1. Information we process
You can browse, search, like, and download themes without creating an account. When you sign in with Google or GitHub to publish, Neon Auth provides the account identifier, name, email address, provider, and session data needed to authenticate the publisher. Publishing requires exactly one public contributor profile. A GitHub profile may be linked through Neon Auth. For X attribution, you provide a public profile URL; we normalize and store its username and canonical profile URL. Get Codex Theme does not call the X API or receive an X access token, refresh token, posts, or email address.
2. Public submissions
A CLI-submitted theme archive, manifest, preview images, automatically inferred category, and the single selected GitHub or X attribution are stored for automated validation. When validation succeeds, the theme assets, contributor username, profile link, license, version, and install metadata become public. GitHub attribution comes from the connected account; X attribution comes from the public profile URL supplied by the publisher. Do not submit private or confidential material or a profile you are not authorized to represent.
3. Downloads, likes, requests, and reports
To produce aggregate download counts without keeping a raw network address, we derive a short-retention, purpose-specific one-way HMAC identifier from the Cloudflare-provided IP address and deduplicate downloads by theme, version, and day. For likes, requests, votes, and claims, we derive a separate one-way HMAC identifier from the authenticated user ID when an account is used. Private content reports use another purpose-specific hash. We store the resulting keyed hashes, not the raw IP address or raw internal user ID.
Theme-request titles, briefs, categories, votes, status, and selected public creator identity are public. Do not place contact details, private information, or confidential material in a request. Reference-image uploads remain disabled until automated quarantine and safety checks are configured.
4. Storage and retention
Submission records may be retained to preserve theme ownership, security evidence, and reproducible releases. Private reports are retained while a correction, rights, privacy, abuse, or removal request is investigated and for a reasonable period needed for legal compliance and repeat-abuse prevention. A creator may request removal of a public theme, while limited records may be retained for those purposes.
5. Service providers
We use Cloudflare for hosting, object storage, database services, and network security; Neon Auth for Google or GitHub sign-in and GitHub profile linking; and GitHub for the open-source repository and CLI release. X is not a website sign-in method and its API is not used for contributor attribution. We do not sell personal information and do not use payment processors because the service does not sell theme packs.
6. Your choices
You may browse and download without signing in, remove your own like or vote by pressing the same action again, sign out at any time, and request correction or deletion of account-associated information subject to integrity, safety, ownership, and legal exceptions.
7. Contact and changes
Material changes will be reflected by the updated date on this page. For privacy, removal, copyright, trademark, or abuse concerns, use the private report form. For product and security questions, use the contact page. Also read the Terms.