Privacy Policy

Last updated: September 2, 2026

1. Introduction

myCodex (“we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use the myCodex platform (“the Service”). By using the Service, you consent to the practices described in this policy.

2. Information We Collect

2.1 Account Information

  • Email address
  • Name and profile image (if provided, e.g. via Google sign-in)
  • Authentication provider information (Google, GitHub, or email magic link)
  • Whether you have consented to receive product-update emails

2.2 Content You Add to Projects

When you add material to a Project — uploaded files, YouTube transcripts, imported web pages, or pasted text (“Content”) — we store and process it to power AI search and chat within that Project.

2.3 Usage Data

  • Questions you ask and the AI answers you receive within Projects
  • Ratings or feedback you leave on answers
  • Features you use, credit/usage counts
  • Device type, browser, country-level location, and IP address (for security and rate limiting)

2.4 Payment Information

Payment processing is handled entirely by Stripe. We do not store card numbers or bank details. From Stripe we receive your customer ID, subscription status, and transaction history.

2.5 Patreon Data

If you connect a Patreon account — as a creator linking your campaign, or as a patron unlocking a creator's Project — we receive from Patreon, with your authorization: your Patreon user ID and email, and your membership status, pledge tier, and pledge amount for the relevant campaign. We use this only to verify and maintain your access, and we keep it in sync via Patreon's webhooks and a periodic check.

2.6 Chrome Extension Data (if used)

If you use the myCodex Chrome Extension, it reads the URL and title of pages you view while it is active to show context in its sidebar, keeps a short local history in your browser (never sent to us), and sends a page's content to our servers only when you choose to import it — handled the same as any other Content. It injects no ads, does not track browsing for analytics, and sends data to no third party beyond myCodex.

3. How We Use Your Information

  • Provide, maintain, and improve the Service
  • Process your Content (chunking, embedding, indexing) to enable AI search and chat
  • Store your chat history so you can return to it
  • Process payments and manage subscriptions and credits
  • Verify and maintain access to Patreon-gated Projects
  • Send account, billing, and content-processing emails (see §7)
  • Send product-update emails, only if you have opted in (see §7)
  • Produce aggregated, anonymized audience insights for the owners of Projects you use (see §5)
  • Enforce limits, prevent abuse, and comply with legal obligations

We do not use your Content, your questions, or your chat history to train AI models.

4. AI Providers

To generate embeddings and chat answers, the relevant Content chunks and your message are sent to the AI provider you have selected for that Project or message:

  • OpenAI (default) — embeddings and chat. Processed in the United States.
  • Anthropic (Claude) — chat, if selected. Processed in the United States.
  • xAI (Grok) — chat, if selected. Processed in the United States.
  • DeepSeek — chat, only if you explicitly select a DeepSeek model. DeepSeek processes requests on servers located in the People's Republic of China, and its own policies and applicable law apply to that processing. If you would prefer your data not be processed in China, do not select a DeepSeek model.

Each provider's API terms state that data sent through their API is not used to train their models. We pass through only what is needed to answer your question within your Project.

5. Creator Analytics — Aggregated and Anonymized Only

Owners of a Project (including Patreon creators) can see insights about what their audience is interested in, so they can plan new content. This is designed to protect the privacy of everyone who asks questions:

  • Owners see themes — grouped topics with counts — synthesized across their entire audience.
  • Owners never see an individual question in its original wording, who asked it, your account or email, your chat history, or anything you uploaded.
  • A theme is shown only when a minimum number of different people have asked about it, so no single person's activity can be identified. Themes below that threshold are not shown at all.
  • Example wording shown for a theme is a machine-generated paraphrase of the shared intent, not your literal text.
  • We do not sell this data and do not share it outside the specific Project's owners.

We retain the underlying questions and answers to build these aggregates and to show you your own chat history. You can delete your chat history at any time (see §8).

6. Third-Party Services

OpenAI / Anthropic / xAI

Embeddings and AI chat responses. Content chunks and your messages are sent to the provider's API. Not used to train their models per their API terms.

DeepSeek

AI chat, only when you select a DeepSeek model. Processed on servers in the People's Republic of China. See §4.

Stripe

Payment processing and subscription management. Stripe's privacy policy governs payment data.

Patreon

Membership verification for Patreon-gated Projects. We receive your Patreon ID/email and pledge status when you authorize the connection.

