Powerful permissions need plain boundaries.

Obelisk uses Android capabilities to intervene between reflex and action. Those capabilities are scoped to the workflow, explained during setup, and never presented as invisible magic.

Your vault remains the reflection layer.

The Obsidian companion plugin accepts written intentions and navigation commands, hands authenticated request references to Android, and writes completed session summaries back into the Daily Note. Sensitive intention text remains in the vault bridge record rather than in the exported Android URI.

Intentions and reflections
Kept in the Obsidian workflow and returned to user-editable Markdown.
Active session state
Stored by the Android app so timers, app access, and recovery survive interruptions.
Diagnostics
Designed to omit intention and reflection content from sanitized exports.

The accessibility service observes package changes only.

Obelisk observes which package is in the foreground so it can apply user-configured app rules. It does not use the accessibility service to read, interpret, or record the contents of another app's screen.

No third-party screen capture.

Cross-app prompts can blur or darken the app beneath them when Android supports it. Obelisk does not capture or store third-party application imagery. The opaque fallback remains the privacy and contrast guarantee when blur is unavailable.

Obelisk is not a security boundary.

The product is designed to support self-control and awareness. Android capabilities can be denied, interrupted, or limited by protected windows and device behaviour. The product must preserve user control and explain those limits rather than claim unbreakable enforcement.

This page describes the current private MVP. A launch privacy policy still needs the final beta submission provider, legal entity details, retention periods, and contact address.