Dark Obsidian Dark Obsidian ← Home

Privacy Policy

Last updated: May 31, 2026

🔒 TL;DR: Your business data stays on your device. We don't sell your data, run ads, or share your information with third parties. Cloud sync is optional.

1. Introduction

Dark Obsidian ("we", "us", "our") is a business management system developed for sole traders, small businesses, and enterprises. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.

By using Dark Obsidian, you agree to the collection and use of information in accordance with this policy.

2. Data We Collect

2.1 Data You Create

All business data you enter into Dark Obsidian (products, customers, transactions, employees, etc.) is stored locally on your device using an encrypted SQLite database. This data is yours - we cannot access it unless you explicitly enable cloud sync.

2.2 Cloud Sync (Optional)

If you enable cloud sync, your business data is encrypted and stored in our Supabase-powered cloud infrastructure. Each business's data is completely isolated using Row Level Security. We use this data solely to sync your data across your devices and provide backup.

2.3 App Settings

We store your app preferences (theme, language, notification settings) locally on your device using your operating system's secure storage mechanisms.

2.4 Anonymous Analytics (Optional)

If you opt-in, we may collect anonymous usage statistics (which modules are used most, crash reports) to improve the product. No personally identifiable information is collected. You can opt out at any time in Settings → Privacy.

3. Data We Do NOT Collect

  • We do not collect your customers' personal data unless you sync to cloud
  • We do not run ads or sell your data to third parties
  • We do not track your location
  • We do not access your camera, microphone, or contacts (except barcode scanner on explicit tap)
  • We do not require an account to use the app - cloud features are all optional

4. Third-Party Integrations

Dark Obsidian supports optional integrations with third-party services:

  • AI Providers (OpenAI, Anthropic, Google, etc.) - only when you configure an API key and explicitly invoke AI features. Your prompts are sent directly to the provider you choose.
  • SMTP Email - for sending invoices and notifications. Your SMTP credentials are stored encrypted on your device only.
  • WhatsApp Business - for sending messages. Only activated when configured.
  • Stripe Payments - for processing payments. We are not PCI-DSS compliant as Stripe handles all payment processing directly.

5. Data Storage & Security

Local data is stored in an encrypted SQLite database. On mobile, additional encryption is provided by the operating system's secure storage (Android Keystore / iOS Keychain). API keys and credentials are stored using flutter_secure_storage which uses platform-level encryption.

Cloud data (if sync is enabled) is stored in Supabase with AES-256 encryption at rest and TLS in transit.

6. Data Retention & Deletion

Your local data persists until you uninstall the app or delete your database. Cloud data is retained as long as your account is active. To delete your cloud data, go to Settings → My Account → Delete Account.

You can export all your data to JSON or Excel at any time from Settings → Backup & Export.

7. Children's Privacy

Dark Obsidian is not intended for use by children under 13. We do not knowingly collect data from children.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via in-app notification. Continued use of the app after changes constitutes acceptance.

9. Cookies

The Dark Obsidian desktop and mobile app does not use cookies. This website (darkobsedian.sameergul.com) uses no third-party cookies or tracking scripts. We only use functional cookies necessary for the site to work.

10. Contact Us

For privacy questions or data requests, contact us at:
[email protected]


Terms of Service ← Back to Home