Privacy Policy.
Obiter Technologies Ltd (“Obiter”, “we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, process, and protect your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are registered with the Information Commissioner’s Office (ICO) under registration number ZC211915.
Obiter Technologies Ltd (company number 17329055), registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, is the data controller for the personal data described in this policy. You can contact us about data protection at privacy@obiter.site.
For data-protection requests (access, deletion, objection), contact privacy@obiter.site.
1. Legal Basis for Processing
We process your personal data based on:
- Consent: you have explicitly given us permission (e.g. marketing emails)
- Contract Performance: processing is necessary to provide the Service (e.g. storing your essays, authentication)
- Legal Obligation: we are required by law (e.g. tax records)
- Legitimate Interests: we have a legitimate business interest not overridden by your rights (e.g. fraud prevention, security)
- Consent: usage analytics and the study suggestions built from it are processed only with your consent, which is off by default and can be withdrawn at any time
2. What Data We Collect
2.1 Data You Provide Directly
- Account Registration: email address, hashed password, name (optional), university/institution (optional), year of study (optional)
- Your Content & Activity: essays and answers, flashcards and study notes, quiz responses and MCQ answers, bookmarks and saved articles, study timer sessions, calendar events from connected calendar providers, search queries, support communications
- Audio Recordings & Transcripts: where you choose to record a lecture or study session into a note, the audio file, its duration, and the transcript we generate from it — see Section 3.5
- Dictated Text: where you use dictation in the note editor, the text produced from your speech is inserted into your note and stored as part of that note. Obiter does not receive the audio of dictation — see Section 3.5
- Photos & Files You Choose to Upload: images you take with the camera or select from your photo library, and documents you select from your device, only when you choose to attach them to a note, import them, or set a profile picture
- Payment Information: billing address and subscription details only — we do not store your full card details (handled by Stripe)
- Mobile Phone Number (optional): if you choose to verify a phone number for the referral programme in Settings, we store the number, its country, whether and when it was verified, and a log of the verification texts sent to it (with the IP address the request came from). We use it only to check that each referral reward goes to a real, separate person and to limit abuse of the text-message service. The number is checked and the code is sent through Twilio. See Sections 6 and 7
2.2 Data Collected Automatically
- Device & Browser: device type, operating system, browser type and version, IP address, user agent
- Usage Data: pages/screens you visit, time spent on features, search queries, button interactions (anonymised), error reports
- Cookies: session cookies, analytics cookies, and preference cookies — see Section 9
- Mobile App Device Data: platform (iOS or Android), operating system version, app version, the device's time zone (used to schedule reminders at the correct local time), and, if you enable notifications, a push notification token — see Sections 2.4 and 3.6
We do not actively track your precise location. Your IP address may reveal approximate country/city.
2.3 Data From Third Parties
- Supabase — database and authentication
- OpenRouter, Inc. — We use OpenRouter as an AI gateway to power the Obiter AI assistant. When you send a message to Obiter AI, the content of that message (and any document text you upload) is transmitted through OpenRouter to the model provider that serves the request: Google LLC (Gemini models, via Google Cloud Vertex AI) or OpenAI (GPT-5 models, via OpenAI and Microsoft Azure). OpenRouter acts as a data processor on our behalf under its terms. Our OpenRouter account enforces zero data retention across every provider and switches off all data-training options, so none of these providers retains your content after processing it or uses it to train AI models. This processing takes place in the United States and the EU; these transfers are subject to appropriate safeguards under UK GDPR including Standard Contractual Clauses.
- OpenAI, L.L.C. — We use OpenAI directly to build the search index for your notes and files (text embeddings). The text of a note or file is sent to OpenAI to generate the numerical index that powers search across your own content. We also use OpenAI's Whisper speech-to-text model directly to transcribe audio recordings that are too long for our primary transcription model, or where that model fails — see Section 3.5. OpenAI acts as a data processor under the same zero-retention, no-training account settings, does not retain your content after processing or use it to train models, and processes it in the United States under Standard Contractual Clauses.
- Google Docs Viewer (optional mobile document previews) — if you choose Allow Google preview, the app sends Google a temporary signed link to the selected document so Google can retrieve its contents and display it. This is separate from Google Gemini AI processing — see Section 3.8.
- Apple Inc. and Google LLC (speech recognition) — when you use dictation in the Obiter mobile app, your speech is converted to text by the speech recognition service built into your device's operating system: Apple's on iOS and Google's on Android. Those services may send audio from your device to Apple or Google under their own privacy terms. Obiter never receives the audio — see Section 3.5.
