Privacy Policy

Last updated: July 25, 2026

This Privacy Policy describes how Eudaimonic Inc. ("DeepSpace," "we," "our," "us") collects, uses, and shares information in connection with the DeepSpace SDK, the developer platform, and apps that developers build and deploy on top of them.

DeepSpace serves two groups, and the rules differ depending on which one you are. Developers are people who sign in to the DeepSpace dashboard, scaffold apps with create-deepspace, and deploy them to the platform. End-users are people who sign in to (or visit) one of those deployed apps. Where the treatment differs, we say so explicitly.

1. Who we are

DeepSpace is operated by Eudaimonic Inc., a Delaware corporation with offices at 23 Wheeler Rd, Setauket, NY 11733, United States. We publish the `deepspace` and `create-deepspace` npm packages, run the platform workers that back deployed apps, and provide the authentication, storage, billing, payments, and integration infrastructure that those apps rely on.

For the purposes of GDPR and similar laws, Eudaimonic Inc. is the controller of the personal information described in this Privacy Policy that we hold about you in your capacity as a DeepSpace developer or as an end-user of the DeepSpace authentication and platform services. We do not currently have an EU representative appointed under Article 27 of the GDPR; if and when we are required to appoint one, we will publish the representative's contact details on this page.

See §14 for contact details.

2. Information we collect

We collect only what we need to operate the service, bill correctly, prevent abuse, and improve the platform. The categories below are organized by which group the information is collected from.

2.1 Developers

  • Account information: name, email address, and profile image supplied by GitHub or Google when you authenticate. Developer sign-in (`npx deepspace login` and the developer dashboard) is GitHub or Google only; we do not expose email-and-password sign-in to developers.
  • Billing information: handled by Stripe, our payment processor. We do not see or store payment card numbers. We store an opaque Stripe customer identifier and your subscription, credit balance, and invoice history.
  • Deploy metadata: names of apps you have deployed, deployment timestamps and version identifiers, the build artifacts you upload (compiled worker code and bundled static assets), Cloudflare resource bindings you have configured, custom-domain bindings, and the integrations enabled in your app's manifest.
  • Application secrets: values you place in the user-managed section of your app's `.dev.vars` file are uploaded as secret bindings on deploy and stored by Cloudflare's secret-binding service so your deployed worker can read them. We do not display these values back to you and we do not use them outside of provisioning your worker.
  • Usage telemetry: per-invocation operational counters (request path, HTTP method, country reported by Cloudflare's network, Cloudflare colocation, HTTP status, CPU and wall-clock time) attributed to each app you own. We use this to enforce quotas, calculate billing, surface analytics in your dashboard, and investigate operational problems. See §6.
  • OAuth tokens for connected services: if you connect your DeepSpace account to a third-party service through a platform integration, the resulting OAuth access and refresh tokens are stored encrypted at rest. See §11.
  • Stripe Connect details: if you opt into receiving developer payouts, Stripe collects your identity, banking, and tax information directly through Stripe Express. We store only the opaque Stripe account identifier and the status flags Stripe reports to us (for example, whether payouts are enabled).
  • Custom-domain purchase evidence: if you purchase a domain through us, we capture the date, IP address, and user-agent associated with your acceptance of the registrar's terms of service. The registries we use require this as evidence for responding to chargebacks and abuse complaints.
  • Managed-repository metadata: if you elect to host your app's source in a DeepSpace-managed GitHub repository, we store the repository's GitHub owner login, the repository name, the GitHub-assigned numeric repository identifier, the HTTPS URL at which it can be cloned, its visibility setting, its lifecycle status (for example, active or deleted), the link between it and your DeepSpace app, and creation and update timestamps. We do not maintain a copy of your source code, branches, or commit history outside of GitHub.
  • Ad-click identifiers: if you arrive at deep.space from one of our own advertisements, the advertising network's click identifier (such as a gclid) is captured in a first-party cookie (see §8), and if you then create an account it is stored alongside your account identifier so we can attribute the signup to our advertising and report it as described in §4.

2.2 End-users of apps built on the platform

When you sign in to an app built on the DeepSpace SDK, you are signing in to DeepSpace. The same DeepSpace account recognizes you on any other app on the platform that you choose to sign in to. DeepSpace is the controller of your account identity. The developer who built the specific app you are using is the controller of the content you create inside that app; we host that content on the developer's behalf as part of operating the platform.

