Auditex
Privacy Policy
Last updated: 3 July 2026 This Privacy Policy explains how MAGRATHEAN UK LTD collects, uses, stores, discloses, and protects personal data in connection with Magrathean websites, products, software, apps, documentation, support, sales, security reporting, and related services. This policy is intended to cover, at a minimum, the following Magrathean products and websites:
- Auditex, including
auditex.hu, the Auditex CLI, MCP surfaces, documentation, examples, reports, exports, and support channels. - Codexex, including
codexex.eu, the Codexex macOS and iOS apps, helper components, App Store listings, support channels, documentation, and related local companion tools. - Magrathean corporate websites and contact points, including
magrathean.ukand email addresses under that domain.
Where a product-specific section below applies, it supplements the general sections of this policy.
Contents
Controller identity and contact details Scope and role allocation Product summary Categories of personal data Sources of personal data Purposes and lawful bases Special category data and criminal offence data Cookies, analytics, and tracking on this website Recipients and third parties International transfers Retention Security Data subject rights Complaints and supervisory authorities Automated decision-making and profiling Children Product-specific deletion and export Support submissions and redaction Changes to this policy Enterprise support and processing role
Controller identity and contact details
The controller for Magrathean website, support, licensing, security-reporting, sales, product, and business-contact processing is:
MAGRATHEAN UK LTD (trading as Magrathean), registered in England and Wales. Company number: 16955343 Registered office: 16 Caledonian Court, West Street, Watford, England, WD17 1RY, United Kingdom Privacy contact: [email protected]
Magrathean has not appointed a statutory Data Protection Officer unless a separate written agreement says otherwise. Privacy requests should be sent to the privacy contact above.
For EU/EEA users and customers: Magrathean can be contacted directly at [email protected]. Magrathean keeps Article 27 EU GDPR representative requirements under review and will publish representative details if required.
For Hungarian users and customers: because Auditex is published on a .hu domain and may be used in Hungary or for Hungarian organisations, Hungarian and EU local-law issues should be confirmed with Hungarian counsel where the operator, customer, users, governing law, or deployment creates a Hungarian nexus. Individuals may contact the Hungarian National Authority for Data Protection and Freedom of Information, known as NAIH, where applicable.
Scope and role allocation
This policy covers personal data that Magrathean processes as controller for its own purposes, including website operation, product distribution, support, sales, licensing, account administration, security reporting, company administration, and legal compliance.
This policy also explains important local-processing behaviour in Auditex and Codexex. Much product data is stored locally on the user’s device, in the user’s tenant, or in output folders controlled by the user or customer. Local processing still matters for transparency, but Magrathean does not automatically receive all such data.
Where a customer, employer, tenant owner, auditor, or operator uses Auditex or Codexex in its own environment, that customer, employer, tenant owner, auditor, or operator is normally responsible for determining its own lawful basis, notices, permissions, retention, security, and user-facing disclosures.
Magrathean acts as a processor only where a signed order, enterprise agreement, support statement of work, data processing agreement, or equivalent written agreement says that Magrathean will process customer data or tenant evidence on the customer’s behalf. If Magrathean receives support bundles, logs, screenshots, tenant outputs, local history, auth material, crash details, or similar customer-provided material, Magrathean processes that material only for the support, security, legal, or operational purpose for which it was provided, unless a separate agreement says otherwise.
Product summary
3.1 Auditex
Auditex is a local-first Microsoft 365 and Google Workspace audit toolkit. It can run authorised audit flows, collect read-only posture evidence, generate local evidence bundles, normalize records, build findings, produce API inventories and proof tables, create customer handoff packs, and expose CLI and MCP review surfaces.
Auditex is designed for authorised tenant auditing. It must be used only against tenants, domains, systems, and accounts that the operator owns or is expressly authorised to assess. Public Auditex audit collectors are intended to be read-only and must not read Gmail message bodies, Google Drive file content, Exchange mailbox body content, SharePoint file content, or OneDrive file content. Metadata and settings may nevertheless include personal data and confidential business data.
