Back to sign in

Obso Privacy Policy

Last updated: 2026-07-28 Effective date: 2026-07-28

1. Who We Are and What This Covers

This Privacy Policy explains how we collect, use, store, share, and protect personal information when you use Obso — our website, web application, AI workspace, chat, model routing, memory, files, connectors, automations, media generation, code execution, browser and computer-use tools, projects, library, publishing, billing, and related services (the "Service").

Data controller JTTTsolutions, Inc., a Delaware corporation doing business as Obso Registered office: Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, New Castle County, Delaware 19713, United States

All privacy enquiries: [email protected]

If you do not agree with this Policy, do not use the Service.

2. Information We Collect

Account information

  • Name and email address.
  • Authentication credentials. Passwords are stored only as salted hashes; we never see your password.
  • Profile and preference data: language, profession, interests, onboarding answers, referral source.
  • Account, feature, memory, model, and notification settings.

Content and workspace data

  • Prompts, messages, chats, conversations, branches, summaries, and instructions.
  • Short-term working memory and long-term memory.
  • Uploaded, imported, and generated files.
  • Documents, spreadsheets, presentations, PDFs, code, websites, applications, diagrams, artifacts, project files, and generated images, audio, and video.
  • Project metadata, deployment metadata, previews, logs, screenshots, browser traces, and application-builder data.
  • Project secrets, environment-variable names, and connector credentials where you choose to store them. Secrets and tokens are encrypted at rest.

AI, tool, and usage data

  • Model selections, routing decisions, tool calls, automation runs, media requests, search requests, code-execution activity, and browser or computer-use activity.
  • Credit estimates, reservations, consumption, costs, provider metadata, and usage logs.
  • Error reports, diagnostic logs, performance data, and stack traces.

Connected services

If you connect a third-party service, we collect what you authorize: connected-account identifiers and profile metadata, OAuth or access tokens, and the files, messages, tasks, calendar entries, documents, repositories, or other content you permit Obso to access. We access a connected service only within the permissions you grant and at your direction.

Billing information

  • What you purchased, the amount, currency, and payment status.
  • Stripe checkout, payment-intent, and transaction identifiers.
  • Purchase history, refunds, chargebacks, and your credit balance.

We never receive or store full card numbers or card security codes. Those go directly to Stripe, which processes them under its own terms and privacy policy.

Device, log, and security data

IP address, device identifiers, browser type, operating system, application version, referring pages, pages viewed, approximate location derived from IP address, session activity, and security and fraud-prevention signals.

Communications

If you contact support, join a waitlist, submit feedback, report a bug or abuse, or answer a survey, we collect your contact details, the content of your message, attachments, and related metadata.

3. How We Use Information

We use personal information to:

  • Provide, operate, maintain, secure, and improve the Service.
  • Create and manage accounts, and authenticate you.
  • Route prompts to AI models and tools, and return outputs.
  • Generate, edit, store, display, export, and organize your content.
  • Provide memory, personalization, summaries, automations, connectors, browser and computer-use workflows, code execution, projects, publishing, and library features.
  • Process purchases, refunds, chargebacks, fraud checks, taxes, and billing support.
  • Estimate, reserve, deduct, reconcile, and display credits.
  • Provide support and respond to your requests.
  • Send service messages, security alerts, and billing notices.
  • Monitor reliability, debug errors, and improve performance.
  • Detect, investigate, and prevent fraud, security incidents, unauthorized access, payment abuse, scraping, spam, and breaches of our Terms.
  • Comply with legal obligations and enforce our agreements.

We do not sell personal information. We do not use your workspace content to train Obso-owned or Obso-operated AI models. If we ever wanted to, we would ask for your explicit opt-in first.

4. Legal Bases

Where the GDPR, UK GDPR, or the Saudi Personal Data Protection Law applies, we rely on:

  • Contract — to provide the Service you asked for, including processing prompts, storing your content, and handling payments.
  • Consent — for connecting third-party accounts, importing data, optional memory features, and marketing where required. You can withdraw consent at any time.
  • Legitimate interests — to secure and improve the Service, prevent fraud and abuse, and understand aggregate usage, where those interests are not overridden by your rights.
  • Legal obligation — for tax, accounting, and law-enforcement requirements.

5. AI Providers and How Your Content Is Processed

When you use an AI feature, we send the content that feature needs — prompts, files, context, memories, conversation excerpts, tool outputs, images, audio, video, or code — to an AI provider so it can return a result.

We send only what the requested feature requires, but AI systems generally need context to work well. Do not submit information you are not authorized to share, or that is too sensitive for this kind of processing.

Principal AI and media providers: Anthropic, OpenAI, Google (Gemini and Cloud Vision), xAI, Mistral, Fireworks AI, OpenRouter, fal.ai, BytePlus, HeyGen, Kling, Alibaba DashScope, and AssemblyAI.

We select providers that contractually commit not to train on customer content submitted through their business APIs, and we configure their services accordingly where that option exists.

Principal infrastructure providers: Neon (database), Cloudflare (object storage and network), Tigris (object storage), Fly.io (isolated execution sandboxes and application hosting), Railway (application hosting), Sentry (error monitoring), Resend (transactional email), and Stripe (payments).

A note on error monitoring: our error-monitoring provider receives diagnostic data when something goes wrong, which can include an account identifier, a request identifier, and technical context surrounding the failure. We configure it to minimize personal data, but stack traces can occasionally capture fragments of whatever was being processed at the moment of the error.

Providers change as the product evolves. A current, complete list of subprocessors is available on request from [email protected].

