Privacy

What is stored, and what is public

There are no accounts here. What the site holds is what sharers send it, and most of that is public by design.

What a share stores

  • Your handle.
  • Per day: responses, recorded input, cached input, output and reasoning tokens, and sessions started.
  • Per month, the longest and the biggest session: start and end time, active time, token counts, model name, and the first 12 characters of the plugin's one-way hash of the session id. The other session summaries a share carries are not kept.
  • The weekly limit windows from your last share: when each started, the plan type, the first and highest percentage of the limit Codex reported, and the tokens and responses counted in it. From them, your own estimate for each plan.
  • The name and version of the client that shared, when you first and last shared, and how many times.
  • Your report page, the HTML the plugin rendered, unless you shared with --no-report or took it down.
  • A hash of your share token. The token itself is never stored, and without it no one, the site included, can update or delete your share through the API.

To cap sign-ups per address, and shares and report uploads per sharer, the server counts requests in fixed one-hour windows. Each counter is filed under a salted hash of the address a first share came from, or of the sharer's id, never the address itself. Every counter carries an expiry time, and a database policy sweeps expired ones away.

What is public

  • On your profile, /u/<handle>, and the leaderboards: your handle, your counts by day and month, totals, ranks, the longest and biggest sessions (with the shortened hash), the plugin version, and when you first and last shared.
  • Your report page, /r/<handle>, to anyone with the link, exactly as the plugin rendered it. Asked to share, the plugin first does a dry run that writes it to your machine, so you can open it before it goes up.
  • Plan estimates only across sharers. Your weekly windows and your own estimate are never shown on their own or beside your handle. The plans page publishes each plan's median and range, rounded to two significant figures, and only once enough sharers are on it. A median or a range end can be one sharer's estimate, rounded, but never with a name on it.

Profiles and report pages ask search engines not to index them. Anyone can still read them, and anyone can read what the site's API returns.

What is not collected

The site sets no cookies, runs no analytics and loads nothing from other sites. Report pages run in a sandbox: they share no cookies or storage with the site, and can load or send nothing. The plugin never sends prompts, outputs, file contents, paths, session titles or your account; How the numbers work lists what it does send.

The site runs on Google Cloud (Firebase Hosting, Cloud Functions and Firestore), which keeps request logs for Hosting and Cloud Functions: the address a request came from, the path it asked for, the time and the browser's user agent.

Deleting and renaming

From the plugin's token-share directory:

cd ~/.codex/plugins/cache/jack-beanstalk-2022/token-counter/*/skills/token-share
python3 scripts/share.py --delete --yes          # delete everything, report page included
python3 scripts/share.py --delete-report --yes   # take down the report page, keep the numbers
python3 scripts/share.py --handle new-name --yes # rename; the old handle is released

Deleting removes your handle, every month, your windows and estimates, your report page and the hash of your token. The hourly rate-limit counters are left to expire on their own. Cached copies of your profile, the leaderboards and your report page can take a couple of minutes to clear. After a rename, anyone can claim the old handle.

Lost your token, or want something taken down that is not yours? Contact says how.