Reviewed Jun 2026 · policies are checked weekly for changes · stated — every cell is read from Obsidian's published policy; none has been tested (run by us) yet.
2Accessstated
Obsidian collects no personal data or telemetry; your notes are local Markdown files you fully hold, any server-side Sync/Publish data is end-to-end encrypted, and account data is self-serve in the obsidian.md account dashboard.
Obsidian — Privacy Policy · accessed Jun 2026 ↗
2Frictionstated
No account is required to use the app; accessing, moving or deleting your notes is ordinary file management, and account/Sync are self-serve via the dashboard — no email, no waiting, no verification.
Obsidian — Privacy Policy · accessed Jun 2026 ↗
2Deletionstated
You delete local notes directly; account deletion is self-serve and permanent via the account dashboard, and Sync data is deleted immediately when you cancel (one month if the subscription lapses).
Obsidian — Privacy Policy · accessed Jun 2026 ↗
1API access — feeds Agent Readiness, not the /12stated
Obsidian exposes no hosted/OAuth API for a remote agent to connect to your data, but your notes are open Markdown files on disk and Obsidian ships a documented local plugin API, so an on-device agent has full read/write access — accessible locally, not remotely.
Obsidian — Developer docs (local plugin API) · accessed Jul 2026 ↗
Source-verified Jul 2026 from Obsidian’s own privacy policy. All cells are "stated" (read from published policy); no live export or deletion has been run to mark any cell "tested."