Version: 1.0
Last updated: February 22, 2026
This Privacy Policy governs your use of Obscura (the "Platform"), a privacy-focused copy trading platform that connects exchange accounts via API keys and utilizes zero-knowledge proofs to verify trading activity without revealing underlying strategy details.
This is a legally binding document. By using Obscura, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
Questions regarding this policy should be directed to: compliance@obscura.finance
| Term | Meaning |
|---|---|
| "Platform" / "Obscura" / "we" / "us" / "our" | The copy trading platform and associated services operated by the legal entity behind Obscura, including the website, application, and related infrastructure. |
| "User" / "you" / "your" | Any individual or entity accessing or using the Platform, including both Traders and Copiers. |
| "Trader" | A User who connects exchange accounts to publish verifiable trading proofs. |
| "Copier" | A User who subscribes to copy the trades of one or more Traders. |
| "API Keys" | Application Programming Interface credentials provided by cryptocurrency exchanges to authorize access to account data and trading functionality. |
| "Zero-Knowledge Proof" / "ZK Proof" | A cryptographic method that allows one party to prove possession of certain information without revealing the information itself. |
| "Personal Data" | Any information relating to an identified or identifiable natural person. |
| "Exchange Partner" | Third-party cryptocurrency exchanges with which Obscura integrates (e.g., Binance, Bybit, OKX). |
We collect only the information necessary to provide and improve our services. We adhere to data minimization principles.
| Category | Examples | Purpose |
|---|---|---|
| Account Information | Email address, username, password (encrypted) | Account creation, login, support communication |
| Profile Information | Trader bio, social media links, public display name | User profiles, discovery, community features |
| Subscription Data | Payment method details (processed by third-party payment processors—we do not store full payment credentials) | Subscription management, billing |
| Communications | Emails, support tickets, feedback | Customer support, product improvement |
| Category | Examples | Purpose |
|---|---|---|
| Usage Data | Pages viewed, features used, time spent, referral source | Analytics, product improvement, user experience optimization |
| Device Information | IP address, browser type, operating system, device identifiers | Security, fraud prevention, troubleshooting |
| Log Data | Server logs, access times, requested URLs | System administration, security monitoring |
When you connect an exchange account via API keys, we collect:
| Data Type | Access Scope | Retention |
|---|---|---|
| Account Balance | Read-only access to current balances | Retained while account connected; deleted upon disconnection |
| Trade History | Historical trade data required for proof generation | Aggregated into proofs; raw trade data handled as specified in Section 3 |
| Open Positions | Current positions for copy trading functionality | Used for real-time copy execution |
| API Key Permissions | Record of permissions granted | Stored to verify proper configuration |
We never request withdrawal permissions. All API keys should be configured with "trading" and "read" permissions only—never "withdraw."
| Data Type | What We Store | What We Don't Store |
|---|---|---|
| Proof Output | Cryptographic proof that trading activity meets certain criteria (e.g., profitability, risk metrics) | Individual trade details, entry/exit prices, position sizes |
| On-Chain Anchors | Hash of proof data recorded on blockchain (public) | Underlying trade data that would reveal strategy |
| Verification Status | Boolean indicator that a Trader is "verified" | Specific performance data beyond what is publicly displayed |
The zero-knowledge proof system is designed to prevent Obscura—and any third party—from accessing your underlying trading strategy while still providing cryptographic verification of your trading activity.
| Aspect | Our Commitment |
|---|---|
| Encryption | All API keys are encrypted at rest using industry-standard AES-256 encryption. |
| Transmission | API keys are transmitted over TLS 1.3+ encrypted connections. |
| Storage Location | Keys are stored in secure, isolated infrastructure with strict access controls. |
| Access Limitations | Only essential automated systems can decrypt keys for trade execution; no human access without explicit User authorization and logging. |
| Key Rotation | We encourage regular key rotation; we provide in-platform tools to facilitate this. |
In the event of a security incident involving API keys, we will:
Obscura anchors proof hashes to public blockchains (e.g., Ethereum, Polygon, Arbitrum). This data is:
| Characteristic | Implication |
|---|---|
| Public | Anyone can view the hash and timestamp on blockchain explorers |
| Immutable | Data cannot be altered or deleted once recorded |
| Pseudonymous | Hashes are not directly linked to your identity unless you publicize the connection |
What remains off-chain (private):
Once data is recorded on a public blockchain, it cannot be erased. By using Obscura's verification features, you acknowledge and accept the permanent, public nature of blockchain records.
