Privacy Policy

Effective Date: November 1, 2025

Version 2.0 - Last Updated: November 1, 2025

Service Provider: Nikolas Lester Zral (Sole Proprietorship, British Columbia, Canada)

1. Introduction

Welcome to Obra. This Privacy Policy explains how Nikolas Lester Zral ("we," "us," "our") collects, uses, and protects your information when you use the Obra iOS application ("App").

Key Principles:

  • ✅ Data stored locally on your device
  • ✅ No collection of personal information
  • ✅ No activity tracking or analytics
  • ✅ No sale of user data
  • ✅ Subscription management via Apple

---

2. Data Controller Information

Service Provider: Nikolas Lester Zral

Business Type: Sole Proprietorship

Location: British Columbia, Canada

Email: privacy@obraos.com

Support: support@obraos.com

Website: https://obraos.com

---

3. Information We Do NOT Collect

We want to be transparent about what we do not collect:

  • ❌ Personal identification (name, email, phone number)
  • ❌ Location data or geolocation tracking
  • ❌ Device identifiers for advertising or tracking
  • ❌ Contacts, address book, or calendar data
  • ❌ Health or fitness data
  • ❌ Financial or payment information
  • ❌ Browsing history or web data
  • ❌ Usage analytics or behavioral data
  • ❌ Biometric data
  • ❌ Social media information

---

4. Information We Process

4.1 Local Device Storage

The following data is stored exclusively on your device:

  • Generated Apps: All applications you create
  • App Settings: Your preferences and configuration
  • Usage Counters: Daily generation/edit limits (Free tier only)
  • Subscription Status: Whether you have an active subscription
  • Image Attachments: Photos you choose to include with prompts

Important: This data:

  • Never leaves your device
  • Is not uploaded to our servers
  • Is protected by iOS security and device encryption
  • Is permanently deleted when you uninstall the App

4.2 Data Sent to Third-Party AI Services

When you generate an app, the following data is transmitted:

To Anthropic Claude API:

  • Your text prompt describing the desired app
  • Any image analysis data (processed via Apple Vision API)
  • Purpose: Generate app code and interface

To OpenAI API:

  • Your app description for icon generation
  • Image data processed through Apple's Vision API (not raw photos)
  • Purpose: Generate app icons and analyze images

Important Processing Details:

  • We do not store your prompts on our servers
  • Requests are sent directly from your device to AI providers
  • We act as a pass-through service only
  • Change from v1.0: Images are now processed using OpenAI Vision API instead of Apple's on-device Vision API for improved accuracy

4.3 Photo Library Access

When you attach an image to a prompt:

What Happens:

1. You select a photo from your library (iOS permission required)

2. The image is processed using OpenAI's Vision API

3. Image analysis is sent with your prompt to Claude

4. We do not store the original photo

Permission Request Text:

> "Obra needs access to your photo library to let you attach images to your app generation prompts. Images are processed using OpenAI's Vision API to help our AI understand visual context and generate better apps. Original photos are never stored or transmitted in their entirety."

4.4 Subscription Information

Managed entirely by Apple through StoreKit:

We Receive:

  • ✓ Subscription status (Free, Maker, or Pro)
  • ✓ Subscription expiration date
  • ✓ Subscription type and tier

We Do NOT Receive:

  • ✗ Payment method details
  • ✗ Billing address
  • ✗ Credit card information
  • ✗ Purchase history details
  • ✗ Any personal financial information

---

5. How We Use Your Data

5.1 App Generation

  • Prompts are sent to Claude API to generate app code
  • Results are returned directly to your device
  • We do not store prompts or generated code on our servers

5.2 Icon Generation

  • Icon descriptions are sent to OpenAI DALL-E API
  • Generated icons are returned to your device
  • We do not store icon prompts or generated images

5.3 Image Processing (**New in v2.0**)

  • Photos you select are processed using OpenAI Vision API
  • Image analysis (not the photo itself) is sent with your prompt
  • Processed data helps AI understand visual context
  • Original photos are never uploaded or stored

5.4 Usage Tracking (Free Tier Only)

  • Daily counters track: apps generated, edits made
  • Stored locally on your device
  • Resets daily at midnight (device time)
  • Used only to enforce free tier limits

---

6. Third-Party Services

6.1 Anthropic Claude

  • What we send: Text prompts, image analysis data
  • Purpose: Generate iOS app code
  • Privacy Policy: https://anthropic.com/privacy
  • Data Location: United States
  • Data Retention: Per Anthropic's policy

6.2 OpenAI (**Updated in v2.0**)

  • What we send:
  • Icon generation requests
  • Images for Vision API processing
  • Combined prompts with image analysis
  • Purpose: Generate app icons and process images
  • Privacy Policy: https://openai.com/privacy
  • Data Location: United States
  • Data Retention: Per OpenAI's policy

6.3 Apple StoreKit

  • What we use: In-App Purchase system
  • Purpose: Subscription management
  • Privacy Policy: https://apple.com/legal/privacy
  • Data Location: Apple's global infrastructure

Important: We do not control these third-party services. Please review their privacy policies to understand how they handle your data.

