Public trust surface
Privacy,
without ambiguity.
Codex Cortex keeps website hosting data separate from Cortex product authority. The public MCP is a narrow release-authority service, not a repository or project-data service.
01 / Website
Hosting analytics are not Cortex telemetry.
Cloudflare hosts and protects this website. It necessarily processes ordinary connection information, such as IP addresses, timestamps and request metadata, to deliver and secure the site.
Cloudflare Web Analytics runs a browser beacon on page views. Cloudflare documents that the beacon receives a page-load identifier; referring and landing page URLs; and navigation, resource, paint, timing, Web Vitals and browser-memory measurements when available. Its analytics dimensions can include country, host and path, referrer, device type, browser, operating system and navigation type.
Cloudflare says it retains unsampled beacon data for seven days, then keeps an approximately ten-percent aggregate for longer-term reporting; the Web Analytics interface exposes the previous six months. The beacon does not use cookies or other browser storage. Cloudflare receives the source IP during ordinary HTTP handling and says it discards that address at the nearest data centre rather than storing it in the RUM service's core databases or logs.
This website analytics describes visits and website delivery. It does not mean Cortex observes repositories, projects or engineering work, it is not Cortex product telemetry, and it is not used to adapt Cortex behaviour.
The website has no Cortex account system and does not add another analytics provider, remote font, advertising tracker or behavioural profile.
02 / Public Cortex MCP
A narrow, authless release authority.
The public Cortex MCP at mcp.codex-cortex.com resolves signed public release, compatibility, withdrawal, schema and Cortex Instant profile information. It does not inspect or operate on a project.
What it accepts
Tool requests contain only a capability choice, a client plugin version and a bounded list of supported schema versions. Public resource requests identify signed public authority artifacts.
What it does not accept
- Repository source, files or paths
- Git state, diffs or commit history
- Project or repository names
- Conversation or prompt content
- Credentials, secrets or account identifiers
- Cortex intervention telemetry
There are no service accounts and no behavioural profiling. Repository inspection, writes, Git operations and repository-specific validation remain local.
03 / Observability
Operational signals contain no project content.
Worker invocation logs are disabled. Sampled application events contain only bounded operational facts such as event class, operation class, HTTP status, latency bucket, rate-limit events and bounded error class. They do not contain request inputs, response content, resource contents, IP addresses, user agents or request identifiers.
Application events are sampled at one percent and retained in Cloudflare Workers Logs for no more than seven days. There is no application log export destination.
Cloudflare still necessarily processes ordinary network metadata—including IP addresses and timestamps—to route, protect and operate the public service. This infrastructure processing is distinct from Cortex product telemetry.
04 / Contact
Questions or corrections.
For questions about this notice, use the support route. Do not send credentials, secrets or proprietary repository contents.