OBSCURA: PRIVACY POLICY
PREAMBLE
This Privacy Policy governs your use of Obscura (the “Platform”), a privacy-focused copy trading platform that connects exchange accounts via API keys and utilizes zero-knowledge proofs to verify trading activity without revealing underlying strategy details.
This is a legally binding document. By using Obscura, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
Questions regarding this policy should be directed to: compliance@obscura.finance
1. DEFINITIONS
| Term | Meaning |
|---|---|
| "Platform" / "Obscura" / "we" / "us" / "our" | The copy trading platform and associated services operated by [Legal Entity Name], including the website, application, and related infrastructure. |
| "User" / "you" / "your" | Any individual or entity accessing or using the Platform, including both Traders and Copiers. |
| "Trader" | A User who connects exchange accounts to publish verifiable trading proofs. |
| "Copier" | A User who subscribes to copy the trades of one or more Traders. |
| "API Keys" | Application Programming Interface credentials provided by cryptocurrency exchanges to authorize access to account data and trading functionality. |
| "Zero-Knowledge Proof" / "ZK Proof" | A cryptographic method that allows one party to prove possession of certain information without revealing the information itself. |
| "Personal Data" | Any information relating to an identified or identifiable natural person. |
| "Exchange Partner" | Third-party cryptocurrency exchanges with which Obscura integrates (e.g., Binance, Bybit, OKX). |
2. INFORMATION WE COLLECT
We collect only the information necessary to provide and improve our services. We adhere to data minimization principles.
2.1 Information You Provide Directly
| Category | Examples | Purpose |
|---|---|---|
| Account Information | Email address, username, password (encrypted) | Account creation, login, support communication |
| Profile Information | Trader bio, social media links, public display name | User profiles, discovery, community features |
| Subscription Data | Payment method details (processed by third-party payment processors—we do not store full payment credentials) | Subscription management, billing |
| Communications | Emails, support tickets, feedback | Customer support, product improvement |
2.2 Information Collected Automatically
| Category | Examples | Purpose |
|---|---|---|
| Usage Data | Pages viewed, features used, time spent, referral source | Analytics, product improvement, user experience optimization |
| Device Information | IP address, browser type, operating system, device identifiers | Security, fraud prevention, troubleshooting |
| Log Data | Server logs, access times, requested URLs | System administration, security monitoring |
2.3 Information from Exchange Connections
When you connect an exchange account via API keys, we collect:
| Data Type | Access Scope | Retention |
|---|---|---|
| Account Balance | Read-only access to current balances | Retained while account connected; deleted upon disconnection |
| Trade History | Historical trade data required for proof generation | Aggregated into proofs; raw trade data handled as specified in Section 3 |
| Open Positions | Current positions for copy trading functionality | Used for real-time copy execution |
| API Key Permissions | Record of permissions granted | Stored to verify proper configuration |
We never request withdrawal permissions. All API keys should be configured with “trading” and “read” permissions only—never “withdraw.”
2.4 Information from Zero-Knowledge Proofs
| Data Type | What We Store | What We Don't Store |
|---|---|---|
| Proof Output | Cryptographic proof that trading activity meets certain criteria (e.g., profitability, risk metrics) | Individual trade details, entry/exit prices, position sizes |
| On-Chain Anchors | Hash of proof data recorded on blockchain (public) | Underlying trade data that would reveal strategy |
| Verification Status | Boolean indicator that a Trader is "verified" | Specific performance data beyond what is publicly displayed |
The zero-knowledge proof system is designed to prevent Obscura—and any third party—from accessing your underlying trading strategy while still providing cryptographic verification of your trading activity.
3. HOW WE USE YOUR INFORMATION
3.1 Core Platform Functionality
- To provide copy trading services: Mirror trades from Traders to Copiers based on subscription relationships.
- To generate verifiable proofs: Create zero-knowledge proofs of trading activity without exposing strategy details.
- To anchor proofs on blockchain: Record proof hashes on public distributed ledgers for tamper-evident verification.
3.2 Platform Improvement
- To analyze usage patterns: Understand how Users interact with features to guide product development.
