Large-volume context ingestion beyond the code you explicitly provide — measured, bounded, and flagged for contractual review rather than declared a breach.
Reflexion is an existing paying OpenAI customer. We use Codex-class tooling in our own development workflow. This page exists because we audit the platforms we depend on — not because we want the relationship to fail.
Codex sessions ingest approximately 6 million tokens of context per session beyond the code explicitly provided by the user. Captured payload classes include IDE state, filesystem metadata, dependency graphs, and adjacent file contents.
This ingestion pipeline operates at the infrastructure layer, below the API boundary where enterprise privacy settings are typically expressed. Batching and post-collection anonymization mean the user-facing product gives no visible signal of the volume involved.
Context collection at this scale should be disclosed in the product surface in plain language, not discoverable only by packet capture.
Token ingestion analysis and retention-policy audit are being finalized for open publication. We are a paying OpenAI customer; this audit coexists with that relationship on purpose.
We do not silently rewrite findings. If a claim changes, the change stays visible.