3.2 Codexex
Codexex is a macOS and iOS companion app for viewing Codex/OpenAI quota state, reset windows, usage history, local Codex session usage, and forecasts. It can use a ChatGPT/OpenAI device-code sign-in flow, a bundled helper, and local app storage. It is local-first: Magrathean does not operate a Codexex quota cloud by default and does not automatically receive your OpenAI tokens, local usage history, local Codex session files, or quota history.
Codexex may connect to OpenAI/ChatGPT endpoints to complete sign-in and fetch quota/account data. Apple may process App Store, TestFlight, crash, device, billing, download, and platform information under Apple’s own terms and privacy notices.
Categories of personal data
Magrathean may process the following categories of personal data, depending on how you interact with Magrathean and the products.
4.1 Website, contact, support, sales, and business data
This may include name, role, organisation, email address, telephone number, postal address, country, billing contact, purchase or licensing information, correspondence, support tickets, security reports, vulnerability details, message contents, attachments, screenshots, logs, IP address, device/browser metadata, server logs, website analytics and usage data, and records of data-subject requests or marketing preferences.
4.2 Auditex local tenant and audit evidence
Auditex may process tenant and workspace metadata collected from Microsoft 365, Azure, Entra ID, Microsoft Graph, Exchange, SharePoint, OneDrive metadata surfaces, Google Workspace, Google Admin, Google Reports, Google Drive metadata, Google Calendar metadata, Google Groups settings, Gmail settings, device-management metadata, alert metadata, domain metadata, OAuth grant metadata, role metadata, user and group records, mailbox settings, sharing settings, login/audit events, app permission metadata, API-call evidence, command-line metadata, diagnostics, blockers, proof-table rows, checksums, and report artifacts.
This may include names, work email addresses, user IDs, group membership, directory attributes, role assignments, admin activity metadata, device identifiers, app names, OAuth scopes, public/external-sharing metadata, timestamps, IP addresses where tenant APIs return them, tenant names, domain names, customer IDs, collector statuses, errors, and coverage information.
Auditex output may include run-manifest.json, summary.json, reports/report-pack.json, index/evidence.sqlite, ai_context.json, validation.json, data-handling.json, audit-plan.json, api-inventory.json, audit-log.jsonl, audit-debug.log, raw/, normalized/, ai_safe/, findings/, reports/, chunks/, blockers/, diagnostics.json, and customer handoff packs.
Auditex is designed not to place tenant credentials, service-account keys, OAuth caches, bearer material, refresh material, raw credential dumps, or customer signing keys into repository defaults or customer packs. Operators must still treat all Auditex outputs as confidential and must review support bundles before sharing them with Magrathean.
4.3 Auditex credentials and authentication metadata
Auditex may use local Azure CLI authentication, Microsoft app credentials, Google service-account keys, Google OAuth client files, Google OAuth token caches, and similar local authentication materials supplied by the operator. These materials are controlled by the operator and should be stored in local secrets folders or another secure location. Magrathean does not automatically receive them. If you deliberately send them to Magrathean, they may be treated as high-risk support material and may require deletion, rotation, and incident handling.
4.4 Codexex authentication and account data
Codexex may process ChatGPT/OpenAI device-code flow data, user codes, device authentication IDs, OAuth authorization codes, code verifiers, access tokens, refresh tokens, ID-token claims, account identifiers, email address, account plan type, token refresh metadata, sign-in status, sign-out status, error messages, and helper state.
Depending on platform and build, Codexex stores OAuth tokens and related authentication metadata locally either in Apple Keychain or in a Codexex helper authentication file under the user’s Application Support area with restrictive local file permissions. Magrathean does not receive those tokens unless you deliberately provide them to us, which you should not do unless we have agreed a secure route.