If you wish to minimize on-chain exposure, you may:
Obscura does not and will not sell your personal information to third parties for marketing or advertising purposes.
| Third-Party Category | Data Shared | Purpose |
|---|---|---|
| Exchange Partners | API calls required for trade execution; no stored data shared | Execute copy trades, verify balances |
| Blockchain Networks | Proof hashes (as described in Section 5) | Anchor verification data |
| Cloud Infrastructure Providers | Encrypted user data, logs | Hosting and operations (e.g., AWS, GCP) |
| Analytics Providers | Aggregated usage data (non-personal) | Product improvement |
| Payment Processors | Payment information (we receive only confirmation) | Subscription billing |
| Professional Advisors | As necessary for legal, accounting, or consulting services | Compliance, audit, business operations |
We may disclose your information if required by:
Where permitted, we will attempt to notify you of such requests unless prohibited by law.
In the event of a merger, acquisition, financing, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such change of control.
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account Information | Until account deletion request + 1 month | Account functionality; processing window for deletion requests |
| API Keys | Deleted within 1 month of account deletion request | Core platform functionality ceases upon request |
| Trade Data (Raw) | Deleted within 1 year of account deletion request | Extended retention for proof verification, dispute resolution, and legal obligations |
| Aggregated Proof Data | Indefinitely (anonymized, non-identifiable) | Platform analytics, historical verification |
| On-Chain Proof Hashes | Permanent (blockchain) | Immutable verification; cannot be deleted |
| Log Files | Deleted within 1 year of account deletion request | Security, debugging |
| Support Communications | Deleted within 1 year of account deletion request | Customer service continuity, dispute resolution |
To opt out and request account deletion:
Exceptions:
Obscura operates globally. Your information may be transferred to, stored in, and processed in countries outside your residence, including the United States and European Union member states.
| Transfer Scenario | Safeguards |
|---|---|
| EU/UK to US | Standard Contractual Clauses approved by European Commission |
| Other international transfers | Data transfer agreements incorporating appropriate safeguards |
By using Obscura, you consent to the transfer of your information to countries that may have different data protection laws than your jurisdiction.
You may request:
You may:
You may:
To exercise any rights:
We will respond within 30 days (extended by up to 60 days for complex requests).
California residents have additional rights:
To exercise California rights, contact compliance@obscura.finance with "CCPA Request" in subject line.
EU/UK residents have rights under the General Data Protection Regulation, including:
Our lawful bases for processing include:
| Measure | Implementation |
|---|---|
| Encryption | TLS 1.3+ for transit; AES-256 for data at rest |
| Access Controls | Multi-factor authentication for internal systems; principle of least privilege |
| Monitoring | 24/7 intrusion detection, anomaly detection, log analysis |
| Penetration Testing | Annual third-party security audits; bug bounty program |
| Key Management | Hardware Security Module (HSM) for encryption keys |
While we implement industry-standard safeguards, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but will promptly notify you of any known breach affecting your data.
Obscura is not intended for individuals under the age of 18 (or the age of majority in their jurisdiction). We do not knowingly collect personal information from minors.
If we become aware that a minor has provided us with personal information, we will delete such information promptly. If you believe a minor has provided personal information, please contact us immediately.
The Platform may contain links to external websites or integrate with third-party services (exchanges, blockchain explorers, etc.). This Privacy Policy does not apply to those third parties.
We encourage you to review the privacy policies of any third-party services you access through Obscura. We are not responsible for the content, privacy practices, or data handling of third parties.
We may update this Privacy Policy from time to time to reflect:
Notification of Material Changes:
Your continued use of Obscura after changes constitutes acceptance of the revised policy. If you do not agree with changes, you must stop using the Platform and submit a deletion request to compliance@obscura.finance.
This section applies to residents of the United States. We comply with applicable federal and state privacy laws. California residents should refer to Section 9.5.
This section applies to residents of the EU/UK. We process personal data in accordance with the General Data Protection Regulation (GDPR) and UK GDPR.
If you are accessing Obscura from outside the United States, please note that your data may be transferred to, stored, and processed in the United States or other jurisdictions where our servers operate.
By using Obscura, you acknowledge:
If you do not agree to this Privacy Policy, you must not use Obscura.
| Processing Activity | Data Categories | Purpose | Legal Basis |
|---|---|---|---|
| Account Creation | Email, username, password | Platform access | Contract |
| Copy Trading | API keys, trade data | Service delivery | Contract |
| Proof Generation | Trade history, ZK proofs | Verification feature | Contract / Legitimate interests |
| On-Chain Anchoring | Proof hashes | Immutable verification | Contract / Consent |
| Analytics | Usage data, device info | Improvement | Legitimate interests |
| Marketing | Email (with consent) | Promotional comms | Consent |
| Term | Definition |
|---|---|
| Controller | The entity that determines purposes and means of processing personal data. |
| Processor | The entity that processes personal data on behalf of the Controller. |
| Personal Data Breach | A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. |
| Consent | Freely given, specific, informed, and unambiguous indication of agreement to processing. |
| Profiling | Automated processing to evaluate personal aspects (e.g., performance, behavior). |
To request account deletion:
Timeline: