Privacy Policy

Last updated: December 30, 2025

1. Overview

This Privacy Policy explains how Obskura (“we”, “us”, “our”) collects, uses, and protects information in connection with our desktop software tool that records publicly available livestreams to your device (the “Service”). By using the Service, you agree to this Policy. If you do not agree, please do not use the Service.

2. What We Do NOT Collect

  • Recorded files: Recordings are stored locally on your device. We do not access, view, upload, or transmit your recordings to our servers.
  • Passwords: We do not store your Google or Discord passwords. Authentication uses Google Sign-In and Discord OAuth (where applicable).
  • Full payment card data: We never receive or store your full card details. Payments are processed by Stripe.

3. Information We Collect

We do not use diagnostics data for advertising or to sell personal information.

  • Account & Authentication Data: Email address and linked account identifiers from Google/Discord to create and maintain your account in our system.
  • Subscription & Billing Metadata: From Stripe, we may receive your subscription status, plan, invoices, and payment confirmations to provide access, manage entitlements, and for tax/ accounting records. We do not store card numbers.
  • Device/License Data: Information necessary to validate licenses, device limits, or anti-abuse measures (e.g., hashed or otherwise minimal device/application identifiers).
  • Diagnostics & Usage: Non-identifiable technical data (e.g., crash reports, error logs, performance metrics) to monitor reliability and support troubleshooting.
  • Communications: Support requests and messages you send us by email or via our Discord server. Posting in support channels requires an active subscription; read-only access is open.

4. How We Use Information

  • Authenticate users and maintain accounts.
  • Provide, operate, and improve the Service.
  • Manage subscriptions, invoices, and access permissions.
  • Detect, prevent, and address fraud or abuse.
  • Provide customer support and communicate important updates.
  • Comply with legal, tax, and accounting obligations.

5. Legal Bases (where applicable)

Where required (e.g., in the EEA/UK), we process personal data based on:

  • Contract necessity (to provide the Service).
  • Legitimate interests (e.g., security, diagnostics, improvements).
  • Legal obligations (e.g., tax and accounting records).
  • Consent where explicitly obtained (e.g., certain communications).

6. Sharing & Processors

We do not sell your personal information. We share data only with service providers (“processors”) to run the Service, including:

  • Stripe — payment processing, subscriptions, invoices.
  • Google — authentication (Google Sign-In).
  • Discord — community/support communications.
  • Hosting/Infrastructure — website hosting and backend services for accounts/licensing (not recordings)

Each processor is contractually required to protect data and use it only to provide their services to us.

7. International Transfers

We are based in Puerto Rico (U.S.). Your information may be processed in the United States and other countries. Where required, we use appropriate safeguards for cross-border transfers (e.g., standard contractual clauses).

8. Data Retention

  • Account data: kept while your account is active and for a reasonable period after deletion for backup, dispute resolution, or as required by law.
  • Billing records & invoices: retained as required by tax and accounting laws.
  • Diagnostics/logs: typically retained for a limited period necessary for support and security (e.g., ~30–180 days) unless extended due to an incident.
  • Recordings: always local on your device; retention is under your control.

9. Your Rights & Choices

Depending on your location, you may have rights to access, correct, delete, or export your personal data, or to object/restrict certain processing. To exercise rights, contact us using the details below. We may need to verify your identity and we will respond as required by applicable law.

  • Access & portability — request a copy of your data.
  • Correction — update inaccurate information.
  • Deletion — request deletion of your data (subject to legal obligations).
  • Opt-out — of non-essential communications.

10. Security

We implement reasonable technical and organizational measures to protect information. No method of transmission or storage is 100% secure. You are responsible for securing your devices and local recordings.

11. Cookies & Local Storage

We may use cookies, local storage, or similar technologies to keep you signed in, remember preferences, and improve functionality. You can control cookies through your browser settings, but disabling certain cookies may limit functionality.

12. Age Requirement

The Service is intended for users 18 years of age or older. By using the Service, you represent that you are at least 18. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with personal information, please contact us and we will take appropriate action.

13. Changes to this Policy

We may update this Privacy Policy from time to time. If changes are material, we will provide notice by reasonable means. Your continued use of the Service after updates take effect constitutes acceptance.

14. Contact

  • General inquiries: [email protected]
  • Technical support: [email protected]
  • Discord: You may join and view read-only channels without a subscription. Posting in support channels and receiving direct support requires an active subscription.

By using Obskura, you acknowledge that you have read and understood this Privacy Policy.