4.5 Codexex quota, local usage, and device data
Codexex may process quota windows, quota percentages, reset times, credit balances, plan type, account email, quota snapshots, timestamps, local history samples, local usage forecasts, forecast confidence, 5-hour usage views, weekly usage views, 30-day usage views, app preferences, onboarding state, refresh cadence, menu-bar display preferences, appearance mode, launch-at-login settings, notifications preferences, notification fingerprints, preview mode settings, selected local Codex sessions path, security-scoped bookmark data, helper paths, executable paths, and local error/status messages.
If enabled or selected, Codexex may read local Codex session JSONL files and related local configuration/session paths to calculate local usage. This may include timestamps, session IDs, turn IDs, model names, token counts, cached token counts, input/output/reasoning token counts, command counts, rate-limit fields, context-window signals, current working directories, project paths, source file paths, and derived usage summaries.
Codexex local usage-history samples are stored locally in the user’s Application Support area. The app is designed to trim local usage-history samples to approximately 90 days and a hard cap of 30,000 samples. Clearing local data, signing out, uninstalling, or using reset controls may remove local app data, but may not delete OpenAI, Apple, system, backup, or customer-controlled records.
4.6 App Store, payments, and platform data
If you obtain Codexex through the Apple App Store, Apple processes purchase, download, billing, refund, family-sharing, device, Apple ID, platform, crash, diagnostic, and analytics information according to Apple’s own terms and privacy notices. Magrathean normally receives only limited App Store reporting, such as sales, territory, refund, tax, crash, diagnostic, or aggregate app analytics made available by Apple. Magrathean does not receive full payment-card details from Apple.
The current Codexex product is intended to be paid upfront and not to include in-app purchases, subscriptions, paywalls, StoreKit products, or entitlement-gated premium paths unless an App Store listing or later product notice expressly says otherwise.
4.7 Product telemetry, analytics, and crash reporting
This section concerns the Auditex and Codexex software products, not the Magrathean websites. Website analytics and tracking are described in the “Cookies, analytics, and tracking on this website” section above, where Google Analytics is active by default. The software products themselves do not carry that website analytics. Auditex is intended not to include external crash telemetry or product analytics by default. Codexex is intended not to include third-party advertising, tracking, or analytics SDKs by default. Apple may provide crash reports, diagnostics, and aggregated app analytics where the user, device, App Store, TestFlight, or Apple settings permit this.
If Magrathean later adds optional analytics, crash reporting, telemetry, or similar SDKs, Magrathean will update this policy and any required consent, permission, App Store privacy-label, and in-product notices before using them.
Sources of personal data
Magrathean may receive personal data from:
- you, when you contact Magrathean, request support, report a vulnerability, buy or request a product, or send logs or attachments;
- your organisation, employer, customer, tenant owner, or authorised administrator;
- local devices and local files selected or configured by the user;
- Microsoft, Google, OpenAI/ChatGPT, Apple, GitHub, package registries, hosting providers, email providers, payment/accounting providers, support tools, and other third-party services used by you, by your organisation, or by Magrathean;
- product-generated local files, logs, reports, diagnostics, support bundles, crash reports, and system records;
- public sources, business directories, security reports, or lawful third-party communications.
Purposes and lawful bases
Magrathean relies on different lawful bases depending on the purpose of processing. Where EU GDPR or UK GDPR applies, the usual lawful bases are contract, legitimate interests, legal obligation, consent, and, where necessary, establishment, exercise, or defence of legal claims.
