Skip to the Privacy Policy
HeadGarden
Terms Contact

On this page

  1. Overview and controller
  2. Privacy promises
  3. Data map
  4. Local app data
  5. Health data
  6. Installation and sessions
  7. Purchases
  8. Advertising
  9. AppsFlyer attribution
  10. Purchase forwarding
  11. Crashlytics
  12. Orb and OpenAI
  13. Backend security data
  14. Website data
  15. Purposes and lawful bases
  16. Recipients and processors
  17. International transfers
  18. Retention
  19. Choices and controls
  20. Your rights
  21. Complaints
  22. Security
  23. Children
  24. Automated decisions
  25. Changes and contact

Privacy, mapped plainly

HeadGarden Privacy Policy

This Policy distinguishes information that stays local, information HeadGarden processes transiently, and information handled by the subscription, advertising, attribution, crash, AI, store, hosting, and security providers that make the app work.

Effective date: 25 August 2026

You can print or save this page using your browser’s standard print command.

Contents
  1. Overview and controller
  2. Privacy promises
  3. Data map
  4. Local app data
  5. Health data
  6. Installation and sessions
  7. Purchases
  8. Advertising
  9. AppsFlyer attribution
  10. Purchase forwarding
  11. Crashlytics
  12. Orb and OpenAI
  13. Backend security data
  14. Website data
  15. Purposes and lawful bases
  16. Recipients and processors
  17. International transfers
  18. Retention
  19. Choices and controls
  20. Your rights
  21. Complaints
  22. Security
  23. Children
  24. Automated decisions
  25. Changes and contact

1 / 25

Overview and controller identity

OBSCURACODE LTD (“CodeObscura”, “we”, “us”, or “our”) is the controller for the personal data described in this Policy where we decide why and how it is processed. We are registered in England and Wales under company number 16120395. Our registered office is 3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE. Privacy questions and rights requests can be sent to legal@codeobscura.com.

HeadGarden is an accountless, general-wellness app for adults aged 18 or over. It provides guided practices, programmes, local progress, optional Health context, subscriptions, eligible free-user advertising, and an AI reflection feature called Orb. It is not a medical, therapy, emergency, or crisis service.

This Policy applies to the HeadGarden app, HeadGarden-operated API services, and the public HeadGarden pages at codeobscura.com and headgarden.codeobscura.com. Apple and the other providers named below also process information under their own responsibilities and privacy terms.

2 / 25

At-a-glance privacy promises

HeadGarden is designed to avoid a consumer profile while still being candid about the technical and provider processing needed to run a modern app:

  • No HeadGarden account. We do not ask you to register with a name, email address, or password, and we do not operate cloud progress sync.
  • Health separation. We do not sell Health data. Health values are not sent to advertising, attribution, subscription, AI, crash-reporting, or HeadGarden server providers.
  • Independent choices. Health read, mindful write, notifications, advertising consent, attribution, and Apple’s App Tracking Transparency permission are separate controls.
  • Premium means no ad request. Once trusted Premium access is resolved, HeadGarden does not request an advertising banner for that user.
  • Bounded Orb context. Only the current Orb message and bounded recent text history needed for the reply are sent; local app history and Health values are excluded.
  • Sanitized crash reports. Release crash reporting uses closed categories and component labels, not original exception messages or app content.

These promises do not mean the app operates without personal data. IP addresses, device or installation identifiers, transaction state, technical signals, and user-chosen Orb text may be personal data even when they do not contain a name.

3 / 25

Data map

This table summarises the main flows. Later sections provide the detail, limits, choices, and provider links.