Cloudflare R2

File storage for uploaded documents, images, and audio.

Neon (PostgreSQL)

Database: accounts, text chunks, embeddings, and metadata.

Vercel

Hosting and serving the web application; standard operational logs.

Inngest

Runs background jobs (document processing, Patreon sync, channel imports).

Resend

Sends account, billing, and (if opted in) product-update emails.

AssemblyAI

Speech-to-text for audio and captionless videos. Media is sent to AssemblyAI for transcription.

YouTube Data API (Google)

Fetches public video and channel metadata and captions for content you import.

7. Marketing Communications

  • Transactional emails — account verification, receipts, subscription changes, and notifications that your Content finished processing — are part of the Service and are sent regardless of your marketing preference.
  • Product-update emails — occasional announcements about new features — are sent only if you opt in, either with the checkbox at sign-up or the toggle in Settings.
  • Every product-update email contains a one-click unsubscribe link. You can also turn them off any time in Settings. Unsubscribing never affects transactional email.
  • We do not sell your email address or share it with advertisers.

8. How We Process Your Content

  • Your Content is chunked and embedded to enable AI retrieval, and stored on Cloudflare R2 (files) and Neon PostgreSQL (text chunks and embeddings).
  • Content is sent to your selected AI provider(s) solely to generate embeddings and answers within your Project.
  • We do not use your Content to train any AI model.
  • We do not share your Content with other users except through the chat interface of the Project it belongs to, and only with people who have access (owners, subscribers, or authorized patrons).
  • You may delete Content or your chat history at any time. Deleted data is removed from active systems promptly; backups may persist for a limited period.

9. Data Sharing

We do not sell your personal information. We share information only:

  • With the third-party providers in §6, solely to operate the Service.
  • With Project owners: an owner can see that you have access to their Project (your email and name). Separately, they receive aggregated, anonymized audience insights as described in §5 — never your individual questions or identity.
  • For legal compliance — if required by law, subpoena, or court order.
  • To protect rights — to enforce our Terms or ensure user safety.
  • Business transfers — in a merger, acquisition, or sale of assets.

10. Data Retention

  • Account data is deleted within 30 days of account deletion.
  • Uploaded Content, chunks, and embeddings are deleted within 30 days.
  • Chat history is deleted within 30 days (or immediately when you clear it).
  • Aggregated, anonymized statistics that cannot identify you may be retained indefinitely.
  • Payment records are retained as required by law and for accounting.

11. Data Security

  • Encryption in transit (HTTPS/TLS) for all communications
  • Encryption at rest for stored data
  • Access controls for administrative access
  • Regular security reviews

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

12. Cookies

We use essential cookies for authentication and session management, and short-lived cookies to carry a referral code or your email-preference choice through sign-up. We do not use third-party advertising cookies or tracking pixels.

13. Your Rights

  • Access — request a copy of the personal data we hold about you.
  • Correction — request correction of inaccurate data.
  • Deletion — request deletion of your data and account.
  • Portability — request your data in a portable format.
  • Objection / withdrawal of consent — object to certain processing, or withdraw marketing consent at any time.

To exercise any of these, contact privacy@mycodex.io. We respond within 30 days.

14. Children's Privacy

The Service is not directed to children under 13 and we do not knowingly collect their information. Users between 13 and 18 should have parental consent.

15. International Users

The Service is operated from the United States. If you use it from elsewhere, your information may be transferred to and processed in the United States and in the countries where our providers operate. In particular, if you select a DeepSeek model, that request is processed in the People's Republic of China (see §4). By using the Service, you consent to these transfers.

16. California Residents (CCPA)

California residents may request to know what personal information we collect and how it is used, request deletion, and opt out of any “sale” of personal information (we do not sell personal information). You will not be discriminated against for exercising these rights. Contact privacy@mycodex.io.

17. European / UK Users (GDPR)

Our legal bases for processing are: your consent (marketing email, DeepSeek use), performance of a contract (providing the Service), legal obligation, and legitimate interests (improving the Service, preventing fraud). You may lodge a complaint with your local data protection authority.

18. Changes to This Policy

We may update this Policy. We will post the updated version and change the “Last updated” date, and for material changes we will notify you. Continued use after changes constitutes acceptance.

19. Contact

privacy@mycodex.io