Privacy
Selected files stay local. Object URLs are tab-scoped; persistence is not promised. The static site is delivered by Cloudflare Pages; site-defined analytics, remote diagnostics, accounts, billing, and Contact submissions are disabled.
Files selected in Builder and Validator
Selected images and theme JSON are processed locally in the browser. The current True MVP does not upload selected files to CodexSkin Tools or an analytics provider. Browser object URLs may be created for preview and must be revoked when an image is replaced, when the workspace is reset, or when it is disposed; they last no longer than the tab lifecycle. Image metadata and SHA-256 values are computed locally. A SHA-256 value may be displayed or included in a report the user chooses to download.
Browser state
The current implementation does not promise persistence across refresh. No image binary, local path, selected-file content, or Contact data may be stored in localStorage or sessionStorage. If non-image Builder state is stored locally in a later release, it must remain at or below 256 KiB, use a versioned schema, provide a clear and reset path, and be disclosed before release.
Analytics and cookies
Analytics is disabled in the True MVP. No third-party analytics script or analytics cookie is loaded while analytics.enabled=false. No local filename, local path, JSON content, image content, or full SHA-256 may be sent as telemetry. Enabling analytics requires prior review of this Privacy notice, consent behavior, Global Privacy Control and Do Not Track handling, IP and user-agent processing, retention, and the selected provider.
Errors and diagnostics
Validation errors remain in the current tab by default. Remote diagnostics are not configured. Any future diagnostic service must exclude filenames, local paths, file content, full hashes, Contact message and email data, cookies, secrets, and sensitive stack-trace data. The service and its retention rules must be disclosed before activation.
Contact requests
The Contact channel is not active until Owner setup is complete. Once active, it may collect category, name, email, subject, message, explicit consent, and optional affected URL, theme slug, and evidence links. File attachments must not be accepted. Provider, recipient, retention period, deletion and export process, rate limiting, spam controls, and acknowledgement wording may be inserted only after configuration and review.
Hosting
This static site is hosted on Cloudflare Pages. To deliver the site, terminate TLS, route requests, and mitigate abuse, Cloudflare may process the visitor's IP address, request URL, HTTP headers including the user-agent, request timing, and network or security signals. Cloudflare Access is not enabled for the public launch. Logpush is not enabled, and this release has no custom Worker, application server, origin database, or site-controlled raw request log. Authorized Cloudflare account administrators may access configuration and provider-generated traffic or security views. CodexSkin Tools does not set a separate retention period for Cloudflare infrastructure records and cannot delete records it does not hold in its own datastore; Cloudflare controls that infrastructure retention and related requests under the Cloudflare Privacy Policy and the account's service configuration.
Requests and updates
Privacy requests may use the Contact page only after a real channel exists. No public email or response deadline is published while that channel is inactive. This notice will be updated before a material data-flow change goes live so that the release behavior and the disclosure continue to match.
Cookie banner status
No banner is required solely for the current product contract because analytics and billing are disabled and no non-essential cookie or local identifier is approved. This must be rechecked against the exact release build and hosting configuration. It is not a jurisdiction-wide legal conclusion.
Current service boundary
The True MVP has no accounts, payment, subscription, cloud sync, or hosted user-content storage. The browser-local contract covers Builder and Validator selections; the independent local Engine is third-party software with its own files, logs, source, license, runtime behavior, and risks.
Independent status
CodexSkin Tools is an independent project and is not affiliated with, endorsed by, or sponsored by OpenAI.
Preview URL lifecycle
A local preview may rely on a temporary browser object URL. The interface must revoke the prior URL when the selected image is replaced, revoke all active preview URLs on reset, and release them when the workspace is disposed. The URL is not a durable library record and should not be presented as one. Leaving or refreshing the tab may remove the preview and draft state, so users should save an intended export locally before ending the session.
Reports and integrity values
A validation report or export may contain locally computed metadata, structural results, and available SHA-256 values. The user chooses whether to save that report. The current browser-local flow must not silently send the report, selected filename, local path, JSON or image content, or full hash to a remote diagnostics or analytics service. Display a failed or unavailable local hash operation as an incomplete check rather than sending the file elsewhere or manufacturing an integrity value.
Release-time privacy review
This notice was reviewed against the static Cloudflare Pages release boundary on July 22, 2026: selected files remain browser-local; site-defined analytics, remote diagnostics, accounts, billing, Contact submissions, Cloudflare Access, Logpush, and custom server-side processing are disabled. Cloudflare still processes the request metadata described in Hosting to deliver and protect the site. Before enabling analytics, Access, Logpush, a Worker, Contact, accounts, billing, uploads, or another provider, the implementation and this notice must be reviewed and updated together.
States
Errors
Frequently asked questions
Are selected Builder and Validator files uploaded?
Under the current True MVP contract, selected images and theme JSON are processed locally in the browser and are not uploaded to CodexSkin Tools or an analytics provider.
Does the site use analytics cookies now?
No third-party analytics script or analytics cookie is loaded while analytics remains disabled in the True MVP.
How can I make a privacy request?
The Contact route may handle privacy requests only after a real delivery channel and its privacy, retention, and security controls are configured and reviewed. No submission is available now.