← Back to Home

Privacy Policy

Effective date: April 10, 2026

Obsidify ("we", "us", "our") is provided by Velodev Digital (sole proprietorship), which operates the website obsidify.tech, the Obsidify web application, the Obsidify Mac application distributed through the Apple App Store, and the Obsidify Android application distributed via Google Play (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.

1. Information We Collect

Account information

When you sign in with Google via Firebase Authentication or Sign in with Apple, we receive and store:

Content you provide

When you publish an Obsidian vault through the Service, we store:

Billing information

Subscription purchases are processed by Apple in-app purchase on Mac and Google Play Billing on Android. We receive a transaction or purchase token and entitlement status from Apple or Google to verify your subscription tier (Starter, Pro, or Team). We do not receive or store your payment card details, bank account information, or billing address.

Usage data

We collect basic, first-party analytics for published sites:

We do not use third-party analytics services, tracking pixels, or advertising cookies.

2. How We Use Your Information

We use the information we collect to:

3. Cookies and Tracking

The Service uses only strictly necessary, first-party session cookies (or equivalent authentication tokens) to keep you signed in. We do not use advertising cookies, social-media tracking cookies, or any third-party tracking technologies.

4. Data Storage and Security

Your data is stored on dedicated servers located in Germany (Netcup GmbH data centers). All data in transit is encrypted via TLS. Access to production servers is restricted to authorized personnel using SSH key authentication.

While we implement commercially reasonable security measures, no method of electronic storage or transmission is completely secure. We cannot guarantee absolute security.

5. Third-Party Services

We rely on the following third-party services to operate:

Firebase Authentication Google

Used for user sign-in via Google OAuth. Firebase processes your email, display name, and authentication tokens. Firebase's privacy policy is available at firebase.google.com/support/privacy.

Sign in with Apple and In-App Purchase Apple

Used for Mac app sign-in and subscription purchase processing. Apple processes your Apple ID authentication and payment information directly. Apple's privacy policy is available at apple.com/legal/privacy.

Google Play Billing Google

Handles subscription payments for the Android app. Google processes your payment information directly. Google's privacy policy is available at policies.google.com/privacy.

GitHub Microsoft

If you choose to sync a vault from GitHub, our GitHub App accesses the specific repository you authorize. We only read repository content needed to build your site. GitHub's privacy statement is available at docs.github.com.

Sentry Functional Software

Used for error monitoring and crash reporting. Sentry may receive error details and limited request metadata to help us diagnose issues. Sentry's privacy policy is available at sentry.io/privacy.

Cloudflare Cloudflare, Inc.

Used as a DNS and CDN proxy for performance and DDoS protection. Cloudflare may process request metadata (IP addresses, headers) in transit. Cloudflare's privacy policy is available at cloudflare.com/privacypolicy.

6. Data Retention

7. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority.

Legal basis for processing

We process your personal data on the following legal bases:

8. Children's Privacy

The Service is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9. International Data Transfers

Your data is primarily stored in Germany. If you access the Service from outside the EEA, your information may be transferred to, and processed in, a country that provides a different level of data protection. We ensure appropriate safeguards are in place for any such transfers.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the updated policy on this page with a revised effective date. We encourage you to review this page periodically.

11. Contact Us

Legal entity: Velodev Digital (sole proprietorship)

If you have questions or concerns about this Privacy Policy, contact us at: