Privacy
Privacy information for the Codex Host beta.
Effective September 23, 2026.
Information Codex Host collects
Account and operations data can include your GitHub identity and account email, authentication/session metadata, Stripe customer/subscription identifiers and billing status, selected plan, provider machine identifiers, resource limits, machine and setup state, lifecycle events, capacity records, and support messages you submit.
Session and support records may include technical metadata such as IP address or browser/user-agent information when supplied by the authentication or web stack.
Product analytics
Codex Host uses PostHog for limited product analytics around acquisition and onboarding: an analytics identifier, page/funnel events, first-touch UTM and referrer context, authenticated user ID after sign-in, setup success/failure state, provisioning timing, and return-use signals. Session replay and DOM autocapture are disabled.
Browser analytics only initialize on the canonical production hostname. Synthetic test users are excluded from server analytics, and developer/admin users are marked so they can be excluded from product-funnel reporting.
Information the analytics layer does not intentionally collect
It does not intentionally collect repository contents, source code, prompts, ChatGPT conversations, OpenAI or GitHub passwords, development OAuth tokens, Codex credentials, device authorization codes, Remote pairing codes, provider API keys, full referrer URLs, or payment-card details.
Development credentials and repositories
Credentials used by Codex and GitHub inside your hosted development machine are intended to stay in that machine rather than the central D1 database. Repository files also live in the hosted environment. The operator and infrastructure provider may nevertheless be technically capable of accessing a managed machine; see the security page for that boundary.
Security modelHow information is used
Information is used to authenticate accounts, bill subscriptions, provision and manage machines, enforce capacity and abuse limits, operate support, debug failures, measure whether onboarding works, prevent duplicate/free-trial abuse, and maintain the reliability and security of the service.
Codex Host does not sell personal information or customer source code.
Service providers
The current service relies on third parties including Cloudflare for the web/control plane, Stripe for billing, Agent37 for hosted compute, GitHub for account identity and repository access, OpenAI for Codex/ChatGPT authentication and usage, and PostHog for product analytics. Those services process data under their own terms and privacy policies.
Local browser storage
The service uses normal authentication/session mechanisms and a small local-storage record for the random analytics identifier, first-touch attribution, and temporary sign-in funnel state.
Retention and deletion
Provider machines are intended to be deleted when compute entitlement ends. The beta does not currently promise a fixed automatic retention period for control-plane account, billing, support, analytics, or lifecycle records. Those records may be kept as needed for service operation, billing history, security, debugging, and abuse prevention.
If you want to request deletion of account-related control-plane data, contact support. Some records may need to be retained where required for billing, security, fraud prevention, or legal obligations.
Questions
Use the signed-in support form for privacy questions. Do not put live credentials or secrets in support messages.
Feedback / support