QuotaGlance Privacy Policy

码量 QuotaGlance 隐私政策

Applies to: QuotaGlance(码量) for iOS and watchOS, including its widgets
Effective date: September 1, 2026 · Last updated: September 1, 2026 · Version 1.1

适用应用:码量 / QuotaGlance(iOS、watchOS 及其小组件)
生效日期:2026 年 9 月 1 日 · 最近更新:2026 年 9 月 1 日 · 版本 1.1

In one sentence

QuotaGlance does not collect, upload, or store any personal information. The developer operates no server, and the app performs no user tracking of any kind. All quota data shown by the app stays on your own devices and in your own private iCloud database, which the developer cannot access.

What the app reads. QuotaGlance reads only your usage quota: how much of your session and weekly limits remains, and when they reset. It never reads your prompts, your code, your conversations, or your project names. It has no developer-operated server and contains no third-party analytics, advertising, or crash-reporting SDK.

Do you need a Mac? A Mac is optional. Sign in on iPhone and it reads your quota directly, with no Mac involved. If you prefer not to sign in on iPhone, the Mac app can collect quota and sync it to your iPhone and Apple Watch through your own private iCloud database.

Where your sign-in lives. Signing in is optional. When you sign in, the credentials stay in that device's own keychain, marked "this device only." They are never written to iCloud, never included in a backup, and never leave the device that obtained them.

1. About This Policy

This Privacy Policy explains how QuotaGlance (码量, the "App") handles information related to you on iPhone, Apple Watch, and in its widgets and complications. The App is developed and published by an independent developer ("we", "us", or "the developer").

By downloading, installing, or using the App, you confirm that you have read and understood this Policy. If you do not agree with any part of it, please stop using the App and delete it.

The App has a companion macOS version. That version collects the quota readings on your own Mac; its behavior is described in Section 6 so that you have a complete picture of where the data comes from.

2. How the App Works

The App shows how much usage quota you have left in the AI coding agent tools you use, and when those quotas reset. A general sense of how the data moves makes the rest of this Policy clear:

Quota readings can reach your iPhone by either of two paths, and you choose which:

Path A — you sign in on this iPhone
Your iPhone
   └─ reads your quota directly from the provider you signed in to
        ├──> displays it, and drives alerts and widgets
        ├──> pushes it to your paired Apple Watch
        └──> saves it to YOUR own private iCloud database

Path B — a Mac collects for you
Your Mac (the companion macOS app)
   └─ reads quota status through your account, or from tools already on that Mac
        └─ syncs it through YOUR own private iCloud database
              ├──> your iPhone (reads and displays)
              └──> your Apple Watch (reads and displays)

Four privacy-relevant facts follow from this:

3. Information the App Processes

The App processes only the information below, and none of it is ever sent to the developer or to any third party.

3.1 Quota status data

This is the only functional data the App transmits over a network, and it is stored in your own private iCloud database. Only the latest status per tool is kept; new readings overwrite old ones and no history is retained. Its contents are limited to:

CategoryDescriptionPersonal data?
Tool identifierWhich AI coding agent tool this quota status belongs toNo
Quota usage ratioThe percentage used / remaining within each quota periodNo
Quota reset timeWhen the current quota period resetsNo
Reading timeWhen this status was captured, on whichever of your devices captured itNo

These are plain percentages and timestamps. They contain nothing that identifies you and nothing about what you did with the AI tools.

3.2 App settings

The alert thresholds you configure (light / important / urgent) and the "weekly quota reset reminder" toggle are stored on your device only. They are not synced to iCloud and never leave your device.

3.3 Alert state

To avoid repeating the same alert, the App records on your device which alert level was last announced. This record contains only a service name and an alert level, and likewise never leaves your device.

3.4 Local cache

So that the last known reading is available offline and at cold start, the most recent status is cached in the App's own sandboxed container, shared by the main app, the widgets, and the watch complications. This container is protected by the operating system and is inaccessible to other apps.

