Back to home

Privacy Policy

How sign-in information and submissions are handled in our community gallery.

Last updated: 2026-09-15

About this policy

Codex Pulse is an independent community gallery for AI-generated pelican drawings. This policy explains what we handle when you browse, sign in, submit a drawing, or contact the project.

Sign-in and account information

You can browse public drawings without signing in. Available sign-in methods may include Google, X, and an email code.

  • Google: we receive your provider account identifier, name, profile image, email address, and email verification status to create your account and authenticate you. We request basic identity permissions, not access to Gmail or Drive.
  • X: we receive your provider account identifier, name, username, and profile image. X sign-in works without an email address. If no email is supplied, we use an internal non-deliverable identifier; it is not a verified email address. We request read-only permissions for your profile and posts, which X requires for identity lookup. We do not request permission to post or send messages.
  • Email codes: we process the address you enter and send a sign-in code through the configured email delivery provider. Verification records are used to check the code and limit attempts.

We store account and session records, including provider identifiers and authentication tokens returned by the sign-in provider, to operate sign-in. Provider passwords are not shared with us. Your account email and profile details are not included in public gallery posts.

Drawings and publication

We store the image, title, model name, prompt, submission language, timestamps, and moderation status you submit or generate through the service. Images are processed for display and sharing.

Pending and rejected submissions are visible to their owner and authorized moderators, not public gallery visitors. Once approved, the image, title, model, prompt, and publication page can be viewed, downloaded, shared, and indexed by search engines. Do not include personal information, secrets, or confidential material in a drawing or its text.

Cookies, security, and service providers

We use cookies and browser storage to maintain sessions, remember language and display preferences, and protect sign-in. A referral cookie may record a campaign source when one is present in a link. Blocking cookies can prevent sign-in from working.

Session information can include IP addresses and browser information. Hosting logs and rate-limit records help operate the service, investigate errors, and prevent abuse; rate-limit identifiers are hashed. We do not use these records to publish your identity in the gallery.

Cloudflare provides hosting, database, image processing, and storage. When email sign-in is available, Cloudflare or Resend processes the destination address and code for delivery, depending on the configured provider. Google and X handle their own sign-in pages under their own policies. We use provider data for account access and service operation; we do not sell it. Public links to GitHub and social sites take you to services with their own policies.

Optional analytics

Google Analytics 4 loads automatically on public gallery, drawing, and guide pages and measures visits using cookies and technical information such as browser and device details. Use Analytics settings to decline or re-enable analytics; declining stops measurement and removes the site's Google Analytics cookies. A saved decline is respected on future visits in the same browser. If browser storage is unavailable, your choice applies only to the current page session.

We measure successful prompt copies, share-link copies, clicks to share on X, and download clicks on public pages. Share and download clicks record intent, not confirmation that a post was published or a file was saved.

We send a public page URL without query parameters or fragments and a generic page category. We do not send your account identifier, email, form contents, drawing prompt, or user-entered title. Login, submission, moderation, and account pages are excluded. Advertising storage, Google signals, and advertising personalization are disabled. Google processes analytics data under its own privacy policy.

Deletion and your choices

You can delete your own submission from My posts. Successful deletion removes its gallery record, stored image, and generated share image from the service. Copies previously downloaded, shared, or indexed elsewhere may remain outside our control. Rejection hides a submission from public view; it does not delete it.

Deleting a submission does not delete your sign-in account or security records. You can revoke the app's access in your Google or X account. For account data access, correction, or deletion requests, contact the project as described below; there is no self-service account deletion page. We do not promise a fixed automatic retention or deletion period for account, security, or hosting records.

Contact and changes

Use the project's GitHub issues for policy questions or to ask how to arrange an account-data request. Issues are public: do not post email addresses, credentials, sign-in codes, or other private data. Ask for a suitable way to provide any information needed to verify ownership before sharing it.

We will update this page and its date when these practices change.