Privacy Policy
Last updated: 14 August 2026
This Privacy Policy explains how CodedWords ("we", "us", "our") handles personal data in connection with the Plexus desktop application ("Plexus", the "App") and our website. We are committed to protecting your privacy and to processing personal data in line with the EU General Data Protection Regulation (GDPR).
Note. This policy describes the anonymous usage analytics Plexus collects (section 3), the feedback you can choose to send us — the one thing here that is not anonymous (section 3a) — and the managed connection service it uses when you connect a git provider (section 5).
1. Who is responsible
The controller for the processing described here is:
- CodedWords (a sole proprietorship / eenmanszaak established in the Netherlands)
- Registered address: Korhoenstraat 124, Tilburg, Netherlands
- KvK number: 75572214
- Contact: timo@codedwords.com
2. Plexus is local-first
Plexus is a desktop application that runs on your own computer. Your code, files, repositories, terminal sessions, credentials, and the prompts and Output you exchange with AI Agents stay on your device; nothing in the App collects them or sends them to us. The one way any of it can reach us is if you send it — by writing to us through Feedback and choosing to attach a picture of the Plexus window or a diagnostic log. That is a deliberate act, one submission at a time, and section 3a describes exactly what it carries.
Some data is stored locally on your machine so the App can work — for example, your settings, workspace and session state (in a local database), and any credentials you ask the App to store (kept in your operating system's secure keychain). This data does not leave your device except where you explicitly connect a third-party service (see section 5) or explicitly send us feedback (see section 3a). The one routine exception is that the App periodically checks our release server for updates (see section 4); that check carries no usage data and none of Your Content.
Three limited exceptions are described below. Two of them are automatic and carry none of your work: when you choose to connect a git provider we use a managed sign-in service (section 5), and Plexus sends anonymous usage analytics (section 3). Neither sends us your code, file contents, prompts, file paths, or repository names. The third is not automatic at all — feedback you write and send us yourself (section 3a), which carries whatever you type and, if you choose them, a picture of the App's own window and a diagnostic log that names repository paths and branch names. It happens only when you press Send, and the App shows you what is in it first. None of the three changes the local-first default.
3. Usage analytics
Plexus sends anonymous usage analytics so we can see how many people use the App, which parts of it they use, and where it breaks. This is part of how the App works and there is no setting to switch it off — because what it sends is anonymous: there is nothing in it that identifies you, and nothing that can be traced back to you, your machine, or your work. What keeps that true is set out below, and we hold ourselves to it. (Earlier versions of the App had a Share anonymous usage data setting. It has been removed, including on installs where it had previously been switched off.)
This section is about the analytics only. Feedback you send us is a separate channel with a separate legal basis, and the two never touch: a feedback submission carries no analytics identifier of any kind, and nothing in the analytics can be linked to a feedback item. See section 3a.
- At most one message a day. The App contacts us once per calendar day and not again that day. There is no per-action, per-session or real-time reporting, and no timestamp finer than the date. It is a daily summary, not a log of what you did or when you did it.
- What is collected. Your operating system and processor type (both coarse — e.g. macOS / Windows / Linux, Arm / Intel-AMD), the app version, and a random install identifier your copy of Plexus generates, which our server turns into a hash under a key that changes every day and never stores as it arrived. Alongside that, the message carries how much the App was used since the previous message — for example how many sessions were run, how many turns you exchanged with an agent, and how many times each feature or Git operation was used — plus a small set of coarse settings and environment facts: your colour theme, which AI model you have selected, whether a Git provider is connected, how many workspaces and projects you have as a range (such as "6-20") rather than an exact figure, your operating-system version, how Plexus was installed, your shell, and the version of the Claude CLI it is driving. We also count total downloads when you download the App.
- What the analytics never collect: your code, file contents, prompts, Output, file paths, repository, project or branch names, commit or pull-request text, error messages, your IP address, or any account or device identifier. Nothing you type is ever part of it, and every value we do collect is either a number or one of a fixed set of options — never free text. (Some of those can appear in a diagnostic log you choose to attach to feedback — that is a different channel, described in section 3a, and it never rides on the analytics message.)
- Why it cannot be tied to you. The usage counts are added into shared daily totals the moment they arrive and are never stored against your install, so no record of "what this install did" exists on our systems at any point. Separately, the daily hash lets us count how many distinct installs were active — and because the key changes every day, the same install looks like a different, unrelated value tomorrow. Those per-install rows are then deleted every night once they have been counted. What remains are aggregates such as "1,240 active installs on macOS running 0.18.0" and "18,300 sessions run in February" — nothing that could be linked back to an install, let alone to a person.
- The install identifier expires. The random identifier stored on your device is replaced with a new one after a year, so it does not persist indefinitely. The identifier is sent to us over an encrypted connection and hashed on arrival; we never store or log it as it arrived.
- All analytics data is stored within the European Union.
