Privacy policy

Updated October 3, 2026

Who we are

CodexPluginStats is an independent plugin catalog and archive. It is not operated by or affiliated with OpenAI. For privacy questions, contact hello@dinershtein.com.

Information we handle

  • Account information: your email address, a password hash and account/session records. If you connect Google or GitHub, we store the provider name and account identifier; we do not store your provider password.
  • Your choices: followed plugins, saved preferences and any plan interest you submit.
  • MCP connections: the connecting client, permissions, token hashes, connection dates and recent use. Access and refresh tokens are issued to the client; their plaintext values are not stored in our database.
  • Requests and diagnostics: the search text and tool arguments needed to answer a request, along with technical information such as IP address, request path, time and errors used to run and protect the service.
  • Support: information you choose to send by email.

How we use it

We use this information to authenticate you, save your preferences, answer catalog requests, operate connections, prevent abuse and provide support. We use session cookies for sign-in and account functionality. The site currently does not include advertising trackers.

Discovery measurement

We use our first-party session to measure whether visitors arriving from search, AI assistants, directories or campaigns explore the catalog, follow plugins and return to their Following list. Measurement records contain a pseudonymous session identifier, source/campaign label, landing-page path without query parameters, event type and time; they do not contain search text, email addresses or IP addresses. Records are retained for up to 30 days and used to compare acquisition channels. Browser Do Not Track and Global Privacy Control signals disable this measurement. No third-party advertising tracker is used. Return counts describe browser sessions, not verified unique people.

Google Analytics

When enabled, Google Analytics measures visits and page usage using cookies and browser/device information. Page URLs and referrers omit query strings and fragments. We do not send account identifiers or email addresses, and disable Google Signals and advertising personalization. We also count plugin, guide and report views, search result counts, selected plugins, clicks to marketplace listings, follow attempts and successful follows, successful registrations, reviewed changes, visits to Following and Pro early-access requests. Events can include public plugin IDs, page type, guide identifiers and link placement. Validated campaign source, medium, name, content and ID labels are sent separately from cleaned page URLs. These events do not include form contents or search text. Do Not Track and Global Privacy Control disable loading Google Analytics. Google processes this information under its own privacy policy.

Connected assistants and providers

MCP returns catalog descriptions, archived files and change evidence to the assistant you connect. Our catalog tools do not return your email, password or private Following list. Your assistant provider processes its conversations and tool results under its own policies.

Hosting and email providers process information necessary to operate the service and handle support. Google or GitHub processes its own sign-in flow when you choose that method. Data may be processed in the countries where these providers operate.

Retention and control

Account records and preferences remain while your account is in use. Operational records and backups may outlast individual sessions. Disconnecting an assistant revokes its connection; it does not delete your account or copies already received by that assistant.

Email hello@dinershtein.com from your account address to request access, correction or deletion. We may verify ownership. Deleted data may remain in backups until those backups are replaced.

Catalog source material

We separately collect plugin listings and available packages to document their contents and observed changes. Publisher names and contact details may appear in that source material. Contact us to report inaccurate information or a concern about archived content.

Changes

We update this page when our data practices change and revise the date above.