dsOS is a private operations workspace. We use connected data to provide the features you request. We do not sell personal information, use it for advertising, or use Google or Microsoft calendar data to train generalized AI models.
1. Scope and operator
This Privacy Policy applies to dsOS at dsos.saiba.app, its backend services, and its authorized integrations. dsOS is operated by Saiba (“Saiba,” “we,” “us,” or “our”). For privacy questions or requests, contact mario@saiba.ws.
2. Information we collect
Account and authentication information
- Your dsOS account email, account identifier, authentication session, and security metadata.
- Basic profile information received from a provider, such as display name, email address, and provider account identifier.
Google account and Calendar data
When you connect Google Calendar, dsOS may access the list of calendars you can view and read-only event data, including event titles, descriptions, start and end times, time zones, recurrence, status, organizers, attendees, locations, conferencing links, and source links. dsOS also receives a refresh token so it can perform the ongoing synchronization you authorize. dsOS requests openid, basic profile/email scopes, and https://www.googleapis.com/auth/calendar.readonly.
Microsoft account and Calendar data
When you connect a Microsoft account, dsOS uses delegated User.Read to identify and label the connected account and Calendars.Read to access calendar lists and read-only event information. Event information may include the same categories listed above. dsOS requests offline_access so the user-authorized connection can continue until revoked or disconnected.
Other connected operations data
If you choose to connect or import other services, dsOS may process tasks, projects, workspace identifiers, meetings, notes, action items, decisions, transcripts, agent responsibilities, messages, approvals, run outputs, and source-system links from services such as Motion, Circleback, or user-configured agent systems.
Technical and security data
We may process IP-derived request information, browser and device information, timestamps, authentication events, integration health, synchronization logs, audit events, and error reports to operate, secure, diagnose, and improve dsOS. dsOS uses browser local storage for the authenticated session and device-level preferences.
3. How we use information
We use information only as reasonably necessary to:
- authenticate authorized users and protect the service;
- display unified tasks, meetings, calendars, businesses, and authorized agent activity;
- synchronize connected sources and preserve source relationships;
- map records to the business or project selected by the user;
- send user-requested commands to explicitly connected agents;
- provide support, troubleshoot errors, prevent abuse, and maintain auditability;
- comply with applicable law and enforce our Terms.
We do not sell or rent personal information. We do not use connected data for behavioral advertising, data brokerage, creditworthiness, insurance eligibility, employment eligibility, or other unrelated profiling.
4. Google API data and Limited Use
dsOS’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is used only to provide or improve the user-facing dsOS features described in this policy. We do not use Google user data for advertising. We do not sell it. We do not allow humans to read it except when the user gives affirmative permission for support, when necessary to investigate abuse or a security incident, when required by law, or when it has been aggregated and anonymized for internal operational purposes consistent with Google policy.
5. Artificial intelligence
dsOS does not use Google or Microsoft calendar data to train generalized or publicly available artificial-intelligence models. Calendar data is not automatically transferred to an AI provider. If a future feature allows a user to intentionally send selected content to a user-chosen agent or AI service, dsOS will provide contextual notice and seek any consent required before using provider data for that feature. Any such processing must remain limited to delivering the user-requested feature and will be disclosed in this policy.
6. How information is disclosed
We disclose information only in these circumstances:
- Infrastructure processors: service providers such as Supabase for database, authentication, and server-side functions, and Vercel for web hosting and delivery.
- Connected providers: Google, Microsoft, Motion, Circleback, or another integration when necessary to authenticate, synchronize, or carry out a request involving that provider.
- User-directed recipients: an agent, service, or person the authorized user explicitly connects or directs dsOS to communicate with.
- Legal and safety: when reasonably necessary to comply with law, protect rights or security, investigate fraud or abuse, or respond to a lawful process.
- Business change: in connection with a merger, financing, reorganization, or transfer, subject to confidentiality protections and notice where required.
Service providers may process information only to deliver contracted services and are not authorized by us to use connected data for their own advertising.
7. Storage, security, and international processing
dsOS uses access controls, row-level database security, least-privilege provider scopes, server-side credential isolation, encryption in transit, and encryption of stored calendar refresh tokens. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
Information may be processed in the United States or other locations where our service providers operate. Where required, we rely on appropriate legal mechanisms for cross-border processing.
8. Retention and deletion
- Provider refresh tokens are retained while the connection is active. Disconnecting a calendar account removes the stored credential and stops future synchronization.
- Synchronized records, operational history, and security logs are retained only as long as reasonably necessary for the service, backup, security, legal, and audit purposes described here.
- A user may request deletion of their dsOS account information and synchronized provider data by emailing mario@saiba.ws. We will verify the request and complete it within 30 days unless retention is required by law or necessary to establish, exercise, or defend legal claims.
You can also revoke Google access from your Google Account connections and Microsoft access from your Microsoft account permissions. Revoking provider access stops new access but does not by itself delete information already synchronized into dsOS; submit a deletion request for that.
9. Your choices and privacy rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent. You may also lodge a complaint with a relevant privacy authority. To exercise a right, contact us. We may need to verify your identity and authority over the connected account.
Within dsOS, users can disable individual calendars, disconnect provider accounts, revoke agent credentials, and control which integrations are active.
10. Children
dsOS is intended for business and adult use and is not directed to children under 18. We do not knowingly collect personal information from children.
11. Third-party services
Third-party services have their own privacy practices and terms. This policy governs dsOS’s processing, not a provider’s independent handling of information in its own service. Google and Microsoft do not endorse or sponsor dsOS.
12. Changes to this policy
We may update this policy to reflect product, legal, or provider-requirement changes. We will update the date above and provide additional notice or obtain consent when required. We will not use previously collected provider data for a materially different purpose without the notice and consent required by applicable law and provider policy.
13. Contact
Privacy, security, access, and deletion requests:
Saiba — dsOS Privacy
Email: mario@saiba.ws
Website: https://dsos.saiba.app/about