Last updated: September 16, 2026.
This policy describes the data handled by the hosted Light Remote MCP service at light-remote.thaiduy.digital. It does not expand the permissions granted by the user-owned device or its Local Wall policy.
Account and authorization data: email address, a salted password hash, OAuth client metadata, scopes, and token identifiers are used only to authenticate the account and authorize MCP access. A password entered on the OAuth authorization page is processed transiently for verification; the raw password is not stored in MCP tool data or application logs.
Device and session data: device name/ID, platform, architecture, effective capabilities, workspace, and opaque continuation handles are used to route an operation to the explicit device and durable session selected by the user.
Task data: file paths/content, commands, process or terminal input/output, and search terms are processed only when needed to perform the requested remote operation. Light Remote does not request or reconstruct the user's full ChatGPT conversation.
Data is disclosed only to the OpenAI client acting for the user, the Light Remote service components required to route the request, the explicitly selected user-owned device/Hub that executes it, and infrastructure providers necessary to transport the request. Light Remote does not sell personal data or use it for advertising or behavioral profiling.
OAuth authorization codes expire after 2 minutes; access tokens after 1 hour; refresh tokens after 30 days; DCR public-client registrations are stateless signed identifiers and remain valid until the service rotates its OAuth signing secret; they do not create a separate server-side client record. Active durable sessions use a 15–60 minute idle grace and session history is kept for up to 7 days. Completed job, managed-process, and PTY state/output caches are kept for up to 6 hours. Account and enrolled-device records remain while the account/device is active and are removed when the account/device is deleted or revoked. Device-local audit logs remain under the device/Hub owner's control until that owner rotates or deletes them.
Users can unlink Light Remote in ChatGPT, close durable sessions, stop processes/terminals, revoke or remove enrolled devices through Light Remote controls, and delete files they created. Account access, correction, or deletion requests can be sent to the support contact.
Light Remote tools are not intended to collect payment-card data, protected health information, government identifiers, passwords, MFA/OTP codes, API keys, private keys, or other authentication secrets. Use local credential stores and environment-based authentication without asking ChatGPT to reveal secret values.
OAuth scopes, exact-device targeting, account isolation, short-lived authorization artifacts, encrypted operator payloads, non-root execution, and device-local policy are used as defense-in-depth controls. Tool responses are minimized and must not expose credentials, cryptographic keys, transport telemetry, or unnecessary internal identifiers.
Privacy and account requests: th.dangduy@gmail.com.