4. Information We Never Collect

The App does not collect, request, read, or upload any of the following:

Worth stating explicitly, because an earlier version of this Policy said otherwise: if you sign in to a provider on your iPhone, that iPhone does contact that provider's official endpoints directly to read your quota. This is what lets the app work without a Mac. It reads your usage quota and nothing else. The Apple Watch app never signs in and never contacts an AI provider; it only displays readings that reached it from your iPhone or your own private iCloud database.

5. Where Information Is Stored and How It Moves

5.1 Your private iCloud database

Quota status is stored in an Apple iCloud private database. A private database is an Apple-provided storage area whose contents are owned and protected by your Apple Account and inaccessible to anyone else, including the app's developer. It uses your own iCloud storage and is governed by the Apple Privacy Policy.

5.2 On your device

Settings, alert state, and the latest cached reading live in the App's sandboxed container, protected by the operating system and deleted when you delete the App.

5.3 Between iPhone and Apple Watch

The iPhone sends the latest readings directly to your paired Apple Watch using the system's device-to-device connectivity. This is a peer-to-peer transfer of exactly what is listed in Section 3.1; no developer or third-party server is involved.

5.4 Network connections

On Apple Watch, the App makes exactly one kind of network request: communication with Apple iCloud to read your own data.

On iPhone, the App communicates with Apple iCloud, and — only if you have signed in to a provider — with that provider's own official endpoints. That is the complete list of hosts the App can contact:

EndpointPurposeWhen
claude.ai/oauth/authorizeClaude sign-in authorization pageOnly while you sign in to Claude
platform.claude.com/v1/oauth/tokenClaude token exchange and renewalOnly if signed in to Claude
api.anthropic.com/api/oauth/usageReads your Claude quotaOnly if signed in to Claude
auth.openai.com/oauth/authorizeCodex sign-in authorization pageOnly while you sign in to Codex
auth.openai.com/oauth/tokenCodex token exchange and renewalOnly if signed in to Codex
chatgpt.com/backend-api/wham/usageReads your Codex quotaOnly if signed in to Codex
Apple iCloud (CloudKit)Reads and writes your own private databaseAlways

The App contacts no other server. In particular, it never contacts a developer-operated server, because none exists. If you sign in to neither provider, the only network destination is Apple iCloud.

5.5 Your sign-in credentials

When you sign in, the credentials stay in that device's own keychain, marked "this device only." They are never written to iCloud, never included in a backup, and never leave the device that obtained them.

Concretely, the credential is stored in the system data-protection keychain, accessible only to this app, with the protection class "after first unlock, this device only" — a class that Apple explicitly excludes from iCloud Keychain sync and from device-migration backups. The credential is used solely as the authorization header on the endpoints listed in Section 5.4. It is never written to logs, never written to app data, never synced, and never sent to the developer or any third party. The App never uses it to send model requests. Signing out deletes it from the keychain.

6. Third Parties and Sharing

We do not sell, rent, trade, or otherwise share your information with any third party, and we do not use it for any purpose beyond those described in this Policy.

6.1 The only third party involved: Apple

The App uses Apple iCloud as the sync channel for your personal data. Your relationship with iCloud is governed by the Apple Privacy Policy and the iCloud Terms of Service.

6.2 No third-party SDKs

The App integrates no analytics (e.g. Firebase, Google Analytics), advertising, attribution, push-provider, or crash-reporting SDKs. It is built exclusively on Apple's own system frameworks.

6.3 What the App asks a provider for

Whether the request comes from your iPhone (Section 5.4) or from the companion Mac, it is always the same kind of request, and it is not a form of sharing: the App uses your own authorization to ask a provider you already have an account with how much of your quota is left. Nothing about you is disclosed to anyone who did not already have it.

6.4 No affiliation with providers

The App is developed independently and is not affiliated with, endorsed by, or sponsored by Anthropic, OpenAI, or any other provider. Provider names appear in the App and in this Policy only to identify which of your own accounts a reading belongs to.

6.5 Legal requests

Because the developer holds none of your data, we are technically unable to provide your personal information to any third party, including law enforcement.

