Privacy Policy

Effective 2026-07-19. Applies to obsideo.io, the Obsideo storage service (signup.obsideo.io, s3.obsideo.io), the obsideo-cli package, and the Obsideo MCP server / desktop extension.

The short version: Obsideo is built so we hold as little as possible. Encryption keys are generated and kept on your machine; we never receive them. Content you encrypt before upload is unreadable to us and to storage providers. We collect what a storage account needs to function (your email, usage totals, operational metadata) and we do not sell or share it for advertising.

1. What we collect

2. The local extension and CLI

The Obsideo MCP server and CLI run entirely on your machine. Your S3 credentials, your Ed25519 account signing key, and any client-side encryption key live in local configuration files (for the MCP server, ~/.obsideo/mcp.json). They are transmitted only as required to use the service (credentials authenticate S3 requests to s3.obsideo.io) and are never sent to any other party. We do not operate, host, or have access to your local extension. Conversation content from your AI assistant is not collected by Obsideo; only the specific tool calls it makes (for example, an upload) reach our service.

3. How we use data

We do not sell personal data. We do not share personal data with third parties for their marketing. We do not train AI models on your data or content.

4. Where data lives, and third parties

5. Retention and deletion

6. Security posture

End-to-end encryption is architectural, not a policy promise: keys never enter Obsideo's systems, so no operator access to our infrastructure can decrypt client-side-encrypted content. Deletes require your cryptographic signature; the platform cannot destroy your data unilaterally. Stored objects are challenge-verified with cryptographic proofs every 4 hours.

7. Your choices and rights

8. Changes and contact

We will update this page when practices change and adjust the effective date above. Questions, requests, or concerns: [email protected].