Obscura
Privacy Policy
Effective Date: [Effective Date]
Welcome to Obscura (“we,” “our,” or “us”). We operate a luxury, invite-only private events and reservations platform designed for verified adult members. We are committed to protecting your privacy and handling your personal information securely and responsibly.
This Privacy Policy explains what information we collect, how we use and protect it, how long we retain it, who we share it with, and the choices and rights available to you regarding your personal data.
1. Information We Collect
We collect information you provide directly to us, information collected automatically through your use of the platform, and information required for identity verification and safety purposes.
1.1 Account Information
- Email address, display name, username, date of birth, and a securely hashed password.
1.2 Identity Verification Data
- Government-issued identification documents (such as a passport or driver’s license), uploaded during our mandatory identity verification process, which is required before you can access gated areas of the app.
- The result of the verification check (approved, rejected, pending) and the timestamp of verification.
1.3 Payment Information
Payment details are handled and stored securely by our third-party payment processor, Stripe. Obscura does not store raw credit card numbers; we store only your subscription status and your Stripe customer and subscription identifiers.
1.4 Location Data
General location data, used to display relevant local events and reservations.
1.5 User-Generated Content
- Profile photos, bios, event listings, reservation and Reserve Post details, and direct messages exchanged between members.
1.6 NDA Signatures
When a member signs a non-disclosure agreement (NDA) for an event or Reserve Post, we record their identity, the terms agreed to, and the signature timestamp.
1.7 Safety and Emergency Data
- If a member uses our in-app emergency (SOS) feature, an incident report is created, which may include an AI-generated summary of the situation, your location at the time of the alert, and the event or reservation you were attending.
- Emergency contacts: if you add an emergency contact in your safety settings, we collect that person’s name and contact information. This is used solely to notify them if you trigger an SOS alert, and is retained for as long as your account remains active or until you remove the contact. Your emergency contact is not an Obscura member and does not have an Obscura account by virtue of being listed.
1.8 Usage and Technical Data
Standard technical and log data, including device type, IP address, app version, and general analytics regarding how you interact with the platform.
2. How We Use Your Information
We use the information we collect to provide, maintain, and improve our services, including to:
- Verify your age (18+ requirement) and identity before granting access to gated platform features.
- Process membership applications, event hosting and attendance, Reserve Post reservations, and venue arrangements.
- Facilitate private messaging and optional NDA execution for privacy-sensitive events and Reserve Posts.
- Manage billing, subscriptions, and secure payment processing through Stripe.
- Send administrative notices, transaction confirmations, and important account updates via Resend.
- Maintain platform security, enforce our Terms of Service, investigate misuse, and respond to safety emergencies.
- Facilitate luxury arrival/concierge integrations (e.g., Uber Black, Lyft Black) when you choose to use them.
3. AI-Assisted Features
Obscura uses OpenAI’s API to power two specific, member-initiated features. We do not use AI to make automated decisions about your account access, and neither feature runs in the background without you taking an action first.
3.1 AI NDA Drafting Assistant
When you use the NDA builder to draft or customize a non-disclosure agreement, the text you enter is sent to OpenAI’s API to generate suggested NDA language. This content is processed to generate your document and is not used by OpenAI to train its models beyond OpenAI’s standard API terms.
3.2 Emergency Incident Summarization
When an SOS/emergency incident is created, relevant incident details may be processed by OpenAI’s API to generate a concise summary for our safety team’s review. This summary becomes part of the permanent safety incident record described in Section 5.
No user data processed through these AI features is used by OpenAI to train its models beyond OpenAI’s standard API terms. If Obscura introduces additional AI-assisted features in the future, we will update this section accordingly.
4. Cookies and Similar Technologies
Obscura uses a limited set of cookies and similar technologies — we do not run third-party advertising trackers, and we do not sell or share data collected through cookies with ad networks.
- Authentication cookies: keep you securely signed in between sessions (via Supabase Auth).
- Payment/checkout cookies: set by Stripe during subscription checkout, governed by Stripe’s own privacy practices.
- Essential functional cookies: remember basic preferences (e.g., theme, last-viewed tab).