7. System Permissions

PermissionWhy it is usedIf you decline
Notifications To send local notifications when your weekly quota falls below a threshold you set, and after a weekly quota resets. Every notification is generated on your device; no remote push is used, and the developer receives no push token. You may decline or revoke at any time. Everything else keeps working; you simply receive no alerts.
Background App Refresh Lets the system wake the App to read the latest quota from your iCloud so widgets and complications stay reasonably fresh. Can be turned off in Settings; the App then refreshes only while open.
iCloud (network) To read the quota records in your own private database. Without iCloud access the App shows a sync-failure message and displays only the local cache.

The App never requests location, contacts, calendars, photos, camera, microphone, health, or any other sensitive permission.

8. Tracking and Advertising

The App performs no user tracking of any kind: it does not read the IDFA, does not build user profiles, does not track you across apps or websites, and does not share information with data brokers. Consequently it never presents an App Tracking Transparency (ATT) prompt. The App contains no advertising.

9. Retention and Deletion

The App is designed to keep only the latest state and stores no history: iCloud holds a single record per service, and new readings overwrite old ones.

You can delete everything yourself at any time:

Since the developer holds none of your data, no deletion request needs to be sent to us afterwards.

10. Security

Please note that no method of storage or transmission is 100% secure. We also recommend protecting your Apple Account with a strong password and two-factor authentication.

11. Children's Privacy

The App is a productivity tool for developers. It is not directed to children under 13 (or under 14 or 16 in some jurisdictions), and we do not knowingly collect personal information from children. Because the App collects no personal information at all, no children's personal information is collected either. Parents or guardians with questions may contact us as described in Section 15.

12. Your Rights

Under laws such as the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and the Personal Information Protection Law of the People's Republic of China (PIPL), you have rights to be informed about, access, correct, delete, port, and withdraw consent for your personal information.

The App's design lets you exercise those rights directly and immediately: all data resides on your own devices and in your own iCloud account, so you can inspect, change, or permanently delete it as described in Section 9, without involving the developer.

Because we have never collected, received, or held your personal information, we cannot identify any data as "yours" and therefore cannot execute access or deletion requests on your behalf. This is not a refusal — it is a direct consequence of the App's architecture.

13. App Store Privacy Label

The App's App Store privacy declaration is "Data Not Collected." In detail:

Data categoryCollectedUsed for tracking
Contact info, identifiers of identityNoNo
Health & fitnessNoNo
Financial infoNoNo
LocationNoNo
Contacts, user contentNoNo
Browsing & search historyNoNo
Identifiers (user ID, device ID)NoNo
Usage data, diagnosticsNoNo

Quota percentages and reset times are processed by the App, but they remain on the user's own devices and in the user's private iCloud database and are inaccessible to the developer, which under Apple's definition does not constitute collection.

The same applies to signing in: the credential is created on your device, stored in that device's keychain, and used only to read your own quota from the provider's official endpoints. The developer never receives it, so no data is collected in Apple's sense.

14. Changes to This Policy

We may update this Policy as the App's functionality changes. Updated versions will be published on this page with a revised effective date at the top. If a change materially affects how information is handled, we will also present a prominent in-app notice. We encourage you to review this page periodically. Continued use of the App constitutes acceptance of the updated Policy.

15. Contact Us

If you have any questions, comments, or complaints about this Policy or the App's privacy practices, please contact us and we will respond within 30 days:

一句话总结

码量不收集、不上传、也不存储任何个人信息。开发者没有任何服务器,本应用也不进行任何形式的用户追踪。应用显示的额度数据全部保存在你自己的设备你自己的 iCloud 私有数据库中,开发者无法访问。

本应用读取什么。码量只读取你的用量额度:会话额度与每周额度还剩多少、什么时候重置。它不读取你的提示词、代码、对话内容或项目名称。它没有开发者自有的服务器,也不含任何第三方分析、广告或崩溃统计 SDK。

