Status and possible purpose
Agent Trust Hub currently uses ChatGPT sign-in for the current session only. This draft does not apply to that sign-in and is not an active consent document.
If a separate email sign-in flow is launched in the future and final consent text is approved, necessary data may be used only to create an account, verify the email address, send a one-time link, protect the session, and prevent abuse.
Data described by the draft
- For the future flow: the email address and an internal user identifier.
- For the future flow: the one-time verification value, its expiry, and the email-verification result.
- For the future flow: the session identifier and expiry, user-agent string, and pseudonymized request-security signals.
- For the future flow: document version, language, time, and a technical record of consent or withdrawal.
The draft does not provide for collecting a date of birth or taking an IP address from untrusted proxy headers.
How consent could be verified
In the proposed flow, form selections would first be stored as an unverified submission and would not be attributed to the email owner before the one-time link in the email was used.
Using the link would verify control of the mailbox. Only then could a separate consent event be bound to the account.
Draft retention periods
The draft gives a one-time link a 5-minute lifetime. An unverified submission could not be bound after 10 minutes and would have to be removed by operational cleanup within 24 hours.
Final periods for account, session, and technical records must be approved before the future flow launches and stated in the active version of the document.
Rights in a possible future flow
If separate email sign-in launches, users must have a way to end a session and request access, correction, restricted processing, or deletion.
Before launch, the final process for requests, withdrawal, and mandatory retention must pass legal and operational review.