Obsidian
Legal

Privacy Policy

Last updated: July 2026

Who we are

Obsidian is a private, invitation-only relationship-intelligence platform. It is used by a small number of authorized members within a single organization to keep track of their professional and personal contacts. This policy explains what data we hold, how the Google integrations work, and the choices you have.

Information we store

We store the contact and relationship information you (or your teammates) enter or import: names, contact details, notes, tags, groups, events, and related context. This data is entered by our members about their own network. All sensitive fields are encrypted at rest.

Google Calendar access

With your explicit permission, Obsidian connects to your Google Calendar to help you keep your relationship timeline current. Specifically:
  • Read-only. We request the calendar.readonly scope only. Obsidian can read your calendar events; it cannot create, edit, or delete anything on your Google Calendar.
  • What we read. Events from your primary calendar — titles, times, and attendees — so they can appear on your Obsidian timeline alongside your contacts.
  • What we store. Event details are stored in your Obsidian workspace so the timeline renders without re-fetching. Your Google authorization (refresh token) is encrypted at rest with AES-256-GCM.
  • How it's used. Only to display your events and enrich your relationship context inside Obsidian. We do not use your calendar data for advertising, and we never sell it.
  • Disconnecting. You can disconnect Google Calendar at any time from your settings. On disconnect we revoke the authorization and stop syncing.

Limited Use disclosure

Obsidian's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer or sell Google user data to third parties, do not use it for advertising, and do not allow humans to read it except with your explicit consent, for security, or as required by law.

AI processing

Obsidian uses AI to help extract and organize the information you add. We do not use your data — including any Google data — to train AI models, and your data is not shared for that purpose.

Data sharing

We do not sell your data. Access is limited to authorized members of your own workspace. We use trusted infrastructure providers strictly to operate the service, under confidentiality obligations.

Security

Sensitive fields, files, and third-party authorization tokens are encrypted at rest. Access requires authentication, and sensitive operations require re-verification.

Your choices

You can view, edit, export, or delete the contacts and data you manage, and disconnect any connected Google account at any time. To request deletion of your account or data, contact your workspace administrator.

Contact

Questions about this policy or your data can be directed to your Obsidian workspace administrator.