需要 Mac 吗?Mac 是可选的。在 iPhone 上登录,它就直接读取你的额度,全程无需 Mac。如果你不想在 iPhone 上登录,也可以由 Mac 版采集,经你自己的 iCloud 私有数据库同步到 iPhone 与 Apple Watch。

登录凭据存在哪里。登录是可选的。登录后,凭据保存在这台设备自己的钥匙串里,标记为「仅本机」。它们不会写入 iCloud、不会进入备份,也不会离开获取它们的那台设备。

1. 关于本政策

本隐私政策说明「码量」(英文名 QuotaGlance,以下简称「本应用」)在 iPhone、Apple Watch 及其小组件上如何处理与你有关的信息。本应用由独立开发者开发和发布(以下简称「我们」或「开发者」)。

下载、安装或使用本应用,即表示你已阅读并理解本政策。如果你不同意本政策的任何内容,请停止使用本应用并将其卸载。

本应用还有一个配套的 macOS 版本。macOS 版本负责在你自己的 Mac 上采集额度数据,其行为在第 6 节中一并说明,以便你完整了解数据的来源。

2. 应用如何工作

本应用用于查看你所使用的 AI Coding Agent 工具还剩多少使用额度、以及多久之后重置。了解数据的大致流向有助于理解本政策:

额度读数到达你 iPhone 的路径有两条,由你选择走哪一条:

方式 A —— 你在这台 iPhone 上登录
你的 iPhone
   └─ 直接向你登录的服务商读取额度
        ├──> 显示,并驱动提醒与小组件
        ├──> 推送给已配对的 Apple Watch
        └──> 写入你自己的 iCloud 私有数据库

方式 B —— 由 Mac 替你采集
你的 Mac(配套的 macOS 版「码量」)
   └─ 通过你的账号,或通过该 Mac 上已有的工具读取额度状态
        └─ 通过你自己的 iCloud 私有数据库同步
              ├──> 你的 iPhone(读取并显示)
              └──> 你的 Apple Watch(读取并显示)

由此得出四个与隐私直接相关的事实:

3. 应用处理哪些信息

本应用只处理下列信息,且这些信息不会发送给开发者或任何第三方

3.1 额度状态数据

这是本应用唯一会通过网络传输的业务数据,存放在你自己的 iCloud 私有数据库中。每个工具只保留最新的一份状态,新数据直接覆盖旧数据,不保留历史。其内容仅限于:

信息类别说明是否属于个人信息
工具标识用于区分这份额度属于哪一个 AI Coding Agent 工具
额度使用比例各额度周期内已使用 / 剩余的百分比
额度重置时间当前额度周期将在何时重置
读数时间这份状态被采集的时间,由你哪台设备采集就记哪台

这些内容是纯粹的百分比与时间戳,不包含任何可以识别你个人身份的内容,也不包含你使用 AI 工具做了什么。

3.2 应用设置

你在设置页中配置的提醒阈值(轻度 / 重要 / 紧急)与「每周额度重置提醒」开关,仅保存在本机,不会同步到 iCloud,也不会离开你的设备。

3.3 提醒状态

为了避免同一档提醒被重复推送,本应用会在本机记录「上一次已经提醒到哪一档」。该记录仅包含服务名与提醒等级,同样不会离开你的设备。

3.4 本地缓存

为了在离线或冷启动时仍能立即显示上一次的读数,最新一份额度状态会缓存在本应用自己的沙盒容器中,供主应用、小组件与表盘复杂功能共同读取。该容器受系统保护,其他应用无法访问。

4. 我们明确不收集的信息

本应用不会收集、请求、读取或上传下列任何信息:

需要特别说明,因为本政策的旧版本曾有相反表述:如果你在 iPhone 上登录了某个服务商,这台 iPhone 确实会直接连接该服务商的官方接口来读取你的额度。这正是本应用可以脱离 Mac 工作的原因。它只读取你的用量额度,不读取别的。Apple Watch 端从不登录,也从不连接任何 AI 服务商,只展示经 iPhone 或你自己的 iCloud 私有数据库到达的读数。