- Legal basis: the data is anonymous within the meaning of Recital 26 GDPR — it does not relate to an identified or identifiable person — so it is not personal data and data-protection law does not apply to it. To the extent any of it were nonetheless treated as personal data, we rely on our legitimate interest in maintaining and improving the App (Article 6(1)(f) GDPR).
- Switching it off completely. Plexus honours the
DO_NOT_TRACKandPLEXUS_NO_TELEMETRYenvironment variables — set either one before launching and the App sends nothing at all. Development builds never send analytics.
3a. Feedback you send us
Plexus has a Feedback button. It is entirely optional, it does nothing until you press Send, and — unlike the analytics in section 3 — it is not anonymous: you are writing to us, and what you write can say anything you choose, including things that identify you.
- What is always sent: the message you type, whether you marked it as a bug, an idea or something else, and a short list of technical facts about your copy of the App — its version, your operating system and its version, your processor type, how Plexus was installed, and the version of the Claude CLI it is driving. Those are the same coarse values the analytics use, and they carry no identifier.
- What is sent only if you choose it, on that one submission:
- Your email address — blank unless you type it. We use it to reply to you and for nothing else; we do not add it to any mailing list. Leave it blank and we simply cannot reply.
- A screenshot — nothing is captured until you press Attach screenshot, and you can remove it again before sending. It is a picture of the Plexus window only, drawn by the App from its own interface. It cannot contain another application, another monitor, anything behind or beside the Plexus window, or your desktop — and because it is not an operating-system screen capture, Plexus never asks for screen-recording permission. It can, of course, contain whatever your own code and file names were on screen at the time, which is why you see the image before you send it.
- A diagnostic log — a technical trace of what the App was doing. Before it leaves your device, Plexus blanks out anything shaped like a credential and rewrites your home folder and username. It deliberately keeps repository paths, branch names, worktree folder names, session identifiers, timings and error text, because those are what make the log useful; it never contains file contents, your prompts, or an AI Agent's Output. You can read the exact text that will be uploaded before you send it.
- What is never sent: your code or file contents, your prompts or an AI Agent's Output, the contents of any secret file, anything from your operating system's keychain, any git provider account you have connected, and any identifier from the usage analytics in section 3 — no install identifier and nothing derived from one.
- You see it before you send it. The App shows the message, the screenshot and the log text in the same dialog as the Send button. If it is not on that screen, it is not uploaded.
- Legal basis: your consent (Article 6(1)(a) GDPR), given by pressing Send on a submission the App has shown you, with the screenshot and the log as separate choices you make each time. You can withdraw it at any point by asking us to delete the submission (below).
- Where it is stored and who sees it: in the European Union, on the same infrastructure as our other managed services. Only our operators can read it, through a sign-in-protected admin panel. We do not use it for advertising, we do not profile you with it, we do not feed it to an AI model, and we do not sell or share it.
- How long we keep it: any screenshot or diagnostic log you attached is deleted after 90 days; the message itself, and the email address if you gave one, after 12 months. Both are enforced by an automated purge.
- Deleting it. When a submission succeeds, Plexus shows you a reference code and keeps it in a list on your device. Email that code to timo@codedwords.com and we will delete the submission and anything attached to it. We only ever delete on a code — we never read a submission back to whoever sends one. If you gave an email address, that identifies your submissions too. If you sent a submission without an email address and no longer have the code, we have no way of finding it — which is the other side of not being asked who you are (Article 11(2) GDPR).
4. Update checks and our website
To let you know when a new version is available, Plexus periodically contacts our release server — the public plexus-releases repository hosted on GitHub — to download a small update manifest and, if you choose to update, the new release. Like any web request, this reveals your IP address and the current app version to GitHub as the host, but it carries no usage data and none of Your Content. This is a routine update check, not the analytics described in section 3.
When you download Plexus from our website, the download button routes through a lightweight redirect that increments an anonymous total-download counter and then forwards you to the file hosted on GitHub. This records standard request metadata (such as your IP address in transient server logs, processed in the EU) but no usage profile and none of Your Content.
When you visit our website, our hosting provider may process limited technical data needed to deliver the site securely and reliably (such as your IP address in server logs). The website is a static site and does not currently use advertising or cross-site tracking cookies. If we add analytics or other cookies in the future, we will update this policy and provide any required cookie controls.
5. Third-party services you connect
Plexus lets you connect third-party services that you choose, such as:
- AI Providers (for example, Anthropic for Claude Code). When you run an AI Agent, your prompts and the relevant parts of Your Content are sent directly from your device to that AI Provider under that provider's own terms and privacy policy. We are not a party to, and do not control, that processing.
- Git hosting providers — GitHub and Bitbucket — when you sign in to manage repositories or pull requests.
Managed connection service (OAuth broker). When you connect a git provider, Plexus uses a small service we operate in the European Union to complete sign-in. The provider returns a short-lived authorization code; the service exchanges it for an access token (and refreshes it) using our confidential app credentials, and the token is returned to your device and stored in your operating system's keychain. We do not receive or store your repositories, pull-request contents, or code — after sign-in your device talks to the provider directly. We process only the minimal technical data needed to complete the exchange (such as the authorization code and the provider's token responses), on the legal basis of performing the connection you asked us to make.
