Privacy policy
Last updated: 2026-07-29
1. Data controller
The controller of your personal data is Svetlin Tzvetanov Minkov (Karnobat, Bulgaria), operating Obseras as a private individual. For any privacy request, email [email protected].
2. What we collect
Your email address and password hash (account), the URLs and settings of your watches, snapshots of the monitored content, notification targets you add (emails, Telegram chat IDs), and standard server logs.
3. What we use it for
Running your watches, sending the notifications you configure, billing (handled by Stripe — we never see your card number), and keeping the service secure. Nothing else. We don't sell data and we don't run third-party ads or trackers.
4. AI change summaries
When a watch detects a change, we send an excerpt of the changed content to an AI provider (OpenRouter, which routes to Anthropic) to generate a short plain-language summary. Only the changed portion is sent, no account details. This provider may process it outside the EU. If you'd rather not have your watches summarized this way, email us and we'll disable it for your account.
5. Change tracker alerts
If you subscribe to the public change tracker without an account, we store only your email address, which source you chose, and the date you confirmed. We email you once to confirm the subscription and never mail you until you do. Every message carries a one-click unsubscribe link, which deletes the record immediately. We use the address for nothing else.
6. Cookies
We use one essential cookie to keep you signed in, and your browser's local storage for the light/dark theme preference. No analytics or marketing cookies.
7. Where data lives and who processes it
Your account and watch data live on servers in the European Union (Germany). We share the minimum needed with a few processors:
- Resend — email delivery
- Telegram Bot API — Telegram alerts, if you enable them
- Stripe — payments (we never see your card number)
- OpenRouter / Anthropic — AI change summaries (see section 4)
The AI provider may process the changed-content excerpt outside the EU; everything else stays in the EU.
8. Your rights
Under the GDPR you can request access, correction, export or deletion of your data at any time — email us and we'll act within 30 days. Deleting your account removes your watches, snapshots and history.
9. Contact
Privacy questions: [email protected].