5. 信息存储位置与传输方式

5.1 你的 iCloud 私有数据库

额度状态存储在 Apple iCloud 的私有数据库中。「私有数据库」是 Apple 提供的一种存储区域,其中的数据由你的 Apple 账户持有并保护,包括应用开发者在内的任何人都无法访问,也不会计入他人可见的公共数据。这部分数据占用的是你自己的 iCloud 存储空间,受 Apple 隐私政策约束。

5.2 你的设备本地

设置、提醒状态与最新读数缓存保存在本应用的沙盒容器内,随应用一起被系统保护,卸载应用即随之删除。

5.3 iPhone 与 Apple Watch 之间

iPhone 会借助系统提供的设备间通信能力,把最新额度读数直接发送给已与之配对的 Apple Watch。这是设备之间的点对点传输,内容与第 3.1 节所列一致,不经过开发者或任何第三方服务器。

5.4 网络连接

Apple Watch 上,本应用发起的网络请求只有一种:与 Apple iCloud 通信以读取你自己的数据。

iPhone 上,本应用会与 Apple iCloud 通信;并且——仅在你登录了某个服务商时——与该服务商自己的官方接口通信。以下是本应用可能连接的全部主机:

接口用途何时发生
claude.ai/oauth/authorizeClaude 登录授权页仅在你登录 Claude 的过程中
platform.claude.com/v1/oauth/tokenClaude 令牌交换与续期仅在已登录 Claude 时
api.anthropic.com/api/oauth/usage读取你的 Claude 额度仅在已登录 Claude 时
auth.openai.com/oauth/authorizeCodex 登录授权页仅在你登录 Codex 的过程中
auth.openai.com/oauth/tokenCodex 令牌交换与续期仅在已登录 Codex 时
chatgpt.com/backend-api/wham/usage读取你的 Codex 额度仅在已登录 Codex 时
Apple iCloud(CloudKit)读写你自己的私有数据库始终

本应用不会连接任何其它服务器。特别地,它从不连接开发者自有的服务器,因为并不存在这样的服务器。如果你两个服务商都没有登录,唯一的网络目的地就只有 Apple iCloud。

5.5 你的登录凭据

登录后,凭据保存在这台设备自己的钥匙串里,标记为「仅本机」。它们不会写入 iCloud、不会进入备份,也不会离开获取它们的那台设备。

具体来说,凭据存放在系统的数据保护钥匙串中,只有本应用可以访问,保护等级为「首次解锁后,仅本机」——这是 Apple 明确排除在 iCloud 钥匙串同步与设备迁移备份之外的等级。凭据只作为第 5.4 节所列接口的授权头使用,不写日志、不写应用数据、不同步,也不会发送给开发者或任何第三方;本应用不用它发送模型请求。退出登录会把它从钥匙串中删除。

6. 第三方服务与信息共享

本应用不出售、不出租、不交换、不以任何形式向第三方共享你的信息,也不会因商业目的将信息用于本政策以外的用途。

6.1 涉及的唯一第三方:Apple

本应用使用 Apple 提供的 iCloud 作为你个人数据的同步通道。你与 iCloud 之间的关系适用 Apple 隐私政策iCloud 服务条款

6.2 不含任何第三方 SDK

本应用未集成任何分析(如 Firebase、友盟、Google Analytics)、广告、归因、推送服务商或崩溃统计 SDK。应用仅使用 Apple 官方系统框架构建。

6.3 本应用向服务商请求了什么

无论请求来自你的 iPhone(第 5.4 节)还是来自配套的 Mac,它始终是同一类请求,而且不构成任何形式的「共享」:本应用使用你自己的授权,向一个你本就拥有账号的服务商询问你的额度还剩多少。不会有任何关于你的信息被披露给原本不掌握它的一方。

6.4 与服务商无隶属关系

本应用由独立开发者开发,与 Anthropic、OpenAI 或任何其它服务商均无隶属、认可或赞助关系。服务商名称出现在本应用与本政策中,仅用于标识某份读数属于你的哪一个账号。

