Obsidian

Legal

Privacy Policy

Free tools collect nothing. Pro's backend collects the minimum needed to license, deliver, and meter - and the website collects almost nothing at all.

Effective: October 1, 2026 · Controller: The Obsidian Team · Contact: [support email]

1. Summary

2. Website

This site is static HTML on Cloudflare Pages. There is no analytics script, no tracking pixel, no cookies, no advertising, and no comment/chat widget. Standard Cloudflare edge logs (IP, user agent, requested path, timestamp) exist for security and debugging and rotate automatically.

The page makes two kinds of outbound request:

No other third parties load (no ad networks, no social widgets). Our Content-Security-Policy blocks the page from connecting anywhere except our own origin, our update Worker, and those font hosts.

You can switch the interface language. Your choice is saved only in your browser's local storage as a functional preference: it is not a cookie and is never sent to us, and clearing site data resets it. The prose on the legal and documentation pages is English.

3. Free tools

The free packer (protector.exe), the desktop packing tool, the SDK headers, and the runtime modules run entirely on your machine. They make zero network requests, create no identifiers, and write only the files you ask them to (protected output, configs, local logs you control). Dropping an .exe into the tool uploads it nowhere - analysis happens locally.

4. Pro toolchain and backend (coming soon)

When Pro launches, the following contacts our backend (Cloudflare Worker + R2 + KV). The client is treated as hostile: the server decides entitlements, and every payload that matters is signed and verified - but verification does not require us to know who your end users are.

EventWhat is sentWhy
License install / activationlicense key, app/toolchain version, coarse platform string, activation IDauthenticate the key, enforce seats/activations, deliver only paid bytes
Gated download / update checklicense key or activation token, channel, current versionserve the signed manifest envelope + artifacts for that channel/version
Rotation seed pulllicense key or activation token, time windowissue the current-window per-license seed; stale seeds stop working
Metered online featuresaggregated counts (seats/activations, GB, rotation frequency)metered billing against the developer's account with estimator + caps

5. Payments

Checkout is handled by a merchant of record (Lemon Squeezy or Gumroad). They process your payment, handle tax/VAT, and issue receipts under their own privacy policy and terms. We receive purchase records (email, purchased features, license key issued, refund/chargeback state) to provision and revoke entitlements - we never receive full card numbers.

6. Retention and rights

← Back to Obsidian · Documentation · Terms of Service