TiboTattle Download

Privacy overview

Your dashboard belongs on your device.

TiboTattle separates personal analysis from public community evidence. Local usage remains useful without an account or contribution.

Public website

This website cannot read local Codex files. It serves product information, current download availability, and a reviewed aggregate community snapshot when one is published. It does not enroll contributors or accept uploads.

Local source inventory

TiboTattle processes metadata in the selected Codex sessions and archived_sessions folders. It also reads Codex state_5.sqlite for rollout lineage, config.toml for service-tier settings, the installed Codex app-server account/read, account/rateLimits/read, and account/usage/read methods.

Local processing and storage

Source records are parsed on your Mac. Prompts and response text may exist in Codex's own rollout files, but TiboTattle does not retain them in derived state. It stores content-free indexes, settings, cached calculations, checkpoints, and prepared contributions in the owner-only Usage Monitor Application Support root. Pseudonymous identity and device credentials use the macOS Keychain.

Processes and network

The app starts a loopback-only local companion and the installed Codex binary's local app-server subprocess. Local analysis works offline. Network access is limited to explicit capabilities such as signed update checks, hosted sign-in, contribution, device disconnect, and public aggregate reads; the website cannot reach the loopback dashboard.

Optional contribution

In the Electron app, fresh installations enable sharing automatically. No social sign-in is required. You can turn sharing off in Settings or Community; that choice persists across restarts and upgrades that preserve your app profile. Local analysis keeps working with sharing off.

  • Saved sharing choices are preserved. Known off, paused, or disconnected installations stay off.
  • An existing installation with no prior choice receives three visible notices while sharing stays off. Activation requires all three notices, at least seven days from the transition's start, and at least one day after the final notice.
  • Choosing Share now or Keep sharing off cancels the remaining reminders. Unreadable or uncertain preference state does not enable sharing.

Shared measurements can include token counts, model labels, quota observations, and pseudonymous continuity identifiers. They exclude prompts, responses, credentials, private paths, and raw account identifiers. The public website has no enrollment or upload control. Older native Mac releases retain their review-and-approve flow.

Hosted identity and data

Accountless sharing uses an installation credential to authenticate one contribution source. It does not prove a unique person, a unique provider account, or the truth of a measurement. A separate device or reinstall without retained state can become another source. Retries within one retained installation are deduplicated; independently created installations can submit overlapping history.

The older Google or Apple sign-in flow proves control of that login, not one unique person. It stores a keyed identity hash rather than the provider's name or email. Accepted contributions are closed, content-free telemetry. Validated closed metadata is stored in Cloudflare D1, while R2 holds only bounded encrypted quarantine objects. Admin operations are exposed only on the Access-protected admin host.

Shared measurements can include opaque account and plan-era pseudonyms, evidence categories, and plan labels. These can link observations within the same enrollment and destination. Accountless sharing uses the installation's current sharing policy; older review-and-approve flows retain their consent requirements. The measurements exclude raw provider account identifiers and do not make uncertain history verified. These pseudonyms are not published in community figures.

Community publication

Eligible contributions from signed-in or accountless installations can enter the public community sample. A contribution source is an installation/account track, not a unique person or verified OpenAI account. Separate installations may submit overlapping history. Receiving an upload does not itself publish it.

The daily view publishes activity totals and API-price-equivalent allowance estimates, including comparisons by plan and model. Estimates and visible sample counts may be based on a single source. Small samples are uncertain and can reveal that source’s estimated capacity, even though no source identifiers are published. This is not a guarantee of anonymity.

Daily publication has no minimum source count or per-source cap. Plan and model comparisons use closed UTC dates and omit stale, incomplete, or unstable estimates. Previously released sealed weekly snapshots retain their original eligibility rules, delay, account thresholds, per-account caps, and rounding. Those rules do not apply to the daily view.

Retention and deletion

The local display window is not a retention limit: accumulated owner-only evidence remains until you run an explicit local erase. Local erase and Keychain identity reset have separate consequences. Turning sharing off stops future automatic delivery; a request already sent may have reached the service. It does not delete previously accepted hosted history or local analysis. In the older sign-in flow, Disconnect this Mac stops that device's uploads; signing out only ends the hosted session and does not disconnect the upload device.

Accepted hosted contributions and aggregates have no blanket short retention limit. Hosted erasure is handled by the service owner, not an in-app deletion control. A deletion record is retained to prevent erased participant data from returning after a backup restore.

For privacy, rights, or erasure requests, see project support guidance. A dedicated private privacy-request intake channel is not documented there. Do not post account identifiers, credentials, or private records in public issues.

Uninstall boundaries

Ordinary app or Homebrew uninstall preserves local analysis state. Homebrew --zap removes the app's Application Support, cache, WebKit, and preference state, but not ~/.codex, Keychain identities, or data already contributed. Use the explicit local identity controls for Keychain state, and see the support guidance above for hosted erasure requests. Uninstalling or disconnecting does not erase hosted history.

What never enters a contribution

Contributions exclude prompts, responses, commands, repository and file paths, URLs, credentials, emails, account names, raw account identifiers, and arbitrary metadata. Unknown fields are omitted by closed schemas. If validation cannot prove a record safe, upload is refused rather than partially redacted or guessed.