Privacy

Your prompts, replies and files never leave your Mac. Quail has no account, no analytics and no telemetry.

What goes over the network

Quail connects to three places, and only for these reasons:

Hugging FaceWhen you browse, check or download models: the model listings, the start of each file (its header) for the fit verdict, and the downloads themselves. Your Hugging Face token is sent only if you added one.
GitHub (raw.githubusercontent.com)Once a week: the latest model catalog, two small JSON files from this project's repository.
GitHub ReleasesThe update check: daily unless you change it in General → Updates, or never. It downloads a small list of versions; the request says which version of Quail is asking, and nothing else about your Mac.

Like any web request, these reveal your IP address to the site. Nothing else is sent: no prompts, no model names you use, no usage.

Once your models are downloaded, Quail works with no connection at all — serving, chatting, benchmarking and quail launch. The project checks this with a test that runs the app and its servers with the network blocked.

The server

The model server runs on your Mac. It answers only this Mac unless you make it reachable from your network, and requires an API key from the start; Quail server, the default runtime, also refuses requests from other web pages. See Network and API key.

What Quail stores, and where

Settings~/Library/Application Support/Quail/config.json
API key, Hugging Face tokenYour Keychain
Models~/Library/Application Support/Quail/Models, or the folder you moved them to
Benchmark results~/Library/Application Support/Quail/benchmarks.json
Logs~/Library/Logs/Quail