Who we are and how to reach us
Obrasken decides how your data is handled, and answers privacy requests by email.
Obrasken ("Obrasken", "we", "us") operates the creative platform at https://obrasken.com. For data protection purposes Obrasken is the controller of the personal data described in this policy — meaning we decide what is collected and why.
- Privacy and data requests
- privacy@obrasken.com
- General support
- support@obrasken.com
- Security reports
- support@obrasken.com
- Operating from
- Canada
What this policy covers
The website, the app, and the emails we send you.
This policy covers the Obrasken website, the signed-in application, and the transactional emails we send. It does not cover third-party services you choose to connect, or sites we link to, which operate under their own policies.
If you connect your own AI provider keys (Bring Your Own Key), work you run through them is processed by that provider under your agreement with them. We describe what we still see in section 6.
What we collect
Account details, what you create, billing records, and technical signals needed to keep the service safe.
Information you give us
- Account: email address, display name, password hash (or a Google account identifier if you sign in with Google), and multi-factor authentication enrolment data.
- Content: prompts, uploaded images and files, drawings, projects, and generated outputs.
- Personalisation: the Creative DNA / Memory Vault signals derived from what you save, skip, and export — used only to tailor your own results.
- Support and consent: messages you send us, and a record of which policy version you accepted and when.
- Billing: handled by Stripe. We store a customer and subscription identifier, plan, and status. We never receive or store your full card number.
Information we generate or observe
- Usage: credit transactions, generation metadata (model, cost, timing, success or failure), and which features you use.
- Security: sign-in events, rate-limit counters, and audit records of sensitive actions such as key changes and deletions.
- Technical: IP address, browser and device characteristics, and request timing. IP is used for rate limiting, abuse prevention, and coarse regional routing.
Why we use it, and our legal basis
Each purpose has a specific lawful basis — we do not rely on consent for things you cannot opt out of.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and operate your account, authenticate you | Account, security | Performance of a contract |
| Run the creative tools and store your work | Content, usage | Performance of a contract |
| Take payment, grant credits, manage subscriptions | Billing, usage | Performance of a contract |
| Personalise results to your taste | Personalisation | Consent — you can disable, reset, or delete it |
| Prevent abuse, fraud, and credit manipulation | Security, technical | Legitimate interests |
| Keep the platform secure and debug failures | Security, technical | Legitimate interests |
| Answer support requests | Support, account | Performance of a contract |
| Send service and transactional email | Account | Performance of a contract |
| Meet tax, accounting, and legal obligations | Billing, consent records | Legal obligation |
Where we rely on legitimate interests, we have considered the impact on you and limited the processing accordingly — for example, rate-limit signals are derived from your IP rather than stored as a browsing history. You can object to processing based on legitimate interests; see section 11.
AI generation and your content
Your prompt goes to the provider that fulfils it. We do not train our own models on your work.
When you run a generation, the prompt and the inputs required for it are sent to the AI provider fulfilling that request. Some features run entirely on your device or on our own servers with no provider call at all; those are labelled in the interface and cost no credits.
- We send the minimum needed to fulfil the request — not your account history, and not your other projects.
- Obrasken does not train its own foundation models on your content.
- Your personalisation profile is private to your account and is never pooled with other users.
- Providers process content under their own terms and may retain it briefly for safety and abuse monitoring. If you need provider-level control, use Bring Your Own Key so the request runs under your own provider account.
If you use ElevenLabs-backed voice features, audio you submit is processed by that provider. Voice recordings can identify a person, so treat them as sensitive and only submit voices you have permission to use.
International transfers
Your data may be processed outside Canada, under contractual safeguards.
Our providers operate in Canada, the United States, and the European Union. This means your personal data may be transferred to and processed in a country other than your own, including the United States.
- For transfers from the EEA, UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), incorporated into our agreements with each provider.
- For transfers from Canada, we remain accountable for your data under PIPEDA regardless of where it is processed, and require comparable protection by contract.
- You may request a summary of the safeguards applying to a specific provider by emailing privacy@obrasken.com.
