Skip to content

Reference

Data & privacy

What Codz reads on your Mac, what leaves it and when, and what Codz’s servers can and can’t see.

Codz is local-first. The free app reads what your agents have already written on your Mac and shows it there, and your usage never leaves the Mac until you choose a feature that syncs it. This page lists what does leave, where it goes, and what Codz’s servers keep.

The Privacy Policy is the formal version.

What stays on your Mac

To show your agents and their usage, Codz reads the files each agent’s own CLI keeps on the Mac, such as ~/.claude, ~/.codex, Cursor’s local database and ~/.local/share/opencode. It reads them in place and doesn’t read your documents. Full Disk Access, if you grant it, is what lets it read the ones macOS protects.

What Codz keeps of its own, such as your chats, projects, issues and settings, is stored on the Mac too. Signing out or cancelling Pro doesn’t delete any of it. Storage & memory covers what is kept where.

What your agents send

When you run a chat, the agent’s own CLI sends your prompt, and whatever it reads to answer it, to that agent’s provider, under that provider’s terms. The conversation doesn’t go through Codz’s servers, except end-to-end encrypted on its way to your phone if you use Codz Remote.

OpenRouter chats run on Codz’s own agent, which talks straight from your Mac to openrouter.ai. DeepSeek chats run on the DeepSeek Harness runtime, which talks to the DeepSeek API.

Logins and API keys

  • Agent CLIs keep their own logins. Codz starts Claude Code, Codex, Cursor and OpenCode with the login each one already holds, and doesn’t copy or store it. An extra Claude Code, Codex or OpenCode login lives in a folder of its own that the CLI signs in to; an extra Cursor login is a Cursor API key kept in the Keychain.
  • OpenRouter and DeepSeek keys stay in the Keychain. The OpenRouter key is sent only to openrouter.ai, and the DeepSeek key only reaches the DeepSeek runtime Codz starts, which sends it to the DeepSeek API. Neither is sent to Codz’s servers, written to logs or printed by codz. Codz never shows a saved key again.
  • Cursor’s account usage. To show what your Cursor account reports, Codz uses the session the Cursor app keeps on this Mac to ask Cursor’s own usage service. The session stays in memory and goes only to Cursor.
  • Your Codz sign-in. The Mac keeps it in the Keychain. Signing in itself happens in your browser, so Codz never handles your credentials.

What sync uploads

Sync runs only while you’re signed in with Pro and Sync usage is on in Settings ▸ Account. The first time you sign in with a Pro account, Codz turns it on unless you already chose a setting.

Each upload is a set of daily rows. A row holds:

  • a day, a provider and a model name,
  • token counts: input, output, cache read, cache write, reasoning and the billable total,
  • whether the figure is billable or reported by the provider’s account.

With them go a random device ID that Codz created for this Mac and the Mac’s name. Sync never uploads your prompts, conversations, code, file contents, diffs, terminal output or project paths.

The first sync sends every day the Mac still has. After that, Codz uploads what’s new a few minutes behind, and Sync now uploads all available history straight away. Rows land in your account, filed under the organization you sync to: Personal unless you choose a team. Sync & profile covers the details.

Codz Remote

Codz Remote is part of Codz Pro. Your Mac does all the work and keeps every credential, and a paired iPhone or iPad reaches only the projects you approve in Settings ▸ Connections.

Everything between your Mac and your phone is end-to-end encrypted. Codz’s servers pass the encrypted messages along, and keep the latest encrypted snapshot for each paired device, but never receive prompts, paths, commands, files, diffs, terminal output, screen captures, provider tokens or the keys that encrypt them. They do keep your Mac’s name, your paired devices’ names and when each was last seen. Notifications carry no prompts, code or output, only that something needs you. Remote security covers pairing and encryption.

Public profile and global stats

Both are off until you turn them on, both need Codz Pro, and both are switched off if Pro ends. You set them in your dashboard’s Settings on codz.com, or under Privacy in Codz Remote’s Settings.

  • Public profile. Anyone with the link to codz.com/username can see your username, display name and the activity built from your synced usage: daily token totals by provider, streaks, and how many models you used. Prompts, projects, files and provider account identifiers aren’t shown.
  • Global stats. Your synced totals join an anonymous aggregate of everyone who opted in, which carries no account identifiers. Turning it off takes you out.

Other requests Codz makes

A few other requests leave the Mac:

  • Update checks. Once a day, Codz asks codz.com which versions of the agent CLIs and which new models are current. The request carries no account, device ID or list of what you have installed; the comparison happens on your Mac.
  • Link icons. When a chat shows a web link, Codz fetches the site’s icon from Google’s favicon service, which receives the link’s site address but not the rest of the link. Local and private network addresses are never sent.
  • Images in replies. A picture in an agent’s reply that points at a web address loads from that address when it scrolls into view.
  • Automatic model picking. Off by default. If you turn on Pick the model automatically in Settings ▸ Agent & composer, each message you send, with the last few turns of the chat, goes to OpenRouter on your connected account so it can pick a model.
  • Installing an agent. When you install or update Claude Code, Codex or Cursor’s CLI from Codz, it downloads the publisher’s own installer from claude.ai, chatgpt.com or cursor.com.

Your account’s data

Your Codz account holds your email address, your username and display name if you set them, your plan, and the sessions you sign in with, including the IP address and browser or device each came from. If you sign in with Google, Apple or GitHub, it also keeps your account identifier there and that service’s sign-in tokens, encrypted; Codz doesn’t use them to read from or act on that account.

If you pay, Stripe or Apple takes the payment. Codz keeps only the subscription’s identifiers, status and renewal date, and never your card details.

To stop sharing usage, turn off Sync usage in Settings ▸ Account. To delete your account, email support@codz.com or use Delete account in Codz Remote’s Settings; deleting it removes your profile, your synced usage and your organization memberships. Codz account has the steps.