HeadGarden information categories and their handling
Category Source Purpose Recipient Lawful basis Retention or criterion
Progress, favourites, history, downloads, settings, reminders, and initial-paywall marker Your app use and choices Provide local app features and remember preferences Your device; Apple notification services where a local notification is scheduled Contract; your requested settings On device until you remove it, clear app data, or uninstall
Selected HealthKit values and mindful-session write Apple Health, only after the relevant permission Show optional context and write a completed mindful session Transiently inside the app; Apple Health receives a write you authorise Your consent and, where applicable, explicit consent Read values are transient; Apple controls Health record retention
Opaque installation principal, app/platform metadata, API bearer, and access lease Generated by the app and HeadGarden service Deliver services and authorise Premium actions without an account HeadGarden service; secure storage on your device Contract; security legitimate interests Principal until local reset; bearer up to 15 minutes; lease up to 72 hours
Products, transactions, subscriptions, entitlements, and store/app identity Apple App Store and RevenueCat Offer, verify, restore, and support purchases Apple, RevenueCat, and HeadGarden’s entitlement service Contract; legal and accounting obligations Provider records according to purchase, fraud, accounting, contractual, and legal needs
Consent state, IP, device/ad identifiers where permitted, coarse location inference, ad delivery and interaction data Your choices, device, network, Google UMP/AdMob, and advertising vendors Resolve privacy choices and show an eligible free-user ad Google and the vendors disclosed in the privacy message Consent where required; legitimate interests for bounded security and contextual delivery where permitted According to the chosen vendors’ policies and legal/advertising requirements
AppsFlyer installation ID, install/session attribution, and permitted technical identifiers AppsFlyer SDK, device, and your privacy choices Measure acquisition and connect eligible subscription outcomes AppsFlyer; RevenueCat receives the matching identifier when configured Your consent; bounded legitimate interests only where law permits identifier-free measurement Under provider settings, contract, opt-out state, and applicable law
Subscription lifecycle and revenue events Apple purchase records processed by RevenueCat Measure subscription outcomes without duplicate client events RevenueCat forwards configured events to AppsFlyer Consent and contract, according to the configured privacy gates According to RevenueCat, AppsFlyer, accounting, fraud, and legal criteria
Sanitized crash category, component label, stack trace, installation identifiers, and standard app/device context Release app and Firebase Crashlytics Diagnose crashes and improve reliability Firebase Crashlytics and authorised CodeObscura personnel Legitimate interests in secure, reliable software Firebase keeps crash records for 90 days before beginning deletion from live and backup systems
Current Orb message and bounded recent text history Text you submit in Orb Generate and return the requested reflection response HeadGarden service and OpenAI API Performance of our contract; your deliberate request Not persisted by HeadGarden; OpenAI default abuse-monitoring controls may retain content up to 30 days
Request identifiers, IP-derived security/rate-limit signals, authorisation outcomes, and sanitized operational errors Your network request and HeadGarden service Protect, rate-limit, debug, and deliver the API HeadGarden and hosting/CDN providers Legitimate interests; contract; legal obligations Only as long as operational, security, abuse, and legal needs require
Ordinary HTTPS request data, including IP address, browser/device headers, path, and timing Your visit to the public website Deliver and secure static pages GitHub Pages, DNS, certificate, and network providers Legitimate interests in publishing and securing the site According to provider security and operational policies

4 / 25

Local app data

HeadGarden stores progress, favourites, history, downloads, settings, reminders, an initial-paywall marker, and related presentation state locally on your device. Secure storage also holds the random installation identity and current session or lease material needed to use protected services. Local databases may contain identifiers and metadata for practices you have used or downloaded.

We do not operate an account-based cloud progress service and do not receive a copy of ordinary progress just because you mark a practice complete. A local notification schedule is managed through the operating system. Apple may process device notification mechanics under its own terms, but HeadGarden does not run a remote marketing-notification profile.

You can remove individual downloads and some local records using app controls. Uninstalling normally removes the app’s ordinary local container; operating-system backups or device-management arrangements may behave according to Apple’s settings. Secure Keychain material can have a different lifecycle under Apple’s platform rules. Reinstalling may create a new opaque principal.

Because there is no account, we generally cannot locate, export, restore, merge, or delete a particular device’s local progress from an email request. You control that data through the device and app.

5 / 25

Health data

Apple Health access is optional and contextual. HeadGarden asks separately for permission to read selected HealthKit values and permission to write an eligible mindful session. You can grant neither, one, or both, and change the permissions in system settings.

