Privacy Policy
How Codex Skin handles local images, submissions, waitlist details, analytics, and cookies.
Last updated: 2026-07-18
Scope
This Privacy Policy applies to the public Codex Skin website at codex-skin.app, including the theme catalog, local Builder, waitlist, and community submission form.
Codex Skin is an independent project and is not affiliated with or endorsed by OpenAI.
Builder images and Theme Recipes
Images selected in the Builder are processed locally by your browser for preview. The current Builder does not upload those images to Codex Skin.
When you export a Theme Recipe, the JSON file is created in your browser. It contains the selected image's file name, media type, file size, dimensions, and the visual settings you chose. It does not contain the image itself and is not automatically sent to Codex Skin.
If this processing model changes, this policy and the Builder disclosure must be updated before the change is released.
Information you choose to submit
The public site currently accepts two kinds of form submissions:
- Builder waitlist: email address, selected preference, consent version, and submission time.
- Community theme submission: name or handle, email address, theme name, source URL, claimed platforms, installation method, preview/source notes, attribution notes, review status, and submission time.
We use this information to manage the waitlist, review catalog submissions, prevent abuse, and communicate about the submission when necessary. Submitting a theme does not guarantee publication.
Do not submit passwords, private keys, payment details, confidential files, or personal information that is not needed for review.
Technical and usage information
Like most websites, the hosting and security infrastructure may process request information such as IP address, browser details, requested URL, timestamps, and error or security logs. This information is used to deliver the site, diagnose failures, enforce rate limits, and protect the service.
If the site is configured to use Google Analytics or Plausible, those services may receive usage information as described by their own policies. The site may also store a first-party utm_source cookie for up to 30 days when you arrive through a URL containing that campaign parameter. This cookie is used for referral attribution.
Analytics and support integrations are configuration-dependent. This policy does not mean every listed integration is active at all times.
Cookies and local storage
The public Codex Skin experience may use:
- browser local storage to remember the English/Chinese interface choice;
- a first-party
utm_sourcecookie for referral attribution; - cookies or storage required by any analytics or support service that is actually enabled.
The image chosen in the Builder is held through a temporary browser-local object URL and is not stored by Codex Skin.
You can remove cookies and local storage through your browser settings. Blocking optional storage may affect preference persistence or analytics but should not prevent local image preview.
Service providers and data sharing
Codex Skin does not sell personal information. Information may be processed by infrastructure providers needed to host the site, store form records, monitor reliability, prevent abuse, or provide analytics/support features when enabled.
We may also disclose information when reasonably necessary to comply with law, respond to a valid legal request, or protect users, the service, and third-party rights.
Theme source URLs, creator information, attribution, and related metadata may become public if a submission is approved for the catalog. Email addresses are not intended to be published as part of a theme listing unless the submitter separately asks for that disclosure.
Retention and security
Waitlist and submission records are retained only for as long as reasonably needed to operate the relevant list or review process, maintain an audit trail, resolve disputes, and protect against abuse. Hosting and security logs may be retained according to the applicable provider's operational settings.
We use reasonable technical and organizational safeguards, including HTTPS, access controls, input validation, and rate limiting. No Internet service can promise absolute security.
Your choices and requests
You may ask to access, correct, or delete personal information you submitted, subject to legal, security, and record-keeping requirements. Use a contact method currently published on the Codex Skin website and identify the email address used for the waitlist or submission so the request can be matched safely.
Children's privacy
Codex Skin is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes
We may update this policy when the product, data flows, or service providers change. The updated date above shows the latest published revision.
Important limitation
This page describes the current product implementation and is general information, not legal advice.