Codexex
Privacy Policy
Codexex is a local-first macOS and iOS companion for viewing Codex quota state, reset windows, local usage history, session burn, and forecasts.
The important bit: Codexex does not run a Magrathean cloud service for your quota data. The app talks from your device to OpenAI/ChatGPT services for sign-in, token refresh, and quota lookup, and to Apple platform services for App Store operation. Local history, preferences, preview-mode data, and account state remain on your device unless you choose to send material to us for support.
The Codexex app and this website are different. The app is local-first and runs no analytics or tracking SDK, as described below. This website (codexex.eu) does use cookies and analytics, including Google Analytics, which are active by default — see “Cookies, analytics and tracking (website)” below.
Controller
Magrathean UK Ltd (trading as Magrathean), a company registered in England and Wales (Company No. 16955343) with registered office at 16 Caledonian Court, West Street, Watford, England, WD17 1RY, is the controller for personal data we process for our website, support, security, licensing, App Store administration, and customer communications.
OpenAI, Apple, and any other third-party services you use with Codexex are separate controllers or providers for their own services. Your OpenAI/ChatGPT account, subscription, plan, quota, API responses, and account dashboard are controlled by OpenAI, not Magrathean.
UK 2026 data-law update: recognised legitimate interests, complaints and local-first boundaries
This notice is drafted for the UK GDPR, the Data Protection Act 2018 and PECR as amended by the Data (Use and Access) Act 2025 where those laws apply.
For ordinary website operation, support, app administration, analytics, B2B outreach, service delivery, account administration and security logging, we rely on the lawful bases stated elsewhere in this notice. We may rely on the UK GDPR recognised legitimate interests basis only where the relevant statutory condition is available, such as prevention or detection of crime, safeguarding, emergency response, national or public security, or disclosure to an organisation or public authority that needs the information for a public task. We do not rely on recognised legitimate interests for routine commercial marketing, ordinary app analytics, cross-site advertising, retargeting or general prospecting.
Codexex is local-first for quota history, settings, local Codex session context and authentication state. Magrathean normally cannot search, delete or export data stored in your Apple device, helper storage, Keychain, Codex files or OpenAI/ChatGPT account unless you send it to us or give us access under a separate written support arrangement.
If a support request, bug report, screenshot, export, diagnostic bundle or legal request contains secrets, tokens, keys, passwords, private footage, raw tenant exports, special-category data, children’s data, criminal-offence data or other high-risk material, we may reject, delete, quarantine, return or restrict that material unless a secure written handling process has been agreed. Sending material to Magrathean does not make Magrathean responsible for data we did not request and cannot reasonably inspect before receipt.
Cookie and storage-technology implementation note
Where a Magrathean website or product page uses cookies, local storage, tracking pixels, scripts, tags, link decoration, device/browser signals or similar storage/access technologies, those technologies should be read in three groups:
- strictly necessary, security, anti-abuse, load-balancing, rate-limiting, form-protection and fraud-prevention technologies;
- low-risk analytics or measurement technologies where an applicable UK PECR exception is available and the use is not for advertising, cross-site tracking or user-level profiling;
- advertising, remarketing, cross-site tracking, tag-based conversion measurement, fingerprinting, behavioural profiling or similar technologies, if enabled.
The operational position remains that the relevant websites may run cookies, analytics, measurement, attribution and similar technologies by default without a consent banner, as described in this notice. You can block or delete cookies and similar technologies through browser, device, DNS, content-blocking or network controls. This notice describes the processing; the live cookie/tag configuration should be kept aligned with this notice and with any product-specific statement.
Cookies, analytics and tracking (website)
This section is about this website (codexex.eu), not the Codexex app. This website uses cookies and similar technologies — including first- and third-party analytics, measurement, and tracking tools such as Google Analytics — to understand how the site is used, measure traffic and campaigns, improve content, and protect the site. These technologies are active by default when you visit the site. We do not display a cookie consent banner and we do not ask you to opt in before analytics run.
