How we handle your information when you use Obsidian Cipher.
This Privacy Policy explains what information we collect, how we use it, and the choices you have. It is incorporated into and subject to our Terms of Use.
"Obsidian," "Cipher," "we," "us," or "our" refers to the operator of the Service. "You" or "Subscriber" refers to the individual accessing the Service. "Service" refers to Obsidian Cipher, a market visibility software application. "Obsidian Eye" refers to the free Obsidian connector for Meta Muse, whose data handling is described in Section 12. "Personal Information" refers to any information that identifies or could reasonably be used to identify you.
We collect and store the following categories of information in connection with your use of the Service:
Your data provider credentials. The Service is designed so that your third-party data provider credentials (API keys) are stored in your own browser. They are transmitted to the Service only to retrieve market data on your behalf and are not stored on our servers or written to our logs.
We use collected information strictly for the following purposes:
We do not sell, rent, or trade your Personal Information to third parties for marketing or advertising purposes. We may share limited information with the following categories of recipients, strictly as necessary:
We retain your Personal Information for as long as your account is active and for a reasonable period thereafter as necessary to: fulfill the purposes described in this Privacy Policy; comply with applicable legal and regulatory retention requirements; resolve disputes; and enforce our Terms of Use. Access logs, session data, and IP records are retained for a limited period for security and compliance purposes. When retention is no longer required, we will delete or de-identify your information using commercially reasonable methods.
We implement commercially reasonable administrative, technical, and physical safeguards to protect your Personal Information against unauthorized access, alteration, disclosure, or destruction. These measures include encrypted data transmission, access-controlled systems, and secure authentication via Discord OAuth. However, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for any activity that occurs under your account.
The Service uses essential cookies, session tokens, and similar technologies strictly necessary to authenticate your session, enforce access controls, and maintain the security of the Service. We do not use advertising cookies, third-party tracking pixels, or behavioral profiling technologies, and we do not serve advertisements within the Service.
The Service is not directed to individuals under the age of eighteen (18). We do not knowingly collect Personal Information from anyone under 18. If we become aware that we have collected information from a minor, we will take reasonable steps to delete such information promptly. If you believe a minor has provided us with Personal Information, please contact us immediately.
Depending on your jurisdiction, you may have certain rights regarding your Personal Information, including the right to access, correct, delete, or port your data, or to object to or restrict certain processing. To exercise any such rights, please contact us using the information provided below. We will respond to verifiable requests within a reasonable timeframe and in accordance with applicable law. Certain data may be exempt from deletion requests where retention is required by law or contractual obligation.
The Service integrates with third-party platforms, including Discord for authentication, third-party payment providers for billing, the market data provider you connect, and, where you choose to enable Obsidian Eye, Meta Muse. These third parties operate under their own privacy policies, which we encourage you to review. We are not responsible for the privacy practices of any third-party service.
We may update this Privacy Policy at any time at our sole discretion. Updated versions will be posted and accessible within the Service with a revised "Last Updated" date. Continued use of the Service following any update constitutes your acceptance of the revised Privacy Policy. If you do not agree to the revised terms, your sole remedy is to discontinue use of the Service.
Obsidian Eye is a free Obsidian connector for Meta Muse that reads chart images you supply. This Section 12 describes what Obsidian Eye receives, why, and for how long. Obsidian Eye is optional, and none of the processing below occurs unless you connect Obsidian Eye inside Meta Muse and send a request to it.
What Obsidian Eye receives. Obsidian Eye receives only what is needed to answer the request you make:
Connector tokens. Connector tokens are stored only as a SHA-256 hash, never in a form we can read back, so a disclosure of our database does not reveal a usable credential. You may revoke every token from your account page at any time. We also record the network address a request arrives from, for a limited period and solely to enforce rate limits that protect Obsidian Eye against automated account creation.
What Obsidian Eye does not receive. Obsidian Eye does not request, receive, or store brokerage credentials, API keys, account numbers, balances, positions, order history, or payment information. Obsidian Eye has no connection to any brokerage account and cannot place an order. Obsidian Eye does not receive your Meta password, your Meta Muse conversation history unrelated to Obsidian Eye, or any other connector's data.
How Obsidian Eye uses what it receives. We use the information above solely to generate the analysis you requested, to maintain the reads saved to your library, to diagnose errors, and to protect Obsidian Eye against abuse. We do not sell Obsidian Eye data, we do not use Obsidian Eye data for advertising or behavioural profiling, and we do not use your chart images to train publicly released third-party models.
Retention and deletion. A chart image submitted for a one-off read is retained only as long as needed to produce and return that read, and is then deleted on a routine schedule. A setup you explicitly save is retained until you delete the setup or disconnect Obsidian Eye. Disconnecting Obsidian Eye inside Meta Muse stops all further processing, and you may request deletion of saved reads at any time using the contact details in Section 13.
Your control. Meta Muse governs which permissions Obsidian Eye holds. You choose whether to connect Obsidian Eye and which requests to send it, and you can review or revoke Obsidian Eye access at any time from within Meta Muse, or delete any saved read from your account page. Meta Platforms, Inc. is an independent third party and processes information under its own privacy policy, which we encourage you to review alongside this one.
For questions, concerns, or requests regarding this Privacy Policy or your Personal Information, please contact us at support@accessobsidian.com.