Privacy incident exposes risks in screen-capable agents

I want to document a privacy incident with Codex and how it was handled, in case it affects others using agentic tools with screen-capture capability.

What happened (June 9, 2026): During a Codex session, the in-app/page screenshot tool timed out. Instead of stopping, Codex fell back to an OS-level full-desktop screenshot — with no consent prompt and no notification. That capture included an unrelated private browser window I had open, and the image was rendered directly into the conversation transcript. The agent itself acknowledged in the transcript that it had used a whole-screen fallback, that it captured the wrong (foreground) window, and — in its own words — “yes, I caused a privacy incident.”

Why this matters beyond me: the failure mode is silent by design. I only discovered it because I happened to scroll the transcript at the right moment. Any user whose primary capture fails could have arbitrary on-screen content captured and stored without ever knowing.

The handling (June 9 → today, June 14):

  • June 9: I filed a formal data-deletion request (dsar@openai.com) asking for erasure of the captured image and confirmation it wouldn’t be used for training. Case opened.
  • June 11: Rather than the privacy request being actioned, my paid Pro subscription was cancelled and refunded without my request, dropping me to the free tier. My free-tier limit was exhausted in 4 messages, effectively blocking my work until July 11.
  • Support told me reinstatement wasn’t possible and that I’d need to re-purchase at full price to restore the access I never asked to lose.
  • A support agent then asked me to send a screenshot of the captured private content with “only the sensitive part blurred,” plus a HAR file — i.e. to re-transmit the very private material I was asking them to erase. I declined that specific request as inappropriate and unnecessary. Instead, I provided precise technical identifiers from the session transcript — exact timestamps, transcript references, and cryptographic hashes of the captured images — which are sufficient to locate and verify the data on their side without any further exposure of the content.
  • As of today (June 14): my access is still not restored, and the actual privacy request — erasure and written confirmation — remains unresolved.

I’m posting this for awareness of the capture-fallback behavior, which I believe is a design issue affecting any user of screen-capable agents. I’ve pursued the resolution itself through the appropriate formal channels.

A few questions for the community:

  1. Has anyone seen Codex (or similar agentic tools) escalate to an OS-level full-desktop capture after an in-app/page screenshot failed?
  2. Has anyone been asked by support to resend sensitive content (even blurred) for a privacy investigation?
  3. Has anyone had a paid subscription cancelled and refunded without requesting it while a support case was open — and then been told the only way back is to re-purchase at full price?

I’d like to understand how common each of these is.

I have not seen this, but also I paid attention to the warnings on the product and don’t allow it access outside of the repo unless by request.

Hi guys, I have experienced security/privacy issue and support has not confirmed any actions on the case since 9th June.
2 days later they cancelled on their side my Pro subscription without my consent and request. I requested subscription to be re-established. There is no result till now.
What are SLAs for support as they are not stated anywhere?

I have detected similar behaviour in the last days of using it - 14 iterations to fix simple frontend bug that Codex created itself. It took it 3 days for deduplicating data that it produced which I solved under 3 minutes myself at the end.
Currently I am facing serious security/privacy breach caused by Codex tools and Open AI support is not taking any real actions to investigate it though I explicitly escalated it several times. It seems that there is no support or interest in security issues by Open AI.
I am not sure that I would recommend Open AI products to any one, on the contrary Open AI is not providing timely support. It is not acceptable for security/privacy issues about sensitive information no action to be taken for 96 hours now.

I have started a large business project and I cannot find Support SLAs, so I cannot proceed it as support is crucial for the large enterprises and is mandatory to be clearly stated? Based on my researches Open AI has never stated their SLAs. How can I get this information as my investors are insisting on this?

Hi @stan.vasev !

I am sure someone from support will reach out via support.openai.com or here in the community forum to look intothe account problem.

It is now a week for security/privacy incident and there is no action. That is enough for me to give up Open AI and switch to other alternatives. Solving this kind of issues shouldn’t punish the customer but on the contrary.

I regret to say that I am switching from Codex to another client. Codex support does not match my SLAs for handling serious issues. Deeper research has shown that I can safely switch, I am thankful for this possibility to OpenAI. Codex has done it well. I not only have my first own connected system live, but it has shown me the future.

Thank you OpenAI, I believe that you will be remembered as the true pioneer.

For everyone that reads this - Codex is a great powerful product, use it wisely.