| Purpose | Typical data | Typical lawful basis |
|---|---|---|
| Provide websites, downloads, documentation, legal notices, and product information | Website logs, device/browser data, contact data | Legitimate interests; legal obligation where applicable |
| Website analytics, traffic measurement, and campaign attribution | Pages viewed, events, referring source, UTM and ad-click identifiers, approximate location from IP, device/browser/OS data | Legitimate interests (Article 6(1)(f) UK GDPR); active by default, no consent banner |
| Provide Auditex and Codexex product functionality | Local product data, account state, product settings, diagnostics | Contract where Magrathean provides the product to you; legitimate interests; local processing controlled by the operator where Magrathean does not receive the data |
| Complete Codexex sign-in and quota features | OpenAI/ChatGPT authentication and quota data | Contract; legitimate interests; user-initiated connection to OpenAI/ChatGPT |
| Process App Store purchases and platform records | App Store transaction reports, territory, refunds, crash data, analytics provided by Apple | Contract; legitimate interests; legal obligation; Apple acts under its own terms for its processing |
| Provide support, troubleshooting, and security response | Support messages, attachments, logs, diagnostics, product data submitted by you | Contract; legitimate interests; legal obligation; explicit consent where required for optional material |
| Handle Auditex enterprise support or customer evidence | Tenant evidence, support bundles, logs, reports, API inventories, customer outputs | Processor basis under customer instructions where a DPA applies; otherwise legitimate interests or contract for support material provided by the requester |
| Improve, secure, debug, and maintain products | Errors, diagnostics, reports, security events, dependency information | Legitimate interests; legal obligation where security law applies |
| Prevent abuse, unauthorised access, fraud, or unlawful use | Logs, account/contact data, security reports, IP/device data, misuse evidence | Legitimate interests; legal obligation; legal claims |
| Manage business, accounting, tax, corporate, and legal records | Invoices, contracts, contacts, payment reports, communications | Contract; legal obligation; legitimate interests |
| Send product, security, or service communications | Contact details, product/customer relationship | Contract; legitimate interests; consent where required |
| Comply with laws and respond to lawful requests | Relevant records | Legal obligation; legitimate interests; legal claims |
Where Magrathean relies on legitimate interests, those interests include operating and securing software products, communicating with customers and users, preventing misuse, debugging and improving products, maintaining accurate business records, enforcing terms, protecting intellectual property, responding to security issues, and defending legal claims.
Special category data and criminal offence data
Magrathean does not intentionally request special category data, criminal offence data, health data, biometric data, or children’s data through Auditex, Codexex, or support channels. Do not send such data unless it is strictly necessary and you are authorised to do so.
Auditex tenant metadata, local Codex session paths, screenshots, reports, or support bundles may incidentally reveal sensitive inferences, confidential business information, trade secrets, employment information, security weaknesses, or regulated data. Operators and customers must review, minimise, redact, and secure material before sharing it.
UK 2026 data-law update: recognised legitimate interests, complaints and local-first boundaries
This notice is drafted for the UK GDPR, the Data Protection Act 2018 and PECR as amended by the Data (Use and Access) Act 2025 where those laws apply.
For ordinary website operation, support, app administration, analytics, B2B outreach, service delivery, account administration and security logging, we rely on the lawful bases stated elsewhere in this notice. We may rely on the UK GDPR recognised legitimate interests basis only where the relevant statutory condition is available, such as prevention or detection of crime, safeguarding, emergency response, national or public security, or disclosure to an organisation or public authority that needs the information for a public task. We do not rely on recognised legitimate interests for routine commercial marketing, ordinary app analytics, cross-site advertising, retargeting or general prospecting.
Auditex is local-first for tenant evidence and raw audit outputs. Magrathean normally cannot search, delete or export evidence stored in your tenant, repository, filesystem or local output folder unless you send it to us or give us access under a separate written support or services arrangement.
If a support request, bug report, screenshot, export, diagnostic bundle or legal request contains secrets, tokens, keys, passwords, private footage, raw tenant exports, special-category data, children’s data, criminal-offence data or other high-risk material, we may reject, delete, quarantine, return or restrict that material unless a secure written handling process has been agreed. Sending material to Magrathean does not make Magrathean responsible for data we did not request and cannot reasonably inspect before receipt.