  • Account information: when you authenticate with GitHub or Google, we receive the name, email address, and profile image those providers supply. Where an app exposes email-and-password sign-in (which the SDK's default sign-in card includes), we receive the email address and the password you choose; the password is stored only as a salted hash, not in clear text.
  • Authentication state: a short-lived signed identity token (default five minutes) issued by our authentication service that the app you signed into presents to its own worker. Deployed apps do not set a long-lived authentication cookie of their own. See §8 for the full cookie inventory and lifetimes.
  • App content: records, messages, files, collaborative-document state, and similar content you save inside an app are stored in databases that DeepSpace operates on the app developer's behalf. The developer's app code is what reads, writes, and decides who within the app can see what.
  • Anonymous use: where an app allows it, you may also participate without signing in. In that case the app sees only a temporary identifier generated for the duration of your visit, and no DeepSpace account is created or persisted for you.
  • Platform-level metadata: session timestamps, IP address (used to operate the network and detect abuse), user-agent, and the per-invocation request metadata described in §6.
  • Cross-app shared data: the SDK exposes platform-wide stores for content that is intended to be shareable across apps — a workspace store and a cross-app conversation store. Developers are required by our Terms of Service (see Terms §4.3) to write only public-safe content to these stores and to keep personal or app-private information in their own per-app data store, where standard role-based access controls apply.
  • AI assistant actions: many apps built on the SDK include an AI assistant that runs under your identity. The assistant can be configured by the developer to read records, and — by default in the SDK scaffold — to create, update, and delete records on your behalf. Those actions are bounded by your own role-based permissions inside the app, but you should treat the assistant as a tool you have asked to act on your data.
  • Payment information: if you make a purchase inside an app (a subscription, a one-time product, or a tip), payment is processed by Stripe through Stripe Checkout. We do not see or store card numbers. We store the purchase amount, the app it was for, the Stripe identifiers needed to issue refunds, and tax data Stripe returns to us.
  • Integration data: where a developer's app asks you to connect a third-party account (for example, Google), the OAuth grant happens between you and the third party. We store the resulting access and refresh tokens encrypted at rest and use them only to fulfill requests you or the app make on your behalf. See §5 for Google specifics.

3. How we use information

  • Operate, maintain, secure, and improve the SDK and the platform.
  • Authenticate you and keep your account secure.
  • Bill developers for their use of paid platform features, and process payments by end-users for purchases inside apps built on the platform.
  • Detect and prevent abuse, fraud, denial-of-wallet attacks, and security incidents.
  • Respond to support requests.
  • Comply with legal obligations.
  • Send service-related emails (account verification, security alerts, billing receipts, deploy notifications).
  • We do not send marketing email without consent.

4. How we share information

We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising (each as defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act). We share information only in the circumstances below.

4.1 Sub-processors used by the core platform

We rely on the following providers to operate the platform itself. They process information on our behalf, under their own terms.

  • Cloudflare, Inc. — Workers for Platforms, Durable Objects, R2, KV, D1, Browser Rendering, Workers Logs, Analytics Engine, Workers AI, and the Cloudflare Registrar. All DeepSpace infrastructure, every deployed app, and the data those apps store run on Cloudflare's edge network.
  • Stripe, Inc. — payment processing and Stripe Connect for developer payouts.
  • Resend, Inc. — transactional email delivery.
  • Anthropic, PBC — Claude model APIs used by SDK-side AI features when an app routes traffic through the Anthropic proxy.
  • OpenAI, L.L.C. — GPT, image, and speech model APIs used by SDK-side AI features when an app routes traffic through the OpenAI proxy.
  • Cerebras Systems, Inc. — inference API offered through the Cerebras proxy.
  • Google LLC — Gemini model API used by SDK-side AI features when an app routes traffic through the Gemini proxy; Google OAuth for sign-in; the Google Workspace APIs that back the Google integration described in §5. Separately, when a signup is attributable to one of our own Google Ads advertisements, we report that conversion to Google Ads: the advertising click identifier that accompanied the visit, the fact and time of the signup, a one-way SHA-256 hash of the email address, used solely so Google can match the conversion to the ad click (see §8 for the cookie involved), and an internal account identifier used only to prevent the same signup from being counted twice. This measurement reporting is the only advertising-related data flow to Google, and it concerns our own ads only. For this reporting, Google acts as an independent controller for its advertising services rather than as our processor; we treat it as measurement of our own advertising, not as "sharing" for cross-context behavioral advertising.
  • GitHub, Inc. — GitHub OAuth for sign-in; private repositories created on a DeepSpace-controlled organization when a developer opts into managed repositories.
  • ElevenLabs, Inc. — text-to-speech, voice synthesis, and conversational-agent APIs when an app enables voice features.
  • LiveKit, Inc. — audio/video room hosting when an app enables real-time AV features. Media streams flow directly between participants and LiveKit; DeepSpace only mints access tokens.
  • Porkbun LLC — domain registration for top-level domains that Cloudflare Registrar does not handle.

