Cmdexa← Back to Cmdexa

Cmdexa privacy policy and telemetry

Last updated: 6 October 2026

1. Who is responsible

The controller of personal data processed by the Cmdexa service is:

Paweł Meller, a sole proprietor, Kaszubska 7, 81-813 Sopot, Poland, NIP 5833097492, REGON 385413838. Contact: kontakt@cmdexa.com

2. What this policy covers

  • the Cmdexa Windows agent and user helper that you install;
  • the Cmdexa relay at relay.cmdexa.com and its dashboard;
  • the public website at cmdexa.com.

It does not cover your AI provider (for example ChatGPT). When you connect Cmdexa to an AI client, the client receives the output of the tools it calls and handles it under the provider's own terms and privacy policy.

3. What Cmdexa is, in one paragraph

Cmdexa lets an AI client run read, search and command tools on a Windows computer you choose. The agent on your computer connects outbound to the relay. The relay passes requests from your AI client to the agent and returns results. You can revoke a device at any time.

4. Data we process

CategoryExamplesWhere it livesWhy
Device informationdevice ID, host name, agent and helper version, protocol version, capabilities, executor health, connection stateRelay memory and relay state filesShow which devices are online and route requests to the right one
Credentialsdevice credentials, pairing codes, OAuth client records, OAuth refresh tokensRelay credential store. Refresh tokens are stored hashed; raw refresh tokens are not keptAuthenticate devices and AI clients
Task datatask ID, request ID, device ID, working directory, execution context (run_as), a command preview, a SHA-256 of the command, status, exit code, error code, timingRelay task store, which can be persisted to a task history fileRun the task, show its progress, diagnose failures
Task outputbounded stdout and stderr, output-gap markersRelay task store, same limits as aboveReturn results to your AI client
Audit entriesstage, device ID, task ID, request ID, command SHA-256, working directory, run_as, policy class, status and error codes. The raw command body is not storedBounded, in-memory audit log on the relayShow what happened and why an action was allowed or blocked
Tool historyredacted records of MCP tool callsOptional JSONL file on the relay, only if the operator enables itDebugging and support
Connection dataIP address and request metadata, which can appear in ordinary server logsRelay serverOperate and secure the service
Contact messagesyour email address and what you write to usThe operator's mailbox. Mail sent to @cmdexa.com addresses is forwarded through Cloudflare Email RoutingAnswer you

We do not collect more than the above to run the service. We do not sell personal data and we do not use advertising trackers.

Tenant data is separated by account for public MCP users. The relay operator's private administrative API has broader service-wide access: the operator can inspect tenant device and task metadata, task output and artifacts, and can issue commands to connected devices. Whether a command can run as SYSTEM depends on device permissions and local execution settings. Administrative actions are recorded in the relay audit data and are limited to service operation, security and support.

5. What stays on your computer

  • C:\ProgramData\Cmdexa\agent.json: relay URL, device ID, device credential and optional local limits;
  • C:\ProgramData\Cmdexa\update.log: updater activity;
  • the installed agent under C:\Program Files\Cmdexa\ and backups the updater keeps for rollback;
  • the user helper and its local state in your Windows profile (used for run_as=user actions and local approval prompts);
  • a local replay spool of recent task output, used to replay output after a reconnect.

Files your AI client reads or writes through Cmdexa stay on your computer unless the AI client reads them and the tool output is returned to it (see section 6).

6. What your AI client receives

Whatever a tool returns goes to your AI client, and from there to your AI provider. That includes file contents you ask it to read, command output, and search results. Cmdexa cannot recall data after it has been returned to the AI client.

Connect Cmdexa only to AI clients and accounts you trust, and only to computers you are allowed to administer.

7. Screenshots

screen_capture_v1 captures one screenshot per request that you approve on the computer itself, every time. The screenshot is saved as a PNG file inside the workspace on your computer. The tool does not return image bytes directly. If your AI client then reads the file with an image-reading tool, the image is returned to that client like any other tool output. Do not capture screens that show information you are not willing to share with your AI provider, or people who have not agreed to it.

