Scope
This Policy explains how VaultSpark Studios ("we", "us") handles personal data when you use Obelisk at obeliskgate.com and the Obelisk identity service (the "Service"). It applies to individual account holders and to organization members.
Data we process
| Category | What | Why |
|---|---|---|
| Account identifiers | Your chosen username and display name | To identify your account and present it to you and relying parties |
| Passkey credentials | Public keys + credential IDs (never private keys) | To verify your sign-ins |
| Authentication factors | TOTP secret (encrypted) and recovery-code hashes, if you enable them | Second-factor and recovery |
| Session & device metadata | Device identifiers, session timestamps, scopes | Security, session management, anomaly detection |
| Only if you provide one (e.g., for magic-link or org invites) | To deliver sign-in links and invites | |
| Security receipts | Hashed, chained records of sensitive actions (no secrets) | Tamper-evident audit |
| Organization & project data | Org membership/roles; per-project profile slices a project stores about you | Team features and the on-top project layer |
What we do NOT do
- We do not use passwords — there is none to store.
- We do not receive or store your biometrics; they never leave your device.
- We do not set advertising or cross-site tracking cookies, and we do not sell or rent personal data.
- We do not log secret material (private keys, TOTP secrets, session tokens).
How we use it & legal bases
We process data to provide and secure the Service (performance of a contract), to protect accounts and detect abuse (legitimate interests and legal obligation), and — where applicable — with your consent (e.g., optional product-update emails). Organization and project-profile data is processed on behalf of the relevant organization or relying party.
Retention
We keep account data for as long as your account exists. Security receipts are retained to preserve audit integrity. When you delete your account, we remove your identity record and credentials; immutable audit entries are minimized to the extent compatible with their tamper-evidence purpose.
Your rights
Subject to applicable law (including GDPR/UK GDPR and similar regimes), you may access, export, correct, or delete your data and object to or restrict certain processing. You can export a portable copy any time from your account, and request deletion via privacy@obeliskgate.com. You may also lodge a complaint with your supervisory authority.
Security
We encrypt the identity database at rest (AES-256-GCM), never expose secret material via APIs, and maintain a tamper-evident audit. See the Security page for details.
International transfers
Obelisk may be operated on infrastructure located in one or more regions. Where data is transferred across borders, we rely on appropriate safeguards consistent with applicable law.
Children
Obelisk is not directed to children under 16, and we do not knowingly process their personal data.
Cookies
Obelisk uses only strictly-necessary cookies. See the Cookie Policy.
Changes & contact
We will update this Policy as the Service evolves and post the new "last updated" date. Questions: privacy@obeliskgate.com.