Raw and derived Health values are transient. Values read for current in-app context are processed in memory and are not persisted, logged, cached, or transmitted by HeadGarden. They are not included in subscription processing, advertising, attribution, crash reports, Orb requests, server logs, or product analytics. HeadGarden does not use them to build a profile or choose ads.

If you authorise a mindful write, the app sends the completed session information to Apple HealthKit on your device. Completion inside HeadGarden does not depend on a successful Health write. Apple controls the Health database, sync, backups, sharing, retention, and other apps you authorise. Review Apple’s privacy information and your Health settings.

We do not receive raw Health values from Apple and cannot respond to a request for a copy of values that never leave your device. You can review or remove Health records and change permissions using Apple’s controls.

6 / 25

Installation identity and entitlement sessions

On first use, HeadGarden creates a random opaque installation principal. It is designed to identify one installation technically without becoming a consumer account. It is not based on your name, email address, advertising identifier, Orb text, or Health data.

To contact protected HeadGarden endpoints, the app sends the principal with limited app and platform metadata and requests an entitlement session. The service verifies the principal and current RevenueCat entitlement, then may issue a short-lived API bearer and, for verified Premium access, a signed finite entitlement lease. The bearer is designed to expire within 15 minutes and the lease within 72 hours or sooner when the trusted entitlement ends.

The bearer and lease are cryptographic authorisation material, not public identifiers. They are held in secure device storage, rechecked at action time, and rejected when malformed, expired, untrusted, or intended for another audience. The service uses keyed, bounded caches for availability and does not create a cloud activity profile from these sessions.

We process this material to perform the service contract, prevent unauthorised access, and protect licensed Premium content. Resetting or losing the installation can prevent us from connecting a later request to earlier technical state.

7 / 25

RevenueCat and Apple purchases

Apple handles payment details, including your card information, billing address, Apple ID billing relationship, tax handling, and refund channel. HeadGarden does not receive your full payment-card number. Apple sends app/store and transaction information needed to provide and manage an in-app subscription.

HeadGarden uses RevenueCat to present offerings, process subscription state, support Restore Purchases, and determine whether an entitlement appears active. RevenueCat may process the opaque HeadGarden principal, app and store identity, products viewed or purchased, transaction and subscription status, expiration and trial information, entitlement status, and provider-generated identifiers.

Device or attribution attributes are sent to RevenueCat only when the applicable privacy gates allow them. Purchase state is advisory until the HeadGarden service verifies it and returns a trusted access lease. We use the information to perform the subscription contract, prevent fraud and unauthorised access, provide support, restore purchases, and meet accounting or legal obligations.

Apple and RevenueCat maintain records under their own terms, legal responsibilities, fraud controls, and retention practices. To manage or cancel an Apple subscription, use Apple’s subscription settings. To request an App Store refund, use Apple’s refund service.

8 / 25

Advertising and Google UMP/AdMob

Advertising is limited to eligible free users. HeadGarden waits for a resolved privacy state, no blocking paywall or modal, and trusted Free access before constructing or loading a banner. Trusted Premium users do not receive an AdMob ad request.

Google’s User Messaging Platform (UMP) may request consent information, display a region-appropriate privacy message, record vendor and purpose choices, and make a Privacy Choices entry available in Settings where required. HeadGarden does not treat dismissal or the mere technical ability to request an ad as permission for identifier-bearing attribution.

When an ad is eligible, the app sends a non-personalized ad request. Non-personalized means the ad is not selected from your past behaviour; it does not mean no information is processed. Google and disclosed advertising vendors may receive the IP address needed for delivery, user agent, app and device information, consent signals, approximate or coarse location inferred from network information, fraud/security signals, ad-performance information, and interaction data. Cookies or mobile identifiers may still be used for frequency capping or aggregated reporting where permitted and consented.

Depending on your region and choices, identifiers such as an advertising identifier may be withheld, limited, or available. Vendors shown in the privacy message process information under their own policies. Google explains personalized and non-personalized ads and its privacy practices.

You can revisit available choices through HeadGarden Settings, change Apple tracking permission in iOS Settings, use device advertising controls, or purchase Premium. Withdrawing a choice affects future processing; providers may retain earlier records where they have a lawful reason.

9 / 25

AppsFlyer attribution

HeadGarden uses AppsFlyer only after the privacy coordinator resolves that attribution may start. Its purpose is consent-gated install and session attribution: understanding which permitted campaign or source led to an installation and connecting later subscription outcomes without creating a broad in-app behaviour stream.

AppsFlyer may generate an AppsFlyer installation ID and process app, platform, device, network, install, launch, campaign, and attribution information. Advertising or vendor identifiers are disabled by default and enabled only when the applicable UMP choice and Apple App Tracking Transparency permission allow them. A denied tracking permission does not automatically cancel every identifier-free measurement purpose where another valid choice and legal basis applies, but HeadGarden does not silently widen an earlier choice during the same launch.

There are no client-side custom Health, Orb, content, purchase, or revenue events. The app does not send practice titles, progress, Health values, Orb messages, subscription receipts, or custom revenue events to AppsFlyer. It reads the AppsFlyer ID only after a successful, permitted start so RevenueCat can match server-side subscription events when configured.

AppsFlyer provides privacy information and privacy-preserving SDK controls. You can withdraw future consent through available in-app or system controls. The app stops the SDK when a resolved state narrows the permitted processing.

10 / 25

RevenueCat-to-AppsFlyer forwarding

When the dashboard integration is configured and the matching identifiers have been set under the privacy gates, RevenueCat acts as the sole purchase-event forwarder from HeadGarden to AppsFlyer. It may send subscription lifecycle and revenue events—such as initial purchase, trial conversion, renewal, cancellation, expiration, billing issue, or product change—together with the AppsFlyer/customer matching identifier and relevant product, currency, price, tax, commission, or store fields.

This server-to-server route helps measure subscription outcomes even when the app is not open. There is no duplicate client purchase tracking; HeadGarden does not also log the same purchase or revenue event through the AppsFlyer client SDK. This follows RevenueCat’s guidance to avoid double counting.

RevenueCat and AppsFlyer apply their integration configuration, event mapping, sharing filters, sandbox settings, fraud controls, and retention policies. If required identifiers or configuration are absent, an event may not be delivered. This forwarding does not change Apple’s role as payment processor or HeadGarden’s server as the sole authority for Premium access.

11 / 25

Firebase Crashlytics

HeadGarden enables Firebase Crashlytics only in a correctly configured release environment. It is disabled by default in native configuration and becomes active only after the app’s closed production validation and Firebase initialisation succeed. Debug, disabled, expired, or failed startup paths remain no-op.

A report is deliberately sanitized before it crosses the reporting boundary. It may contain a fixed error category, fixed component label, permitted stack trace, app version, operating-system and device context, Crashlytics installation UUID, and Firebase installation ID. Crashlytics may also process standard technical context described in Firebase’s privacy information.

Reports never intentionally include original exception messages, Health values, Orb text, catalogue content, the installation principal, API bearers, entitlement leases, signed URLs, credentials, secrets, or original media metadata. Prior global error handlers are chained with a newly constructed sanitized object rather than the original error.

Google documents that Firebase Crashlytics keeps crash stack traces, extracted minidump data, and associated identifiers for 90 days before starting the process of removing them from live and backup systems. Minidump input used for processing native crashes may have a different temporary lifecycle as described by Google.

We use crash information under our legitimate interests in securing, diagnosing, and improving release reliability. Access is limited to authorised personnel who need it for those purposes.

12 / 25

Orb and OpenAI

When you send a message to Orb, the app transmits the current message and bounded recent text history to the HeadGarden service. The service sends that bounded text to the OpenAI API to generate a response and returns the result. Health values, local progress, downloads, advertising identifiers, purchase receipts, and unrelated app content are excluded.

The HeadGarden service does not log or persist Orb request or response text. It applies request-size, rate-limit, authorisation, and sanitized-error controls, but does not build a conversation profile. Orb history visible in the app is local device state and can be removed with local app data.