8. Redaction, and its limits

Cmdexa redacts secrets in several diagnostic tools (for example configuration reads, environment information, log search and tail, startup items, and the support diagnostics bundle). It also blocks its file-reading tools from returning known credential locations, such as the Cmdexa configuration file, SSH keys, .env files and common credential stores.

These are defensive filters, not a guarantee. They do not protect arbitrary commands run through the execute tools. If you ask Cmdexa to print a secret, it can return it. Do not paste tokens, pairing codes, private keys, cookies or full installer commands into an AI chat or a bug report.

9. How long we keep data

The relay limits what it keeps. The default limits in the Cmdexa software, which the operator can change, are:

  • 4 MiB of output per task;
  • 1024 replay events per task;
  • terminal tasks kept for 1 hour;
  • at most 10,000 terminal tasks;
  • at most 25 concurrent public tasks per tenant;
  • at most 100 stored artifacts and 64 MiB of artifact data per tenant;
  • at most 60 public MCP and artifact requests per tenant per minute;
  • the in-memory audit log is bounded and is not kept across restarts.

The operator can change the per-tenant defaults through relay configuration.

Ordinary server logs are kept only as long as needed to operate and secure the service. Contact messages are kept for up to 12 months after the last message. You can ask us to delete data we hold about you (see section 13).

10. Who we share data with

  • Your AI provider, as described in section 6, because you chose to connect it.
  • Hosting provider: Oracle Cloud Infrastructure, region Frankfurt, Germany, which runs the relay server.
  • Cloudflare: DNS for cmdexa.com and email forwarding for @cmdexa.com addresses.
  • Email provider: messages sent to @cmdexa.com addresses are forwarded to the operator's mailbox at Google (Gmail).
  • Authorities or other third parties only where the law requires it.

The agent and updater connect only to your configured relay (by default relay.cmdexa.com). Cmdexa does not include third-party analytics, advertising or crash-reporting services.

11. Cookies and tracking

The public website at cmdexa.com does not set cookies, run scripts or load third-party resources at the time of writing. The private dashboard, which only you and the operator use, keeps your API token in the browser tab's session storage so you stay signed in while the tab is open.

12. Legal bases

We process the data above to provide the service you request (performance of a contract or steps before a contract), to keep it secure and reliable (our legitimate interest), and to answer your messages (our legitimate interest or your request). Where the law requires consent, for example for screenshots of other people, you are responsible for obtaining it.

13. Your rights

If GDPR applies to you, you can ask us for access to your data, correction, deletion, restriction of processing, a copy in a portable format, and you can object to processing based on legitimate interest. To use these rights, write to kontakt@cmdexa.com. You can also complain to the supervisory authority, in Poland the President of the Personal Data Protection Office (UODO).

You can also act directly: revoke a device from the dashboard to cut off its access, and rotate its credential to invalidate the old one.

14. Transfers outside the EEA

The Cmdexa relay is hosted in Germany (EU). Cloudflare, which handles DNS and email forwarding for @cmdexa.com addresses, and Google, which provides the operator's mailbox, can process data outside the EEA under their own data protection terms. Your AI provider may also process data outside the EEA under its own terms.

15. Security

Connections use HTTPS. Agents authenticate with per-device credentials, OAuth refresh tokens are stored hashed, risky actions can require explicit approval on your computer, and new pairings start in read-only mode. No system is perfectly secure. Report a security problem privately to kontakt@cmdexa.com (see SECURITY.md).

16. Children

Cmdexa is for professional and technical use and is not directed at children.

17. Changes

If we change this policy in a way that matters, we will update the date above and, for registered users, tell them in advance.

Paweł Meller, Kaszubska 7, 81-813 Sopot, Poland · NIP 5833097492 · REGON 385413838kontakt@cmdexa.comPrivacyTerms