Legal

Privacy Policy

Obelisk is privacy-respecting by design: passkey-first, no passwords, no tracking or advertising cookies, and you can export or delete your data.

Last updated 2026-07-29

Scope

This Policy explains how VaultSpark Studios ("we", "us") handles personal data when you use Obelisk at obeliskgate.com and the Obelisk identity service (the "Service"). It applies to individual account holders and to organization members.

Data we process

CategoryWhatWhy
Account identifiersYour chosen username and display nameTo identify your account and present it to you and relying parties
Passkey credentialsPublic keys + credential IDs (never private keys)To verify your sign-ins
Authentication factorsTOTP secret (encrypted) and recovery-code hashes, if you enable themSecond-factor and recovery
Session & device metadataDevice identifiers, session timestamps, scopesSecurity, session management, anomaly detection
EmailOnly if you provide one (e.g., for magic-link or org invites)To deliver sign-in links and invites
Security receiptsHashed, chained records of sensitive actions (no secrets)Tamper-evident audit
Organization & project dataOrg membership/roles; per-project profile slices a project stores about youTeam features and the on-top project layer

What we do NOT do

  • We do not use passwords — there is none to store.
  • We do not receive or store your biometrics; they never leave your device.
  • We do not set advertising or cross-site tracking cookies, and we do not sell or rent personal data.
  • We do not log secret material (private keys, TOTP secrets, session tokens).

How we use it & legal bases

We process data to provide and secure the Service (performance of a contract), to protect accounts and detect abuse (legitimate interests and legal obligation), and — where applicable — with your consent (e.g., optional product-update emails). Organization and project-profile data is processed on behalf of the relevant organization or relying party.

Retention

We keep account data for as long as your account exists. Security receipts are retained to preserve audit integrity. When you delete your account, we remove your identity record and credentials; immutable audit entries are minimized to the extent compatible with their tamper-evidence purpose.

Your rights

Subject to applicable law (including GDPR/UK GDPR and similar regimes), you may access, export, correct, or delete your data and object to or restrict certain processing. You can export a portable copy any time from your account, and request deletion via privacy@obeliskgate.com. You may also lodge a complaint with your supervisory authority.

Security

We encrypt the identity database at rest (AES-256-GCM), never expose secret material via APIs, and maintain a tamper-evident audit. See the Security page for details.

International transfers

Obelisk may be operated on infrastructure located in one or more regions. Where data is transferred across borders, we rely on appropriate safeguards consistent with applicable law.

Children

Obelisk is not directed to children under 16, and we do not knowingly process their personal data.

Cookies

Obelisk uses only strictly-necessary cookies. See the Cookie Policy.

Changes & contact

We will update this Policy as the Service evolves and post the new "last updated" date. Questions: privacy@obeliskgate.com.