Privacy Policy
This policy explains what the Odex: Codex Coding Agent iOS companion app (“the app”) collects, how it is used, and your choices. The app is a companion client for a coding agent that runs on your own laptop. It is not a standalone service.
Who we are
The app is operated by the maintainer of the Odex project (“we” or “us”). For any privacy question, email support@codexing.com.
What the app collects
Odex minimizes data collection. The app stores session state on your device and transmits a small amount of information through the Odex relay service in order to connect you to your own laptop host.
| Category | What | Why |
|---|---|---|
| Email address | Collected when you sign in with a one-time code. | Authenticates your account with the Odex relay so your phone can reach your laptop. |
| Device push token | Apple-issued opaque identifier for this device. | Delivers run-completion notifications from your laptop to your phone. Not used for marketing. |
| Pairing identifiers | Opaque session and laptop identifiers exchanged when you scan the Trust Laptop QR code. | Routes messages between your phone and your trusted laptop. |
| Conversation content | Messages, follow-ups, and approvals you send to the agent; agent responses you receive. Any image you attach from Photos. | Relayed between your phone and your laptop so you can steer the coding agent remotely. The relay passes them through; your laptop and any model provider you configure see them. |
| Product analytics | Interaction events (screens viewed, actions taken), exceptions, and an opaque user identifier derived from your account. Captured via the PostHog iOS SDK and sent to PostHog’s US region (us.i.posthog.com). |
Helps us understand how the app is used and diagnose crashes. Not used for advertising. |
What the app does not do
- No advertising SDKs. No ad tracking. No ad IDs.
- No selling of personal data to data brokers.
- No location collection.
- No access to contacts, microphone, calendar, or health data.
- Camera access is used only to scan the Trust Laptop QR code. No images from the camera are stored or uploaded.
- Photo library access is used only when you explicitly pick an image to attach to a message.
Who receives your data
- Odex relay — our own Cloudflare-hosted service that authenticates you and forwards messages between your phone and your laptop.
- Your own laptop — the Odex daemon running on hardware you control.
- Model providers you configure — if you use Codex (OpenAI) or Anthropic as the underlying model, prompts and responses flow through those providers under their own privacy policies. We do not sit between you and them; your laptop makes those calls directly.
- PostHog Inc. — third-party product-analytics processor. Events and exceptions are sent to PostHog’s US region. No personally identifiable information (name, email, address) is intentionally included in event payloads; an opaque account identifier is used so we can correlate sessions for a single user. See posthog.com/privacy.
How long we keep data
The relay retains only what is needed to route active sessions and deliver queued notifications. Conversation history lives on your laptop, not on the relay. Push tokens are removed when you sign out or uninstall the app.
Your choices
- Sign out at any time from Settings in the app to revoke your device’s access.
- Uninstall the app to remove local state on your phone.
- Email support@codexing.com to request deletion of your account, relay-side data, and PostHog analytics data associated with your identifier.
Children
The app is not directed at children under 13, and we do not knowingly collect personal information from children.
Changes to this policy
If we make material changes, we will update the effective date above and, where appropriate, notify you in the app.