Legal
Privacy policy
Effective September 29, 2026
The software does not upload your Codex data to us. Vault encrypts conversation content before writing it to the local or cloud-sync folder you choose; migrations run directly between Macs you control.
What the software collects
The open-source CLI and local dashboard include no analytics or telemetry. Segeren Studio does not receive your conversations, encrypted Vault contents, recovery key, repositories, credentials, migration inventory, or verification report through the software. Your selected storage or sync provider processes the encrypted files under its own terms; Segeren Studio does not operate that storage.
Website analytics
This public website uses Google Analytics to understand page views, traffic sources and campaigns, approximate city or region, device and browser type, returning visits, clicks to the free CLI, You.one and the team-pilot email link, and successful launch-email and team-pilot requests. An email-link click does not tell us whether you sent a message. Analytics does not receive your name, email address, team size, Codex usage choice, conversations, repositories, migration inventory, credentials, or local dashboard activity. We do not enable ads personalization or use analytics to enroll you in marketing.
In markets where prior consent is not required, analytics cookies are enabled by default. In the European Economic Area, United Kingdom, and Switzerland, Google Analytics starts in consent mode without analytics or advertising cookies and shows a compact choice. Declined visits may still send cookieless measurements that Google uses for aggregate and modeled reporting. Accepting enables the full cookie-based measurements described here.
Where full analytics is enabled, Codex Migrate-specific first-party measurement cookies may last for up to 14 months and refresh when you return. Google Signals may add aggregate, thresholded demographic, interest, and cross-device insights for eligible Google users; these reports do not identify an individual visitor to us and may be unavailable when traffic is low. Select analytics choices to allow or decline cookies. Your choice is stored in this browser’s local storage. Declining removes this site’s product-specific analytics cookies, while cookieless measurement remains active in consent-required markets. Google processes website-usage data under its own terms and privacy policy.
Vercel hosts the site and its signup endpoint, which also accepts team-pilot requests, and may process standard request information such as IP address, device information, requested URL, and timestamps to deliver and protect it. The endpoint is rate limited to reduce abuse.
Purchase data
Stripe processes checkout and payment information on our behalf. We receive transaction records and contact details needed to confirm your purchase, deliver access, provide support, prevent fraud, and process refunds. We do not receive or store your full payment-card number.
Stripe Checkout may offer an optional choice to receive one checkout-recovery email. If you opt in and leave checkout unfinished, Stripe may provide the email address you entered and a private recovery link after that checkout expires. We send at most one reminder for that checkout, do not add you to a marketing list, and disable open and click tracking. If you do not opt in, we do not send a recovery reminder.
When you start checkout, this tab stores a random checkout-attempt reference to reuse on retries and help prevent duplicate checkout sessions. Reloads reuse a reference created within the last 30 minutes. It is not an analytics identifier and is removed when the tab’s session ends.
The purchase-delivery system uses a separate Neon database for your purchase reference, email address, app release, and delivery status. SendGrid sends the download email and a purchase alert containing the buyer email, paid amount, release, and Stripe references to Joshua Segeren’s two operator inboxes. Operator alerts do not contain the private download link. Purchase emails do not subscribe you to marketing. The private download page uses the same region-aware Google Analytics controls as this website and records a generic purchase event after a successful verification. It does not send your email address, payment details, or private download-link credential to Google Analytics. The credential is removed from the address before analytics starts and is not included in server request URLs.
After verifying a download, the purchase page keeps its private recovery token in this tab’s session storage for reuse for up to 30 minutes, so refreshing does not lose access. It is not stored in a persistent cookie or local storage, and payment and refund status are checked again before each download link is issued. After it expires, reopen your purchase email’s link. Browsers normally clear session storage when the tab closes, but restoring a browser session may restore it; the 30-minute reuse limit still applies.
Launch emails, team-pilot requests, and early-build requests
When you submit the launch form and give consent, Vercel processes your email address and sends the request through Twilio SendGrid to Joshua Segeren’s inbox. The message includes your email, consent, submission time, and the website origin. Joshua manages these requests personally; there is no separate subscriber database or automated newsletter. We use the address for the requested launch notice and any necessary confirmation, not unrelated marketing. Signup success means SendGrid accepted the message, not a guarantee of inbox delivery.
When you request a team-pilot conversation, we send your work email, selected team-size range, selected Codex usage, consent, submission time, and website origin through SendGrid to Joshua’s inbox. He may reply personally about the proposed pilot. This is not enrollment, a purchase, or consent to a newsletter. The form does not ask for conversation content or repositories. A successful form response means SendGrid accepted the request, not that the email was delivered. Ask Joshua to remove your request at any time.
Early-build and support links open your email app. Those messages are processed by your email provider and ours and handled individually. No payment is required. Email Joshua to opt out or request removal. Launch requests are kept until the notice has been sent or you ask for removal, except records needed for abuse prevention or legal obligations. Do not send credentials, conversations, or repository contents. Sending an early-build request does not guarantee access.
How data is shared
We share data only with service providers needed to operate the site, website analytics, email, and checkout, including Vercel, Neon, Google Analytics, Twilio SendGrid, our mailbox provider, and Stripe, or when required by law. We do not sell personal data.
Retention and security
Purchase records are retained as needed for delivery, support, accounting, tax, fraud prevention, and legal obligations. We use the access controls and security features provided by our hosting and payment providers. No internet system can be guaranteed perfectly secure.
Your choices
You can use the free CLI without buying anything or creating an account with us. To request access to, correction of, or deletion of your contact or purchase-related information where legally available, email Joshua Segeren privately. Do not post sensitive information in a public issue.
Changes
Material changes will be posted here with a new effective date.