1DSG ONE
DSG ONE / PRIVACY

Data handling with a bounded execution mindset.

This policy explains what DSG ONE may process when you use DSG Spacetime, why it is processed, who may receive it, the default retention approach, and the controls available to you.

EFFECTIVE · 15 SEP 2026DSG SPACETIMENO DATA SALE
1 / SCOPE

Who this policy covers

DSG ONE is a founder-led software service operated by Thanawat Suparongsuwan. This policy covers the public DSG ONE site and hosted DSG Spacetime service, including an OpenAI/ChatGPT plugin connection when enabled. For privacy questions or requests, contact t.dealer01@dsg.pics.

2 / DATA CATEGORIES

Information we may process

CategoryExamplesPurpose
Identity & account metadataEmail/subject identifier from the authentication provider and workspace contextAuthentication, permission binding, abuse prevention
Requests & action parametersTool arguments, approved plan/route inputs, requested targetsEvaluate and perform governed requests
Evidence & governance recordsDecision states, hashes, plan/execution/evidence identifiers, repair proposals, replay or verification recordsAuditability, proof, troubleshooting, replay
Operational telemetryTimestamp, status, latency, error class, evidence verification telemetry, and W3C trace identifiers where configuredReliability, security, incident investigation
Support communicationsEmail and information you choose to provideRespond to support and security requests
3 / PURPOSE

How we use data

  • Provide and secure DSG Spacetime.
  • Authorize actions against plan, route, entitlement, and approval state.
  • Create evidence and verification outputs required by a workflow.
  • Diagnose incidents and improve reliability.
  • Meet legal obligations and protect users or the service.

We do not sell personal data or use plugin data for targeted advertising.

4 / PROVIDERS

Who may process data

We may use OpenAI/ChatGPT as the interaction channel, Auth0 for identity, Microsoft Azure for hosting including the DSG-Agent-v0 governed inference surface, and PostHog for bounded operational telemetry when configured. If you direct an approved workflow to an external MCP, API, browser, repository, or provider, relevant request data may be sent to that provider as necessary to perform the authorized action.

5 / RETENTION

Default retention policy

Current DSG Spacetime execution records may be ephemeral where the runtime reports durable=false. Where DSG ONE directly controls durable operational or security records, the default policy is to retain them for no longer than 90 days unless a customer agreement, active incident, abuse investigation, or legal obligation requires longer retention. Support correspondence may be retained for up to 12 months after the matter is closed. Provider-managed logs may follow the configured provider retention period.

Truth boundary: an ephemeral runtime record can disappear earlier than these maximum windows; the service does not represent an ephemeral record as durable storage.
6 / SECURITY

Safeguards

DSG ONE uses HTTPS, authenticated service boundaries, plan-bound execution controls, bounded permissions, and evidence-oriented verification. Secrets should use approved secret-reference mechanisms rather than prompts, evidence, or support messages. Management-plane credentials such as scoped PATs are kept outside model/evidence payloads and are not intended to substitute for Realtime user/session authorization. Realtime access should remain bound to project/session authorization, RLS, explicit schema/table selection, row filters, and selected columns. No internet service can guarantee absolute security.

7 / YOUR CONTROLS

Access, correction, deletion

You may request access, correction, deletion, restriction, or an explanation of personal data associated with you, subject to applicable law and records that must be retained for security or legal reasons. You can also disconnect the plugin or revoke provider authorization through the relevant account/provider interface.

8 / INTERNATIONAL PROCESSING

Cloud infrastructure

Cloud, identity, observability, and interaction providers may process data in countries other than your own. Their own privacy terms and safeguards apply to their processing.

9 / CHILDREN

Not directed to children

DSG Spacetime is developer and business infrastructure and is not directed to children. Do not intentionally submit children’s personal data unless you have a lawful basis and appropriate safeguards.

10 / CHANGES & CONTACT

Policy updates

We may update this policy as the product, providers, or legal requirements change. The effective date above identifies the current public version.