Legal Notice & Compliance

Privacy Policy

Effective Date: July 22, 2026 | Document Reference: PRIV-2026-V1

1. Executive Overview

At OsciWave ("we", "our", or "us"), privacy and infrastructural security are foundational principles. This Privacy Policy governs the processing of personal data and operational metrics collected when you interact with our real-time WebSocket broadcast engine, REST endpoints, management dashboard, and associated services.

By registering for an account, generating API credentials, or utilizing our socket infrastructure, you acknowledge that you have read, understood, and agreed to the data processing practices detailed herein.

2. Information We Collect

We strictly limit data collection to information necessary to fulfill our service contract, maintain high-throughput real-time routing, prevent unauthorized usage, and process billing transactions.

A. Account Identity Data

Full legal name, email address, password hashes (argon2id/bcrypt), company affiliation, team memberships, and WebAuthn/Passkey public keys associated with multi-factor authentication.

B. API Credentials & Access Keys

Public App IDs (`ow_...`), HMAC secret keys (`sk_...`), IP address white-lists, and authorization tokens generated to authenticate your server application requests.

C. Financial & Billing Records

Subscription plan selections, Creem customer identifiers, order transaction histories, and tax exemption metadata. Credit card details are processed directly by our merchant and never touch OsciWave servers.

D. Network & Technical Diagnostics

Connecting IP addresses, socket transport types (WSS vs WS fallback), user-agent strings, geographic region routing nodes, and TLS cipher protocol negotiation metadata.

3. Ephemeral WebSocket Payload Handling

OsciWave operates as an in-memory event broker. Broadcasted message payloads dispatched to `/api/apps/{app_id}/events` are routed instantaneously to subscribing WebSocket connections.

  • Zero Persistence Policy: Payload contents are held in volatile RAM only for the sub-millisecond duration required to frame and transmit WebSocket packets. Payloads are never logged to disk or stored in persistent databases.
  • Encrypted Channels: Private and presence channel broadcasts require server-signed HMAC SHA-256 signatures, ensuring payload integrity and preventing unauthenticated interception.
  • Customer Responsibility: Customers are responsible for ensuring that payload contents transmitted over OsciWave conform to applicable data privacy standards and do not contain unencrypted Sensitive Personal Information (SPI).

4. Telemetry & Connection Tracking

To enforce concurrent connection quotas defined in our plan tiers (Free: 100, Starter: 500, Pro: 1,500, Scale: 3,000) and monitor infrastructure load, we record aggregated connection telemetry:

Metric Collected Purpose Retention Period
Peak Concurrent Connections Subscription Quota Verification Rolling 90 Days
Total Event Dispatch Volume System Health & Rate Limiting 30 Days
Disconnection Timestamps Socket Slot De-allocation Immediate Removal

5. Sub-processors & Merchant Provider

We engage trusted third-party service providers to facilitate infrastructure operation and subscription billing. Each provider undergoes strict security evaluation:

Creem (Merchant of Record)

Handles payment checkout, recurring subscription billing, sales tax compliance, and invoice generation.

PCI-DSS Level 1 Compliant

6. Data Security Protocols

We implement rigorous organizational and technical safeguards designed to prevent unauthorized access, disclosure, or destruction of platform data:

  • Transit Encryption: All WebSocket traffic is secured over TLS 1.3 / WSS protocols using modern ECDHE key exchange.
  • API Authentication: Dual-key architecture comprising public App Keys and private HMAC Secret Keys with timed token signatures.
  • Access Control: Administrative infrastructure access is restricted via hardware WebAuthn passkeys and strict IP boundary controls.

7. Data Retention & Erasure

We retain account identity records for as long as your account remains active. Upon receiving a formal account closure request or subscription cancellation, all associated API credentials, webhook endpoints, and team memberships will be permanently scrubbed within 30 days, excepting financial transaction audit logs required by law.

8. Rights Under GDPR & CCPA

Depending on your location, you hold explicit rights regarding your personal data under the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA):

Right of Access

Request a complete export of personal data linked to your account.

Right to Rectification

Update or correct inaccurate profile and billing information at any time.

Right to Erasure

Request total deletion of account data and API key records.

9. Contact & Data Protection Officer

If you have questions regarding this Privacy Policy or wish to exercise your data protection rights, please reach out to our legal team:

OsciWave Legal & Privacy Team
Email: privacy@osciwave.test
Security Incident Escalation: security@osciwave.test