How long we keep it
Content lasts until you delete it. Billing records are kept because tax law requires it.
| Category | Retention |
|---|---|
| Account record | For as long as your account exists, then deleted or anonymised on account deletion |
| Content and generated outputs | Until you delete them, or on account deletion |
| Personalisation profile | Until you reset or delete it, or on account deletion |
| Credit and transaction ledger | Retained after deletion where needed to evidence billing, then anonymised |
| Billing and tax records | As required by Canadian tax and accounting law (generally six years) |
| Consent records | For as long as needed to evidence the consent, including after account deletion |
| Security and audit logs | A limited period for fraud and abuse prevention, then deleted |
| Support correspondence | Kept while needed to resolve the matter and for a reasonable period afterwards |
Backups are cycled on a rolling basis, so deleted data can persist in backups for a short window after deletion before being overwritten.
Security
Specific measures, and an honest limit on what any of them guarantee.
- Encryption in transit for all traffic, and encryption at rest for stored provider keys.
- Row-level security so account data is isolated at the database layer, not only in application code.
- Optional multi-factor authentication, with step-up challenges on sensitive actions.
- Rate limiting and audit logging on sensitive endpoints.
- Secrets are held server-side and are never exposed to the browser.
No system is perfectly secure, and we will not claim otherwise. If we become aware of a breach affecting your personal data, we will notify the relevant supervisory authority and affected users without undue delay where the law requires it, and describe what happened and what we did.
If you believe you have found a vulnerability, report it to support@obrasken.com. We will not pursue action against good-faith research that avoids privacy violations, service disruption, and data destruction.
Automated decisions and profiling
We personalise results. We do not make legal or financial decisions about you automatically.
We use your personalisation profile to shape creative output, and automated rules to enforce rate limits and detect abuse. These do not produce legal effects of the kind that would trigger a right to human review under GDPR Article 22.
If an automated abuse control restricts your account and you believe it is wrong, contact support and a person will review it.
Your rights and how to use them
Most controls are self-serve in Settings; the rest are one email away.
Depending on where you live you may have some or all of the following rights. We apply them to everyone as a matter of practice, not only where legally compelled.
- Access
- Get a copy of the personal data we hold about you. Export is available in Settings.
- Correction
- Fix inaccurate data. Profile fields are editable in Settings.
- Deletion
- Delete individual generations, reset your personalisation profile, or request full account deletion — all from Settings.
- Portability
- Receive your data in a machine-readable format. The export is JSON.
- Restriction and objection
- Ask us to pause processing, or object to processing based on legitimate interests.
- Withdraw consent
- Turn off personalisation at any time. This does not affect processing needed to run your account.
- Non-discrimination
- We will not degrade your service for exercising a privacy right.
Self-serve controls live in Settings. For anything else, email privacy@obrasken.com. We respond within 30 days, and will tell you if we need longer where the law allows an extension. We may ask you to verify your identity — we will not ask for a password. An authorised agent may act for you with written proof.
Children
Not for under-16s, and we delete accounts we discover.
Obrasken is not directed to children. You must be at least 16 years old to create an account, or older if your country sets a higher age for consenting to online services. We do not knowingly collect data from children below that age; if we learn we have, we delete the account and its content. If you believe a child has created an account, tell us at privacy@obrasken.com.
Regional information
Extra rights that apply depending on where you live.
EEA, UK, and Switzerland
You may lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office. We would appreciate the chance to resolve it first. We have not appointed an EU or UK representative under GDPR Article 27; if you require one for a formal matter, contact us and we will address it directly.
California
We collect the categories described in section 3 for the purposes in section 4. We do not sell personal information and do not share it for cross-context behavioural advertising, so no opt-out is required. You may exercise access, deletion, correction, and non-discrimination rights via section 11. We do not use or disclose sensitive personal information for purposes requiring a limitation right.
Canada
We handle personal information in accordance with PIPEDA and applicable provincial legislation. You may direct a complaint to the Office of the Privacy Commissioner of Canada, or to your provincial authority where one has jurisdiction.
Changes to this policy
Material changes are announced, and we ask you to accept them.
We version this policy and keep a changelog at the end of the page. If we make a material change we will notify you in-app or by email, and where the change affects what you agreed to, we will ask you to accept the new version before continuing to use Obrasken.
Version history
- Version 2.02026-07-29
- Named every sub-processor individually (previously only Supabase and Stripe were disclosed), added legal bases per purpose, per-category retention, international transfer terms, automated decision-making, breach notification, and region-specific sections for the EEA/UK, California, and Canada.
- Version 1.02026-07-11
- First published policy.