OpenAI is a separate processor with its own Privacy Policy and API data controls. Current API documentation states that API content is not used to train OpenAI models by default. Under default abuse-monitoring controls, prompts and responses may be retained in abuse-monitoring logs for up to 30 days, unless a longer period is required by law or reasonably needed to protect services or others. Stricter approved project controls may reduce that handling, but this Policy does not promise that such a control applies unless we have verified it.

Do not send information you do not want those systems to process. Orb is for general-wellness reflection and not for medical, therapy, crisis, legal, financial, or other professional advice.

13 / 25

Backend and delivery security data

Requests to HeadGarden’s catalogue, session, media, and Orb endpoints necessarily contain network and protocol information. We and our hosting or content-delivery providers may process an IP address, request time, route, user agent, request identifier, coarse security or rate-limit signals, response status, authorisation outcome, and sanitized operational error.

This information is used to deliver requested data, issue bounded sessions, prevent abuse, enforce Free/Premium access, investigate failures, protect licensed content, and maintain service availability. Credentials, signed media URLs, request bodies, Orb text, Health data, and original exceptions are excluded from logs by design. Access observations retain only closed labels and bounded identifiers needed to understand service health.

We rely on performance of our contract for requested delivery and our legitimate interests in security, fraud prevention, reliability, and protecting users and licensed resources. We may also process or preserve a limited record where required by a legal obligation or a valid legal request.

14 / 25

Website data

The HeadGarden marketing site and these legal documents are static pages. They contain no account form, contact form, marketing sign-up, third-party script, behavioural analytics, or advertising. The HeadGarden marketing page sets no analytics cookies and runs no tracking code.

Delivering any website still requires ordinary HTTPS and IP request data. GitHub Pages, DNS, certificate, browser, and network providers may process your IP address, request path, time, user agent, TLS and security information, and related technical logs so the page can reach your device and abuse can be detected.

Those providers process the information under their own terms and retention controls. GitHub describes its practices in the GitHub Privacy Statement. We do not receive a visitor-level marketing dashboard from custom tracking code on these pages.

If you select the email link, your email provider and ours process the message and addressing information needed to deliver and respond to it. Do not include Health data, passwords, payment-card data, or unnecessary sensitive information in an email.

15 / 25

Purposes and lawful bases

Under UK data-protection law, we rely on different lawful bases for different purposes:

  • Performance of our contract: providing requested app functions, delivering catalogue and media, generating an Orb response, administering and restoring subscriptions, and issuing entitlement sessions.
  • Your consent: optional Health permissions, mindful writes, notifications where consent is required, identifier-bearing advertising or attribution, and provider/vendor purposes presented through UMP or Apple ATT. Where our processing of Health information requires an Article 9 condition, we rely on your explicit consent.
  • Legitimate interests: securing the app and service, preventing fraud and abuse, rate limiting, diagnosing sanitized release crashes, publishing static pages, protecting licensed resources, maintaining reliability, and using bounded identifier-free measurement or contextual delivery where permitted. Our interests do not override your rights, and you may have a right to object.
  • Legal obligations: complying with tax, accounting, consumer, regulatory, court, law-enforcement, and other duties that apply to us.

Providing Orb text is optional, but Orb cannot generate a response without it. Technical request and authorisation data are necessary to provide protected network features. If you decline an optional permission, the related optional feature may not work, while unrelated features remain available where practicable.

Provider roles can vary by processing activity and law. Apple, for example, determines substantial parts of App Store payment processing. This Policy does not imply that every named provider acts only on our instructions for every purpose.