- Expo (650 Industries, Inc.) — push notification delivery for the mobile app. If you enable notifications, we send the notification's title, text, and a link to open inside Obiter to Expo's push service, which delivers it to your device through Apple or Google's notification services — see Section 3.6.
- Stripe — payment processing
- Resend — transactional emails
- MailerLite — our newsletter platform. If you opt in to marketing emails, or join the waitlist or a flyer offer with marketing consent, we send MailerLite your email address, your name and, where you gave it, your university, so that it can send you the newsletter. When you opt out, we tell MailerLite to stop
- Twilio — phone number checks and verification texts. If you verify a phone number, we send Twilio the number so that it can confirm the number is a mobile number in a supported country and text you a one-time code
- Functional Software, Inc. (Sentry) — application error and performance monitoring. We have disabled the sending of personally identifying information to Sentry (sendDefaultPii is false). Sentry processes data from our web servers in the United States under Standard Contractual Clauses; the mobile app's crash reports are configured for Sentry's European Union data region — see Section 3.7.
- Google LLC — when you connect Google Calendar, we receive calendar event data via the Google Calendar API
- Microsoft Corporation — when you connect Outlook Calendar, we receive calendar event data via Microsoft Graph
2.4 Data We Collect on the Mobile App
The Obiter mobile app for iOS and Android collects the same account, content and usage data as the web app, and in addition may use the following device features. Each is used only when you take the action described, and each requires the operating system's permission prompt, which you can decline or later revoke in your device settings.
- Microphone: requested only when you tap Record on a note or tap Dictate in the note editor. Recording never starts without your action, and a recording pauses while the app is in the background — see Section 3.5
- Speech recognition: requested only when you use dictation. Recognition is performed by your device's operating system, not by Obiter — see Section 3.5
- Camera and photo library: accessed only when you choose to take a photo or pick an image to attach to your notes and files, or to set a profile picture. We do not scan or upload your photo library
- Notifications: if you allow notifications, a push token identifying the app on your device is stored against your account — see Section 3.6
- Device details: platform, operating system version, app version, and time zone, as described in Section 2.2
The mobile app does not access your device calendar, contacts, precise location, or advertising identifier, and does not track you across other companies' apps or websites. Calendar integration on mobile works only through the Google or Microsoft account connections described in Section 4, or through iCal (.ics) files you choose to import or iCal feed links you add. The mobile app contains no advertising and no third-party analytics software.
3. How We Use Your Data
3.1 Essential Uses
We process your data to: create and maintain your account; authenticate you; provide the Service; send transactional emails; comply with legal obligations; detect and prevent fraud; enforce our Terms of Service; and respond to law enforcement requests.
3.2 Service Improvement
We use your data to understand how you use Obiter, identify and fix bugs, improve algorithms, test new features, and personalise your experience.
3.3 Marketing (Consent Required)
We will only send you marketing emails if you explicitly opt-in. You can opt-out at any time via the unsubscribe link or in Settings. Marketing emails are sent through Resend or MailerLite, which act only on our instructions (see Section 7). Apart from that, we will not sell, share, or rent your email address to third parties.
3.4 AI-Powered Features
Your conversations with Obiter AI are never used to train AI models. Neither Obiter Technologies Ltd nor the AI providers we route to through our gateway OpenRouter (Google and OpenAI) use your conversation data for model training purposes. Your study questions, uploaded documents, and legal discussions remain private to you and are used solely to generate your responses.
When you use essay feedback or AI explanations, your content is sent through our AI gateway (OpenRouter) to the model provider that generates the response. Obiter does not use your essays or answers to train AI models. AI feedback is generated by machine learning and may not be perfect — review it critically and always verify against authoritative sources.
The same applies on the mobile app: Obiter AI chat, essay and question generation, transcript import for your grades, and audio transcription on mobile are served by the same providers, under the same zero-retention, no-training settings, as on the web.
3.5 Audio Recording, Transcription and Dictation
Lecture recording (Unlimited feature). In My Files, you can record audio into a note. Recording starts only when you tap Record and grant microphone access; it stops when you tap Stop or automatically after 90 minutes. When the recording ends, the audio file is uploaded to our file storage (hosted in the United Kingdom, see our Sub-Processors page) under your account, alongside its duration and file size, and counts towards your storage allowance like any other file.
