Consent is enforced by the server, not by policy
Plenty of vendors describe themselves as transparent and then ship a setting that makes the agent invisible. Quillclock cannot be configured that way. The admin sends a monitoring invite; the employee must accept it inside the desktop app; and until they do, the ingest endpoint rejects every sample the agent sends.
Revocation works the same way. When consent is withdrawn, collection stops immediately at the server — not at the next agent restart, not after a sync.
Exactly what is captured — and what never is
Captured: counts of keystrokes and mouse events per minute, active seconds, the foreground application name and window title, and — only if you switch it on for that person — periodic screenshots.
Never captured: the content of what is typed, message text, file contents, passwords, or anything from a personal device. Counting keystrokes to estimate activity is not the same as recording them, and Quillclock only does the former.
Screenshots that come with limits your team can verify
Screenshots are off by default and enabled per employee, not org-wide. When they are on, the employee's own app shows a badge, the images auto-delete after seven days, and the employee sees exactly the same captures in their portal. There is no long-term archive quietly accumulating in the background.
Is employee monitoring legal?
In most jurisdictions, monitoring company-owned devices during working hours is lawful when it is disclosed. Disclosure is the part organisations get wrong, and it is the part regulators act on — European data protection authorities have issued substantial fines for monitoring that was excessive or inadequately communicated.
Quillclock is structured so disclosure is not something you have to remember to do: consent is a precondition of collection. Read the full data flow before you deploy, and check the rules that apply where your staff are located. This is not legal advice.