6. Who We Share Information With

We share personal information with:

  • The AI, media, and infrastructure providers named above, to deliver the features you use.
  • Stripe and, where relevant, banks, card networks, and fraud-prevention services, to process payments and disputes.
  • Third-party services you explicitly connect.
  • Professional advisers — lawyers, accountants, auditors — under confidentiality obligations.
  • Law enforcement, regulators, or courts where legally required, or to protect rights, safety, or property. Where we are legally permitted to tell you first, we will.
  • An acquirer or successor in a merger, acquisition, financing, or asset sale, subject to confidentiality. We will notify you if your information becomes subject to a different privacy policy.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

7. International Transfers

Obso is operated from the United States, and our providers are located in the United States and elsewhere. Using the Service means your information is transferred to and processed outside your own country.

Where we transfer personal information out of the European Economic Area, the United Kingdom, or Saudi Arabia, we rely on:

  • Standard Contractual Clauses approved by the European Commission, and the UK International Data Transfer Addendum, for transfers to countries without an adequacy decision.
  • Adequacy decisions, where the relevant authority has recognized a country as providing adequate protection.
  • Contractual and technical safeguards required of every subprocessor.

For users in Saudi Arabia, transfers are made in accordance with the Personal Data Protection Law and its implementing regulations.

You may request details of the safeguards we use by writing to [email protected].

8. Retention

We keep personal information only as long as needed for the purposes it was collected for, to meet legal obligations, resolve disputes, and enforce our agreements.

DataRetention
Account informationLife of the account, then deleted within 90 days of a deletion request
Workspace content (prompts, files, projects, memories)Life of the account; deleted within 30 days of a deletion request
Billing and transaction records7 years from the transaction, for tax and accounting law
Usage and credit logs24 months
Error and diagnostic logs90 days
Security and fraud-prevention logs24 months
Support communications3 years from last contact
BackupsRotated; deleted content disappears from backups within 30 days

After these periods we delete or irreversibly anonymize the data. We may keep aggregated or anonymized data that cannot identify you.

A legal hold, live dispute, or fraud investigation can require us to retain data longer.

9. Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, encryption of stored secrets and tokens, access controls, audit logging, isolated execution sandboxes for code and browser workloads, rate limiting, and monitoring.

No system is perfectly secure. Keep your credentials safe, use a strong unique password, protect your devices, and avoid submitting sensitive information you do not need to.

Report a security concern to [email protected]. We investigate good-faith reports and will not pursue researchers who disclose responsibly.

10. Data Breach Notification

If a personal data breach is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by the GDPR, UK GDPR, and Saudi PDPL.
  • Notify affected users without undue delay where the breach is likely to result in a high risk to them.
  • Explain what happened, the categories and approximate volume of data involved, the likely consequences, and what we are doing about it.
  • Keep an internal record of every breach, whether or not notification was required.

11. Your Rights

Subject to applicable law, you may:

  • Access a copy of the personal information we hold about you.
  • Correct inaccurate or incomplete information.
  • Delete your personal information, subject to legal retention obligations.
  • Restrict or object to processing, including processing based on legitimate interests.
  • Port your data — receive it in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting the lawfulness of earlier processing.
  • Complain to your data protection authority.

How to exercise them: email [email protected]. We respond to verified requests within 30 days and may need to verify your identity first. There is no charge, and we will not treat you differently for asking.

Export it yourself: you can export your workspace content from within the Service at any time. For a full export including account and billing records, email us.

European Union and United Kingdom

You may lodge a complaint with your national data protection authority or, in the UK, the Information Commissioner's Office.

Saudi Arabia

The PDPL additionally gives you the right to be informed of the legal basis for processing and to report violations to the Saudi Data & AI Authority (SDAIA).

California and other US states

You have the rights listed above, plus the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not process it for cross-context behavioral advertising. We honor these rights for all users regardless of whether we currently meet the statutory thresholds.

12. Cookies and Local Storage

We use only strictly necessary cookies, plus local storage for your preferences.

  • Strictly necessary cookies keep you signed in, maintain your session, and protect against fraud and abuse. The Service cannot function without them and they cannot be switched off.
  • Local storage on your device remembers preferences such as language and theme.

We do not use advertising cookies, analytics cookies, tracking pixels, or any cross-site or cross-context behavioral tracking. Because we place no non-essential cookies, no cookie consent banner is required and we do not show one.

If we ever introduce analytics or any non-essential cookie, we will update this Policy and put a proper consent mechanism in place before doing so.

You can block or delete cookies in your browser settings, but the Service will not work correctly without the necessary ones.

13. Children

Obso is not intended for anyone under 18, or under the age of legal majority where that is higher. We do not knowingly collect personal information from children. If you believe a child has given us personal information, email [email protected] and we will delete it.

14. Automated Processing

Obso uses AI and automated systems to generate responses, route model requests, produce content, estimate credits, detect abuse, personalize features, summarize memories, and run automations.

We do not make decisions producing legal or similarly significant effects about you by automated means alone, with one exception: automated fraud and abuse controls can restrict or suspend an account. If an automated control affects your account you can request human review by emailing [email protected], and you may contest the outcome.

Obso should not be used as the sole basis for decisions with legal, financial, medical, employment, housing, educational, insurance, immigration, law-enforcement, or safety-critical effects without human review.

15. Marketing

We send service communications about your account, security, billing, and important product changes. These are part of the Service and cannot be opted out of while you hold an account.

Any marketing email carries an unsubscribe link, and we send marketing only where permitted by law. Unsubscribing never affects service communications.

16. Changes to This Policy

We may update this Policy. The updated version is posted with a new "Last updated" date. Where changes are material we will give notice by email or in the Service before they take effect.

17. Contact

JTTTsolutions, Inc., doing business as Obso Registered office: Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, Delaware 19713, United States

Privacy requests, security reports, data-subject requests, and all other enquiries: [email protected]

Users in Saudi Arabia may also contact the Saudi Data & AI Authority (SDAIA).