Privacy

What is stored, and what is public

There are no accounts here. What the site holds is what sharers send it, and most of that is public by design.

What a share stores

  • Your handle.
  • Per day: responses, recorded input, cached input, output and reasoning tokens, and sessions started.
  • Per month, the longest and the biggest session: start and end time, active time, token counts, model name, and the first 12 characters of the plugin's one-way hash of the session id. The other session summaries a share carries are not kept.
  • The weekly limit windows from your last share: when each started, the plan type, the first and highest percentage of the limit Codex reported, and the tokens and responses counted in it. From them, your own estimate for each plan.
  • Your response times from your last share that carried them: the days they span, how many responses and turns were timed, their median and 90th percentile, and the same per model and reasoning effort, with the plugin's estimated output rate and time above its fastest pace; and the same medians by hour of the day and day of the week, in UTC. No tool names.
  • The name and version of the client that shared, when you first and last shared, and how many times.
  • Your report page, the HTML the plugin rendered, unless you shared with --no-report or took it down.
  • A hash of your share token. The token itself is never stored, and without it no one, the site included, can update or delete your share through the API.

To cap sign-ups per address, and shares and report uploads per sharer, the server counts requests in fixed one-hour windows. Each counter is filed under a salted hash of the address a first share came from, or of the sharer's id, never the address itself. Every counter carries an expiry time, and a database policy sweeps expired ones away.

What is public

  • On your profile, /u/<handle>, and the leaderboards: your handle, your counts by day and month, totals, ranks, the longest and biggest sessions (with the shortened hash), your response times, the plugin version, and when you first and last shared.
  • Your report page, /r/<handle>, to anyone with the link, exactly as the plugin rendered it. Asked to share, the plugin first does a dry run that writes it to your machine, so you can open it before it goes up.
  • Plan estimates only across sharers. Your weekly windows and your own estimate are never shown on their own or beside your handle. Nor are your response times by hour and day of the week: the plans page publishes each hour's and day's median across sharers, only once six of them have 20 or more responses in it, and never how many. Those medians can still shift when you share, which hints at the hours you were active, as the start and end times of your longest and biggest sessions on your profile already show. The plans page publishes each plan's median and range, rounded to two significant figures, and only once enough sharers are on it. A median or a range end can be one sharer's estimate, rounded, but never with a name on it.

Profiles and report pages ask search engines not to index them. Anyone can still read them, and anyone can read what the site's API returns.

What is not collected

The site sets no cookies, runs no analytics and loads nothing from other sites. Report pages run in a sandbox: they share no cookies or storage with the site, and can load or send nothing. The plugin never sends prompts, outputs, file contents, paths, session titles or your account; How the numbers work lists what it does send.

The site runs on Google Cloud (Firebase Hosting, Cloud Functions and Firestore), which keeps request logs for Hosting and Cloud Functions: the address a request came from, the path it asked for, the time and the browser's user agent.

Deleting and renaming

From the plugin's token-share directory:

cd ~/.codex/plugins/cache/jack-beanstalk-2022/token-counter/*/skills/token-share
python3 scripts/share.py --delete --yes          # delete everything, report page included
python3 scripts/share.py --delete-report --yes   # take down the report page, keep the numbers
python3 scripts/share.py --handle new-name --yes # rename; the old handle is released

Deleting removes your handle, every month, your windows and estimates, your response times, your report page and the hash of your token. The hourly rate-limit counters are left to expire on their own. Cached copies of your profile, the leaderboards and your report page can take a couple of minutes to clear. After a rename, anyone can claim the old handle.

Lost your token, or want something taken down that is not yours? Contact says how.