← Back to home

This Privacy Policy describes how Obscura ("we", "us") handles personal data. It applies to three groups: people who use Obscura Cloud, people who run the open source Engine, and visitors to this website. Our guiding principle is to collect only what we need to provide the service you asked for.

01The open source engine collects nothing

The Obscura Engine is open source software that runs on your own machines. It contains no telemetry, no analytics, and no phone-home. It does not send usage data, identifiers, or the contents of the pages you visit back to us. When you run the Engine yourself, we receive no data about it, and this policy's cloud sections do not apply to you.

02Data we collect in Obscura Cloud

When you use the hosted Service, we collect the following, and nothing more than we need:

Account data

We authenticate with passwordless email codes, so the account data we hold is your email address. We do not store passwords. When you sign in, we create a session and record the session token (stored only as a hash), the time, your IP address, and your browser's user-agent string, so we can keep you signed in and detect suspicious activity.

Usage data

To run the Service, bill orders accurately, and prevent abuse, we record one event per request you make through the hosted endpoints. Each event contains: the target URL, the outcome (success, error, blocked, or timeout), the HTTP status code, the bytes returned, the duration, and which proxy egress was used. Each event is linked to your account and the API key that made the request.

Content you process

The Service fetches and processes the pages and data you direct it to ("Your Content"). We process Your Content only to deliver results to you and to run the work in your order. We do not sell it and we do not use it to train models. Where an order requires us to store deliverables, we hold them only for as long as that order needs and then delete them.

Communications

If you contact us or book a demo, we keep the messages and details you provide so we can respond and manage the relationship.

03How we use data

We do not use your data for advertising, and we do not sell personal data.

04Legal bases

Where the GDPR or similar laws apply, we rely on these bases: performance of a contract to provide the Service you asked for; legitimate interests to secure the Service and prevent abuse, balanced against your rights; and legal obligation where the law requires us to retain or disclose data.

05Service providers and subprocessors

We use a small number of providers to run the Service. They process data only on our instructions and under contract. As of the date above, they are:

ProviderPurposeData involved
CloudflareWebsite and dashboard delivery, TLS, DNS, edge securityIP address, request metadata
PurelyMailSending passwordless login codes and transactional emailEmail address
Cal.comDemo schedulingName, email, booking details you provide
The hosted infrastructure that runs your sessions and stores account, session, and usage data is operated on servers under our control. We will keep this list current as our providers change. If you need a formal, countersigned subprocessor list or a data processing agreement, contact us.

06Proxies and egress

Requests made through the Service leave from proxy egress IPs. Where you bring your own proxy, the routing and any logging that your proxy provider performs are governed by your agreement with that provider, not by us. We record only which egress was used for each request, as described in Section 2.

07Retention

We keep account data for as long as you have an account, and usage data for as long as needed to operate and bill the Service and to meet legal and accounting requirements, after which we delete or anonymize it. Sessions expire automatically and expired session records are removed. Deliverables tied to an order are deleted when the order no longer requires them, unless you ask us to delete them sooner.

08Security

We protect data with measures appropriate to its sensitivity. Login codes and session tokens are hashed, not stored in plaintext. The control plane is not exposed to the public internet beyond the endpoints it must serve, administrative interfaces are kept off the public surface, and access to production data is limited to those who need it. No system is perfectly secure, but we work to keep the bar high and to respond quickly to issues.

09International transfers

We and our providers may process data in countries other than yours. Where we transfer personal data across borders, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, where required by law.

10Your rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. If you are in the EEA or UK, the GDPR applies; if you are a California resident, the CCPA/CPRA applies, including the right to know, delete, and opt out of sale, which we do not do. To exercise any of these rights, email us at hello@obscura.sh. We will respond within the period the law requires. You also have the right to complain to your local data protection authority.

11Cookies

This marketing site uses no tracking or advertising cookies. The Obscura Cloud dashboard uses a single strictly necessary session cookie to keep you signed in. It is not used for advertising or cross-site tracking.

12Children

The Service is for businesses and developers and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

13Changes to this policy

We may update this policy as the Service evolves. We will revise the "Last updated" date above and, for material changes, give reasonable notice through the Service or by email.

14Contact

For any privacy question or request, contact hello@obscura.sh.