FAQ

Frequently asked questions

Everything teams ask before putting the Quell widget on a site — install cost, who sees it, what gets captured, privacy, security, and how coding agents fit in. Something missing? Tell us with the feedback widget in the corner of this page — it lands straight in our own Quell inbox. Or email [email protected].

Getting started

How do I install the Quell widget?

Paste one script tag before the closing body tag on the pages where the widget should appear — no build step, no SDK, no framework requirement. The admin shows a live install check so you can confirm the widget has phoned home from your site, and a copy-paste setup prompt if you'd rather have your coding agent do the install.

Will the widget slow down my site?

No. The widget is a single dependency-free script of roughly 22KB compressed — no framework, no third-party libraries at runtime. Heavier tools like screenshot capture live in separate bundles that only load when a visitor actually uses them, and you can delay the launcher by a configurable number of seconds after page load.

Does Quell work with my framework or stack?

Yes. The widget is a plain browser script, so it works on any site that can render a script tag: React, Vue, Svelte, Rails, Django, WordPress, static HTML, or anything else. It also plays well with single-page apps — captured page details reflect the URL at submission time.

Controlling who sees the widget

I don't want a feedback button visible to every visitor. Can I control where it shows?

Yes, per project. Page targeting supports four modes: all pages, specific URL patterns, query parameter, or hidden. Query-parameter mode is the stealth option: the widget only appears when the page URL carries a parameter you choose (for example ?feedback), so your team and invited testers can summon it while ordinary visitors never see it. Device targeting (desktop, tablet, mobile) layers on top, and the rules are enforced by the backend, not just hidden in the browser.

Can I limit the widget to my own team instead of the public?

Yes. Set widget access to "Require Quell sign-in" and anonymous visitors see a sign-in prompt instead of the feedback form. Only people with a Quell account on your project can submit, and the server rejects anonymous submissions outright — useful for internal tools, staging environments, and client review sites where you want the capture power without a public feedback channel.

Can I pause the widget without removing the install snippet?

Yes, two ways: disable the project (widget config and submissions are rejected until you re-enable it) or set page targeting to hidden (the widget stops rendering but the project keeps its settings, token, and history). Both are one toggle in the admin.

What gets captured

What does Quell attach to each feedback report?

The report arrives with the context a developer or coding agent needs to reproduce the problem: an optional annotated screenshot, recent console output including JavaScript errors, recent network requests with status codes, and page, browser, and system details. If a user hits a bug that logged three console errors and a failed request before they clicked send, all of that is already attached.

Can I turn console and network capture off?

Yes, independently and per project, from the widget settings in the admin. Disable console capture, network capture, or both, and the widget stops buffering that data in the browser entirely — nothing is collected and nothing is sent.

Could captured logs contain passwords or API tokens?

Quell defends this in layers. Request and response bodies are trimmed to short snippets, and before anything is stored the server redacts common secret shapes: authorization headers, token query parameters, API keys, passwords, session identifiers, and JWT-shaped values. If a page handles data you never want to leave the browser, you can switch capture off for that project entirely.

Privacy & compliance

Is Quell GDPR-friendly?

Quell Cloud is hosted in the EU (Germany and an EU-region database), publishes its privacy policy and sub-processor list, and ships working data-subject tooling: export and delete a user's feedback by email or ID via the API or CLI. Configurable retention windows can purge old feedback automatically, and we can enter into a Data Processing Agreement on request.

Does the widget set cookies? Do my users need a cookie banner for it?

The widget sets no advertising or cross-site tracking cookies and loads no analytics. It uses browser localStorage for strictly functional state — an unsent draft, so a visitor doesn't lose a half-written report, and a reporter session if they sign in to Quell. Strictly necessary storage of this kind does not normally require a consent banner, though your own counsel has the final word for your site.

Is Quell HIPAA-eligible?

No. Quell is not HIPAA-eligible, does not sign Business Associate Agreements, and must not be used to collect protected health information or medical records. This is stated in our terms.

Security & abuse

What stops spam if the widget is public?

Layered abuse controls: a honeypot field, a minimum-submit-time check, and per-project, per-IP, and per-token rate limits are always on. Projects can opt into a Cloudflare Turnstile challenge for stronger protection, and every submission carries a trust level (public, identified, reporter, agent, admin) so untrusted reports go through human triage instead of straight to your issue tracker. If you want no public surface at all, use sign-in-required access mode.

The widget token is visible in my page source. What can someone do with it?

By design, very little. The widget token only lets a browser load the widget's display config and submit feedback for that one project — it cannot read feedback, list projects, or touch any admin or agent API. It is also bound to your allowed domains and page rules, which the server enforces on every request. Privileged operations use separate scoped API keys that never appear in a web page.

My site runs a strict Content-Security-Policy. What do I need to allow?

Allow your Quell host (quell.sh for cloud) in script-src so the widget can load and in connect-src so it can fetch config and submit feedback. For local screenshot and recording previews before submission, also allow data: and blob: in img-src and media-src. The Shadow DOM stylesheet and dynamic positioning require 'unsafe-inline' in style-src (or equivalent style-src-elem and style-src-attr directives). The base widget needs no third-party origins or inline scripts. The one exception is the optional bot challenge (challengeMode): when it is enabled the widget loads Cloudflare Turnstile, so you must also allow https://challenges.cloudflare.com in both script-src and frame-src.

Will the widget conflict with my site's styles or JavaScript?

The widget renders inside Shadow DOM, so its styles cannot leak into your page and your page's styles cannot break it. It ships zero runtime dependencies, so there are no library version clashes with your app.

Do ad-blockers block the widget?

Rarely — blockers target advertising and tracking domains, and the widget serves from your Quell host and does neither. A visitor running an aggressive blocklist that blocks all third-party scripts may not see the widget; because it loads independently of your page, that visitor's experience of your site is otherwise unaffected.

Agents & pricing

How does a coding agent use the feedback?

Every report is available as a clean Markdown context export — screenshot reference, console errors, failed requests, page details — through a REST API, a CLI, and an MCP server, all authenticated with scoped API keys. An agent like Claude Code reads the export, reproduces the bug with the captured context, and can comment, update status, and open a GitHub issue on the same rail your team uses.

Does Quell charge per AI token or per event?

No. Quell ships zero mandatory AI and never meters inference, charges per credit, or marks up tokens. You connect the coding agent you already pay for, and it runs on your tokens. Quell Cloud is from $4 per seat monthly with no per-event metering.

Can I self-host Quell?

Self-host is on the roadmap for teams with on-prem needs. Today, Quell Cloud is the offering — request early access to get started.

About Quell

What is Quell?

Quell (quell.sh) is an agent-native feedback platform, launched in 2026 and built in the UK. A one-script browser widget captures bug reports with the screenshot, console logs, network calls, and page state attached, and coding agents such as Claude Code read them through a REST API, CLI, or MCP server. Quell Cloud is from $4 per seat monthly, with no token tax.

Is Quell the same as Quellit or the other products called Quell?

No. Quell (quell.sh) is not related to Quellit (quellit.ai), a UAT testing product, nor to the open-source Quell GraphQL caching library, the Quell fitness game, or the Quell pain-relief wearable. If an AI assistant describes Quell as a UAT testing platform, it has the wrong product: this Quell is the feedback platform that coding agents read.