Your words should stay yours.
This policy explains what Obelisk collects, where it is kept, why it is needed, and how to ask for access, correction, or deletion.
Effective 2 August 2026
Who is responsible.
Obelisk is an independent project operated from Queensland, Australia. In this policy, “Obelisk”, “we”, and “us” refer to the operator of the Obelisk website, private beta, Android app, and Obsidian companion plugin.
Privacy questions and requests can be sent to privacy@obelisk.md.
Private-beta applications.
When you apply, we collect your email address, optional name, Android device description, level of Obsidian experience, your answer about the workflow you want to test, the time you consented, and the version of this privacy notice you accepted.
We use this information only to assess private-beta fit, manage the beta, prevent form abuse, and contact you about your application or participation. Applying does not add you to a general advertising list, and we do not sell your details.
The open-text answer is not intended for health, medical, or other sensitive personal information. Please keep it to the phone habit or product workflow you want to test.
- Where it is stored
- Cloudflare D1, accessed through an internal Cloudflare Worker rather than a public database connection.
- Retention
- Up to 12 months from application, unless you ask us to delete it sooner or we must retain a limited record to meet a legal obligation.
- Your choice
- You do not have to apply. Without the required fields and beta-contact consent, we cannot assess or respond to the application.
Website protection and measurement.
The site is hosted and protected by Cloudflare. Requests necessarily provide technical information such as IP address, browser and device headers, requested pages, timestamps, and security signals to Cloudflare so the site can be delivered and protected.
The beta form uses Cloudflare Turnstile to distinguish people from automated abuse. Turnstile processes signals including IP address, user-agent, TLS characteristics, the site key, and the page origin. Cloudflare Web Analytics provides aggregated page and performance measurement and is designed not to track visitors across websites.
Cloudflare may process information outside Australia, including in the United States and other places where it or its service providers operate. Its processing is governed by our Cloudflare agreement and Cloudflare’s privacy and data-processing terms.
Android and Obsidian stay local-first.
The Android app and Obsidian plugin do not send intentions, reflections, session history, your installed-app catalogue, or vault contents to Obelisk servers. The Android app stores active session state, app rules, reliability events, and configuration on your device. The plugin stores bridge records and completed session summaries in the Obsidian vault you choose.
Your vault may be copied by Obsidian Sync, device backup software, or another synchronisation provider you choose. Those services are controlled by you and governed by their own privacy terms.
- Intentions and reflections
- Remain in the local Android workflow while needed and return to user-editable Markdown in your vault.
- Bridge records
- Carry a short-lived authenticated request reference between Obsidian and Android. Successfully completed temporary requests are deleted; an interrupted or rejected record can remain in your vault until you remove it.
- Diagnostics
- Stay on the device unless you deliberately preview and share a sanitized export using Android’s share sheet.
Powerful permissions have narrow purposes.
Accessibility observation
Obelisk observes foreground-package changes so it can apply app rules you configure. It does not use the accessibility service to retrieve, interpret, or record another app’s window content.
Vault access
You choose the Obsidian vault directory and grant Android read and write access. Obelisk uses that grant for its documented app-rule, Daily Note, template, and bridge workflows.
Overlays and notifications
These permissions show intentional-session controls, guards, timers, and recovery information. Obelisk does not capture or store third-party application imagery.
Security and deletion.
We use scoped service bindings, parameterised database queries, input limits, bot verification, access controls, and Cloudflare’s security controls to protect beta applications. No internet service can be guaranteed completely secure.
Beta records are scheduled for deletion after 12 months. Local Android data is removed when you clear the app’s storage or uninstall it, except for records already written to your Obsidian vault. You control and can delete those vault files in Obsidian. Copies held by a sync or backup provider may follow that provider’s retention rules.
Access, correction, deletion, and complaints.
You may ask what beta information we hold about you, request a copy or correction, withdraw beta-contact consent, or ask for deletion by emailing privacy@obelisk.md. We may need to verify that the email address belongs to you before acting.
If you make a privacy complaint, describe what happened and how you would like it resolved. We will acknowledge it and aim to respond within 30 days. If you are not satisfied and the Australian Privacy Act applies, you may contact the Office of the Australian Information Commissioner.
Changes to this policy.
We will update the effective date when this policy changes. If a material change affects an existing beta application, we will provide notice using the contact details associated with that application where practical.
Obelisk is an intentional-use and self-awareness tool. It is not a clinical treatment and not an adversarial security boundary.