Transcription. To produce a transcript, the audio file is sent to our AI provider. Shorter recordings (up to 20 minutes and 15 MB) are transcribed by Google's Gemini model through our AI gateway, OpenRouter. Longer recordings, and any recording the primary model fails to transcribe, are sent directly to OpenAI's Whisper model. Both operate under the zero-retention, no-training settings described in Section 2.3, so neither provider retains your audio after transcribing it. The resulting transcript is stored with the recording and appended to your note as text. We also record the number of minutes transcribed each month against your account, to monitor the cost of the feature; this is a count only and contains no audio or transcript content.
Retention and deletion. We do not apply a separate expiry to recordings: a recording and its transcript are kept for as long as the note they belong to exists. The recording, its transcript and the audio file are removed when you permanently delete that note, when the bin is emptied after 30 days, and with the rest of your content when you delete your account. Any transcript text you have kept in the body of the note is part of the note and is deleted with it.
Dictation. The note editor's Dictate button converts your speech to text as you speak. On the mobile app this uses the speech recognition service built into your device's operating system — Apple's on iOS and Google's on Android — which may send audio from your device to Apple or Google for recognition under their own privacy policies. In a web browser, it uses the browser's own speech recognition, which may likewise be provided by the browser vendor. Obiter's servers never receive dictation audio: only the recognised text reaches Obiter, where it becomes part of your note. Dictation is available on every plan.
Recordings may capture the voices of other people, such as lecturers and classmates. You are responsible for ensuring that you have any permission you need before recording others.
3.6 Push Notifications (Mobile App)
If you allow notifications in the mobile app, the app obtains a push token from Expo's notification service and registers it against your account, together with the platform (iOS or Android). The token identifies the Obiter app on that device only; it is not an advertising identifier and cannot be used to identify you outside Obiter. When Obiter has a notification for you — for example a deadline reminder — our server sends the notification's title, text and an in-app link to Expo, Inc. (650 Industries, Inc., United States), which delivers it through Apple's or Google's notification service. We do not send the content of your notes, essays or messages in push notifications. Your device's time zone is stored on your account so that scheduled reminders arrive at the correct local time.
The token is deleted when Apple or Google report that the device is no longer registered, and when you delete your account. You can withdraw notification permission at any time in your device settings; the token then stops working and is removed on the next delivery attempt.
3.7 Crash and Error Reporting
We use Sentry to detect crashes and errors so that we can fix them. On the mobile app, reporting is active only in production builds. Sentry receives technical details of the error (the error message, the stack trace, the app version and operating system version); we have switched off Sentry's collection of personally identifying information and do not attach your account identifier, so mobile crash reports are not linked to you. We do not use session replay or screenshots. The mobile app's Sentry project is configured for Sentry's European Union data region. Our web servers also report errors to Sentry, as described in Section 2.3.
3.8 Optional Document Previews (Mobile App)
PDF, Word and spreadsheet previews in the mobile app use Google Docs Viewer. Before loading that service, the app explains that Google will receive a temporary signed link to your selected file and its contents, and asks you to choose Allow Google preview. Google uses the link to retrieve the file and display its preview. Only allow this if you have permission to share the document with Google.
This preview is optional. You can choose Open in another app instead without authorising Google preview. Google Docs Viewer is separate from the Gemini AI processing described above; the AI-provider retention statements in this policy do not describe this viewer. See Google's Privacy Policy for information about Google's handling of data.
4. Third-Party Calendar Integrations
4.1 What We Access
When you connect Google Calendar or Microsoft Outlook Calendar to Obiter, we receive read-and-write access to your calendar events. This means we can: read event title, description, start time, end time, location, and unique identifier; create new events you add inside Obiter that you choose to save to that calendar; modify events you edit inside Obiter; and delete events you delete inside Obiter. We do not access attendee email addresses, attachments, or anything outside event-level data. We only write to the calendar when you take an explicit action inside Obiter (creating, editing, or deleting an event). For iCal URL subscriptions, we fetch the publicly accessible calendar feed at the URL you provide; whatever the source publishes in that feed is what we receive — iCal subscriptions are read-only.
4.2 Why We Access It
The sole purpose is to display your existing calendar events inside Obiter's calendar view alongside your academic deadlines, study sessions, and exam dates — giving you a single planning view. This is the only purpose for which we use Google or Microsoft calendar data.
