Privacy Policy

Last updated: March 17, 2026

1. Introduction

Obsidian Clad Labs LLC (“we,” “us,” or “our”) operates ConfigShield (“the Service”), a secure environment variable management platform available at configshield.app. This Privacy Policy describes how we collect, use, and protect your personal information when you use our Service.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and a hashed version of your password. We never store passwords in plain text.

Usage Data

We collect information about how you use the Service, including page visits, feature usage, IP addresses, browser type, and device information. This data is collected through Vercel Analytics and is used to improve the Service.

Secrets and Configuration Data

Your secrets (environment variables, API keys, configuration values) are encrypted using AES-256 encryption before being stored. We do not access, read, or analyze the content of your stored secrets.

3. How We Use Your Information

  • To provide, maintain, and improve the Service
  • To process transactions and send billing-related communications
  • To send service-related notifications (security alerts, maintenance, etc.)
  • To respond to your support requests
  • To detect and prevent fraud or abuse
  • To generate anonymized, aggregate analytics

4. Data Encryption and Security

All secrets stored in ConfigShield are encrypted at rest using AES-256 encryption. Data in transit is protected using TLS 1.3. We employ industry-standard security measures including regular security audits, access controls, and monitoring. Our infrastructure is hosted on secure, SOC 2-compliant platforms.

5. Third-Party Services

We use the following third-party services to operate ConfigShield:

  • Stripe — Payment processing. Stripe handles all payment data under their own privacy policy.
  • Vercel — Frontend hosting and analytics.
  • Railway — Backend hosting and database infrastructure.
  • Resend — Transactional email delivery.
  • Vercel Analytics — Anonymous usage analytics to improve the Service.

6. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal information and all stored secrets within 30 days. Anonymized analytics data may be retained indefinitely. Audit logs are retained for 90 days on the Pro plan and 30 days on the Free plan.

7. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data (including secrets)
  • Opt out of marketing communications

To exercise any of these rights, contact us at support@configshield.app.

8. Cookies

We use essential cookies to maintain your login session. We do not use tracking cookies or advertising cookies.

9. Children's Privacy

ConfigShield is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Obsidian Clad Labs LLC

Email: support@configshield.app