---

7. International Data Transfers

7.1 Cross-Border Data Flow

AI Service Locations:

  • Anthropic Claude: United States
  • OpenAI: United States

Legal Basis for Transfers:

  • Your explicit consent when using AI generation features
  • Necessity for service performance
  • Standard Contractual Clauses (where applicable)

7.2 Regional Compliance

European Economic Area (EEA) & United Kingdom:

  • GDPR-compliant data processing
  • Lawful basis: Consent and contract performance
  • Data protection rights fully respected

California (CCPA/CPRA):

  • We do not sell personal information
  • Right to deletion honored immediately
  • No discrimination for exercising privacy rights

Canada (PIPEDA):

  • Minimal data collection principle
  • Transparent privacy practices
  • User consent for all data processing

Brazil (LGPD):

  • Compliance with data protection principles
  • User rights fully respected
  • Transparent data processing

Other Jurisdictions:

  • We comply with applicable local data protection laws
  • Contact us for jurisdiction-specific questions

---

8. Data Security

8.1 Technical Measures

  • Local Storage: Protected by iOS security features and device encryption
  • Network Security: All API requests use HTTPS/TLS 1.3 encryption
  • No Servers: No user data stored on our servers = no server breaches possible
  • No Accounts: No login credentials to compromise

8.2 Third-Party Security

  • AI providers (Anthropic, OpenAI) implement industry-standard security
  • Apple StoreKit uses Apple's secure payment infrastructure

---

9. Your Privacy Rights

9.1 Universal Rights (All Users)

Right to Access:

  • All your data is stored locally on your device
  • You have complete access at all times

Right to Deletion:

  • Delete the App to permanently remove all local data
  • Contact us to request deletion of any data with AI providers

Right to Data Portability:

  • Export your generated apps at any time
  • No lock-in or proprietary formats

9.2 Additional Rights (Region-Specific)

EEA/UK Users (GDPR):

  • Right to rectification
  • Right to restriction of processing
  • Right to object to processing
  • Right to lodge a complaint with supervisory authority

California Users (CCPA/CPRA):

  • Right to know what personal information is collected
  • Right to know if personal information is sold or shared
  • Right to opt-out of sale/sharing (N/A - we don't sell data)
  • Right to non-discrimination

Canadian Users (PIPEDA):

  • Right to access personal information
  • Right to correct inaccuracies
  • Right to withdraw consent

To Exercise Your Rights:

---

10. Data Retention

10.1 Local Data

  • Retained indefinitely on your device until you delete the App
  • Controlled entirely by you

10.2 Third-Party Data

  • AI prompts: Per Anthropic and OpenAI retention policies
  • Subscription data: Per Apple's retention policies
  • We do not retain copies of your data

---

11. Children's Privacy

Age Restriction: 13+ (17+ in some jurisdictions)

We do not knowingly collect personal information from children under 13 (or applicable age in your jurisdiction). If you believe a child has used the App, please contact us immediately at privacy@obraos.com.

Parental Controls: We recommend parents use iOS Screen Time and parental controls.

---

12. Cookies and Tracking Technologies

We Do NOT Use:

  • ❌ Cookies
  • ❌ Web beacons
  • ❌ Analytics trackers (Google Analytics, etc.)
  • ❌ Advertising trackers
  • ❌ Social media pixels
  • ❌ Fingerprinting technologies
  • ❌ Any tracking technologies

Your privacy is our priority.

---

13. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • Changes in legal requirements
  • New features or services
  • Improvements to privacy practices

Notification Methods:

  • Update "Effective Date" at the top
  • In-app notification for material changes
  • Email notification (if you've contacted us)
  • App Store update notes

Your Consent: Continued use after changes constitutes acceptance.

---

14. Contact Information

Privacy Questions:

General Support:

Data Protection Officer (DPO):

Mail:

Nikolas Lester Zral

Obra - Privacy Department

British Columbia, Canada

---

15. Supervisory Authorities

Canada:

EEA/UK:

United States:

---

16. Summary (TL;DR)

What Obra Does:

  • 📱 Stores all data locally on your device
  • 🔒 Sends prompts securely to AI providers via HTTPS
  • 🖼️ Processes images using OpenAI Vision API (new in v2.0)
  • 💳 Uses Apple for subscription management
  • 🚫 Does NOT collect, store, or sell personal data

What You Control:

  • ✅ Your prompts and generated apps
  • ✅ Your photos and image data
  • ✅ Your subscription (iOS Settings)
  • ✅ Your data (delete app = delete all local data)

Our Promise:

We built Obra with privacy-first principles. Your data stays on your device. We only process what's necessary for AI generation. We don't collect what we don't need. Simple as that.

---

17. Version History

Version 2.0 (November 1, 2025):

  • Added Maker subscription tier ($9.99/month)
  • Updated for OpenAI Vision API integration
  • Enhanced international compliance provisions
  • Expanded regional privacy rights sections
  • Added comprehensive children's privacy section
  • Clarified data retention and deletion policies

Version 1.0 (January 2025):

  • Initial release

---

Last Updated: November 1, 2025

Version: 2.0

By using Obra, you acknowledge that you have read, understood, and agree to this Privacy Policy.

Contact Us

If you have questions about this document, please contact us:

© 2025 Nikolas Lester Zral. All rights reserved.