4.3 What We Do Not Do
- We only modify, create, or delete events when you explicitly trigger that action in the Obiter UI — we never write to your calendar automatically
- We do not use your calendar data for advertising, profiling, machine-learning training, or any purpose other than displaying and managing it within the Obiter app
- We do not sell or share calendar data with any third party
4.4 Storage and Retention
Calendar events you sync are stored in our database, encrypted at rest, and linked only to your Obiter account. OAuth refresh tokens are stored encrypted. You can disconnect a calendar at any time from Obiter's calendar page, which removes the OAuth token and deletes the synced events from our database. If you delete your Obiter account entirely, all calendar data is removed with it.
4.5 Google API Services User Data Policy
Obiter's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4.6 Microsoft Graph Data
Obiter's use of Microsoft Graph data complies with Microsoft's Services Agreement and follows the same limited-use principles described above.
5. Third-Party File Storage Integrations
5.1 What We Access
When you connect Google Drive, Microsoft OneDrive, or Dropbox to Obiter, we receive: the ability to browse your file list and folders (file names, IDs, modified dates, MIME types), read the contents of files you explicitly import into Obiter, and create or update files in a folder you nominate. For Google Drive specifically, we request the drive.readonly scope (read access to your Drive so you can browse and import) and the drive.file scope (write access only to files Obiter creates or that you explicitly select). For OneDrive we request the equivalent Microsoft Graph scopes (Files.ReadWrite). For Dropbox we request the equivalent scopes to browse and import files you select.
5.2 Why We Access It
To let students import lecture notes, past papers, case briefs, and other study materials from their Drive, OneDrive, or Dropbox into Obiter's note-taking system, and to save Obiter-generated notes and essays back to their cloud storage when they choose to.
5.3 What We Do Not Do
- We only read or write files when you take an explicit action (clicking “Connect Drive”, picking a file from the browser, choosing “Save to Drive”)
- We do not scan, index, or process files outside what you explicitly import
- We do not use file contents for advertising, profiling, or machine-learning training
- We do not sell or share file contents or metadata with any third party
5.4 Storage and Retention
Files you import are stored in our database, encrypted at rest, and scoped to your account. OAuth refresh tokens are stored encrypted. You can disconnect Google Drive, OneDrive, or Dropbox at any time from Settings, which removes the connection token and stops future access. Files and notes you previously imported remain in your Obiter account until you delete them. If you delete your Obiter account, all imported file content is removed with it.
5.5 Google API Services User Data Policy
Obiter's use and transfer of information received from Google APIs (including Drive) adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5.6 Microsoft Graph Data
Obiter's use of Microsoft Graph data (including OneDrive files) complies with Microsoft's Services Agreement and follows the same limited-use principles described above.
6. Data Retention
- Account & Personal Data: retained while your account is active; deleted within 30 days of account deletion
- User Content: retained while your account is active; deleted within 30 days of account deletion (backups up to 90 days)
- Payment Records: retained for 6 years (UK tax law)
- Hosting-provider server logs: retained under the hosting provider's log-retention settings. This is separate from the records we keep in our own database
- Usage and marketing analytics: automatic age-based expiry is currently paused. Identifiable records are subject to consent withdrawal, account deletion and applicable erasure requests. Summary statistics containing no personal data may be retained indefinitely
- Security and error logs we keep ourselves: records of verification texts sent (phone number and IP address), and error records that may include your account identifier, email address, IP address or browser details, currently have no automatic age-based expiry. Retention depends on whether records are needed for an unresolved security incident, error investigation or support request; account-linked records are removed or de-identified when you delete your account
- Phone number: retained while your account is active, and deleted with your account
- Newsletter: your newsletter subscription record is kept until you unsubscribe or delete your account; delivery records currently have no automatic age-based expiry and remain subject to applicable erasure requests and account deletion. Unsubscribing stops future marketing messages
- AI Document Uploads: extracted text and uploaded images have no separate automatic age-based expiry; they remain available with the conversation until it or your account is deleted, or an applicable erasure request is fulfilled
- Audio recordings and transcripts: retained for as long as the note they belong to exists; deleted when you permanently delete the note, when a trashed note is purged after 30 days, or with your account — see Section 3.5
- Push notification tokens: retained while the device is registered; deleted when the device is reported as no longer registered, or with your account — see Section 3.6
- Grades and academic records: your degree structure, modules, marks and grade goals are retained for as long as your account is active, and are deleted with the rest of your content within 30 days of account deletion. We do not apply a shorter automatic window to them: a grade you entered in first year is still the thing your predicted classification is calculated from in final year, so expiring it would silently break the feature. You can delete any year, module or assessment yourself at any time from My Grades, and that deletion is immediate
- Suggestion history: where we have suggested a subject and you have accepted, dismissed or let it expire, we keep that record while analytics is enabled so that we do not ask you the same thing again — a dismissal suppresses that suggestion for 30 days, or 90 days if you have dismissed it before, and we need the record to honour that. Automatic age-based expiry is currently paused; the record is deleted if you switch analytics off or delete your account
Pausing automatic expiry does not remove your deletion rights. Retention depends on whether your account or conversation still uses the data, whether analytics consent remains in place, or whether a specific unresolved security, delivery or support issue requires the record. Contact privacy@obiter.site to request deletion or ask about a record's retention.
