← DexThemes

Privacy Policy

Effective August 24, 2026

DexThemes is an open-source theme discovery and creation service for Codex. This policy covers the website, API, ChatGPT/Codex MCP app, and distributed plugins.

Data processed by ChatGPT and Codex tools

When you invoke DexThemes from ChatGPT or Codex, OpenAI sends the tool inputs you choose to DexThemes and receives the tool results needed to answer or render the app. Depending on the tool, those inputs can include a search query; a theme inspiration, name, summary, ID, palette, code-theme choice, contrast, or light/dark variant; and text you ask DexThemes to place in a draft GitHub issue. Do not place secrets, credentials, hidden prompts, private repository contents, or other sensitive information in these fields.

Tool results can include public theme names and IDs, summaries, palettes, public creator display names, popularity counts and ranks, validation messages, Codex import strings, and redacted GitHub issue drafts. Signed-in account tools can also return your GitHub display name or username, your published themes, creator and activity totals, ranks, popularity history, and achievement names. The optional employee achievement reveals only whether the achievement is unlocked; tool results do not return the work email address. DexThemes removes database document IDs, account IDs, authentication secrets, and debug payloads from MCP results.

Private drafting, validation, preview, apply preparation, and issue preparation do not by themselves persist a new theme in the DexThemes database. OpenAI may retain the conversation and tool inputs or outputs under the policy and workspace settings that apply to your OpenAI account. A theme becomes public only after the signed-in review screen displays the exact payload and the user activates Publish to DexThemes community.

Other data we collect

Purposes and public visibility

DexThemes uses this data to authenticate users, find and generate themes, render previews, prepare Codex imports, publish user-confirmed community themes, calculate creator stats and achievements, operate leaderboards, prepare user-reviewed GitHub feedback, moderate content, prevent abuse, provide support, and maintain service reliability.

Public theme publication displays the confirmed theme data and creator display name. Public leaderboards can show theme names, creator display names, and aggregated counts. Supporter status never requires public listing; the supporter wall shows a public GitHub name, username, avatar, and unlock date only after explicit opt-in. A prepared GitHub issue is not posted by DexThemes; if you continue to GitHub and submit it, the issue and your GitHub identity become subject to the repository's visibility and GitHub's policies.

Recipients and service providers

Data is disclosed only as needed to operate the requested feature: OpenAI for ChatGPT/Codex tool routing and optional AI theme generation; Auth0 for MCP OAuth; GitHub for sign-in, public attribution, and user-submitted issues; Convex for application data and backend processing; Cloudflare for current website hosting and request delivery; Vercel for retained rollback deployment infrastructure that does not handle canonical production requests; Statsig for configured product analytics; and Buy Me a Coffee for supporter verification. These providers process data under their own terms and instructions applicable to the service. Public theme and leaderboard fields are available to anyone who uses DexThemes. DexThemes does not sell personal data.

Retention

Your controls

You can use anonymous discovery and drafting tools without linking a DexThemes account; decline OAuth linking; review a theme before publication; stop before pressing Publish; avoid opening or submitting a prepared GitHub issue; opt out of the public supporter wall without losing supporter access; and revoke connected-app access through the applicable identity provider. You may request access, correction, deletion where applicable, unpublished-account closure, or removal of your public content or supporter listing through the support page. Do not put private information in a public issue; the maintainer will continue identity verification through GitHub account controls without asking you to post private details.

Security

DexThemes uses OAuth with PKCE, signed token verification, scoped access, hashed credentials and network identifiers where applicable, rate limits, server-derived identity, output allowlists, and exact-payload review before public submission. No online service can guarantee absolute security.

Children and changes

DexThemes is not directed to children under 13. Material changes will be posted here with a new effective date.

Contact

For privacy or security questions, use the support page. Do not include secrets or private workspace data in a public issue.