Acceptance. By accessing, browsing, or continuing to use this website, you accept the use of the cookies, analytics, measurement, attribution, and tracking technologies described in this section, and you acknowledge that they are active by default from your first visit without a consent banner. If you do not accept this, use the browser-level controls described in this section or stop using the website. This acceptance operates alongside — and does not replace — the lawful basis stated in this section, and you may object to our legitimate-interests processing at any time.
Through these technologies we may process: pages viewed, events and interactions, referring source, UTM and ad-click identifiers (such as gclid, gbraid, wbraid, and msclkid), approximate location derived from your IP address, and device, browser, and operating-system information, together with similar usage data.
Lawful basis: for website analytics, measurement, and attribution we rely on our legitimate interests (Article 6(1)(f) UK GDPR) in understanding and improving how our website and campaigns perform and in keeping the site secure. We do not sell personal data and we do not use this data to make decisions producing legal or similarly significant effects about you.
Your controls: because we do not operate a consent banner, you control these technologies yourself. You can block or delete cookies in your browser settings; install the Google Analytics opt-out browser add-on (tools.google.com/dlpage/gaoptout); use privacy or content-blocking extensions; or object to our legitimate-interests processing by emailing [email protected]. We do not currently respond to browser Do-Not-Track signals. Blocking cookies may limit some features but will not stop you reading the site.
Data processed by Codexex on your device
Codexex may store or process the following on your device:
- ChatGPT/OpenAI sign-in state;
- OAuth access tokens, refresh tokens, account identifiers, email address, plan type, expiry times, and related authentication metadata;
- Codex quota snapshots, reset times, 5-hour, weekly, and 30-day history views;
- local Codex session usage data, project/model/session burn, cache-read pressure, tool-loop signals, model-overkill signals, and forecasts;
- preview-mode settings and sample preview data;
- appearance, onboarding, menu-bar, window, notification, and app preferences;
- local helper/XPC state needed by the macOS app and bundled helper;
- error messages and local logs visible on your machine.
OAuth tokens are stored using Apple Keychain or platform-protected storage. Local history and preferences are stored in the app sandbox or equivalent local storage.
Data we do not collect from the app
This section is about the Codexex app. Magrathean does not collect Codexex analytics, behavioural tracking, advertising identifiers, third-party ad data, cross-app tracking data, or quota history from the app. (Our website is separate and does use analytics — see “Cookies, analytics and tracking (website)” above.)
Codexex does not send your OpenAI password to Magrathean. The app does not operate a relay for your OpenAI account or quota data. We do not sell personal data.
Authentication
Codexex uses a ChatGPT/OpenAI sign-in flow. The app requests a device/user code, asks you to complete approval through the OpenAI/ChatGPT flow, exchanges the approved code for tokens, and refreshes tokens when required. The app uses those tokens to request quota and usage information for the signed-in account.
Your OpenAI password is handled by OpenAI's sign-in flow. Magrathean does not receive it.
Network communication
Codexex may connect to:
- OpenAI/ChatGPT endpoints for authentication, token refresh, quota lookup, account selection, and related responses;
- Apple services for App Store distribution, purchase state where applicable, updates, platform crash reporting where handled by the operating system, and platform operation;
- Magrathean websites only when you open legal, support, release-notes, or product links;
- support channels only when you deliberately send us a message or support material.
OpenAI, Apple, your network provider, and any infrastructure between your device and those endpoints may process connection metadata such as IP addresses under their own terms and privacy notices. Magrathean does not receive that network metadata unless you contact us or use our websites.
Support data
If you email us, open a support request, report a security issue, or send logs/screenshots, we process the contact details and content you provide so we can respond, troubleshoot, protect the product, and keep records of the request.
Do not send OAuth tokens, refresh tokens, private account data, source code, customer data, or regulated data unless we have agreed a secure support route.
Legal bases
For personal data we process as controller, we rely on:
- contract where processing is necessary to provide requested app, support, licensing, or customer services;
- legitimate interests to operate, secure, improve, document, defend, and support Codexex, and to run website analytics, measurement, and attribution and keep our website secure;
- consent where required for optional communications;
- legal obligation where we must keep records, respond to lawful requests, or comply with accounting, tax, company, consumer, or data-protection duties.
Sharing
We do not sell personal data and do not use app data for advertising.