We do not use cookies for cross-site behavioral advertising. Because we do not engage in the sale or sharing of personal information for cross-context behavioral advertising, Global Privacy Control (GPC) signals do not change your experience on Obscura — there is nothing to opt out of. If this changes in the future, we will honor GPC signals and update this section.
5. Data Retention
We retain your personal information only as long as necessary to fulfill the purposes described in this policy, subject to the following rules:
- Account deletion: if you request account deletion, your profile data, photos, direct messages, and follow relationships are permanently deleted following a 14-day grace period, during which your account and data remain recoverable.
- Subscriptions: any active paid subscription is cancelled immediately upon an account deletion request.
- NDA signatures: retained in full and permanently, even after account deletion. NDAs are legal agreements between members that exist independently of your app account and must remain enforceable.
- Safety and emergency records: retained permanently, even after account deletion, for legal, safety, and liability reasons.
- Admin audit logs: retained permanently.
For members whose accounts remain active and are never deleted, account and content data is retained for as long as the account exists, so that the platform continues to function as expected.
6. Third-Party Sharing
We share your information only with trusted service providers necessary to operate the platform:
- Supabase — database hosting, authentication, and file storage.
- Stripe — payment processing, under full PCI compliance. Obscura never stores raw card numbers.
- Resend — transactional email delivery (confirmations, notices, platform updates).
- OpenAI — processes NDA drafting requests and emergency incident summaries, as described in Section 3.
We do not sell, rent, or trade your personal information to outside marketers. We disclose information beyond the above only: with your consent; to comply with law, legal process, or a government request; to protect the rights, property, or safety of Obscura, our members, or the public; or as part of a merger, acquisition, or sale of assets (in which case affected members will be notified).
7. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights regarding your personal data:
- Right to access — request a copy of the personal data we hold about you.
- Right to correct — request correction of inaccurate or incomplete personal data.
- Right to delete — delete your account and associated data directly through our in-app self-service tools, subject to the retention rules in Section 5 (such as permanent NDA and safety records).
- Right to know / data portability — request the categories of personal data we’ve collected, used, and disclosed about you in the preceding 12 months, and request a portable copy of your data.
- Right to opt out of non-essential communications.
- Right to non-discrimination — we will not deny you service, charge you a different price, or provide a different quality of service because you exercised a privacy right.
7.1 California and Other State Privacy Rights
If you are a California resident, the rights above are provided to you under the California Consumer Privacy Act (CCPA), as amended by the CPRA. Residents of Virginia, Colorado, Connecticut, and other states with comprehensive privacy laws have similar rights under their respective state laws.
Do Not Sell or Share: Obscura does not sell personal information, and does not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA.
Sensitive personal information: government ID documents are “sensitive personal information” under the CCPA. We use this data solely to verify your identity and age and for no secondary purpose.
To exercise any right in this section, contact us using the information in Section 12. We may need to verify your identity before fulfilling a request. You may designate an authorized agent to submit a request on your behalf, consistent with applicable law.
8. Data Security
We implement technical and organizational security measures — including encryption in transit and at rest, secure password hashing, and access controls limiting who can view sensitive records — designed to protect your personal information from unauthorized access, alteration, disclosure, or destruction.
In the event of a data breach affecting your personal information, we will notify affected members and any applicable regulatory authorities as required by applicable law.
9. Children’s Privacy
Our platform is strictly for adults aged 18 and older. We do not knowingly collect personal data from anyone under the age of 18. If we discover that an individual under 18 has provided personal data, we will terminate their account and delete their information, subject to the legal-record retention described in Section 5.
10. International Data Transfers
Obscura is a US-based platform. Your information is primarily stored and processed in the United States. If any of our service providers process data outside the United States, we require appropriate safeguards consistent with applicable law.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we do, we will revise the Effective Date above and, for material changes, notify members through the platform or by email before the change takes effect.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:
Email: obscurabusiness2026@gmail.com
This page is a draft and is not indexed by search engines. It will be marked final once legal review is complete and the placeholders above are filled in. See our Terms of Service.