- To optimize performance: Identify and fix bugs, improve loading times, enhance user experience.
- To train algorithms: Improve trade mirroring execution, risk control recommendations, and trader matching.
3.3 Security and Compliance
- To prevent fraud: Monitor for suspicious activity, unauthorized access attempts, API key misuse.
- To enforce terms: Investigate violations of our Terms of Service.
- To comply with legal obligations: Respond to lawful requests from authorities (see Section 8).
3.4 Communication
- To send service notifications: Subscription confirmations, security alerts, feature updates.
- To provide support: Respond to inquiries, troubleshoot issues.
- To share marketing communications: Only with your explicit consent (opt-in). You may opt out at any time.
4. API KEY SECURITY AND STORAGE
4.1 How We Handle API Keys
| Aspect | Our Commitment |
|---|---|
| Encryption | All API keys are encrypted at rest using industry-standard AES-256 encryption. |
| Transmission | API keys are transmitted over TLS 1.3+ encrypted connections. |
| Storage Location | Keys are stored in secure, isolated infrastructure with strict access controls. |
| Access Limitations | Only essential automated systems can decrypt keys for trade execution; no human access without explicit User authorization and logging. |
| Key Rotation | We encourage regular key rotation; we provide in-platform tools to facilitate this. |
4.2 Your Responsibilities
- Permission configuration: You are responsible for setting API key permissions to “trading enabled” (if copying) and “withdrawals disabled.”
- Key confidentiality: You must not share your API keys outside the Platform.
- Revocation: You may revoke API access at any time through your exchange account or by disconnecting within Obscura.
4.3 Breach Notification
In the event of a security incident involving API keys, we will:
- Notify affected Users within 72 hours of confirmation
- Provide guidance on key rotation and account securing
- Cooperate with relevant authorities and exchanges
- Conduct and publish a post-mortem analysis
5. BLOCKCHAIN DATA AND PUBLIC INFORMATION
5.1 On-Chain Data
Obscura anchors proof hashes to public blockchains (e.g., Ethereum, Polygon, Arbitrum). This data is:
| Characteristic | Implication |
|---|---|
| Public | Anyone can view the hash and timestamp on blockchain explorers |
| Immutable | Data cannot be altered or deleted once recorded |
| Pseudonymous | Hashes are not directly linked to your identity unless you publicize the connection |
5.2 What Is Revealed On-Chain
- Hash of proof data: A fixed-length string derived from your trading proof
- Timestamp: When the proof was recorded
- Wallet address: The Obscura-controlled address submitting the proof (consistent across Users)
What remains off-chain (private):
- Individual trade details
- Entry and exit prices
- Position sizes
- Exchange used
- Your identity or email
5.3 Your Choices Regarding On-Chain Data
Once data is recorded on a public blockchain, it cannot be erased. By using Obscura's verification features, you acknowledge and accept the permanent, public nature of blockchain records.
If you wish to minimize on-chain exposure, you may:
- Choose not to use verification features
- Use privacy-focused blockchains with enhanced pseudonymity
- Generate proofs less frequently
6. DATA SHARING AND DISCLOSURE
6.1 We Do Not Sell Your Personal Data
Obscura does not and will not sell your personal information to third parties for marketing or advertising purposes.
6.2 Categories of Third Parties With Whom We Share Data
| Third-Party Category | Data Shared | Purpose |
|---|---|---|
| Exchange Partners | API calls required for trade execution; no stored data shared | Execute copy trades, verify balances |
| Blockchain Networks | Proof hashes (as described in Section 5) | Anchor verification data |
| Cloud Infrastructure Providers | Encrypted user data, logs | Hosting and operations (e.g., AWS, GCP) |
| Analytics Providers | Aggregated usage data (non-personal) | Product improvement |
| Payment Processors | Payment information (we receive only confirmation) | Subscription billing |
| Professional Advisors | As necessary for legal, accounting, or consulting services | Compliance, audit, business operations |
6.3 Legal Compliance
We may disclose your information if required by:
- Valid legal process (court order, subpoena, warrant)
- Applicable law or regulation
- Government or regulatory authority request
Where permitted, we will attempt to notify you of such requests unless prohibited by law.
