Privacy
Privacy Policy
Effective date: March 7, 2026
1. Scope
This policy explains how OBSCURA collects, uses, stores, and protects personal data and uploaded files during service operation.
2. Data We Process
- Account data (username/email, authentication source, display name, avatar).
- Security data (hashed passwords, developer API keys, verification keys, audit logs, request rate-limit metadata).
- Content data (uploaded and generated image files, watermark mode and notes, timestamps).
3. Purposes of Processing
- Provide watermark embedding, verification, and robustness testing features.
- Authenticate users and secure accounts.
- Detect abuse, investigate incidents, and maintain service reliability.
4. Legal Basis and Compliance Intent
OBSCURA is designed to support privacy and security principles such as data minimization, access control, and auditability. Production deployments should map this policy to local legal requirements (including the Data Privacy Act where applicable).
5. Retention
Data is retained only as needed for operational, security, and legal purposes. Users may remove uploaded outputs through in-app controls.
6. Data Sharing
OBSCURA does not sell personal data. Data may be disclosed only when required for legal compliance, security response, or service operation.
7. Security Measures
- Password hashing and secure cookie-based sessions.
- Per-user verification keys for private image verification workflows.
- Audit logging and request throttling to mitigate abuse.
8. User Rights
Subject to law, users may request access, correction, or deletion of personal data. Organizations deploying OBSCURA should establish a request workflow and response SLA.
9. Cross-Border Processing
If hosted or accessed from multiple jurisdictions, operators should implement appropriate safeguards for cross-border data transfers.
10. Policy Updates
We may update this policy to reflect legal, operational, or technical changes. Material updates should include a revised effective date.
Note: This policy is a technical/legal baseline template and not legal advice. Have legal counsel review before production use.