6.1 AI Conversation Data
Your conversation history with Obiter AI is stored and linked to your account for as long as your account remains active. You may delete individual conversations or your entire conversation history at any time from within the app. If you delete your account, all conversation history is permanently deleted within 30 days. Obiter staff may access anonymised conversation data in limited circumstances for safety monitoring and product improvement, subject to strict internal access controls. Conversations are never reviewed by Obiter staff in a personally identifiable form except where required to investigate a breach of these Terms, a safety concern, or a legal obligation.
6.2 AI Document Uploads
When you upload a document to Obiter AI, we extract the text content of that document for processing. For most documents we extract and retain the text; uploaded images may also be stored with the conversation. These records currently have no separate automatic age-based expiry and are removed when the conversation or account is deleted, or an applicable erasure request is fulfilled. Transcripts imported into your grades tracker are different: where you upload a PDF, the file itself is sent to our AI provider so that the modules and marks can be read out of it. Your transcript is not used to train AI models and is not retained by our AI provider beyond processing it. Extracted text is transmitted to our AI provider for AI processing (see Section 7). You can request deletion of uploaded document data at any time by contacting privacy@obiter.site or using the in-app data deletion tools. Do not upload documents containing sensitive personal data about third parties, as such data will be transmitted to our AI provider.
7. Data Sharing & Third Parties
7.1 Who We Share With
For core Obiter processing, we share data with service providers bound by Data Processing Agreements: Supabase (database and file storage), OpenRouter (AI gateway) and the model providers it routes to, Google LLC and OpenAI (AI model processing, including audio transcription), OpenAI (note-search embeddings and Whisper transcription), Expo (mobile push notification delivery), Stripe (payments), Resend (email), MailerLite (newsletter, only if you opt in), Twilio (phone number checks and verification texts, only if you verify a phone number), Functional Software, Inc. (Sentry — application error and performance monitoring), and legal or regulatory authorities if required by law. We also receive data from Google LLC (Google Calendar API, Google Drive API), Microsoft Corporation (Microsoft Graph), and Dropbox, Inc. when you connect those services — see Sections 4 and 5 for details on how that data is used. When you use dictation, your device's operating system sends speech to Apple or Google for recognition under their own terms; that audio does not pass through Obiter — see Section 3.5.
Separately, if you allow a mobile document preview, the selected file's temporary signed link and contents are shared with Google Docs Viewer to display that preview. This optional service is described in Section 3.8 and is distinct from our Google Gemini integration.
7.2 What We Do Not Do
- We do not sell your personal data to advertisers or data brokers
- We do not share your essays with our AI providers for model training
- We do not share your data with competitors
7.3 International Transfers
Some service providers are based outside the UK. The following processors are based in the United States, and for AI model processing via Google also the EU, with transfers subject to Standard Contractual Clauses (SCCs): OpenRouter, Inc. (AI gateway); Google LLC (AI model processing, USA and EU); OpenAI, L.L.C. (AI model processing, audio transcription and note-search embeddings); Expo (650 Industries, Inc.) (mobile push notification delivery); Stripe, Inc. (payments); Functional Software, Inc. (Sentry — error monitoring; the mobile app's project is in the EU region); Dropbox, Inc. (file storage integration). Speech recognition for dictation is performed by Apple Inc. or Google LLC as the provider of your device's operating system, outside Obiter's systems. Where MailerLite and Twilio process your data, and the safeguard that applies to any transfer, are listed on our Sub-processors page. Contact us for further details on the safeguards in place.