16 / 25

Recipients and processors

Information is disclosed only to the categories needed for the purposes above, subject to privacy gates and contracts where applicable:

  • Apple for App Store distribution, subscription payment and management, HealthKit, device permissions, and platform services;
  • RevenueCat for offerings, transactions, entitlement state, restoration, and configured server-side AppsFlyer forwarding;
  • Google and disclosed advertising vendors for UMP privacy messages and eligible free-user AdMob delivery;
  • AppsFlyer for permitted acquisition attribution and configured subscription measurement;
  • Firebase Crashlytics for sanitized release crash diagnosis;
  • OpenAI for the Orb text generation request;
  • GitHub Pages for static website hosting; and
  • HeadGarden’s server, hosting, content-delivery, DNS, certificate, security, and network providers for service operation.

We may also disclose limited information to professional advisers, insurers, auditors, potential business transferees under confidentiality, regulators, courts, or public authorities where reasonably necessary and lawful. We do not disclose Health values to these app-service providers because those values do not leave the device through HeadGarden.

17 / 25

International transfers

Several providers operate globally, including from the United States and other countries outside the United Kingdom. As a result, personal data described above may be processed in countries with different data-protection laws.

Where UK transfer restrictions apply, we use an available lawful mechanism appropriate to the recipient and transfer. This may include UK adequacy regulations, the UK Extension to an applicable Data Privacy Framework, the International Data Transfer Agreement or UK Addendum to approved standard clauses, or other recognised contractual safeguards. Providers may also rely on their own lawful transfer mechanisms for processing they independently control.

Transfer safeguards do not eliminate every difference in foreign law. You may contact legal@codeobscura.com for more information about the safeguards relevant to a particular HeadGarden processing activity, subject to confidentiality and legal limits.

18 / 25

Retention

We keep information only for the period needed for its purpose, to protect the service, or to meet legal, accounting, fraud, dispute, and contractual requirements. Where a fixed period is not appropriate, we use those criteria and the sensitivity of the data.

  • Local app data: remains on the device until you remove it, clear app storage, or uninstall, subject to Apple backup and secure-storage behaviour.
  • Health read data: is transient in memory. HeadGarden does not persist it. Apple controls any Health record you authorise the app to write.
  • Entitlement material: the API bearer is designed for no more than 15 minutes and the Premium lease for no more than 72 hours. The opaque principal remains until local reset or uninstall behaviour changes it.
  • Orb: HeadGarden does not persist the request or response text. OpenAI’s default API abuse-monitoring handling may retain content up to 30 days, with the qualifications explained in section 12.
  • Crash reports: Firebase documents a 90-day period before beginning removal of crash stack traces and associated identifiers from live and backup systems.
  • Purchases: Apple and RevenueCat retain transaction, entitlement, fraud, tax, accounting, and support records under their legal and contractual criteria.
  • Advertising and attribution: Google, disclosed vendors, AppsFlyer, and RevenueCat retain permitted records according to the selected settings, opt-out state, contracts, fraud controls, and applicable law.
  • Operational and website data: we and infrastructure providers retain bounded security and request records only as long as operational, abuse-prevention, contractual, and legal needs require.

Withdrawing consent or uninstalling stops or limits future HeadGarden processing but does not necessarily require a provider to erase a record it must retain for a separate lawful reason.

19 / 25

Choices and controls

You can exercise practical controls without creating an account:

  • manage Health read and mindful-write permissions independently in Apple Health or iOS Settings;
  • manage Apple App Tracking Transparency permission and device advertising controls in iOS Settings;
  • use Privacy Choices in HeadGarden Settings when UMP reports that the form is required or available;
  • decline an optional consent message or withdraw a consent for future processing, recognising that a related feature or ad mode may change;
  • manage notification permission and HeadGarden reminder settings;
  • delete local history, favourites, downloads, or other state through available app controls, or uninstall the app;
  • use Restore Purchases to ask Apple and RevenueCat to re-check an eligible subscription; and
  • manage or cancel subscription renewal through Apple’s subscription settings.

HeadGarden treats advertising eligibility, attribution, and identifier collection as separate decisions. A choice allowing one does not automatically allow the others. Premium store state does not alone unlock protected content or silently bypass privacy resolution.

20 / 25

Your data-protection rights

Depending on the processing and law that applies, you may have the right of access, right to rectification, right to erasure, right to restriction, right to data portability, and right to object. You may also withdraw consent at any time for future consent-based processing. Withdrawal does not make earlier lawful processing unlawful.

