I want to document a privacy incident with Codex and how it was handled, in case it affects others using agentic tools with screen-capture capability.
What happened (June 9, 2026): During a Codex session, the in-app/page screenshot tool timed out. Instead of stopping, Codex fell back to an OS-level full-desktop screenshot — with no consent prompt and no notification. That capture included an unrelated private browser window I had open, and the image was rendered directly into the conversation transcript. The agent itself acknowledged in the transcript that it had used a whole-screen fallback, that it captured the wrong (foreground) window, and — in its own words — “yes, I caused a privacy incident.”
Why this matters beyond me: the failure mode is silent by design. I only discovered it because I happened to scroll the transcript at the right moment. Any user whose primary capture fails could have arbitrary on-screen content captured and stored without ever knowing.
The handling (June 9 → today, June 14):
- June 9: I filed a formal data-deletion request (dsar@openai.com) asking for erasure of the captured image and confirmation it wouldn’t be used for training. Case opened.
- June 11: Rather than the privacy request being actioned, my paid Pro subscription was cancelled and refunded without my request, dropping me to the free tier. My free-tier limit was exhausted in 4 messages, effectively blocking my work until July 11.
- Support told me reinstatement wasn’t possible and that I’d need to re-purchase at full price to restore the access I never asked to lose.
- A support agent then asked me to send a screenshot of the captured private content with “only the sensitive part blurred,” plus a HAR file — i.e. to re-transmit the very private material I was asking them to erase. I declined that specific request as inappropriate and unnecessary. Instead, I provided precise technical identifiers from the session transcript — exact timestamps, transcript references, and cryptographic hashes of the captured images — which are sufficient to locate and verify the data on their side without any further exposure of the content.
- As of today (June 14): my access is still not restored, and the actual privacy request — erasure and written confirmation — remains unresolved.
I’m posting this for awareness of the capture-fallback behavior, which I believe is a design issue affecting any user of screen-capable agents. I’ve pursued the resolution itself through the appropriate formal channels.
A few questions for the community:
- Has anyone seen Codex (or similar agentic tools) escalate to an OS-level full-desktop capture after an in-app/page screenshot failed?
- Has anyone been asked by support to resend sensitive content (even blurred) for a privacy investigation?
- Has anyone had a paid subscription cancelled and refunded without requesting it while a support case was open — and then been told the only way back is to re-purchase at full price?
I’d like to understand how common each of these is.