Skip to content
ObiquityObiquity

Legal

Privacy Policy

Last updated September 1, 2026

This Privacy Policy explains what Obiquity collects, why, how long we keep it, and the rights you (and, in some cases, people who pull through your domain) may have. It covers the current redirect-mode service only. A later authenticated proxy mode would collect different data and would need its own notice.

1. Who we are

Obiquity operates a custom-domain OCI redirect service. For privacy requests contact legal@obiquity.io. This policy applies to the website, dashboard, API, and pull redirects we serve.

2. Account and configuration data

If you create an account, we collect:

  • email address and a hashed password;
  • when you accepted the Terms of Service;
  • whether and when you verified ownership of that email address;
  • hostnames, DNS verification tokens, routes, and related settings you configure;
  • API keys (the secret is shown once and stored only as a hash);
  • plan limits, usage counters, and waitlist signups if you ask to be notified about a paid tier;
  • session cookies needed to keep you logged in.

We use this data to provide the service, enforce quotas and domain limits, verify that you control a hostname, issue TLS via our certificate partner, and communicate about your account (including the signup verification email).

3. Pull logs — including people who never signed up

When someone (or a CI system or kubelet) pulls an image through a customer's domain, we record a pull event. That log is not limited to the customer who owns the domain. It includes metadata about the customer's downstream users — people and machines who may have never created an Obiquity account.

Each event may include:

  • image name and reference (tag or digest);
  • HTTP status (for example 307, 404, 429);
  • client user-agent;
  • a salted SHA-256 hash of the client IP address — not the raw address.

We do not persist the raw IP. Hashing with a server-side salt reduces the chance of casual reversal, but under GDPR a hash of an IP is generally still pseudonymized personal data, not anonymized data. It remains in scope of that law. We do not treat hashing as a way to step outside privacy obligations.

Customers are on notice, and agree in the Terms, that pulls through their domains are logged this way. If you are a customer, you are responsible for providing any notice or obtaining any permission your own users or jurisdiction require.

4. Why we process this data

We process the data above to:

  • operate redirects, quotas, and the dashboard analytics you see;
  • detect and respond to abuse, malware, phishing, and copyright complaints;
  • secure the service (including certificate issuance gates);
  • comply with law and enforce the Terms and Acceptable Use Policy.

Where GDPR or similar law applies, we rely on performance of a contract with account holders, and on legitimate interests in operating, securing, and metering a redirect service for pull logs (including hashed IPs of downstream clients). We do not sell personal data.

5. Retention

Raw pull events are retained for 90 days by default (configurable as OBIQUITY_EVENT_RETENTION_DAYS on our side), then purged. Daily per-domain aggregates (counts of pulls and errors, not hashed IPs) are kept so long-term usage charts survive that purge.

Account, domain, and route data last until you delete them or we close the account. Admin audit logs of operator actions are kept so a record of suspensions and takedowns outlives the affected resource.

6. Sharing and processors

We share data with infrastructure providers needed to run the product (currently hosting, DNS-adjacent TLS via Let's Encrypt / Caddy, and Resend for transactional email such as signup verification). We may disclose data if required by law, to protect the service, or in connection with a reorganization. We may share a copyright complaint with the tenant whose domain is named in it.

After a redirect, the client talks to the upstream registry you configured. That registry's privacy policy then applies to the rest of the pull. We do not receive image bytes.

7. International processing

The MVP runs on a single virtual machine. Data may be processed in the United States or wherever that infrastructure is located. If you access the service from elsewhere, you understand that transfer.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export personal data, to object to or restrict certain processing, and to complain to a supervisory authority. Email legal@obiquity.io. We may need to verify the request. Downstream users who never created an account may still contact us; we may need the customer's help to identify the relevant logs, and a hashed IP alone may not identify a person.

9. Children

The service is not directed at children under 18, and we do not knowingly collect their data.

10. Data processing agreements

Formal DPAs for regulated customers are an Enterprise / later-phase item, not part of the free-tier MVP. If you need a DPA before that exists, we cannot currently offer one; do not use Obiquity where a DPA is required.

11. Changes

We may update this policy by posting a new version here. Material changes will also be reflected by the "Last updated" date. Continued use after that date is acceptance of the update.