6.4 Business Transfers
In the event of a merger, acquisition, financing, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such change of control.
7. DATA RETENTION AND DELETION
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account Information | Until account deletion request + 1 month | Account functionality; processing window for deletion requests |
| API Keys | Deleted within 1 month of account deletion request | Core platform functionality ceases upon request |
| Trade Data (Raw) | Deleted within 1 year of account deletion request | Extended retention for proof verification, dispute resolution, and legal obligations |
| Aggregated Proof Data | Indefinitely (anonymized, non-identifiable) | Platform analytics, historical verification |
| On-Chain Proof Hashes | Permanent (blockchain) | Immutable verification; cannot be deleted |
| Log Files | Deleted within 1 year of account deletion request | Security, debugging |
| Support Communications | Deleted within 1 year of account deletion request | Customer service continuity, dispute resolution |
7.1 Opt-Out and Deletion Process
To opt out and request account deletion:
- Submit request via email to: compliance@obscura.finance
- Verification: We may request additional information to verify your identity
- Processing timeline: We will cease all data processing and delete your account within 1 month of verified request
- Complete data deletion: All personally identifiable information will be deleted within 1 year of the deletion request, subject to:
- Legal obligations requiring longer retention
- Anonymized data retained for analytics
- On-chain proof hashes (cannot be deleted)
7.2 What “Deletion” Means
- Account inaccessible: You will no longer be able to log in or access Platform features
- Personal data removed: Email, name, and direct identifiers purged from active databases
- Backup purging: Data will be removed from backups within the 1-year window
Exceptions:
- Anonymized aggregate statistics may be retained
- Blockchain records remain immutable
- Legal holds override deletion requests
8. INTERNATIONAL DATA TRANSFERS
Obscura operates globally. Your information may be transferred to, stored in, and processed in countries outside your residence, including the United States and European Union member states.
| Transfer Scenario | Safeguards |
|---|---|
| EU/UK to US | Standard Contractual Clauses approved by European Commission |
| Other international transfers | Data transfer agreements incorporating appropriate safeguards |
By using Obscura, you consent to the transfer of your information to countries that may have different data protection laws than your jurisdiction.
9. YOUR RIGHTS AND CHOICES
9.1 Access and Portability
You may request:
- Confirmation of whether we process your personal data
- A copy of your personal data in structured, machine-readable format
- Information about how your data is processed
9.2 Correction and Deletion
You may:
- Update account information through Platform settings
- Request correction of inaccurate data
- Request deletion of your personal data as described in Section 7.1
9.3 Objection and Restriction
You may:
- Object to processing based on legitimate interests
- Request restriction of processing in certain circumstances
- Withdraw consent at any time (where processing is based on consent)
9.4 Exercising Your Rights
To exercise any rights:
- Submit request via: compliance@obscura.finance
- Provide sufficient information to verify identity
- Specify the right(s) you wish to exercise
We will respond within 30 days (extended by up to 60 days for complex requests).
9.5 California Privacy Rights (CCPA)
California residents have additional rights:
- Right to know categories and specific pieces of personal information collected
- Right to deletion
- Right to opt-out of sales (we do not sell)
- Right to non-discrimination for exercising rights
To exercise California rights, contact compliance@obscura.finance with “CCPA Request” in subject line.
9.6 EU/UK Privacy Rights (GDPR)
EU/UK residents have rights under the General Data Protection Regulation, including:
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to lodge a complaint with a supervisory authority
Our lawful bases for processing include:
- Contract performance: Providing requested services
- Legitimate interests: Platform security, improvement, fraud prevention
- Legal obligation: Compliance with applicable laws
- Consent: Marketing communications
11. SECURITY MEASURES
11.1 Technical Safeguards
| Measure | Implementation |
|---|---|
| Encryption | TLS 1.3+ for transit; AES-256 for data at rest |
| Access Controls | Multi-factor authentication for internal systems; principle of least privilege |
| Monitoring | 24/7 intrusion detection, anomaly detection, log analysis |
| Penetration Testing | Annual third-party security audits; bug bounty program |
| Key Management | Hardware Security Module (HSM) for encryption keys |
11.2 Organizational Safeguards
- Employee training: Annual privacy and security training
- Confidentiality agreements: All employees sign confidentiality agreements
- Access logging: All internal access to user data is logged and audited
- Vendor review: Third-party processors are vetted for security compliance
11.3 No Absolute Security
While we implement industry-standard safeguards, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but will promptly notify you of any known breach affecting your data.
12. CHILDREN’S PRIVACY
Obscura is not intended for individuals under the age of 18 (or the age of majority in their jurisdiction). We do not knowingly collect personal information from minors.
If we become aware that a minor has provided us with personal information, we will delete such information promptly. If you believe a minor has provided personal information, please contact us immediately.
13. THIRD-PARTY LINKS AND SERVICES
The Platform may contain links to external websites or integrate with third-party services (exchanges, blockchain explorers, etc.). This Privacy Policy does not apply to those third parties.
We encourage you to review the privacy policies of any third-party services you access through Obscura. We are not responsible for the content, privacy practices, or data handling of third parties.
14. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect:
- Changes in our practices
- Legal or regulatory requirements
- New features or services
Notification of Material Changes:
- In-platform notification
- Email to registered Users (if material)
- "Last Updated" date at top of policy
Your continued use of Obscura after changes constitutes acceptance of the revised policy. If you do not agree with changes, you must stop using the Platform and submit a deletion request to compliance@obscura.finance.
15. CONTACT INFORMATION
Email for Privacy Inquiries: compliance@obscura.finance
Email for Deletion Requests: compliance@obscura.finance
16. SPECIFIC PROVISIONS BY JURISDICTION
16.1 United States
This section applies to residents of the United States. We comply with applicable federal and state privacy laws. California residents should refer to Section 9.5.
16.2 European Union / United Kingdom
This section applies to residents of the EU/UK. We process personal data in accordance with the General Data Protection Regulation (GDPR) and UK GDPR.
16.3 Other Jurisdictions
If you are accessing Obscura from outside the United States, please note that your data may be transferred to, stored, and processed in the United States or other jurisdictions where our servers operate.
17. ACKNOWLEDGMENT AND AGREEMENT
By using Obscura, you acknowledge:
- You have read and understood this Privacy Policy
- You consent to the collection, use, and sharing of your information as described
- You understand the public, immutable nature of blockchain records
- You accept the security measures and residual risks described
- You understand that deletion requests must be sent to compliance@obscura.finance and that complete data deletion may take up to one year
If you do not agree to this Privacy Policy, you must not use Obscura.
APPENDIX A: DATA PROCESSING SUMMARY
| Processing Activity | Data Categories | Purpose | Legal Basis |
|---|---|---|---|
| Account Creation | Email, username, password | Platform access | Contract |
| Copy Trading | API keys, trade data | Service delivery | Contract |
| Proof Generation | Trade history, ZK proofs | Verification feature | Contract / Legitimate interests |
| On-Chain Anchoring | Proof hashes | Immutable verification | Contract / Consent |
| Analytics | Usage data, device info | Improvement | Legitimate interests |
| Marketing | Email (with consent) | Promotional comms | Consent |
APPENDIX B: KEY DEFINITIONS (LEGAL)
| Term | Definition |
|---|---|
| Controller | The entity that determines purposes and means of processing personal data. |
| Processor | The entity that processes personal data on behalf of the Controller. |
| Personal Data Breach | A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. |
| Consent | Freely given, specific, informed, and unambiguous indication of agreement to processing. |
| Profiling | Automated processing to evaluate personal aspects (e.g., performance, behavior). |
APPENDIX C: DELETION REQUEST PROCESS
To request account deletion:
- Send email to: compliance@obscura.finance
- Subject line: “ACCOUNT DELETION REQUEST — [Your Username]”
- Include: Your registered email address and username
- Verification: We may reply requesting identity verification
- Confirmation: You will receive confirmation within 5 business days
- Timeline:
- Processing halted: Within 1 month
- Account deleted: Within 1 month
- All personal data purged: Within 1 year
- Blockchain data: Permanent (cannot be deleted)