CODEX · Terms of Use · Privacy Policy
CODEX Privacy Policy
Effective October 7, 2026. Published by Danny Santiago.
- CODEX runs on your own hardware. What's in your console stays there, and we can't see it.
- CODEX doesn't send analytics, telemetry or usage data to us.
- We collect only what you send us: a beta request, a live chat, or a support request.
- We never sell your information or use it for advertising.
1. Who we are and what this covers
CODEX is published by Danny Santiago ("we", "us"). This policy covers the CODEX pages on this website, requests for beta access, support, and the CODEX software itself. The Terms of Use also apply.
2. Data inside your CODEX console
CODEX is installed on-site, on a server you own or control. Each console is standalone. Its accounts, passkeys, chats, documents, records, recordings, logs and settings are stored on that server and on the storage you connect to it.
- We don't receive it. CODEX doesn't phone home. It sends no analytics, telemetry, crash reports or usage data to us, and we have no remote access to your console.
- You're in control. The organization that runs a console decides who has accounts, what they can reach, and how long data is kept. If you use a console someone else runs, contact them about your data.
- If this changes, it'll be your choice. Central management for customer consoles is planned. If we add any feature that sends information from your console to us, it will be off until you turn it on, and we'll describe it here before it ships.
3. Services your console connects to
Some features send data from your console straight to other services, using the accounts and keys your console is set up with:
- Cloud AI (Anthropic Claude): only for chats and bots that use a Claude model. Local models run on your own hardware, and the "Local only" setting keeps an assistant on local models entirely.
- Accounts you connect, such as Google or Gmail, Synology or Home Assistant: only when someone with the right role sets up the connection.
- Public sources: public-records searches, RSS feeds and web research contact the sites being searched.
- Updates and apps: downloading an update, app or AI model connects to the place it's published. Like any download, that reveals your network address.
Those providers handle that data under their own terms and privacy policies. We don't receive it.
4. Privacy features in CODEX
CODEX includes tools that help you protect the people who use your console:
- Voice is transcribed and spoken on your server, with local Whisper and Piper.
- Face recognition in the Rudi voice assistant can be switched off completely.
- AI reads records with the asking person's own permissions, and protected personal fields such as HR and bank details are masked from it.
- People see only their own chats. Access & Audit records who can reach what, and when.
- Notifications are off by default. Network and NAS tools are read-only unless an admin allows changes.
These features support your own obligations, such as notices to employees or visitors and consent for cameras or recordings. They don't replace them.
5. What we collect from you
Beta requests and messages
When you use the Contact us form, we receive what you enter: your name, email address, phone number, company, subject and message. It's delivered to us as email and stored in this website's system, which runs on our own server.
Live chat
If you use the chat on this website, we keep the conversation and basic details about your visit, such as the page you were on. An AI assistant may answer chats. When it does, your messages are processed by Anthropic's Claude to write the reply, under terms that don't let Anthropic use them to train its models. Please don't share sensitive personal information in chat.
Support
If you ask for help, you may choose to send us logs, screenshots, configuration details or files from your console. We use them only to fix your problem, and we delete them when they're no longer needed for that.
Website basics
Like most websites, our server records technical details for each request, such as your IP address, browser type, the pages you visit and the time. We use these records for security and to keep the site working. The website uses cookies only to run the site, for example to keep you signed in, remember your language and keep a chat open. We don't use analytics or advertising cookies, and we don't track you across other websites.
6. How we use it
- To review beta requests, invite participants and set up their access.
- To answer your questions and provide support.
- To tell beta participants about updates, security fixes and changes to these policies.
- To send newsletters, only if you sign up for them. You can unsubscribe at any time.
- To protect the website and CODEX from abuse, and to meet legal requirements.
7. Sharing
We don't sell or rent your personal information, and we don't share it for advertising. We share it only:
- With services that help us run the website and answer you, such as email delivery and the AI provider behind live chat. They may use it only for that work.
- When the law requires it, or to protect the rights, property or safety of people or of the service.
- With a company that takes over CODEX, for example one we form to run it. That company will remain bound by this policy for information it receives under it.
8. How long we keep it
We keep beta requests, messages and support records only as long as we need them for the purposes above. That's usually while you take part in the beta, plus a reasonable time afterward for our records. Server logs are kept for a limited time for security. When we no longer need information, we delete it.
9. Security
This website and the systems behind it run on our own hardware, behind HTTPS. Access is limited to the people who need it and protected by strong sign-in. No system is perfectly secure. If a breach affects your personal information, we'll let you know as the law requires.
10. Your choices and rights
You can ask us to show you, correct or delete the personal information we hold about you, or to stop sending you messages. Depending on where you live, laws such as the California Consumer Privacy Act may give you more rights. We'll honor them and won't treat you differently for using them. We don't sell or "share" personal information as those laws define it, and we don't track you across sites, so there's nothing to opt out of. To make a request, use the Contact us form. We'll answer within 30 days.
For data inside a CODEX console, contact the organization that runs it. We don't hold that data.
11. Children
The CODEX website and beta are meant for administrators, businesses and government entities. They aren't directed to children under 13, and we don't knowingly collect information from them. If you believe a child has sent us information, contact us and we'll delete it. Inside a console, accounts for minors are the responsibility of the organization or parent who creates them.
12. Where data is kept
We're based in the United States, and this website and our systems are located there. If you contact us from another country, your information is processed in the United States.
13. Changes and contact
If we change this policy, we'll update the effective date above. We'll let beta participants know about significant changes before they take effect. Questions or requests: use the Contact us form.