4.2 Per-integration third-party services

When a developer enables a platform integration, calls made through that integration leave the platform and reach the named third-party service. Each integration's provider is the controller of whatever an app sends to it through that integration. The current set of third-party services that may receive data through the platform's integration catalog, grouped by the role they play, is:

  • AI model providers: Anthropic (chat completions, and a grounded web-search endpoint that Anthropic itself runs), OpenAI (chat completions, image generation, text-to-speech, and Whisper speech-to-text), Cerebras Systems (chat completions, exposed through a passthrough proxy that forwards the request to Cerebras's API as-is), and Google (Gemini chat completions and Gemini image generation).
  • Voice and conversational-AI provider: ElevenLabs (text-to-speech, voice listing, and conversational agents).
  • Real-time audio and video: LiveKit (room hosting; media streams flow between participants and LiveKit directly, and DeepSpace mints access tokens only).
  • Web search, scraping, and extraction: SerpAPI (which backs our general web-search, scholar search, Amazon product search, and LinkedIn lookups, each grouped in our catalog under the kind of result the developer is asking for), Exa, and Firecrawl.
  • News, weather, sports, and finance: NewsAPI, OpenWeatherMap, API-Sports (football, basketball, baseball, and American football), Finnhub, Alpha Vantage, the public Coinbase market-data API, and the public Polymarket markets API.
  • Transactional email: Resend (we send our own platform email through Resend, and apps can send email through the email integration).
  • Files and media generation: CloudConvert (file conversion), Submagic (video captioning), and Freepik (image and video generation).
  • Social and messaging platforms: Slack and TikTok (each only when an app makes a call through that integration).
  • Developer and content-platform metadata (read-only catalog access): GitHub (public repository, commit, pull-request, issue, contributor, and tree metadata), YouTube (video search and video metadata), and Instagram (public-post content extraction).
  • Reference data: Wikipedia, NASA's public APIs, the New York City MTA public feeds, and the public Jolpica / Ergast Formula 1 API.
  • Self-hosted services we operate: a LaTeX rendering service we run on Cloudflare for compiling LaTeX source to PDF.

4.3 App developers

When you sign in to an app built on the SDK, the app receives your DeepSpace user identifier, name, email, and profile image so it can recognize you. The developer of that app is responsible for handling that information, and any content you create in the app, under their own privacy policy and terms.

4.4 Legal and safety

We may disclose information if we believe disclosure is required by law, court order, or governmental request, or if disclosure is necessary to investigate suspected fraud or abuse, enforce our Terms, or protect the rights, property, or safety of users or the public.

4.5 Business transfers

If Eudaimonic Inc. is involved in a merger, acquisition, financing, or sale of assets, user information may transfer as part of that transaction. We will notify affected users where required by law.

5. Google user data

This section describes how DeepSpace handles user data obtained through Google APIs. It applies in addition to the rest of this Privacy Policy, and controls where there is any conflict with respect to Google user data.

DeepSpace's use and transfer to any other application of information received from Google APIs adheres to the Google API Services User Data Policy, available at https://developers.google.com/terms/api-services-user-data-policy, including the Limited Use requirements.

5.1 Scopes we request and the purpose of each

When a user connects a Google account through a DeepSpace platform integration, we request the minimum OAuth scopes needed for the feature the user explicitly enables. The scopes we may request are:

  • openid, https://www.googleapis.com/auth/userinfo.profile, and https://www.googleapis.com/auth/userinfo.email — used to authenticate the user, retrieve the user's display name, profile image, and email address from Google, and associate the user's Google identity with their DeepSpace account.
  • https://www.googleapis.com/auth/gmail.readonly — read-only access to the user's Gmail messages, threads, labels, and message metadata. DeepSpace uses this scope solely to display the user's email correspondence alongside the contact, deal, and account records the user has chosen to maintain inside a DeepSpace app, so that the user can review their own customer-relationship context in one place. DeepSpace does not send, draft, modify, label, move, archive, delete, or otherwise alter any message, thread, or mailbox state through this scope.
  • https://www.googleapis.com/auth/calendar.events — reading, creating, and deleting events on calendars the user owns, only when the user or the app the user is using initiates the action.
  • https://www.googleapis.com/auth/drive.file — limited Drive access scoped to files the user has explicitly created with, or opened with, the connected DeepSpace app.
  • https://www.googleapis.com/auth/contacts.readonly — read-only access to the user's Google Contacts so the connected DeepSpace app can show contact information alongside the user's other app data.

