§ I
Your phone should answer to you alone.
A device you carry against your body should not report what it sees, hears, or touches — not to Google, not to Apple, not to the eighteen analytics vendors baked into every "free" app. We built OBSCURA because this had stopped being obvious.
§ II
The hardware chain is the whole argument.
If the boot chain isn't verifiable and re-lockable, nothing above it matters. Only Google Pixel lets us flash a hardened OS and re-lock the bootloader. That's the reason our catalog is what it is.
§ III
Open-source, or it didn't happen.
Every layer we assemble is public, inspectable, reproducible. GrapheneOS. WireGuard. nftables. Threema's protocol documentation. You should be able to rebuild what we sold you — and you wouldn't need us.
§ IV
Privacy is infrastructure, not a feature.
A toggle, a checkbox, a permission dialog — these are the form privacy takes when companies want credit without commitment. We wire it from the kernel up. The killswitch is nftables, not a button.
§ V
We will say no out loud.
We will refuse warrants we can legally refuse, push back on those we cannot, and publish what we refused and when. Our warrant canary republishes on the first of every month. Its absence is the notice.
§ VI
Honesty about limits is a feature.
A phone cannot make you anonymous. A phone cannot undo a call made in the clear. OBSCURA stops passive collection, commercial tracking, and vendor harvesting. The rest is your tradecraft. We will keep saying this.
§ VII
Shipped, not promised.
Every device in Batch 01 is hardened, re-locked, provisioned, sealed, and signed by a named operator in Zürich. An attestation hash is printed on the seal. Verify on arrival. Mismatch → we swap at no cost.