Permission checks on a connected provider. A provider can narrow what an already-issued token is allowed to do, and nothing tells the App when that happens — so while a git provider is connected, Plexus makes one small request to that provider to check whether the token it holds still carries the access the App needs. This runs shortly after the App starts, when the window regains focus, on a background timer that pauses while the Plexus window is hidden, after a run of refused provider requests, and after you sign in again. Each check goes directly from your device to GitHub or Bitbucket; it carries the access token already in your keychain and nothing else — no code, file contents, file paths, repository names, or usage data — and Plexus reads only whether the request was allowed and which permissions the provider names in reply. Nothing about it reaches us: the request does not pass through our servers, we are not told that it happened, and the result stays on your device (as with every provider call, a token close to expiring is refreshed first through the managed connection service described above). Repeat checks are throttled — once a provider has answered, Plexus waits six hours before asking it again, though a check that could not reach the provider, or a refusal you run into while working, can make it ask sooner. You can change that wait, or stop the checks entirely, with Check that provider connections still work and How often to check provider connections (hours) under Settings → Git & PRs; turned off, no such request is made at all. Disconnecting the provider stops it too.
Pull request review comments. When a session has a pull request, Plexus can show that pull request's review conversation in the Review tab. It is requested directly from GitHub or Bitbucket by your device, using the token in your keychain — only when you open the Review tab, when the App window regains focus, or when you press Refresh; the conversation itself is never fetched on a background schedule, and never through us. If you reply to a thread, post a new comment, or resolve one, the text you write and the action you take go straight from your device to that provider, where they are published on the pull request under your provider account and are then governed by that provider's own terms and privacy policy. The same applies when you choose to publish an inline note that was stored on your device: its text — including text an AI Agent drafted for you, which the published comment marks as such — is sent from your device to that provider and published on the pull request under your provider account, and the local copy is then deleted from your device. Nothing is published without you asking for it, note by note or as a batch you confirm, and nothing about it passes through us. The conversation that comes back — including other people's usernames and the comments they wrote — is kept in memory on your device only: it is not written to the local database and is not sent to us. Comment bodies are rendered with remote images and other remote media blocked, so opening a review does not cause your device to request anything from a third-party image host. If you choose to send review comments to an AI Agent, their text becomes part of the prompt sent to your AI Provider, as described above.
Commit author avatars (Gravatar). The project Git client can show avatars next to commits. To resolve an avatar, Plexus sends a one-way SHA-256 hash of a commit author's email address (taken from your local repository's history) directly from your device to Automattic's Gravatar service (gravatar.com), which is how Gravatar is designed to be queried; the email address itself is never sent, and we receive nothing. Results — including "no avatar exists" — are cached on your device so each author is looked up at most occasionally. You can turn this off with the git.avatars.gravatar setting (Settings → Git), in which case Plexus renders initials locally and makes no request. Gravatar's own processing is described in Automattic's privacy policy.
Automatic fetching from your git remotes. The project Git client periodically runs git fetch in the background so that branch ahead/behind counts and the commit graph stay current. These requests go directly from your device to the git remotes you configured yourself (for example your GitHub, Bitbucket or self-hosted server), using the credentials git already holds on your machine; nothing is sent to us or to any third party we control, and we receive no notice that a fetch happened. It only downloads — nothing in your repository is merged, checked out, deleted, or otherwise changed. Fetching pauses while the Plexus window is hidden, and you can turn it off globally or for a single project with the Fetch from remotes automatically setting (Settings → Git & PRs), or from the Pull button's menu in the project Git client.
We encourage you to review the privacy policies of any service you connect. We are not responsible for how those third parties process your data.
6. How long we keep data
Data stored locally on your device remains until you delete it or uninstall the App. For the analytics described in section 3, the usage counts are never stored per install at all — they are added into shared daily totals on arrival — and the per-install rows used to count active installs are deleted every night, as soon as the day they belong to has been counted. What is left are aggregate totals per day, which hold no per-install value and which we keep for up to 400 days. We do not retain provider tokens — they live only in your keychain.
Feedback you send us (section 3a) is kept on its own clock, because it is the one thing here that is not anonymous: a screenshot or diagnostic log you attached is deleted 90 days after we receive it, and the message and any email address you gave after 12 months. A submission you ask us to delete is removed sooner.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability, where these rights apply. Because Plexus is local-first, most data is under your direct control on your own device. For any personal data we process, you can exercise your rights by contacting us at timo@codedwords.com.
For feedback you have sent us, the practical route is the reference code described in section 3a. Where you sent a submission without an email address and no longer hold its code, we cannot tell which submission is yours, and Article 11(2) GDPR applies.
You also have the right to lodge a complaint with a supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
8. Children
Plexus is not directed to children and is not intended for use by anyone under 18.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will update the "last updated" date above and, for material changes, provide additional notice where appropriate.
10. Contact
Questions about this Privacy Policy or your personal data? Contact us at timo@codedwords.com.