5.2 Limited Use of Google user data

In accordance with the Google API Services User Data Policy Limited Use requirements:

  • DeepSpace uses Google user data only to provide or improve user-facing features of the DeepSpace app the user has connected their Google account to. We do not use Google user data for any unrelated purpose.
  • DeepSpace does not transfer Google user data to others except (i) as necessary to provide or improve those user-facing features, (ii) to comply with applicable law, or (iii) as part of a merger, acquisition, or sale of assets with notice to users.
  • DeepSpace does not use Google user data to serve advertisements, including retargeting, personalized advertising, or interest-based advertising.
  • DeepSpace does not sell, rent, lease, or trade Google user data.
  • Scope note: the commitments in this section concern Google user data obtained through the Google Workspace APIs described in §5.1. The email address on your DeepSpace account (however you signed up, including via Google sign-in) is part of our own account records; its only advertising-related use is the one-way-hashed conversion-measurement report described in §4 and §8, which involves no ad serving, retargeting, personalization, or interest-based advertising.
  • DeepSpace does not use Google user data, including data accessed through the Gmail API, to develop, improve, train, fine-tune, or evaluate any generalized or non-personalized artificial-intelligence or machine-learning model. Google user data is not transmitted to Anthropic, OpenAI, Cerebras, Google Gemini, ElevenLabs, or any other third-party model provider listed in §4.1.
  • DeepSpace personnel do not read or otherwise access Google user data, including data accessed through the Gmail API, except (a) with the user's explicit consent, for example to investigate and resolve a support issue the user has reported, (b) where strictly necessary for security purposes such as investigating abuse, fraud, or a suspected violation of these terms, (c) to comply with applicable law, or (d) for internal operations where the data has been aggregated and de-identified such that it cannot be linked to any individual user.

5.3 Storage, encryption, and processing location

  • Gmail message content — headers, bodies, attachments, and labels — is retrieved on demand from the Gmail API at the moment a user views it within a connected DeepSpace app, transmitted to the user's authenticated browser session, and is not persisted in DeepSpace's databases or backups. An app developer can choose to copy content into the app's own data collections; in that case the developer's own retention and deletion rules apply.
  • OAuth access and refresh tokens issued by Google are stored encrypted at rest. Encryption is applied at the application layer using AES-256-GCM with a per-record random initialization vector. The encryption key is derived via HKDF-SHA256 from a secret managed outside of the database and held only in the worker runtime, in addition to the encryption-at-rest provided by the underlying storage platform.
  • All processing of Google user data takes place on Cloudflare Workers infrastructure operated by DeepSpace, within the same Cloudflare account that runs the DeepSpace platform. Google user data is not passed to any sub-processor listed in §4.1 other than Cloudflare, and is never passed to a sub-processor that is not listed in §4.1.
  • DeepSpace enforces application-layer access controls, request rate limiting, audit logging, and security response headers on the endpoints that handle Google user data, in keeping with the Cloud Application Security Assessment (CASA) Tier 2 requirements applicable to applications that request Gmail restricted scopes.

5.4 Revoking access and deleting Google user data

A user may disconnect a connected Google account from a DeepSpace app at any time from the integrations area of that app's settings. When a user disconnects:

  • DeepSpace immediately calls the Google OAuth token revocation endpoint to revoke the OAuth grant on the Google side.
  • The encrypted access and refresh tokens are deleted from DeepSpace's database.
  • No further Gmail data is fetched on the user's behalf after revocation.
  • Because DeepSpace does not persist message content server-side (see §5.3), there is no server-side message store to delete in addition to revoking the token.

5.5 Contact regarding Google user data

Questions, complaints, or requests that relate specifically to data obtained through Google APIs, including Gmail data, may be sent to contact@eudaimonic.one. We will respond in accordance with the Google API Services User Data Policy and applicable law.