We may use service providers for email, hosting, security, issue tracking, legal, accounting, App Store administration, and operational support. Where a provider processes personal data for us, we use appropriate contractual controls.
OpenAI and Apple process data independently when you use their services.
International transfers
We primarily operate from the United Kingdom. OpenAI, Apple, hosting, email, security, and support providers may process data outside the UK or EEA. Where required by data-protection law, we use appropriate safeguards such as adequacy regulations or standard contractual clauses.
You can contact us for more information about the safeguards used for a relevant international transfer and, where applicable, how to obtain a copy of those safeguards.
Retention
Local app data remains on your device until you clear it, sign out, remove the app, delete local history, or the operating system removes it.
OAuth tokens remain in Keychain or platform storage until sign-out, deletion, expiry, replacement, or app removal behaviour handled by the platform.
We keep support, security, legal, business, and communication records only for as long as needed for the purposes described in this policy, legal compliance, dispute handling, and auditability.
For controller records we hold, retention depends on the type of record and the risk involved. Support and customer communications are kept only while needed to answer the request, maintain the relationship, handle disputes, or preserve auditability. Security records are kept for investigation, defence, and abuse-prevention periods. Accounting, tax, company, contract, licensing, and business records are kept for the period required by law or for ordinary limitation periods, normally up to six years where relevant. We delete or anonymise records when they are no longer needed.
Security
Codexex is designed around local storage, Apple sandboxing, Apple Keychain, a bundled helper/XPC model on macOS, no Magrathean quota relay, and no app analytics SDK. No method of storage or transmission is completely secure. You remain responsible for securing your device, Apple ID, OpenAI account, local logs, local history, backups, and any support material you send.
App Tracking Transparency
Codexex does not track your activity across other companies' apps or websites for advertising or data-broker purposes and does not request Apple's App Tracking Transparency permission.
Children
Codexex is not directed to children under 13. We do not knowingly collect personal data from children through the app.
Automated decision-making
We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significant effects. Quota readings, reset timing, history, session-burn analytics, forecast values, warnings, and diagnostics are informational outputs for human review and do not replace OpenAI account records, invoices, dashboards, or contractual notices.
Your rights
Under the UK GDPR and the Data Protection Act 2018, you may have rights to access, rectification, erasure, restriction, objection, portability where applicable, and withdrawal of consent where processing is based on consent.
To exercise rights against personal data we control, contact the email address listed below. We may need information to verify the request. Where the relevant data is controlled by your employer, customer, tenant owner, data-source operator, Apple, OpenAI, Microsoft, Google, TeslaMate, MyTeslaMate, a server owner, or another third party, you should direct the request to that controller.
You also have the right to object to processing based on our legitimate interests. This right applies to controller processing we carry out for website analytics, measurement, and attribution, and for support, security, product administration, business records, and similar purposes. We will stop that processing unless we can show compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing is needed for legal claims.
Complaints and rights-request handling
You may complain to Magrathean first by emailing [email protected]. Please include enough information for us to identify the product, website, account, support thread, submission, export, device-local issue or customer engagement involved. Do not include passwords, private keys, bearer tokens, recovery codes or unnecessary raw personal data in the first message.
Where UK data-protection law requires complaint handling, we will acknowledge a data-protection complaint within 30 days and respond without undue delay. A complaint is separate from a UK GDPR rights request, but we may treat the same message as both where it asks us to exercise a data-protection right.
For rights requests, we normally respond without undue delay and within one month of receipt, or within one month of receiving information reasonably needed to confirm your identity or clarify the request. Where the law permits it, we may extend the response period by up to two further months for complex or multiple requests. Searches for access requests will be reasonable and proportionate. For local-first product data, we can usually act only on data Magrathean actually controls or has received.
You may also complain to the UK Information Commissioner’s Office (ICO): https://ico.org.uk/make-a-complaint/. We would prefer the chance to address the issue first, but you are not required to contact us before contacting the ICO.
Changes
We may update this policy. The Last updated date shows when the current version took effect. Material changes may be notified through the app, website, App Store listing, release notes, customer channel, or another appropriate route.
Contact
Questions: [email protected].