aayygent

Privacy / plain language

Privacy promise

Your work stays yours.

Last updated August 2, 2026.

Ayygent is designed so the hosted relay never needs your prompt, Codex response, source code, commands, files, or filesystem path.

What leaves your computer

An anonymous installation identifier, a deduplication identifier, the completion time, and either a short project alias or the generic word “Codex.”

What never leaves through Ayygent

Prompt text, assistant output, reasoning, tool output, code, diffs, logs, repository remotes, absolute paths, credentials, and files.

What stays on your computer

Ayygent keeps its installation setting, project paths and aliases, completion identifiers and times, delivery status, and a bounded retry queue locally. The installation secret is kept in macOS Keychain or Windows Credential Manager. Local history and queued notifications can be deleted from Settings.

What the relay retains

The relay keeps an installation identifier and hashed secret, your Telegram chat identifier and optional username, project aliases, opaque completion identifiers, completion times, delivery status, notification usage, and license-provider identifiers. Short-lived hashes derived from network addresses are used only for abuse limits; raw network addresses are not stored in the application database.

Telegram

The final fixed notification is delivered through Telegram and is consequently subject to Telegram's own storage and privacy practices.

Payments

Payment information is handled by the checkout provider. Ayygent retains only the identifiers needed to issue or revoke a license and meet legal accounting obligations.

Service providers

Ayygent uses OpenAI Sites and its Cloudflare infrastructure to host the relay, Telegram to deliver messages, and Lemon Squeezy to process purchases, receipts, taxes, and license keys. Those providers process the limited information required for their part of the service under their own privacy terms.

Retention

Removing Ayygent's app data deletes local notification history. Hosted completion records are removed after 30 days. Expired pairing and checkout sessions are removed after 24 hours. Legally required transaction and active-license records may be retained longer.

Your controls

Settings lets you disconnect Telegram, delete local history and the pending queue, view a redacted diagnostic report, or delete this installation and its relay delivery data. Accounting and fraud records that must be retained by law or the payment provider are not erased by deleting an installation. Questions or deletion help can be sent to support@ayygent.com.