Privacy Policy
DexThemes is an open-source theme discovery and creation service for Codex. This policy covers the website, API, ChatGPT/Codex MCP app, and distributed plugins.
Data processed by ChatGPT and Codex tools
When you invoke DexThemes from ChatGPT or Codex, OpenAI sends the tool inputs you choose to DexThemes and receives the tool results needed to answer or render the app. Depending on the tool, those inputs can include a search query; a theme inspiration, name, summary, ID, palette, code-theme choice, contrast, or light/dark variant; and text you ask DexThemes to place in a draft GitHub issue. Do not place secrets, credentials, hidden prompts, private repository contents, or other sensitive information in these fields.
Tool results can include public theme names and IDs, summaries, palettes, public creator display names, popularity counts and ranks, validation messages, Codex import strings, and redacted GitHub issue drafts. Signed-in account tools can also return your GitHub display name or username, your published themes, creator and activity totals, ranks, popularity history, and achievement names. The optional employee achievement reveals only whether the achievement is unlocked; tool results do not return the work email address. DexThemes removes database document IDs, account IDs, authentication secrets, and debug payloads from MCP results.
Private drafting, validation, preview, apply preparation, and issue preparation do not by themselves persist a new theme in the DexThemes database. OpenAI may retain the conversation and tool inputs or outputs under the policy and workspace settings that apply to your OpenAI account. A theme becomes public only after the signed-in review screen displays the exact payload and the user activates Publish to DexThemes community.
Other data we collect
- Account and identity: GitHub's stable account identifier and public username, display name, and avatar used for sign-in, attribution, support, and account recovery. OAuth providers also process the authorization request, token, scopes, and session data needed to connect the account.
- Employee achievement: when enabled and explicitly verified, the identity provider supplies an email and verification claim so DexThemes can check the exact
@openai.comdomain. DexThemes stores only the eligibility boolean and resulting achievement state, not that work email address. - Theme and community activity: published theme names, summaries, IDs, palettes, creator attribution, likes, copy and qualified-adoption counts, achievements, leaderboard results, moderation reports, and timestamps.
- Supporter claims: the Buy Me a Coffee transaction ID, supporter name and email supplied by that service, amount, currency, claim status, and relevant webhook event identifiers.
- Security and operations: short-lived OAuth state and plugin sessions, one-way network or identity hashes, rate-limit counters, request status and route logs, and error information needed to prevent abuse and operate the service. DexThemes does not return these fields in MCP tool results.
- Website analytics: bounded product events such as page or feature use and a pseudonymous or signed-in user reference when Statsig is configured. DexThemes does not use this data for third-party advertising.
- AI theme generation: if you use the website's AI generation feature, the prompt and theme settings needed to generate the palette are sent to OpenAI's API and the resulting palette is returned to DexThemes.
Purposes and public visibility
DexThemes uses this data to authenticate users, find and generate themes, render previews, prepare Codex imports, publish user-confirmed community themes, calculate creator stats and achievements, operate leaderboards, prepare user-reviewed GitHub feedback, moderate content, prevent abuse, provide support, and maintain service reliability.
Public theme publication displays the confirmed theme data and creator display name. Public leaderboards can show theme names, creator display names, and aggregated counts. Supporter status never requires public listing; the supporter wall shows a public GitHub name, username, avatar, and unlock date only after explicit opt-in. A prepared GitHub issue is not posted by DexThemes; if you continue to GitHub and submit it, the issue and your GitHub identity become subject to the repository's visibility and GitHub's policies.
Recipients and service providers
Data is disclosed only as needed to operate the requested feature: OpenAI for ChatGPT/Codex tool routing and optional AI theme generation; Auth0 for MCP OAuth; GitHub for sign-in, public attribution, and user-submitted issues; Convex for application data and backend processing; Cloudflare for current website hosting and request delivery; Vercel for retained rollback deployment infrastructure that does not handle canonical production requests; Statsig for configured product analytics; and Buy Me a Coffee for supporter verification. These providers process data under their own terms and instructions applicable to the service. Public theme and leaderboard fields are available to anyone who uses DexThemes. DexThemes does not sell personal data.
Retention
- OAuth state, review-continuity tokens, and plugin sessions expire automatically or are removed when revoked.
- Unpublished MCP drafts are not stored as community records by DexThemes. Conversation retention is controlled by OpenAI and the user's OpenAI workspace settings.
- Published themes, attribution, aggregated activity, achievements, and moderation history remain while the content or account is active and as needed for integrity, abuse prevention, legal obligations, and dispute resolution.
- Rate-limit, security, and operational records are retained only for the period reasonably needed to protect and troubleshoot the service.
- Supporter claim records remain while needed to verify access, prevent fraud, process refunds or revocations, meet legal obligations, and resolve support requests.
- Content submitted to GitHub or another provider is retained according to that provider's settings and policies.
Your controls
You can use anonymous discovery and drafting tools without linking a DexThemes account; decline OAuth linking; review a theme before publication; stop before pressing Publish; avoid opening or submitting a prepared GitHub issue; opt out of the public supporter wall without losing supporter access; and revoke connected-app access through the applicable identity provider. You may request access, correction, deletion where applicable, unpublished-account closure, or removal of your public content or supporter listing through the support page. Do not put private information in a public issue; the maintainer will continue identity verification through GitHub account controls without asking you to post private details.
Security
DexThemes uses OAuth with PKCE, signed token verification, scoped access, hashed credentials and network identifiers where applicable, rate limits, server-derived identity, output allowlists, and exact-payload review before public submission. No online service can guarantee absolute security.
Children and changes
DexThemes is not directed to children under 13. Material changes will be posted here with a new effective date.
Contact
For privacy or security questions, use the support page. Do not include secrets or private workspace data in a public issue.