Cookie and storage-technology implementation note
Where a Magrathean website or product page uses cookies, local storage, tracking pixels, scripts, tags, link decoration, device/browser signals or similar storage/access technologies, those technologies should be read in three groups:
- strictly necessary, security, anti-abuse, load-balancing, rate-limiting, form-protection and fraud-prevention technologies;
- low-risk analytics or measurement technologies where an applicable UK PECR exception is available and the use is not for advertising, cross-site tracking or user-level profiling;
- advertising, remarketing, cross-site tracking, tag-based conversion measurement, fingerprinting, behavioural profiling or similar technologies, if enabled.
The operational position remains that the relevant websites may run cookies, analytics, measurement, attribution and similar technologies by default without a consent banner, as described in this notice. You can block or delete cookies and similar technologies through browser, device, DNS, content-blocking or network controls. This notice describes the processing; the live cookie/tag configuration should be kept aligned with this notice and with any product-specific statement.
Cookies, analytics, and tracking on this website
This website uses cookies and similar technologies — including first- and third-party analytics, measurement, and tracking tools such as Google Analytics — to understand how the site is used, measure traffic and campaigns, improve content, and protect the site. These technologies are active by default when you visit the site. We do not display a cookie consent banner and we do not ask you to opt in before analytics run.
Acceptance. By accessing, browsing, or continuing to use this website, you accept the use of the cookies, analytics, measurement, attribution, and tracking technologies described in this section, and you acknowledge that they are active by default from your first visit without a consent banner. If you do not accept this, use the browser-level controls described in this section or stop using the website. This acceptance operates alongside — and does not replace — the lawful basis stated in this section, and you may object to our legitimate-interests processing at any time.
We may process: pages viewed, events and interactions, referring source, UTM and ad-click identifiers (such as gclid, gbraid, wbraid, msclkid), approximate location derived from IP address, and device, browser, and operating-system information, together with similar usage data.
Lawful basis. For website analytics, measurement, and attribution we rely on our legitimate interests (Article 6(1)(f) UK GDPR) in understanding and improving how our website and campaigns perform and in keeping the site secure. We do not sell personal data and we do not use this data to make decisions producing legal or similarly significant effects about you.
Your controls. Because we do not operate a consent banner, you control these technologies yourself: block or delete cookies in your browser settings; install the Google Analytics opt-out browser add-on (tools.google.com/dlpage/gaoptout); use privacy or content-blocking extensions; or object to our legitimate-interests processing by emailing [email protected]. We do not currently respond to browser Do-Not-Track signals. Blocking cookies may limit some features but will not stop you reading the site.
We do not use advertising cookies, ad personalisation, or cross-site advertising tracking on this website. Local app storage is different from website cookies but can still involve storing or accessing information on a user’s device. Codexex uses local app storage, helper state, preferences, history files, and security-scoped bookmarks for product functionality. Auditex uses local files, output directories, configuration, logs, and caches selected by the operator for product functionality. These product-local technologies are described in the product sections of this policy and, unlike this website, do not include analytics or tracking.
Recipients and third parties
Magrathean may share or make personal data available to the following categories of recipients where necessary:
- hosting, DNS, CDN, website, email, security, monitoring, and infrastructure providers;
- website analytics and measurement providers, including Google (Google Analytics), for the website analytics described above;
- support, issue-tracking, project-management, and communications providers;
- payment, accounting, banking, tax, and corporate administration providers;
- Apple, where Codexex is distributed through the App Store, TestFlight, notarisation, crash reporting, App Store analytics, or related Apple services;
- Microsoft, Google, OpenAI/ChatGPT, GitHub, package registries, or other platform providers where the user or operator configures the product to interact with them;
- professional advisers, auditors, insurers, banks, regulators, courts, law enforcement, and other public authorities where legally required or reasonably necessary;
- business transferees or counterparties in connection with a corporate transaction, subject to appropriate confidentiality and legal safeguards;
- customers, tenant owners, or authorised administrators where Magrathean is acting under their instructions.
Magrathean does not sell personal data. Magrathean does not share Codexex local quota history, local session files, or tokens with advertisers. Magrathean does not automatically upload Auditex tenant evidence to Magrathean.
