Privacy Policy
Effective Date: July 22, 2026 | Document Reference: PRIV-2026-V1
Document Outline
1. Executive Overview
At OsciWave ("we", "our", or "us"), privacy and infrastructural security are foundational principles. This Privacy Policy governs the processing of personal data and operational metrics collected when you interact with our real-time WebSocket broadcast engine, REST endpoints, management dashboard, and associated services.
By registering for an account, generating API credentials, or utilizing our socket infrastructure, you acknowledge that you have read, understood, and agreed to the data processing practices detailed herein.
2. Information We Collect
We strictly limit data collection to information necessary to fulfill our service contract, maintain high-throughput real-time routing, prevent unauthorized usage, and process billing transactions.
A. Account Identity Data
Full legal name, email address, password hashes (argon2id/bcrypt), company affiliation, team memberships, and WebAuthn/Passkey public keys associated with multi-factor authentication.
B. API Credentials & Access Keys
Public App IDs (`ow_...`), HMAC secret keys (`sk_...`), IP address white-lists, and authorization tokens generated to authenticate your server application requests.
C. Financial & Billing Records
Subscription plan selections, Creem customer identifiers, order transaction histories, and tax exemption metadata. Credit card details are processed directly by our merchant and never touch OsciWave servers.
D. Network & Technical Diagnostics
Connecting IP addresses, socket transport types (WSS vs WS fallback), user-agent strings, geographic region routing nodes, and TLS cipher protocol negotiation metadata.
3. Ephemeral WebSocket Payload Handling
OsciWave operates as an in-memory event broker. Broadcasted message payloads dispatched to `/api/apps/{app_id}/events` are routed instantaneously to subscribing WebSocket connections.
- Zero Persistence Policy: Payload contents are held in volatile RAM only for the sub-millisecond duration required to frame and transmit WebSocket packets. Payloads are never logged to disk or stored in persistent databases.
- Encrypted Channels: Private and presence channel broadcasts require server-signed HMAC SHA-256 signatures, ensuring payload integrity and preventing unauthenticated interception.
- Customer Responsibility: Customers are responsible for ensuring that payload contents transmitted over OsciWave conform to applicable data privacy standards and do not contain unencrypted Sensitive Personal Information (SPI).
4. Telemetry & Connection Tracking
To enforce concurrent connection quotas defined in our plan tiers (Free: 100, Starter: 500, Pro: 1,500, Scale: 3,000) and monitor infrastructure load, we record aggregated connection telemetry:
5. Sub-processors & Merchant Provider
We engage trusted third-party service providers to facilitate infrastructure operation and subscription billing. Each provider undergoes strict security evaluation:
Creem (Merchant of Record)
Handles payment checkout, recurring subscription billing, sales tax compliance, and invoice generation.
6. Data Security Protocols
We implement rigorous organizational and technical safeguards designed to prevent unauthorized access, disclosure, or destruction of platform data:
- Transit Encryption: All WebSocket traffic is secured over TLS 1.3 / WSS protocols using modern ECDHE key exchange.
- API Authentication: Dual-key architecture comprising public App Keys and private HMAC Secret Keys with timed token signatures.
- Access Control: Administrative infrastructure access is restricted via hardware WebAuthn passkeys and strict IP boundary controls.
7. Data Retention & Erasure
We retain account identity records for as long as your account remains active. Upon receiving a formal account closure request or subscription cancellation, all associated API credentials, webhook endpoints, and team memberships will be permanently scrubbed within 30 days, excepting financial transaction audit logs required by law.
8. Rights Under GDPR & CCPA
Depending on your location, you hold explicit rights regarding your personal data under the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA):
Right of Access
Request a complete export of personal data linked to your account.
Right to Rectification
Update or correct inaccurate profile and billing information at any time.
Right to Erasure
Request total deletion of account data and API key records.
9. Contact & Data Protection Officer
If you have questions regarding this Privacy Policy or wish to exercise your data protection rights, please reach out to our legal team: