STL / PRIVACY

Privacy Policy

Effective 31 August 2026

Data processed locally

The desktop companion starts the locally installed Codex App Server and reads only the fields needed to show usage windows, reset times, account type and plan. It does not read, copy or store Codex access tokens, API keys, prompts, source code or conversation content.

A manually selected Codex executable path stays in the computer's local application configuration and can be cleared from Source Settings.

Universal encrypted relay

Sync is optional. Pairing creates an AES-256 encryption key on the desktop and transfers it directly to the mobile device with a short-lived, single-use credential. Publisher and reader credentials are role-separated and stored in the operating system secure store.

The relay receives a random channel identifier, SHA-256 hashes of random credentials, an opaque AES-256-GCM ciphertext and timestamps required for expiration and replay protection. It cannot decrypt the quota snapshot and never receives Codex credentials, email addresses, prompts or source code.

QR scanning on Android

Camera frames and decoded QR contents are processed on-device. Statusline does not store or transmit them. The bundled ML Kit barcode component may collect device and app information, an installation identifier, API configuration, feature events, performance measurements and error diagnostics for Google's diagnostics and usage analytics. Statusline does not receive that telemetry.

Read Google's ML Kit data disclosure.

Hosting, abuse prevention and logs

The Cloudflare deployment applies abuse limits using a SHA-256 digest of the source IP address. Neither the source IP nor that digest is written to the Statusline D1 database.

Persistent Worker invocation logs are disabled. Cloudflare may still process IP addresses and request metadata at its edge for delivery, security, abuse prevention, aggregate metrics and billing. Statusline contains no advertising SDK and no first-party product analytics SDK.

Retention and deletion

Pairing links expire after ten minutes. Channels expire after thirty days without a successful publication, and a daily task removes expired rows. Rate-limit state is scoped to 60-second windows and is not stored in the relay database.

Disconnecting the desktop attempts to delete the remote channel and removes its local credential. Disconnecting the mobile reader removes its local credential and encryption key.

See Delete Statusline data for step-by-step instructions and the complete retention details.

Questions

Email founder@inmerzion.io or use the Statusline support page for privacy questions or reports. Never include pairing links, QR codes, API keys, access tokens or private Codex configuration.