Obsidian Club — Privacy Policy
Effective date: October 1, 2026 · Last updated: August 11, 2026
1. Who we are
This Privacy Policy explains how Obsidian Club (operated by [legal entity — formation in progress], "we," "us") collects, uses, and shares personal information when you use obsidianclub.online and related services (the "Platform"). Obsidian Club is a private, invitation-only community for verified adults. Contact: privacy@obsidianclub.online / [notice address — to be added].
By using the Platform you agree to this Policy and our Terms of Service. Because the Platform serves adults and hosts sensitive personal expression, we try to collect the minimum necessary and to protect it carefully.
2. Information we collect
a. Information you provide.
- Account data: name, email address, and password; or, if you use Google sign-in, the basic profile and email Google shares (we do not receive your Google password).
- Age/identity verification data: information you or our verification provider submit to confirm you are 18+ (see Section 3). Depending on the method, this may include a government-ID check performed by a third-party provider.
- User Content: posts, photographs, comments, and messages you create in community feeds, spaces, and chat rooms. This content can be intimate or sensitive by nature.
- Communications: messages you send us (support, reports).
b. Information collected automatically.
- Device/usage and log data: IP address, browser/device information, timestamps, and pages/actions.
- Security and rate-limit logs: IP-based logs used to prevent abuse, brute-force attempts, spam, and evasion of enforcement.
- Cookies / similar technologies: essential cookies for authentication and security; see Section 8.
c. Information from others.
- Invitations/sponsorship: the fact and source of your invitation token and, if applicable, the member who sponsored you.
- Verification provider: a pass/fail age result and limited metadata from the age-verification method described in Section 3.
We do not intentionally collect payment-card data on the Platform (the Platform is free); any Torross purchases occur through separate commerce channels with their own notices.
3. Age verification and the `ageVerified` status
Access requires confirmation that you are 18 or older. For the launch cohort, verification is manual review by administration; a third-party verification provider will be added before general availability. We store an age-verified status flag (`ageVerified`) on your account, plus limited verification metadata (method, date, result). Where a government-ID check is used, the provider performs it; we aim to store only the result and minimal metadata, not full ID images, unless retention is legally required.
4. How we use information
We use personal information to: (a) create and secure your account and verify age; (b) operate the community — display your content, enable comments, chat, and spaces; (c) moderate and enforce our Terms, Acceptable Use Policy, and red lines, including investigating reports and preventing minors' access, non-consensual content, and abuse; (d) protect the Platform and members (fraud/abuse prevention, rate-limiting, security); (e) communicate with you (transactional email via Resend — verification, security, service notices); (f) comply with legal obligations and respond to lawful requests; and (g) improve reliability and features. We do not use your intimate User Content to train advertising profiles, and we do not sell it.
Legal bases (if you are in a region that requires them): performance of our contract with you; our legitimate interests in operating a safe community; consent where required (e.g., certain sensitive data / verification); and legal obligation.
5. How we share information
We share personal information only as follows:
- With other members, to the extent you choose to post it. Your User Content and profile are visible to the community per your settings and the nature of the space. Assume other members can see, and could misuse, what you post — our anti-leak rules prohibit off-Platform sharing but cannot guarantee others' conduct.
- With service providers ("processors") who act on our instructions under contract: - Vercel — application hosting/delivery. - Supabase — database and authentication (data hosted on AWS, us-east-2). - Resend — transactional email delivery. - At launch, age/identity verification is manual review by administration — no third-party processor is used for this yet; one will be added and listed here before general availability. These providers are permitted to use the data only to provide services to us.
- For legal and safety reasons: to comply with law, enforce our Terms, respond to lawful requests, protect rights and safety, and — where required — to report suspected child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC) and/or authorities, as required by 18 U.S.C. §2258A.
- In a business transfer: if we are involved in a merger, acquisition, or asset sale, subject to this Policy.
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law (see Section 9).
6. Retention
We keep personal information only as long as needed for the purposes above:
- Account/profile: while your account is active and for a limited period after closure for security, dispute, and legal-compliance purposes.
- User Content: until you delete it or your account is closed, subject to residual backups and any legal-hold or reporting obligation.
- Security/rate-limit logs: a limited rolling window ([e.g., 30–180 days]).
- Verification metadata: [retention period]; ID images (if ever stored) only as legally required, then deleted.
- Enforcement/red-line records: retained as needed to enforce bans and meet legal/reporting obligations.
7. Security
We use technical and organizational measures — encryption in transit, access controls, authentication, rate-limiting, and least-privilege practices — to protect personal information. No system is perfectly secure. Given the sensitivity of community content, we design for data minimization and restricted access. If a breach affecting your information occurs, we will notify you and regulators as required by law.
8. Cookies and tracking
We use essential cookies and similar technologies for authentication, session management, security, and rate-limiting. We do not use third-party advertising trackers. Where required, we will present a cookie notice/controls. You can control cookies through your browser, but disabling essential cookies may break sign-in.
9. Your California privacy rights (CCPA/CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the CPRA:
- Right to know / access the categories and specific pieces of personal information we collected, the sources, purposes, and third parties.
- Right to delete personal information we hold, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of sale/sharing — we do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of; if this changes we will provide a "Do Not Sell or Share My Personal Information" link.
- Right to limit use of sensitive personal information — see below.
- Right to non-discrimination for exercising your rights.
Categories collected (CCPA): identifiers (name, email, IP, account ID); internet / network activity (usage and security logs); audio/visual/User Content (your posts and photos); and, potentially, sensitive personal information — which may include account credentials and, depending on the content you choose to share and the inferences that could be drawn, information the CPRA treats as sensitive.
Purposes are described in Section 4; disclosures to processors in Section 5. We collect these categories from you, automatically, and from our verification provider and sponsors.
How to exercise rights: email privacy@obsidianclub.online or use in-product controls. We will verify your request (typically via your account email) and respond within the timelines the law requires (generally 45 days, extendable). You may use an authorized agent. We do not charge for most requests.
Shine the Light (Cal. Civ. Code §1798.83): we do not share personal information with third parties for their own direct marketing.
10. Other U.S. state rights
If you reside in a U.S. state with a comprehensive privacy law (e.g., Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and others), you may have similar rights to access, correct, delete, and opt out of targeted advertising, sale, or certain profiling. We honor these where they apply; contact privacy@obsidianclub.online. Because we do not sell data or run targeted advertising, several opt-outs do not apply.
11. Children
The Platform is strictly for adults 18+. We do not knowingly collect information from anyone under 18. If we learn that a minor has accessed the Platform or that content involves a minor, we will terminate access, remove and preserve content as required, and report as legally mandated.
12. International users and data location
The Platform is operated from the United States and data is stored in the U.S. (including AWS us-east-2). If you access it from outside the U.S., you understand your information is processed in the U.S. under U.S. law.
13. Changes to this Policy
We may update this Policy. Material changes will be notified (email or in-product) and reflected in the "Last updated" date. Continued use after the effective date means you accept the updated Policy.
14. Contact
Privacy questions or requests: privacy@obsidianclub.online, or Obsidian Club (operated by [legal entity — formation in progress]), [notice address — to be added].