operated by this project, because there is no such server.
- Sign-in: a loopback redirect with PKCE. qrate opens your browser, you consent to Google directly, and Google returns the result to a port on your own machine. qrate never sees your Google password.
- Tokens: qrate keeps the access and refresh tokens Google issues on your own computer, so it does not ask for consent on every export. It never sends them to us.
- Retention and deletion: we hold no copy of your Google data, so there is nothing for us to delete. Removing qrate's access from your Google account, or deleting the local qrate data directory, ends it completely.
You can withdraw consent at any time from your Google account's third-party access page. Sheets qrate has already created stay in your Drive and remain yours.
Limited Use
In practice that means Google user data is used only to provide the export you requested. It is not sold, not transferred to anyone, not used for advertising, and not read by any human.
Other things qrate can reach
- Release checks, the plugin catalog and components. qrate requests signed release and catalog metadata from
qrate.dvnl.work. When you install a component, qrate downloads its files from the source listed for that component, such as GitHub or Hugging Face. These requests carry standard connection information required to serve the request, not your project data. - Dictionaries. If you add a spell-check language, qrate downloads that word list from its public repository. The request carries no identifying information beyond what any download requires.
- Plugins. Plugins run from a folder you control. A plugin you install may contact a server you point it at, for example an Islandora site that checks vocabulary terms. That connection is yours, and that service's own policy governs it.
- Preview tools. PDFium and ffmpeg run locally. They send nothing anywhere.
Optional AI agent
qrate includes an optional terminal agent that runs on your device. It starts with OpenRouter'sopenrouter/free model router. If you use the agent, your prompts and the project information you ask it to read can be sent from your device to OpenRouter and the model provider that handles the request. Those prompts and responses do not pass through qrate's servers. OpenRouter and the model provider apply their own privacy, retention and model-use terms.
The agent can read project data through a local connection that is protected by a token renewed each time qrate starts. It can stage suggested findings for you to accept or ignore; it cannot change a cell through that connection. The embedded Pi agent stores session history, settings and any sign-in credential in a local profile under qrate's data folder. qrate may pass a credential from your existing Pi OpenRouter login to the agent process for that session. It does not send the credential to qrate servers. Do not include sensitive data in a prompt unless you have reviewed the provider's terms.
Children
qrate is a professional cataloguing tool and is not directed at children under 13.
Changes
If this policy changes, the date at the top of this page changes with it, and the previous text stays in the site's git history.
Contact
Questions about this policy, or about data qrate touches: qrate@dvnl.work. See also the terms of service and the license.