6.5 法律要求

由于开发者不持有你的任何数据,我们在技术上无法应任何第三方(包括执法机构)的要求提供你的个人信息。

7. 系统权限说明

权限用途拒绝后的影响
通知 在每周额度低于你设定的阈值时、以及每周额度重置后,发送本地通知。所有通知都在你的设备上生成,不使用远程推送,开发者不会获得设备推送令牌。 可随时拒绝或关闭;应用其余功能不受影响,仅收不到提醒。
后台 App 刷新 让系统在后台唤醒应用,读取一次你 iCloud 中的最新额度,以便小组件与表盘保持较新的数值。 可在系统设置中关闭;应用仅在打开时刷新。
iCloud(网络) 读取你自己私有数据库中的额度记录。 未登录 iCloud 或未授权时,应用会显示同步失败提示并仅展示本地缓存。

本应用不会请求定位、通讯录、日历、相册、相机、麦克风、健康或任何其它敏感权限。

8. 追踪与广告

本应用不进行任何形式的用户追踪:不读取 IDFA、不构建用户画像、不做跨应用或跨网站跟踪、不与数据经纪商共享信息。因此本应用不会弹出 App 跟踪透明度(ATT)授权请求。本应用不含任何广告

9. 信息保留与删除

本应用采用「只保留最新状态」的设计,不保存历史记录:每个工具在 iCloud 中只保留最新的一份状态,新数据直接覆盖旧数据。

你可以随时自行删除全部数据:

由于开发者不持有你的任何数据,上述操作完成后无需再向我们提出删除申请。

10. 信息安全

请注意:任何存储与传输方式都无法保证 100% 安全。请同时妥善保管你的 Apple 账户密码并开启双重认证。

11. 儿童隐私

本应用是面向开发者的效率工具,不面向 13 岁以下儿童(在部分司法辖区为 14 或 16 岁以下),也不会有意收集儿童的个人信息。由于本应用完全不收集个人信息,因此也不存在收集儿童个人信息的情形。如你是监护人并认为有相关疑问,请通过第 15 节的方式联系我们。

12. 你的权利

根据《中华人民共和国个人信息保护法》(PIPL)、欧盟《通用数据保护条例》(GDPR)、《加利福尼亚州消费者隐私法案》(CCPA/CPRA)等法律,你对自己的个人信息享有知情、访问、更正、删除、复制、撤回同意等权利。

本应用的设计使这些权利可以由你直接、即时地自行行使:所有数据都保存在你自己的设备与 iCloud 账户中,你随时可以查看、修改或按第 9 节的方式彻底删除,无需经过开发者。

由于开发者从未收集、接收或持有你的个人信息,我们无法定位到「属于你的数据」,因此也无法代为执行访问或删除请求 —— 这不是拒绝,而是本应用架构上的必然结果。

13. App Store 隐私标签对照

本应用在 App Store「App 隐私」中的声明为 「未收集数据」(Data Not Collected)。对照说明如下:

数据类别是否收集是否用于追踪
联系信息、身份信息
健康与健身
财务信息
位置
联系人、用户内容
浏览与搜索记录
标识符(用户 ID、设备 ID)
使用数据、诊断数据

额度百分比与重置时间虽由应用处理,但其始终保存在用户自有的设备与 iCloud 私有数据库中,开发者无法访问,按 Apple 的定义不构成「收集」。

登录同理:凭据在你的设备上生成、保存在该设备的钥匙串中,只用于向服务商官方接口读取你自己的额度。开发者从未收到过它,因此按 Apple 的定义也不构成「收集」。

14. 本政策的变更

当应用功能发生变化时,我们可能会更新本政策。更新后的版本会发布在本页面,并同步更新顶部的「生效日期」。如果变更涉及信息处理方式的实质性调整,我们会在应用内以显著方式提示。建议你定期查看本页面。继续使用本应用即表示你接受更新后的政策。

15. 联系我们

如果你对本隐私政策或本应用的隐私实践有任何疑问、意见或投诉,请通过以下方式联系我们,我们会在 30 天内回复: