KEYSTONE LegalTerms of ServicePrivacy PolicyData Deletion

KEYSTONE — Privacy Policy

Obsidian Solutions Holdings LLC · PO Box 152, Rogue River, OR 97537 · legal@obsidiansolutions.global · Last updated: August 25, 2026 (adds §4.1 Social Accounts & Platform Data) · Effective upon posting

1. Scope & Roles

This Policy explains how Obsidian handles personal information in connection with the Service. For Account Data (your registration, billing, telemetry), Obsidian is the controller. For Customer Data you load into your Organization (including End Customer information and communications), you are the controller and Obsidian processes it on your documented instructions as a processor/service provider; your privacy notices govern that data, and requests from your End Customers should be directed to you.

2. Information We Collect

Account and profile details (name, email, phone, company, role); billing and subscription metadata (via your processor — we do not store full card numbers); Customer Data you submit (boards, contacts, files, invoices, messages, call/text metadata); Connected-Service tokens and exchanged data you authorize; usage, device, log, and diagnostic data (including error telemetry via Sentry); cookies and similar technologies for authentication, preferences, and analytics; support communications.

3. How We Use Information

To provide, operate, secure, and support the Service; to process transactions you initiate; to send service, security, and administrative communications (and, for Account Data, product updates you may opt out of); to monitor, debug, and improve performance and features; to create aggregated or de-identified analytics; to enforce terms, prevent fraud and abuse, and comply with law. We do not sell personal information and do not use Customer Data to train third-party foundation models.

4. Sharing & Subprocessors

We share information only: with subprocessors that host and power the Service — currently including Supabase (database, auth, storage, functions), Vercel (hosting/CDN), GitHub (code infrastructure), Stripe (payments, on your account), Google and Microsoft (when you connect them), RingCentral (when you connect it), OpenAI and Anthropic (AI features), Sentry (error monitoring), Resend (system email, when enabled), and Trigger.dev (jobs) — each bound to protect data and act only on instructions; with Connected Services at your direction; with professional advisors; in a corporate transaction (with continuity of protections); and when required by law or to protect rights, safety, and the Service. We will maintain an updated subprocessor list and may modify it with notice.

4.1 Social Accounts & Platform Data (KEYSTONE SM)

(a) What we collect when you connect a social account. Account identifiers and profile basics (handle, display name, avatar, account/page/channel IDs), the credentials or tokens you grant (OAuth access/refresh tokens, app passwords, API keys, webhook URLs, bot tokens, stream keys), platform capability metadata (e.g., character limits), and publishing records (drafts, scheduled posts, delivery receipts, permalinks, and platform responses including errors).

(b) How we use it. Solely to provide KEYSTONE SM at your direction: verifying the connection, publishing and scheduling content you initiate, retrieving the status and permalinks of that content, showing analytics for your own posts, and maintaining the connection (token refresh). We do not sell Platform Data, do not use it for advertising, do not use it to train AI models, and do not access your social accounts except to perform features you invoke.

(c) How it is protected. Credentials and tokens are stored server-side in a restricted credential vault, encrypted in transit, never exposed to the browser after entry, accessible only to service processes under least-privilege controls, and deleted per the Data Deletion Instructions at /legal/data-deletion.

(d) Google and YouTube. KEYSTONE SM uses YouTube API Services for YouTube features. By using them you also agree to the YouTube Terms of Service; Google's handling of your data is described in the Google Privacy Policy. KEYSTONE's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access Google user data only with your consent, only for the features described here, and we do not transfer it except to provide those features, for security, or to comply with law. You can revoke KEYSTONE's access to your Google/YouTube data at any time via Google security settings.

(e) Meta platforms (Facebook, Instagram, Threads). We receive and process Platform Data (as defined by Meta) only as a service provider to you and per Meta's Platform Terms; we do not sell it or use it for our own advertising. Disconnect at any time in KEYSTONE (Accounts → unlink) or from your Meta settings (Settings → Apps and Websites / Business Integrations); see the Data Deletion Instructions for full removal.

(f) Revoking any connection at the source. In addition to unlinking inside KEYSTONE, you can cut access from each platform directly: Google (myaccount.google.com/permissions) · Meta (Settings → Apps and Websites) · X (Settings → Security and account access → Apps and sessions) · TikTok (Settings → Security → Manage app permissions) · LinkedIn (Settings → Data privacy → Permitted services) · Pinterest (Settings → Security → Connected apps) · Reddit (preferences → apps) · Bluesky (revoke the app password) · Mastodon (Preferences → Account → Authorized apps) · Discord (delete the webhook) · Telegram (remove the bot as admin or revoke via @BotFather) · Twitch and Kick (Settings → Connections) · Rumble (revoke the API token) · streaming destinations (reset the stream key). Revocation at the source immediately invalidates our stored credential.

(g) Retention. Social credentials persist while the connection is active; unlinking marks the connection revoked and the credential is deleted from the vault within a commercially reasonable period (see the Data Deletion Instructions). Publishing records (what was posted, when, where, receipts) are Customer Data retained under Section 6.

5. Security

We use technical and organizational safeguards appropriate to the risk, including encryption in transit, row-level access controls, credential vaulting, least-privilege tokens, and audit logging. No system is perfectly secure; you are responsible for account credentials, Seat management, and configuring permissions appropriately.

6. Retention

We retain Account Data while your account is active and as needed for legitimate business and legal purposes. Customer Data is retained while your Organization is active; after termination, standard export is available for 30 days, after which data is deleted or de-identified within a commercially reasonable period, subject to backups that roll off on schedule and legal holds.

7. Your Rights

Depending on your location, you may have rights to access, correct, delete, or port personal information, to object to or restrict certain processing, and to withdraw consent. Submit requests to legal@obsidiansolutions.global or the mailing address above; we will verify and respond as law requires and will not discriminate for exercising rights. End Customers should contact the Organization that holds their data; we will assist that Organization as processor.

8. Cookies & Do Not Track

We use strictly necessary cookies (authentication, security) and limited functional/analytics cookies. Browser Do-Not-Track signals are not currently honored due to lack of standardization; where legally required, we honor recognized opt-out preference signals.

9. Children

The Service is for business users 18+; we do not knowingly collect information from children. If you believe a child provided data, contact us for deletion.

10. International Transfers

We are U.S.-based; data is processed in the United States and other locations where our subprocessors operate, under appropriate safeguards where required.

11. Breach Notice

If a security incident affects personal information, we will notify affected Organizations and authorities as required by applicable law, without undue delay.

12. Changes; Contact

We may update this Policy by posting a revised version with a new date; material changes will be notified via the Service or email. Continued use is acceptance. Questions, requests, and legal notices: Obsidian Solutions Holdings LLC, PO Box 152, Rogue River, OR 97537 · legal@obsidiansolutions.global.

Obsidian Solutions Holdings LLC · PO Box 152, Rogue River, OR 97537 · legal@obsidiansolutions.global · admin@obsidiansolutions.global