최종 수정일

개인정보

개인정보처리방침

Code Remote Manager가 사용자의 기기와 사용자가 선택한 외부 서비스 사이에서 데이터를 처리하는 방식을 설명합니다.

앱은 무료로 다운로드하며 모든 원격 기능을 실행 계정 1개로 사용할 수 있습니다. Android Pro 비소모성 일회성 구매는 한도를 5개로 확장합니다. 별도 회원가입이나 중앙 중계 서버는 필요하지 않습니다.

1. 운영자와 문의

Code Remote Manager의 운영자는 MakeCdev입니다. 개인정보·보안 문의는 coderemote@makecdev.com으로 접수합니다.

2. 처리할 수 있는 데이터

3. 외부 서비스와 Android SDK

Codex/OpenAI는 prompt와 응답을, Tailscale은 연결 메타데이터를, Web Speech 제공자는 사용자가 선택한 음성 입력을 처리할 수 있습니다.

Pro 구매·복원 시 Google Play 구매 토큰을 HTTPS로 Cloud Run 검증 서비스에 일시적으로 전달합니다. 원본 토큰은 저장하지 않으며, Firestore에는 SHA-256 토큰 해시, 상품 ID, 구매 상태, 검증·무효화 시각을 최소 구매 기록으로 보존합니다. Pub/Sub은 Google Play 실시간 개발자 알림을 전달합니다. 공개 검증 경로는 구매 토큰과 설치 바인딩을 검증하고 rate limit을 적용합니다.

앱과 개발자는 이 검증을 위해 Google 이메일이나 결제수단 정보를 수집하지 않으며, 검증 기록에는 Codex identity가 포함되지 않습니다.

Google ML Kit은 QR 영상과 결과를 기기에서 처리하며 이를 Google 서버로 전송하지 않습니다. 포함된 ML Kit 구성요소는 진단과 사용 분석을 위해 기기 정보, 앱 정보, 기기 또는 설치별 식별자, 성능 지표, API 구성, 입력·출력 크기, 기능 버전, 이벤트 유형과 오류 코드를 Google에 전송할 수 있습니다. 이 지표 데이터는 HTTPS로 암호화되며 Google 설명상 제3자와 공유되지 않습니다.

4. 로컬 저장과 보관

모바일 기기는 연결정보, 초안, 환경설정, 알림과 캐시를 저장할 수 있습니다. Windows PC는 구성, 세션 캐시, 첨부, pairing 기록, 로그와 중복 실행 방지 기록을 저장할 수 있습니다. 활성 구매 기록은 구매가 유효한 동안, 무효화 기록은 180일, Pub/Sub 수신 기록은 30일 보존합니다. 로컬 자동 보관 기준은 abandoned upload 24시간, 완료·실패 세션 캐시 30일, 사용량 기록 최대 31일, 운영 로그와 중복 실행 방지 기록 7일입니다.

5. 삭제와 사용자 권리

앱의 이 기기 초기화와 Windows PC의 Code Remote Manager 데이터 초기화 기능을 사용할 수 있습니다. 이 기능은 Codex Chat/history, Codex 로그인·설정, 프로젝트 파일, 백업, OpenAI 계정 또는 Tailscale 계정을 삭제하지 않습니다. 최소 서버 구매 기록의 삭제 요청은 지원 연락처로 접수할 수 있으며 재사용 방지나 법률상 의무에 필요한 기록은 명시된 기간 동안 남을 수 있습니다. 자세한 절차는 데이터 삭제 안내를 확인하세요.

6. 분석·광고와 플랫폼

현재 출시에는 개발자가 운영하는 광고, 교차 앱 추적, 자체 analytics 또는 crash reporting이 없습니다. 현재 모바일 대상은 Android이며 향후 Apple 플랫폼 출시는 실제 빌드를 기준으로 별도 검토합니다.

Last updated

CODE REMOTE MANAGER PRIVACY NOTICE

Effective date: August 2, 2026 Developer: MakeCdev Privacy and support contact: coderemote@makecdev.com

Code Remote Manager is a personal remote control for a Codex environment running on a Windows PC owned or authorized by the user. MakeCdev is the public developer name, not a membership or sign-up service. The app does not provide its own membership, sign-up account, or Code Remote login. The Developer does not operate a central relay for prompts, responses, project files, or commands.

The app is free to download and all remote features work with one execution account. The Android one-time non-consumable Pro purchase expands the limit to five execution accounts. It does not purchase Codex access or an OpenAI subscription.

For Pro activation and restoration, the Android app sends the Google Play purchase token transiently to the verification service over HTTPS to verify the purchase with Google Play. The raw token is used only for that request and the service does not retain or store the raw purchase token. It derives a SHA-256 purchase token hash and receives an installation public-key thumbprint so it can issue an entitlement bound to that Windows installation. This processing is necessary to provide or activate Pro and prevent fraud or abuse.

