Privacy Policy
Effective Date: November 1, 2025
Version 2.0 - Last Updated: November 1, 2025
Service Provider: Nikolas Lester Zral (Sole Proprietorship, British Columbia, Canada)
1. Introduction
Welcome to Obra. This Privacy Policy explains how Nikolas Lester Zral ("we," "us," "our") collects, uses, and protects your information when you use the Obra iOS application ("App").
Key Principles:
- ✅ Data stored locally on your device
- ✅ No collection of personal information
- ✅ No activity tracking or analytics
- ✅ No sale of user data
- ✅ Subscription management via Apple
---
2. Data Controller Information
3. Information We Do NOT Collect
We want to be transparent about what we do not collect:
- ❌ Personal identification (name, email, phone number)
- ❌ Location data or geolocation tracking
- ❌ Device identifiers for advertising or tracking
- ❌ Contacts, address book, or calendar data
- ❌ Health or fitness data
- ❌ Financial or payment information
- ❌ Browsing history or web data
- ❌ Usage analytics or behavioral data
- ❌ Biometric data
- ❌ Social media information
---
4. Information We Process
4.1 Local Device Storage
The following data is stored exclusively on your device:
- Generated Apps: All applications you create
- App Settings: Your preferences and configuration
- Usage Counters: Daily generation/edit limits (Free tier only)
- Subscription Status: Whether you have an active subscription
- Image Attachments: Photos you choose to include with prompts
Important: This data:
- Never leaves your device
- Is not uploaded to our servers
- Is protected by iOS security and device encryption
- Is permanently deleted when you uninstall the App
4.2 Data Sent to Third-Party AI Services
When you generate an app, the following data is transmitted:
To Anthropic Claude API:
- Your text prompt describing the desired app
- Any image analysis data (processed via Apple Vision API)
- Purpose: Generate app code and interface
To OpenAI API:
- Your app description for icon generation
- Image data processed through Apple's Vision API (not raw photos)
- Purpose: Generate app icons and analyze images
Important Processing Details:
- We do not store your prompts on our servers
- Requests are sent directly from your device to AI providers
- We act as a pass-through service only
- Change from v1.0: Images are now processed using OpenAI Vision API instead of Apple's on-device Vision API for improved accuracy
4.3 Photo Library Access
When you attach an image to a prompt:
What Happens:
1. You select a photo from your library (iOS permission required)
2. The image is processed using OpenAI's Vision API
3. Image analysis is sent with your prompt to Claude
4. We do not store the original photo
Permission Request Text:
> "Obra needs access to your photo library to let you attach images to your app generation prompts. Images are processed using OpenAI's Vision API to help our AI understand visual context and generate better apps. Original photos are never stored or transmitted in their entirety."
4.4 Subscription Information
Managed entirely by Apple through StoreKit:
We Receive:
- ✓ Subscription status (Free, Maker, or Pro)
- ✓ Subscription expiration date
- ✓ Subscription type and tier
We Do NOT Receive:
- ✗ Payment method details
- ✗ Billing address
- ✗ Credit card information
- ✗ Purchase history details
- ✗ Any personal financial information
---
5. How We Use Your Data
5.1 App Generation
- Prompts are sent to Claude API to generate app code
- Results are returned directly to your device
- We do not store prompts or generated code on our servers
5.2 Icon Generation
- Icon descriptions are sent to OpenAI DALL-E API
- Generated icons are returned to your device
- We do not store icon prompts or generated images
5.3 Image Processing (**New in v2.0**)
- Photos you select are processed using OpenAI Vision API
- Image analysis (not the photo itself) is sent with your prompt
- Processed data helps AI understand visual context
- Original photos are never uploaded or stored
5.4 Usage Tracking (Free Tier Only)
- Daily counters track: apps generated, edits made
- Stored locally on your device
- Resets daily at midnight (device time)
- Used only to enforce free tier limits
---
6. Third-Party Services
6.1 Anthropic Claude
- What we send: Text prompts, image analysis data
- Purpose: Generate iOS app code
- Privacy Policy: https://anthropic.com/privacy
- Data Location: United States
- Data Retention: Per Anthropic's policy
6.2 OpenAI (**Updated in v2.0**)
- What we send:
- Icon generation requests
- Images for Vision API processing
- Combined prompts with image analysis
- Purpose: Generate app icons and process images
- Privacy Policy: https://openai.com/privacy
- Data Location: United States
- Data Retention: Per OpenAI's policy
6.3 Apple StoreKit
- What we use: In-App Purchase system
- Purpose: Subscription management
- Privacy Policy: https://apple.com/legal/privacy
- Data Location: Apple's global infrastructure
Important: We do not control these third-party services. Please review their privacy policies to understand how they handle your data.