6. Telemetry and logs

  • We record per-invocation operational metadata for every request made to a deployed app. This includes the app name, the request path (with the query string removed), the HTTP method, the outcome of the invocation (for example, ok, exception, or canceled), the HTTP response status, the country reported by Cloudflare's network, the Cloudflare colocation that served the request, and the CPU and wall-clock time the request consumed. Records are indexed by the app developer's user identifier so each developer can see usage and be billed for their own apps; they are not indexed by individual end-user identifier. We use this data to enforce quotas, calculate billing, surface analytics to the developer of each app, and investigate operational problems.
  • The per-invocation record does not contain the body of the request, the values of HTTP headers, the URL query string, or the contents of any database read or write.
  • Apps that use compute-style Cloudflare bindings can emit a separate per-call usage event so the developer can be billed for that consumption. The SDK currently ships dedicated meters for Workers AI calls and Vectorize queries, plus a generic meter that an app can use for any other compute-style binding the developer enables (for example, R2, KV, D1, Queues, or Hyperdrive). These usage events record the binding type, the operation performed, and a numeric usage figure (for example, tokens or bytes) — not the content of the call.
  • Per-invocation and per-call usage records are stored in Cloudflare Analytics Engine and retained according to that service's default retention window, which is approximately three months at the time of writing.
  • Cloudflare Workers Logs additionally captures structured runtime logs for the platform workers and for each deployed app worker. These logs are retained according to Cloudflare's published retention windows for that service.
  • Operational logs are kept for the period needed to investigate incidents and to satisfy our security and audit obligations. We do not use these logs for advertising.

7. AI features

Apps built on the SDK can route traffic through proxies we operate to large-language-model and other AI providers, including Anthropic, OpenAI, Cerebras, Google (Gemini), and ElevenLabs. The proxies forward each request to the chosen provider together with whatever content the requesting app includes in the request body. Whatever a developer's app sends — including content authored by you, the end-user, that the app chooses to include as context — is transmitted to the chosen provider.

We do not currently set provider-specific opt-out headers on outbound AI traffic. Each provider treats prompts and outputs according to its standard API default, which for most providers in this list excludes use of the content for training new models but may allow short-term retention for safety, abuse monitoring, or service quality. You should treat any content you send through an AI feature as visible to, and processable by, the chosen provider on that provider's standard API terms.

We do not separately store the contents of AI proxy traffic for our own use beyond what is required to count tokens for billing.

The SDK's scaffolded AI chat feature does, by default, save each turn of an AI conversation — your messages, the assistant's replies, and any tool calls the assistant makes — into the app's own database, so the conversation is durable across page reloads. That persisted chat history is content of the app you are using and is governed by that app developer's privacy policy and terms.

The scaffolded AI feature also gives the assistant the ability to act on records on your behalf — by default, the assistant can read, create, update, and delete records, bounded by the role-based access controls the developer has configured for your role inside the app. App developers can narrow this default. You should treat the assistant as a tool you have asked to act on your data, and review what it does.

8. Cookies and local storage

  • Authentication is held in two related artifacts. (a) On the central DeepSpace authentication origin, and separately on the DeepSpace dashboard, an HttpOnly, Secure, SameSite=Lax session cookie is set when you sign in. The cookie at the central authentication origin has a default lifetime of seven days; the dashboard's session cookie has a lifetime of thirty days. The session cookie is not visible to, and cannot be read by, code running on a deployed app at a different origin. (b) When you sign in to a deployed app, the central authentication service delivers a short-lived signed identity token (default five minutes) through a one-time exchange, which the app then presents to its own worker. Deployed apps do not set a long-lived authentication cookie of their own.
  • Short-lived CSRF cookies used by the OAuth sign-in and CLI sign-in flows, scoped to the corresponding callback path, marked HttpOnly, Secure, and SameSite=Lax, with lifetimes that match the flow (five minutes for the social-login flow and ten minutes for the CLI flow).
  • Interface preferences (theme, sidebar state, drafts) stored in your browser's localStorage on each app.
  • If you arrive at deep.space from one of our own advertisements (for example, a Google Ads click), the landing page stores the advertising network's click identifier (such as a gclid) in a first-party cookie on the deep.space domain for up to 90 days. We use it for one purpose: attributing signups to our own advertising, including reporting that a signup occurred back to the advertising platform the click came from. It is set and read only by us and is not used to track you across other sites. It is set only when the address of the page you land on carries such a click identifier — normally the case only when you arrive through an advertisement — and never during ordinary browsing. We honor the Global Privacy Control (GPC) signal: if your browser sends it, this cookie is not set at all.
  • We do not use third-party advertising cookies or cross-site tracking.