The purchase record retained in Firestore contains the SHA-256 token hash, product ID, purchase state, verification timestamps, and invalidation data. An active purchase record is retained while the purchase remains valid. An invalidated record is retained for 180 days after invalidation to prevent reuse and is then deleted, unless applicable law requires a different period. Pub/Sub delivery receipts are retained for 30 days. The Developer does not collect Google account email addresses or payment-method details for this verification, and the verification record contains no Codex identity.

Google Play processes the purchase, payment, and purchase status under Google's terms. The Cloud Run verification service checks purchase status and issues the installation-bound entitlement. Firestore stores the minimal purchase record. Pub/Sub delivers Google Play real-time developer notifications. These Google Cloud services may process data in regions selected for the deployed service and under Google's applicable security and privacy terms. The public purchase-verification route does not require a Code Remote login; it validates the Google Play purchase token and installation binding and is rate-limited by client IP and purchase-token hash. Internal Pub/Sub RTDN and Scheduler requests are OIDC-authenticated. All routes are encrypted in transit and logged without authorization headers, request bodies, raw purchase tokens, or Google error payloads.

Outside Pro verification, the app may process prompts, responses, Chat metadata, project labels, changed files, selected images, speech transcripts, account display information, usage status, device connection information, notifications, and diagnostics as needed to provide its features. Production traffic moves between the user's device and the user's Windows PC through Tailscale. The user's Codex/OpenAI account may process prompts and responses, Tailscale may process connection metadata, and a platform Web Speech provider may process voice input when selected.

Android QR images and results are processed on-device and are not sent to Google by ML Kit. Included Google ML Kit components may send device and app information, device or installation-scoped identifiers, performance metrics, API configuration, input and output sizes, feature versions, event types, and error codes to Google for diagnostics and usage analytics. ML Kit encrypts this metrics data in transit using HTTPS and states that it is not shared with third parties.

The mobile device may store its PC address and device authentication, selected context, drafts, preferences, notifications, previews, and caches. The Windows PC may store configuration, session cache, attachments, previews, preferences, pairing records, logs, duplicate-execution protection records, the installation entitlement key, and signed Pro certificates. Current automatic retention includes 24 hours for abandoned uploads, 30 days for completed or failed session cache, up to 31 days for local usage history, and 7 days for production logs and duplicate-execution records. Some configuration and Codex data remain until the user explicitly deletes them.

The app contains controls to reset this device's app data and Code Remote Manager runtime data on the Windows PC. These controls do not delete Codex Chat/history, Codex login or settings, project files, configuration backups, OpenAI accounts, or Tailscale accounts. For deletion requests concerning the minimal server purchase record, use the support contact; records required to prevent reuse or meet legal obligations may remain for the stated period.

The Developer does not operate advertising, cross-app tracking, first-party analytics, or crash-reporting services. The current mobile target is Android. Any later Apple-platform release requires a fresh review of the actual build, permissions, included SDKs, and store privacy disclosures.

KOREAN SUMMARY / 한국어 요약

Pro 구매·복원 시 Android 앱은 Google Play 구매 토큰을 HTTPS로 검증 서비스에 일시적으로 전달합니다. 원본 구매 토큰은 검증 요청에만 사용하고 저장하지 않습니다. Firestore에는 SHA-256 구매 토큰 해시, 상품 ID, 상태, 검증·무효화 시각만 보존하며 설치 공개키 지문에 묶인 권한을 발급합니다. 활성 구매 기록은 구매가 유효한 동안, 무효화 기록은 재사용 방지를 위해 180일, Pub/Sub 수신 기록은 30일 보존합니다.

처리 목적은 Pro 제공·활성화와 부정 사용 방지입니다. Google Play는 결제와 구매 상태를, Cloud Run은 검증을, Firestore는 최소 구매 기록을, Pub/Sub은 실시간 개발자 알림을 처리합니다. 앱과 개발자는 검증을 위해 Google 계정 이메일이나 결제수단 정보를 수집하지 않으며 원본 구매 토큰을 보존하지 않습니다. 공개 구매 검증 경로는 Code Remote 로그인을 요구하지 않고 구매 토큰·설치 바인딩 검증과 rate limit을 적용합니다. 내부 Pub/Sub RTDN·Scheduler 요청은 OIDC로 인증합니다. 삭제·개인정보 문의는 coderemote@makecdev.com으로 요청할 수 있습니다.

Privacy: https://coderemotemanager.makecdev.com/privacy

Terms: https://coderemotemanager.makecdev.com/terms

Support: https://coderemotemanager.makecdev.com/support

Data deletion instructions: https://coderemotemanager.makecdev.com/delete-account