---
7. International Data Transfers
7.1 Cross-Border Data Flow
AI Service Locations:
- Anthropic Claude: United States
- OpenAI: United States
Legal Basis for Transfers:
- Your explicit consent when using AI generation features
- Necessity for service performance
- Standard Contractual Clauses (where applicable)
7.2 Regional Compliance
European Economic Area (EEA) & United Kingdom:
- GDPR-compliant data processing
- Lawful basis: Consent and contract performance
- Data protection rights fully respected
California (CCPA/CPRA):
- We do not sell personal information
- Right to deletion honored immediately
- No discrimination for exercising privacy rights
Canada (PIPEDA):
- Minimal data collection principle
- Transparent privacy practices
- User consent for all data processing
Brazil (LGPD):
- Compliance with data protection principles
- User rights fully respected
- Transparent data processing
Other Jurisdictions:
- We comply with applicable local data protection laws
- Contact us for jurisdiction-specific questions
---
8. Data Security
8.1 Technical Measures
- Local Storage: Protected by iOS security features and device encryption
- Network Security: All API requests use HTTPS/TLS 1.3 encryption
- No Servers: No user data stored on our servers = no server breaches possible
- No Accounts: No login credentials to compromise
8.2 Third-Party Security
- AI providers (Anthropic, OpenAI) implement industry-standard security
- Apple StoreKit uses Apple's secure payment infrastructure
---
9. Your Privacy Rights
9.1 Universal Rights (All Users)
Right to Access:
- All your data is stored locally on your device
- You have complete access at all times
Right to Deletion:
- Delete the App to permanently remove all local data
- Contact us to request deletion of any data with AI providers
Right to Data Portability:
- Export your generated apps at any time
- No lock-in or proprietary formats
9.2 Additional Rights (Region-Specific)
EEA/UK Users (GDPR):
- Right to rectification
- Right to restriction of processing
- Right to object to processing
- Right to lodge a complaint with supervisory authority
California Users (CCPA/CPRA):
- Right to know what personal information is collected
- Right to know if personal information is sold or shared
- Right to opt-out of sale/sharing (N/A - we don't sell data)
- Right to non-discrimination
Canadian Users (PIPEDA):
- Right to access personal information
- Right to correct inaccuracies
- Right to withdraw consent
To Exercise Your Rights:
---
10. Data Retention
10.1 Local Data
- Retained indefinitely on your device until you delete the App
- Controlled entirely by you
10.2 Third-Party Data
- AI prompts: Per Anthropic and OpenAI retention policies
- Subscription data: Per Apple's retention policies
- We do not retain copies of your data
---
11. Children's Privacy
Age Restriction: 13+ (17+ in some jurisdictions)
We do not knowingly collect personal information from children under 13 (or applicable age in your jurisdiction). If you believe a child has used the App, please contact us immediately at privacy@obraos.com.
Parental Controls: We recommend parents use iOS Screen Time and parental controls.
---
12. Cookies and Tracking Technologies
We Do NOT Use:
- ❌ Cookies
- ❌ Web beacons
- ❌ Analytics trackers (Google Analytics, etc.)
- ❌ Advertising trackers
- ❌ Social media pixels
- ❌ Fingerprinting technologies
- ❌ Any tracking technologies
Your privacy is our priority.
---
13. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
- Changes in legal requirements
- New features or services
- Improvements to privacy practices
Notification Methods:
- Update "Effective Date" at the top
- In-app notification for material changes
- Email notification (if you've contacted us)
- App Store update notes
Your Consent: Continued use after changes constitutes acceptance.
---
14. Contact Information
Privacy Questions:
General Support:
Data Protection Officer (DPO):
Mail:
Nikolas Lester Zral
Obra - Privacy Department
British Columbia, Canada
---
15. Supervisory Authorities
Canada:
EEA/UK:
United States:
---
16. Summary (TL;DR)
What Obra Does:
- 📱 Stores all data locally on your device
- 🔒 Sends prompts securely to AI providers via HTTPS
- 🖼️ Processes images using OpenAI Vision API (new in v2.0)
- 💳 Uses Apple for subscription management
- 🚫 Does NOT collect, store, or sell personal data
What You Control:
- ✅ Your prompts and generated apps
- ✅ Your photos and image data
- ✅ Your subscription (iOS Settings)
- ✅ Your data (delete app = delete all local data)
Our Promise:
We built Obra with privacy-first principles. Your data stays on your device. We only process what's necessary for AI generation. We don't collect what we don't need. Simple as that.
---
17. Version History
Version 2.0 (November 1, 2025):
- Added Maker subscription tier ($9.99/month)
- Updated for OpenAI Vision API integration
- Enhanced international compliance provisions
- Expanded regional privacy rights sections
- Added comprehensive children's privacy section
- Clarified data retention and deletion policies
Version 1.0 (January 2025):
---
Last Updated: November 1, 2025
Version: 2.0
By using Obra, you acknowledge that you have read, understood, and agree to this Privacy Policy.
Contact Us
If you have questions about this document, please contact us:
© 2025 Nikolas Lester Zral. All rights reserved.