International transfers
Magrathean is established in the United Kingdom. Personal data may be processed in the UK, the EEA, the United States, and other countries depending on the providers used, user configuration, support routing, App Store operation, and customer instructions.
Where EU GDPR or UK GDPR transfer rules apply, Magrathean uses appropriate transfer mechanisms where required, such as adequacy decisions or regulations, the UK International Data Transfer Agreement or UK Addendum, EU Standard Contractual Clauses, or another lawful safeguard or derogation. You may contact Magrathean for information about the relevant transfer mechanism for controller data that Magrathean holds.
Where operators use Microsoft, Google, OpenAI/ChatGPT, Apple, GitHub, AI tools, MCP clients, support tools, or other services, those providers may make their own international transfers under their own terms and privacy notices.
Retention
Magrathean keeps personal data only for as long as reasonably necessary for the purposes described in this policy, including product operation, support, security, legal compliance, accounting, dispute resolution, and enforcement.
Typical retention periods or criteria are:
- Local Auditex outputs remain under the operator’s control until the operator deletes them.
- Local Codexex data remains on the user’s device until the user signs out, deletes local data, uses reset controls, uninstalls the app, changes system storage, or another retention rule applies. Codexex local usage history is intended to trim to approximately 90 days and a hard cap of 30,000 samples.
- Support tickets, emails, and related correspondence are retained while needed to answer the request, maintain the relationship, investigate security or product issues, and handle disputes.
- Security reports may be retained for investigation, remediation, abuse prevention, legal defence, and vulnerability-history purposes.
- Business, contract, licensing, accounting, tax, company, and payment records are normally retained for up to six years, unless law or a dispute requires a longer or shorter period.
- Website logs are retained for security, abuse-prevention, debugging, and operational periods appropriate to the risk and system configuration.
- Material sent to Magrathean by mistake, such as secrets or tokens, may be deleted earlier, quarantined, or handled under an incident process.
Backups may retain deleted data for a limited period until overwritten or expired, unless restoration is needed for security, legal, or continuity reasons.
Security
Magrathean uses technical and organisational measures designed to protect personal data, including access controls, local-first product design where appropriate, minimisation, secure support practices, restricted permissions, local file-permission hardening where implemented, secret hygiene, and separation of local customer evidence from Magrathean-controlled systems.
No software, network, or storage system is perfectly secure. You are responsible for securing your own devices, accounts, tenant permissions, local files, output directories, service-account keys, OAuth caches, API keys, passwords, tokens, backups, and support transfers.
Do not send Magrathean tokens, passwords, service-account keys, OAuth caches, bearer material, refresh material, tenant raw evidence, or other secrets unless Magrathean has specifically requested them and agreed a secure transfer route.
If you believe that personal data or credentials have been exposed through a Magrathean product or support channel, contact [email protected] promptly.
Data subject rights
Depending on where you live and which law applies, you may have rights to:
- access your personal data;
- correct inaccurate personal data;
- delete personal data;
- restrict processing;
- object to processing based on legitimate interests;
- receive a portable copy of data you provided;
- withdraw consent where processing is based on consent;
- complain to a supervisory authority;
- challenge certain automated decisions, where applicable.
To exercise rights against Magrathean as controller, contact [email protected]. Magrathean may need to verify your identity and may refuse or limit requests where permitted by law, including where a request is manifestly unfounded or excessive, would affect another person’s rights, or relates to data that Magrathean does not control.
If your request concerns tenant evidence, employer data, OpenAI/ChatGPT data, Apple App Store data, Microsoft data, Google Workspace data, or another customer-controlled environment, Magrathean may direct you to the relevant controller, platform provider, employer, tenant owner, or administrator.
Complaints, supervisory authorities and rights-request handling
You may complain to Magrathean first by emailing [email protected]. Please include enough information for us to identify the product, website, account, support thread, submission, export, device-local issue or customer engagement involved. Do not include passwords, private keys, bearer tokens, recovery codes or unnecessary raw personal data in the first message.
