Account & privacy
Your data, your analytics, and how the beta works.
Your account#
The pill at the foot of the dashboard sidebar is your account: your initials, your name, and your email — or Email not verified if it still needs confirming. Its menu holds everything an account owns.
| Item | What it does |
|---|---|
| Verify your email | Appears only while the address is unconfirmed; sends the verification link again |
| Change your name | The name that appears on decks you present and share |
| Change email | Moves the account to a new address, which must then be verified |
| Change password | At least eight characters |
| Sign out | Ends the session on this device |
Editable account fields support ⏎ to save and Esc to cancel. Signing out ends the session, but is not a full erasure of browser data. Local document copies and preferences can remain on the device. On a shared device, finish syncing or export work you need, then use the browser's site-data controls to remove Quodra's local data before handing it over.
Cloud accounts and local accounts#
Settings → Profile & sign-in identifies the account type. The hosted beta uses cloud accounts; local accounts are supported in local configurations.
- A cloud account syncs your decks. They follow you to any device you sign in on, and cloud features — sharing, comments, feedback, MCP — are available.
- A local account stores its account and decks in this browser without cloud sync. Loading the application, fetching packages and using optional integrations can still make network requests.
- Signed-out visitors can use the public sample demo, whose temporary edits do not save to a personal library. The full hosted application requires sign-in and beta access.
Clearing your browser's site data removes a local account and the decks stored with it. If the work matters, sign in — or export it. Export JSON on a deck's menu writes a file you keep.
Your decks#
Everything you make with a cloud account autosaves to your device first and syncs from there, so the library never waits on the network. The save centre keeps a revision history you can restore from, and restoring adds a new revision rather than overwriting one — you never lose a version by looking at an older one.
Sharing and access#
- You own the decks you create; only the owner manages who else has access.
- Can edit opens the editor and its comments; Can view opens a read-only slide viewer, where Python does not run. The current deck viewer has no comment controls.
- Revoking someone removes them from both the document and any live session.
See Collaboration for the full model.
What Quodra collects#
Usage analytics, error diagnostics and operational logs have different purposes and controls.
Usage analytics — optional and off by default. Settings → Diagnostics & analytics carries the Usage analytics switch. Collection requires both your opt-in and analytics configured for the deployment. When active, PostHog receives a fixed list of events, such as project creation, saving, presentation starts and code-run failures, with identifiers, app version and environment. These events do not include deck content, code or titles. Automatic page capture and session recording are disabled. Turning the switch off stops collection and resets the client.
Error diagnostics — separate from the analytics switch. Sentry receives error reports only when configured for the deployment. Reports are filtered to redact sensitive fields and recognized tokens, email addresses and URLs; they may include an account id, error details, feature flags and technical context. Filtering reduces the data sent but is not a guarantee that arbitrary error text cannot contain sensitive information.
Operational logs support hosting, API reliability and security. They can contain request metadata and error information, independently of optional browser analytics. See the Privacy Policy and Subprocessors for the services involved.
Sending feedback#
Send feedback is in the dashboard sidebar and under File and Help in the editor. You choose a category — Something broke, Suggestion, or I'm stuck — a severity, a one-line summary, and a description. A screenshot of the current screen is attached unless you switch it off.
The report includes what you write, your account association, the release and commit, environment, current application route, an error correlation id when available, and a truncated browser string. An attached screenshot can contain visible slide content or other information on screen. Turn off Attach a screenshot of this screen before sending if you do not want that image included.
Your MCP token#
Settings → Model Context Protocol provides connection details where supported by your sign-in configuration. A session token lets an external AI tool act with your permissions. Treat it as a password and share it only with a client you trust. See AI assistants (MCP).
The beta#
Quodra is in active beta. Features and availability can change, and failures can occur. Export .quodra.json to keep the Quodra document, or use PDF and PowerPoint with the format limitations in mind. You can request account and data deletion at hello@quodra.app; the Privacy Policy explains retention and applicable exceptions. Your acceptance of the beta terms is recorded with its version against your account.
A few consequences worth knowing:
- Feature availability can vary by account and deployment. Canvas requires enablement; Matter Lab, Python and other studios can also be restricted during the beta.
- Invites to people who aren't in the beta yet are parked, and unlock when they join.
- An admin can pause an account. Your beta access is paused says so directly, and "Your decks and data are untouched — access can be restored at any time."
- Things change quickly; where a page describes account-specific behaviour, it says so.
Next#
- Introduction — back to the start.
- The dashboard — where accounts, settings, and decks meet.
- Your first deck — build something.