Privacy

VDO.Ninja Connect is maintained by Steve Seguin. This page describes the browser client, local background service and hosted connector software.

What the software processes

The browser stores your private pairing key locally so it can reconnect. The background service stores pairing keys, conversation identifiers, recent request records, selected files and connection settings on its computer. Codex stores its own conversation history. Messages and attachments that you submit to a model are processed by that provider.

The hosted MCP connector stores a separate pairing key, OAuth client registration, hashed tokens and request fingerprints. Its stored database is encrypted with a deployment key. It processes explicitly sent messages, replies and selected text files in memory to pass them between your client and agent. It does not store message bodies or file contents in its connector database and does not read your other conversations or arbitrary local files.

Why and with whom

Pairing keys and tokens authorize your chosen connection. Request identifiers and fingerprints prevent repeated work. VDO.Ninja infrastructure provides signaling and optional TURN relay. Connected WebRTC peers may learn each other's IP addresses. GitHub Pages serves the public browser client. A hosted connector's operator and infrastructure process its traffic. The configured model provider processes your requests; OpenAI processes recorded audio submitted for transcription. Browser dictation may use your browser vendor's speech service, and speech synthesis uses your device's available voices.

Retention

Browser pairing data remains until you use Forget this pairing or clear site storage. Background files and conversation records remain until removed on the agent computer. Recent completed request records are eligible for pruning after twenty minutes when more requests arrive. Codex history is managed separately.

Hosted authorizations last up to seven days, bounded by the invitation expiry. Access tokens last at most one hour; refresh tokens expire with the authorization. Expired grants and tokens are removed on the next maintenance cycle, normally within one minute while the service is running. OAuth client registration metadata remains until the operator removes it, so clients can reconnect without invalidating their registered client ID. Revoking a hosted connection removes its credentials, tokens and request references immediately. In-memory rate-limit counters expire after one minute. Hosting providers may retain network access logs under their own policies; deployment operators should disable request-body logging and define their infrastructure log retention.

Your controls

Use Disconnect agent to remove hosted access. Revoke the paired peer on the agent computer to block it and cancel its requests. Forget this pairing removes browser credentials; it does not revoke a copy held elsewhere. Delete selected files through the client and remove retained local history through the relevant application. Closing the browser does not stop the background service.

Microphone and camera capture begins only with your action. File transfer does not automatically attach content to a model request. Avoid sending passwords, API keys or other sensitive credentials as message content. Paste a fresh pairing invitation only into the dedicated connection or consent page.

Contact

Use the support page for questions. Public support issues must not include private invitations, tokens or personal file contents.