Where UK data-protection law requires complaint handling, we will acknowledge a data-protection complaint within 30 days and respond without undue delay. A complaint is separate from a UK GDPR rights request, but we may treat the same message as both where it asks us to exercise a data-protection right.
For rights requests, we normally respond without undue delay and within one month of receipt, or within one month of receiving information reasonably needed to confirm your identity or clarify the request. Where the law permits it, we may extend the response period by up to two further months for complex or multiple requests. Searches for access requests will be reasonable and proportionate. For local-first product data, we can usually act only on data Magrathean actually controls or has received.
You may also complain to the UK Information Commissioner’s Office (ICO): https://ico.org.uk/make-a-complaint/. We would prefer the chance to address the issue first, but you are not required to contact us before contacting the ICO.
Because Auditex is published on a .hu domain and may be used in Hungary or for Hungarian organisations, you may also be able to complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) where EU/Hungarian law applies.
If EU GDPR applies to your use, you may also complain to a supervisory authority in the EU Member State where you live, where you work or where you believe an infringement occurred.
Automated decision-making and profiling
Magrathean does not use website, support, Auditex, or Codexex data for solely automated decisions that produce legal or similarly significant effects on individuals.
Auditex may generate audit findings, reports, risk labels, coverage blockers, summaries, and proof tables. Codexex may generate forecasts, warnings, usage insights, and local quota projections. These outputs are informational. They are not legal, employment, credit, insurance, billing, disciplinary, or regulatory decisions by Magrathean. Customers and operators are responsible for human review before relying on product outputs.
Children
Magrathean products are intended for business, professional, developer, auditor, administrator, and technical users. They are not directed to children. Magrathean does not knowingly collect children’s personal data through Auditex, Codexex, or Magrathean websites. If you believe a child has provided personal data to Magrathean, contact [email protected].
Product-specific deletion and export
17.1 Auditex
Auditex run directories, reports, exports, handoff packs, diagnostics, caches, and local secrets are controlled by the operator. Operators can delete or export local data using their file-system, backup, customer-retention, and tenant-governance processes. Deleting local Auditex outputs does not delete records from Microsoft, Google, the tenant, backups, support tickets, or third-party systems.
17.2 Codexex
Codexex local data may be cleared by signing out, using any available reset or delete-local-data controls, uninstalling the app, deleting local app support files, or managing device backups. Signing out or deleting local data does not delete your OpenAI/ChatGPT account, Apple ID, App Store purchase history, Apple crash reports, or records held by OpenAI, Apple, or another controller.
Support submissions and redaction
Before sending logs, screenshots, support bundles, reports, exports, local history, tenant outputs, crash reports, or diagnostics to Magrathean, review and redact material that is not necessary for the support request. In particular, do not send secrets, tokens, refresh material, service-account keys, OAuth caches, tenant raw evidence, customer confidential data, special category data, or children’s data unless strictly necessary and covered by an agreed secure process.
Magrathean may delete, quarantine, or refuse unnecessary high-risk material.
Changes to this policy
Magrathean may update this policy to reflect product changes, legal changes, operational changes, or improvements in wording. The updated policy will show a new “Last updated” date. Where required by law or contract, Magrathean will provide additional notice or seek consent.
Enterprise support and processing role
Magrathean acts as processor for tenant evidence only where there is a separate written agreement, support statement of work, data-processing agreement, or enterprise contract that says so. Without that written arrangement, Magrathean does not host, monitor, back up, recover, review, or process tenant evidence for the customer.
Support material and secure intake
Do not send secrets, refresh tokens, private keys, tenant evidence, raw logs, customer data, or unnecessary personal data through public channels. Use a secure route agreed with Magrathean before sending high-risk material.
Contact
Privacy, legal, security, and support enquiries may be sent to: