DSDS Agentic OS Brain

PRIVACY POLICY

Private intelligence stays private.

Last updated August 31, 2026

What this application is

DS Agentic OS Brain is a private, single-owner command center. Access is restricted to the configured owner account. It is not a public communications service, advertising platform, or data broker.

Data the Brain may access

Only after the owner authorizes a connection, the Brain may retrieve approved Microsoft Outlook mail and calendars, Gmail and Google Calendar data, local project memories, Obsidian notes, registered application and skill context, Apple Health snapshots, Plaid personal-finance data, and bounded Rizen CRM data exposed through its separate scoped API. Owner-authorized financial, health, contact, proprietary, legal, and privileged information is eligible for private retrieval and reasoning; sensitivity alone does not exclude it from the single-owner Brain.

How data is used

Private all-sources discovery is the default for owner questions. The Brain discovers across the approved source catalog, then retrieves bounded live or indexed content from the relevant ready domains to search, summarize, prioritize, correlate, answer questions, and prepare owner-requested actions. A catalog entry is not presented as current live data unless a dedicated Brain connection is ready. Browser voice recognition sends its transcript through the same private Brain request as a typed question; audio is not stored by the Brain, though the browser or operating-system speech provider may process it under that provider's terms. DS's spoken greeting and wake-word mode are optional, off by default, and controlled in the authenticated interface. Email sending is never autonomous: the recipient, subject, and message must be reviewed and explicitly confirmed before each send.

Storage and retention

Mailbox, calendar, and Plaid finance content is retrieved live and is not stored durably by default. Short follow-up context stays in server memory for no more than six turns and 45 minutes and can be cleared with New conversation. OAuth and Plaid access tokens are encrypted at rest in separate private application vaults and are never stored in source control. The latest approved Apple Health snapshot is separately encrypted at rest and can be cleared from the dashboard. Owner-created Brain captures are encrypted at rest, retained with provenance in approved private storage, and removable from their node inspector; credential-shaped content is rejected.

Sharing and service providers

The Brain does not sell personal information or use it for advertising. Data is disclosed only as needed to operate owner-authorized features through service providers such as Microsoft, Google, Apple, Plaid, OpenAI, Railway, and the Rizen CRM API. One connected source is not copied into another without an owner-approved action.

Google API data

Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Controls and security

The owner can disconnect Microsoft, Google, or a Plaid institution and can clear the hosted Apple Health snapshot from the authenticated dashboard. Spoken greeting and wake-word listening have visible on/off controls; wake mode runs only while the authenticated tab is open and visible and requires “DS” before a command. Provider access can also be revoked at its source. Plaid is used only for retrieval and exposes no Brain payment, transfer, or trading action. Apple Health is read-only. The service uses HTTPS, an allowlisted identity, encrypted storage, bounded API retrieval, and a separate API-only CRM boundary.

Contact

Privacy questions or access requests may be sent to matthewc.isaac@gmail.com.