Your right to object: where we rely on legitimate interests, you can object based on your particular situation. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed for legal claims.

To exercise a right, email legal@codeobscura.com and explain the processing you mean. We may ask for proportionate information to verify the request and avoid disclosing data to the wrong person.

The accountless design creates practical limits. We may be unable to identify an accountless installation from your name or email, because neither is linked to the opaque principal. Local progress and Health values that never reach us are controlled on your device. We will not collect extra sensitive data merely to create a link that does not already exist, but we will assist with identifiable records where reasonably possible.

Some providers offer direct controls for data they independently handle. Your rights may be limited by exemptions, another person’s rights, fraud prevention, or legal retention duties. We normally respond within the period required by applicable law and will explain if an extension or limitation applies.

21 / 25

Questions and complaints

We would welcome the opportunity to resolve a privacy concern. Contact legal@codeobscura.com with enough detail for us to understand the issue, but do not send unnecessary Health values, passwords, payment-card data, or secrets.

You also have the right to complain to the Information Commissioner’s Office, the United Kingdom’s data-protection supervisory authority. Official guidance and complaint routes are available at ico.org.uk/make-a-complaint. If you live elsewhere, you may be entitled to complain to the supervisory authority where you live or work or where an alleged infringement occurred.

Contacting us first is optional and does not affect your right to approach a regulator or court.

22 / 25

Security

HeadGarden uses transport encryption for network requests, random installation identities, short-lived bearer tokens, signed finite access leases, audience and expiry checks, fail-closed Premium decisions, rate limits, bounded caches, secure device storage, least-data provider boundaries, and sanitized operational and crash reporting.

Protected media paths are resolved on the server against private ownership and access records before signing. The public catalogue omits delivery object keys. Store state, a local download, or an interface flag cannot impersonate a trusted entitlement.

Access to provider dashboards and operational information is limited according to role and need. Dependencies and configurations are reviewed, and optional native services remain unconstructed or disabled when release configuration is incomplete.

Security is a shared and changing process. There is no absolute security guarantee: no system, device, provider, or transmission method can be guaranteed secure in every circumstance. Keep your device and Apple ID protected, install trusted updates, and contact us if you believe HeadGarden security has been affected.

23 / 25

Children

HeadGarden is for adults aged 18 or over and is not directed to children. We do not knowingly offer the service to a child or design Orb, advertising, or subscriptions for a child audience.

If you believe a child has used HeadGarden and sent identifiable information to a provider, contact legal@codeobscura.com. Because there is no account and ordinary progress stays local, we may need limited information about the device, time, and feature to investigate without collecting unnecessary details.

24 / 25

Automated decisions

HeadGarden makes technical decisions about whether a request is authenticated, whether a trusted lease permits Premium access, whether privacy choices have resolved, and whether a free-user banner is eligible. Orb automatically generates text in response to a request.

We make no solely automated decision based on your personal data that produces a legal or similarly significant effect about you. Entitlement and advertising gates affect app functionality only. Apple and providers may operate separate fraud, payment, consent, and eligibility systems under their own responsibilities.

If you believe a technical gate is incorrect, use Restore Purchases, review the relevant privacy control, retry when service is available, or contact us. Premium content remains locked unless the server returns a current trusted lease.

25 / 25

Changes and contact

We may update this Policy when HeadGarden, a provider, the law, or our processing changes. We will change the effective date and provide additional notice in the app or another appropriate channel where a change is material. We encourage you to review the current version before making a new privacy choice.

Questions, rights requests, and privacy concerns can be sent to legal@codeobscura.com.

OBSCURACODE LTD
Company number 16120395
Registered office: 3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE
Registered in England and Wales
legal@codeobscura.com
codeobscura.com

OBSCURACODE LTD
Company number 16120395
Registered office: 3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE
Registered in England and Wales
legal@codeobscura.com
HeadGarden website Terms of Use CodeObscura

© 2026 OBSCURACODE LTD. All rights reserved.