DSG ONE / PRIVACY
Data handling with a bounded execution mindset.
This policy explains what DSG ONE may process when you use DSG Spacetime, why it is processed, who may receive it, the default retention approach, and the controls available to you.
EFFECTIVE · 15 SEP 2026DSG SPACETIMENO DATA SALE
1 / SCOPE
Who this policy covers
DSG ONE is a founder-led software service operated by Thanawat Suparongsuwan. This policy covers the public DSG ONE site and hosted DSG Spacetime service, including an OpenAI/ChatGPT plugin connection when enabled. For privacy questions or requests, contact t.dealer01@dsg.pics.
2 / DATA CATEGORIES
Information we may process
| Category | Examples | Purpose |
|---|
| Identity & account metadata | Email/subject identifier from the authentication provider and workspace context | Authentication, permission binding, abuse prevention |
| Requests & action parameters | Tool arguments, approved plan/route inputs, requested targets | Evaluate and perform governed requests |
| Evidence & governance records | Decision states, hashes, plan/execution/evidence identifiers, repair proposals, replay or verification records | Auditability, proof, troubleshooting, replay |
| Operational telemetry | Timestamp, status, latency, error class, evidence verification telemetry, and W3C trace identifiers where configured | Reliability, security, incident investigation |
| Support communications | Email and information you choose to provide | Respond to support and security requests |
3 / PURPOSE
How we use data
- Provide and secure DSG Spacetime.
- Authorize actions against plan, route, entitlement, and approval state.
- Create evidence and verification outputs required by a workflow.
- Diagnose incidents and improve reliability.
- Meet legal obligations and protect users or the service.
We do not sell personal data or use plugin data for targeted advertising.
4 / PROVIDERS
Who may process data
We may use OpenAI/ChatGPT as the interaction channel, Auth0 for identity, Microsoft Azure for hosting including the DSG-Agent-v0 governed inference surface, and PostHog for bounded operational telemetry when configured. If you direct an approved workflow to an external MCP, API, browser, repository, or provider, relevant request data may be sent to that provider as necessary to perform the authorized action.
5 / RETENTION
Default retention policy
Current DSG Spacetime execution records may be ephemeral where the runtime reports durable=false. Where DSG ONE directly controls durable operational or security records, the default policy is to retain them for no longer than 90 days unless a customer agreement, active incident, abuse investigation, or legal obligation requires longer retention. Support correspondence may be retained for up to 12 months after the matter is closed. Provider-managed logs may follow the configured provider retention period.
Truth boundary: an ephemeral runtime record can disappear earlier than these maximum windows; the service does not represent an ephemeral record as durable storage.
6 / SECURITY
Safeguards
DSG ONE uses HTTPS, authenticated service boundaries, plan-bound execution controls, bounded permissions, and evidence-oriented verification. Secrets should use approved secret-reference mechanisms rather than prompts, evidence, or support messages. Management-plane credentials such as scoped PATs are kept outside model/evidence payloads and are not intended to substitute for Realtime user/session authorization. Realtime access should remain bound to project/session authorization, RLS, explicit schema/table selection, row filters, and selected columns. No internet service can guarantee absolute security.
7 / YOUR CONTROLS
Access, correction, deletion
You may request access, correction, deletion, restriction, or an explanation of personal data associated with you, subject to applicable law and records that must be retained for security or legal reasons. You can also disconnect the plugin or revoke provider authorization through the relevant account/provider interface.
8 / INTERNATIONAL PROCESSING
Cloud infrastructure
Cloud, identity, observability, and interaction providers may process data in countries other than your own. Their own privacy terms and safeguards apply to their processing.
9 / CHILDREN
Not directed to children
DSG Spacetime is developer and business infrastructure and is not directed to children. Do not intentionally submit children’s personal data unless you have a lawful basis and appropriate safeguards.
10 / CHANGES & CONTACT
Policy updates
We may update this policy as the product, providers, or legal requirements change. The effective date above identifies the current public version.