1. Scope and controller
Pagonya LLC publishes TokenX and operates pagonya.co. This policy applies to the TokenX plugin, visits to this website, and support email sent to Pagonya LLC.
2. TokenX plugin processing
Data categories and purpose
TokenX reads the current root prompt in memory to classify task complexity and choose a native Codex route. It produces route, model profile, reasoning effort, sibling-agent budget, bounded reason codes, timestamps, and opaque decision and session identifiers. Prompt-free session outcome counters may also record retry escalation, sensitivity denials, smart fallbacks, and the last delegated route. This processing enforces routing and concurrency policy and explains the selected route.
Storage and network behavior
TokenX stores no raw prompt, conversation transcript, model response, repository content, diff, credential, or authentication token. TokenX operates no separate classifier, analytics, telemetry, or other TokenX-controlled network service. For eligible uncertain work, it can invoke the user's configured Codex environment for one bounded classification assessment.
Retention
A routing decision expires after one hour by default
(decisionMaxAgeMs). Codex session-end cleanup removes
the session record when that event is delivered. Prompt-free
outcome counters use the same bounded window. User configuration
remains on the user's device until the user resets it, removes
plugin data, or uninstalls TokenX.
3. Website data
This website uses no analytics, advertising trackers, cookies, accounts, or JavaScript forms. When a browser requests a page, normal web-server logs can contain the IP address, timestamp, requested URL, response status, referrer, and user-agent string. Pagonya uses those logs only for availability, abuse prevention, and security investigation.
Website access and error logs rotate daily and are retained for no more than 11 days, including the active log, before deletion.
4. Support email
If a person emails support, Pagonya receives the sender's email address, name if provided, message, and attachments. Pagonya uses that information to answer the request, investigate defects or security reports, and maintain necessary support history.
Support correspondence is retained for up to 12 months after the last message, then deleted unless a longer period is required to address an active security incident or legal obligation. Senders should not include credentials, private prompts, proprietary source, or unnecessary personal data.
5. Recipients and sharing
- Amazon Web Services hosts this website and processes connection data needed to deliver it.
- Squarespace provides email forwarding for the support address and uses Mailgun to process support correspondence.
- OpenAI provides Codex. Prompt and model processing performed by Codex is governed by the user's OpenAI account, product, and workspace terms; TokenX does not send that data to Pagonya LLC.
Pagonya does not sell personal data, use it for targeted advertising, or share it with data brokers.
6. Your controls
Users can inspect TokenX diagnostics, remove stale local state, reset configuration, or uninstall the plugin. A support sender can request access, correction, or deletion of support correspondence by emailing info@pagonya.co. Pagonya may retain the minimum information required by law or an active security investigation.
TokenX is a developer tool and is not directed to children under 13.
7. Changes and contact
Pagonya will update the effective date and this page before a material change to TokenX data collection or hosted services. A new data category or hosted TokenX service also requires updated plugin review materials before publication.
Privacy questions can be sent through TokenX support.