9. Data location and international transfers

Our infrastructure runs on Cloudflare's global edge network and on the Cloudflare account we operate. Data may be processed in any region Cloudflare operates from. We rely on the contractual protections offered by our providers, including standard contractual clauses where applicable, for international transfers.

10. Your rights

Depending on where you live, you may have rights including access, correction, deletion, portability, and the right to object to certain processing.

  • You can update profile information through the settings area of the dashboard or of an app you are signed into.
  • You can request deletion of your DeepSpace account by emailing contact@eudaimonic.one. When we delete an account we remove your identity record from our authentication database (your name, email address, profile image, and the link to the OAuth provider you used to sign in). Content you created inside individual apps built on the platform is governed by those apps' own policies, and you may need to contact the developer of each app to delete it there. Records we are required to keep for tax, accounting, fraud-prevention, audit, or security-incident reasons — for example, invoice ledgers, refund and dispute records, and operational logs — may persist for the periods set out in §12 even after your identity record is removed.
  • You can request a copy of the personal information we hold about you by emailing contact@eudaimonic.one.
  • We will not retaliate against you for exercising any of these rights.

11. Security and operator access

  • All traffic to and from the platform is encrypted in transit using TLS. Data is encrypted at rest using the encryption that the underlying Cloudflare storage services provide. OAuth tokens for third-party integrations are additionally encrypted at the application layer using industry-standard authenticated encryption (currently AES-256-GCM), with a key derived from a secret managed outside the database. We may update the specific cipher or key-derivation function over time as cryptographic best practice evolves; the Google-specific guarantees described in §5.3 take precedence over this paragraph where the two overlap.
  • DeepSpace personnel have administrative access to the platform infrastructure that is technically capable of reading data we host on Cloudflare. Access is limited to a small operations team and is used only for the purposes described in this policy: investigating support requests, investigating suspected abuse or security incidents, responding to legal obligations, and operating the service.
  • This operator access is distinct from any "admin" role a developer may assign inside their own app. A developer's assignment of an in-app admin role to a particular end-user controls what that end-user can do within that one app and is separate from any DeepSpace personnel access to platform infrastructure.
  • We have not yet completed a third-party SOC 2 or ISO 27001 assessment and we do not currently claim compliance with those standards. Consider this before sending us regulated personal data.
  • Report suspected vulnerabilities to contact@eudaimonic.one. We appreciate responsible disclosure.

12. Data retention

  • Active account data — your identity record and the apps and content tied to it — is kept for as long as your account is active.
  • Per-invocation telemetry and binding-usage records are retained for approximately three months in Cloudflare Analytics Engine and then rotated out by that service.
  • Operational logs captured by Cloudflare Workers Logs are retained for that service's default window.
  • Short-lived authentication artifacts — CLI sign-in sessions (10 minutes), social-login codes (5 minutes), and per-flow CSRF cookies — are cleared automatically by the timers built into the flow.
  • Billing records (invoices, refunds, disputes, and the related Stripe identifiers) are retained for at least seven years to satisfy applicable tax, accounting, and consumer-protection obligations, even after an account is closed.
  • Encrypted OAuth tokens for third-party integrations are deleted when you disconnect the integration. If you delete your account without disconnecting first, the tokens are deleted as part of removing the identity record.
  • When you ask us to delete content, we remove it from active systems within 30 days and from routine backups within 90 days. Records covered by a legal hold, a security investigation, or the retention obligations above are not removed until those holds expire.

13. Children

DeepSpace is not directed to, or intended for use by, children under the age of 13 (or, in the European Economic Area and certain other jurisdictions, under the age of 16). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at contact@eudaimonic.one and we will delete the information.

14. Contact and changes

Privacy questions, requests, and notices may be sent by email to contact@eudaimonic.one or by mail to Eudaimonic Inc., Attn: Privacy, 23 Wheeler Rd, Setauket, NY 11733, United States.

We may update this policy from time to time. Material changes will be communicated through the platform or by email. The "Last updated" date at the top of this page reflects the most recent revision.

By using the DeepSpace SDK, the platform, or any app built on the platform, you acknowledge that you have read this Privacy Policy.

DeepSpace

The first app engine — secure, scalable, and production-ready from day one.

If the page stays like this, your browser may be out of date — the links above still work.