Privacy Policy
Effective date: September 5, 2026
Keyphore is a free Mac utility maintained by Barry Barry Wu. This policy covers the Keyphore app and this website. Its core purpose is to turn local Codex task events into keyboard lighting signals, not to collect your work.
1. What the app processes
After you approve the Codex integration, Keyphore processes lifecycle event types, session, agent and turn identifiers where applicable, and receipt times. It uses these fields to calculate task states and summary counts. Hook payloads are filtered to these allowed fields; prompts, responses, transcripts and tool content are not retained as task records.
Keyphore also processes your lighting preferences, setup and consent state, and keyboard connection and protocol health. Device discovery uses hardware metadata such as model/product information, vendor and product IDs, interface information and transport type. It does not record what you type.
2. Local storage and permissions
Task state, settings and managed diagnostic state are stored on your Mac, primarily in ~/Library/Application Support/Keyphore. Integration also creates Keyphore-owned Codex configuration and user-scoped background registrations. Keyphore has no product account or cloud synchronization and does not automatically upload task data, telemetry or diagnostic reports.
Setup asks for approval before installing and enabling its Codex Hooks. Changed Hook definitions require renewed approval. macOS may require Input Monitoring permission for USB HID communication; Keyphore uses that access for keyboard lighting commands and protocol responses, not keystroke logging. Login launch can be disabled in settings. Permissions can be revoked in macOS System Settings, which may stop related features.
3. Diagnostics you choose to share
You can review and export a diagnostic ZIP. It contains app and macOS versions, Codex integration, Hook and background-component health, keyboard/protocol status, redacted error health and, when available, lighting-test time and results. The report excludes conversation content, usernames and full local paths. It is saved to a location you choose, not uploaded automatically.
If you contact us, we receive whatever contact information, message or report you send. We use it to respond and troubleshoot, retaining it only as needed for that purpose or legal obligations. Review attachments first and avoid posting sensitive material in public support channels.
4. Updates and external services
When a release has a configured update feed, Keyphore uses Sparkle to check for updates automatically and when requested. Update servers receive normal request information, including an IP address and request headers, which may identify app or system versions. Installation requires your approval. Task records and diagnostic ZIPs are not part of update requests. Builds without a configured update channel cannot perform these checks.
Codex, download hosting and websites opened from the app operate under their own privacy policies. This policy does not describe or control how OpenAI processes your Codex work.
5. This website
The site stores your chosen language in browser local storage under keyphore-language. Clearing this site's browser data removes it. Theme selection follows your system preference. The site's own code does not set advertising cookies or include advertising or behavioral analytics scripts.
Cloudflare hosts and delivers this site. It may process IP addresses, request times, URLs and technical request information to deliver, secure and operate the service. Infrastructure processing may occur outside your country; provider retention and safeguards are described in Cloudflare's Privacy Policy. Visiting GitHub, Tutti or social links is a separate interaction with the destination service.
6. Retention and your choices
Local settings and managed files can remain until changed or removed; task state is updated as events are processed and is not a permanent task-history service. Use Keyphore's in-app removal flow before deleting the app to remove its owned integration, background registration, profile and managed state. Simply dragging the app to Trash is not the same cleanup. Exported ZIPs, backups and browser storage are separate and remain under your control.
We do not sell your task information or use it for advertising. For information you send us directly, you may request access, correction or deletion, and exercise any other rights available under applicable law. Because task records stay on your Mac, we cannot retrieve or delete those local records remotely. No storage or transmission method can be guaranteed perfectly secure.
7. Contact and changes
For privacy questions or requests, contact Barry Barry Wu via X (@BarryBarrywu) or the contact channels on the developer's website. Do not send passwords or Codex conversation content. If data practices change, this page's effective date will be updated; additional permission will be requested where required.