CODE REMOTE MANAGER PRIVACY NOTICE

Effective date: August 2, 2026
Developer: MakeCdev
Privacy and support contact: coderemote@makecdev.com

Code Remote Manager is a personal remote control for a Codex environment running
on a Windows PC owned or authorized by the user. MakeCdev is the public developer
name, not a membership or sign-up service. The app does not provide its own
membership, sign-up account, or Code Remote login. The Developer does not operate
a central relay for prompts, responses, project files, or commands.

The app is free to download and all remote features work with one execution
account. The Android one-time non-consumable Pro purchase expands the limit to five
execution accounts. It does not purchase Codex access or an OpenAI subscription.

For Pro activation and restoration, the Android app sends the Google Play purchase token
transiently to the verification service over HTTPS to verify the purchase
with Google Play. The raw token is used only for that request and the service does
not retain or store the raw purchase token. It derives a SHA-256 purchase token hash
and receives an installation public-key thumbprint so it can issue an entitlement
bound to that Windows installation. This processing is necessary to provide or
activate Pro and prevent fraud or abuse.

The purchase record retained in Firestore contains the SHA-256 token hash, product
ID, purchase state, verification timestamps, and invalidation data. An active
purchase record is retained while the purchase remains valid. An invalidated
record is retained for 180 days after invalidation to prevent reuse and is then
deleted, unless applicable law requires a different period. Pub/Sub delivery
receipts are retained for 30 days. The Developer does not collect Google account email
addresses or payment-method details for this verification, and the
verification record contains no Codex identity.

Google Play processes the purchase, payment, and purchase status under Google's
terms. The Cloud Run verification service checks purchase status and issues the
installation-bound entitlement. Firestore stores the minimal purchase record.
Pub/Sub delivers Google Play real-time developer notifications. These Google Cloud
services may process data in regions selected for the deployed service and under
Google's applicable security and privacy terms. The public purchase-verification
route does not require a Code Remote login; it validates the Google Play purchase
token and installation binding and is rate-limited by client IP and purchase-token
hash. Internal Pub/Sub RTDN and Scheduler requests are OIDC-authenticated. All
routes are encrypted in transit and logged without authorization headers, request
bodies, raw purchase tokens, or Google error payloads.

Outside Pro verification, the app may process prompts, responses, Chat metadata,
project labels, changed files, selected images, speech transcripts, account display
information, usage status, device connection information, notifications, and
diagnostics as needed to provide its features. Production traffic moves between the
user's device and the user's Windows PC through Tailscale. The user's Codex/OpenAI
account may process prompts and responses, Tailscale may process connection
metadata, and a platform Web Speech provider may process voice input when selected.

Android QR images and results are processed on-device and are not sent to Google by
ML Kit. Included Google ML Kit components may send device and app information,
device or installation-scoped identifiers, performance metrics, API configuration,
input and output sizes, feature versions, event types, and error codes to Google for
diagnostics and usage analytics. ML Kit encrypts this metrics data in transit using
HTTPS and states that it is not shared with third parties.

The mobile device may store its PC address and device authentication, selected
context, drafts, preferences, notifications, previews, and caches. The Windows PC
may store configuration, session cache, attachments, previews, preferences, pairing
records, logs, duplicate-execution protection records, the installation entitlement
key, and signed Pro certificates. Current automatic retention includes 24 hours for
abandoned uploads, 30 days for completed or failed session cache, up to 31 days for
local usage history, and 7 days for production logs and duplicate-execution records.
Some configuration and Codex data remain until the user explicitly deletes them.

The app contains controls to reset this device's app data and Code Remote Manager
runtime data on the Windows PC. These controls do not delete Codex Chat/history,
Codex login or settings, project files, configuration backups, OpenAI accounts, or
Tailscale accounts. For deletion requests concerning the minimal server purchase
record, use the support contact; records required to prevent reuse or meet legal
obligations may remain for the stated period.

The Developer does not operate advertising, cross-app tracking, first-party
analytics, or crash-reporting services. The current mobile target is Android. Any
later Apple-platform release requires a fresh review of the actual build,
permissions, included SDKs, and store privacy disclosures.

KOREAN SUMMARY / 한국어 요약

Pro 구매·복원 시 Android 앱은 Google Play 구매 토큰을 HTTPS로 검증 서비스에
일시적으로 전달합니다. 원본 구매 토큰은 검증 요청에만 사용하고 저장하지 않습니다.
Firestore에는 SHA-256 구매 토큰 해시, 상품 ID, 상태, 검증·무효화 시각만 보존하며
설치 공개키 지문에 묶인 권한을 발급합니다. 활성 구매 기록은 구매가 유효한 동안,
무효화 기록은 재사용 방지를 위해 180일, Pub/Sub 수신 기록은 30일 보존합니다.

처리 목적은 Pro 제공·활성화와 부정 사용 방지입니다. Google Play는 결제와 구매
상태를, Cloud Run은 검증을, Firestore는 최소 구매 기록을, Pub/Sub은 실시간 개발자
알림을 처리합니다. 앱과 개발자는 검증을 위해 Google 계정 이메일이나 결제수단
정보를 수집하지 않으며 원본 구매 토큰을 보존하지 않습니다. 공개 구매 검증 경로는
Code Remote 로그인을 요구하지 않고 구매 토큰·설치 바인딩 검증과 rate limit을
적용합니다. 내부 Pub/Sub RTDN·Scheduler 요청은 OIDC로 인증합니다. 삭제·개인정보
문의는 coderemote@makecdev.com으로 요청할 수 있습니다.

Privacy:
https://coderemotemanager.makecdev.com/privacy

Terms:
https://coderemotemanager.makecdev.com/terms

Support:
https://coderemotemanager.makecdev.com/support

Data deletion instructions:
https://coderemotemanager.makecdev.com/delete-account