8. Your GDPR Rights
Under UK GDPR, you have the right to:
- Access: request a copy of all personal data we hold about you
- Rectification: correct inaccurate or incomplete data (update in Settings or email us)
- Erasure: request deletion of your personal data (delete your account in Settings — see Section 8.2)
- Data Portability: receive your data in a portable format (CSV/JSON) via Settings → Data & Privacy
- Object: object to certain processing, including marketing (click Unsubscribe or email us)
- Restrict Processing: request that we limit how we use your data
- Lodge a Complaint: with the ICO at ico.org.uk/make-a-complaint
To exercise any right, email privacy@obiter.site. We will respond within 30 days.
8.1 AI Conversation Data in Subject Access Requests
Your Obiter AI conversation history is personal data and is included in any Subject Access Request (SAR) you make. If you exercise your right to erasure, your AI conversation history will be deleted in addition to your other account data. You may also delete your conversation history directly in the app without submitting a formal SAR.
8.2 Deleting Your Account
You can delete your account yourself, without contacting us, from either of these places:
- In the mobile app: Settings → Delete my account. You will be asked to confirm by typing DELETE.
- On the web: sign in at app.obiter.site/settings and choose Data & Privacy → Delete my account. This works whether or not you still have the mobile app installed.
Both routes run the same process: any active subscription is cancelled, and your account together with all of the content and records listed in this policy — including notes, recordings and transcripts, flashcards, essays, grades, calendar data and connection tokens, push notification tokens, analytics events and usage records — is removed from our live database in a single operation at the moment you confirm. Backup copies expire on the schedule set out in Section 6. Payment records that we must keep under tax law are retained as described in Section 6.
9. Cookies
We use:
- session_token — authentication (required, keeps you logged in)
- obiter_theme — remember your theme preference (essential)
- obiter_cookie_consent — stores your cookie consent preference (essential)
- stripe_session — payment processing (required for checkout)
If you select “Accept All” on the cookie banner, we record usage analytics — which pages and features you use, and when — linked to your Obiter account. This is first-party: it is stored only in our own database (hosted in the European Union) and is not shared with any third-party analytics provider. We record only the specific events we have defined rather than everything you click, and not your screen — we do not use session replay. We never record the content of your notes, essays, messages or searches. If you select “Essential Only”, none of this is collected.
You can manage cookies in your browser settings. Disabling essential cookies may limit functionality. See our full Cookie Policy.
The mobile app does not use cookies. The same usage analytics choice is presented there as the “Help us improve Obiter” toggle, off by default, which you can change at any time in the app's Settings. Your choice is stored on your account and enforced by our server: while it is off, the server discards any usage event other than the record of the choice itself and the record that sign-up completed. Mobile analytics events carry the platform (iOS or Android), operating system version and app version so that we can tell which apps are in use; they are first-party, stored only in our own database, and never contain the content of your notes or messages.
9a. Suggestions based on your activity
If you have switched analytics on, Obiter looks at which subjects you have been studying — the flashcards you review, essays you open, and articles you click — and works out which topics you have spent the most time on recently. We use this to occasionally suggest adding a subject to your interests, or to point you at ready-made card sets. Every suggestion tells you why it appeared.
This is simple arithmetic on your own activity, not artificial intelligence, and it never changes your profile by itself — only you can accept a suggestion. You will see at most one suggestion a week, and saying “No thanks” stops that suggestion for at least a month.
If you have not switched analytics on, none of this happens: we do not build the profile at all. Switching analytics off later deletes it.
We keep a record of suggestions you have been shown and how you responded, so that we do not repeat one you have declined. These records are deleted on the same 24-month schedule as the rest of your usage analytics, or immediately if you delete your account.
10. Security
We implement industry-standard security: HTTPS/TLS encryption in transit, AES-256 encryption at rest for sensitive data, bcrypt password hashing, access controls with multi-factor authentication, and regular security audits. If a breach occurs, we will notify you within 72 hours as required by law.
11. Children's Privacy
Obiter is not intended for children under 16. We do not knowingly collect data from children under 16. If we discover we have done so, we will delete it immediately.
12. Changes to This Policy
We may update this Privacy Policy as needed. Material changes will be posted on this page and notified via email at least 30 days in advance.
13. Contact
Obiter Technologies Ltd (company number 17329055), registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, is the data controller for the personal data described in this policy. You can contact us about data protection at privacy@obiter.site.
For privacy questions or requests: privacy@obiter.site