Legal

Privacy Policy

Effective: October 2026 · Codex Labs

What we collect

  • ›Account data — name, email, hashed password, organization membership.
  • ›Billing data — subscription state, invoices, and usage totals. Card details are handled entirely by our payment provider and never touch our servers.
  • ›Usage measurements — token counts, model names, request timing, tool-call counts, and installation identity for metering and diagnostics.
  • ›Support data — tickets, messages, and attachments you submit to the help desk.

What we never collect

  • ›The contents of your source code or prompts — usage records carry measurements only.
  • ›Raw hardware fingerprints — installations are identified by revocable random identities.
  • ›Your password in any recoverable form — stored only as a bcrypt hash.

How we use it

  • ›Operating subscriptions, entitlements, metering, and billing.
  • ›Providing support and investigating reported issues.
  • ›Security: rate limiting, abuse detection, and audit logging.
  • ›Aggregate, de-identified analytics to improve the platform.

Sharing

We share data with payment processing and transactional email providers only as required to operate the service, and with authorities only where legally compelled. We do not sell personal data.

Retention & your controls

Usage and billing records are retained as required for accounting; support tickets for the life of your account unless you ask us to delete them. You can revoke installations, rotate API keys, and delete your account from the dashboard. Deletion requests propagate to backups within 90 days.

Security

Data is encrypted in transit; sessions and tokens are stored hashed; tenant isolation is enforced at the query layer and covered by tests. See /security for the full posture.

Privacy questions: open a ticket marked “security” from your dashboard.