1. Overview
This Privacy Policy explains how Save2Obsidian (“we,” “us,” or “our”) handles personal information when you use our website, X connection, processing service, dashboard, and Obsidian plugin. We aim to collect only what is needed to turn the X posts you request into notes and deliver them to your vault.
2. Information we collect
Account information
When you sign in with X, we receive your X user ID, handle, and display name. We use an OAuth flow and a short-lived X access token to identify you. We do not store that X access token after the sign-in flow is complete.
Saved-post information
When you mention @save2obsidian, we may process and store the post URL, text, title, author, site name, available thread context, images, timestamps, generated markdown, and technical identifiers needed to avoid duplicate saves.
Service and device information
We may receive limited request metadata such as IP address, user agent, timestamps, error records, and security signals when you use the website or API. Our infrastructure providers may process this information to operate and protect the Service.
Billing information
Paid plans are not currently active. If subscriptions launch, Creem will process checkout and payment information. We expect to receive subscription status, plan, billing identifiers, and transaction metadata, but not full payment-card details.
3. How we use information
- create and maintain your account and sign-in session;
- link your X account to your personal plugin key;
- retrieve, process, store, and deliver the posts you request;
- show account details and recent saves on your dashboard;
- detect abuse, secure the Service, troubleshoot errors, and prevent duplicates;
- understand and improve performance and user experience;
- comply with law and enforce our terms.
4. Storage and service providers
Account records, sessions, and processed saves are stored on Cloudflare infrastructure. Cloudflare may process request and storage data as our infrastructure provider. The Obsidian plugin writes downloaded markdown and images to the local vault location you configure; we do not host or control that local vault.
We may also rely on X for sign-in and source-post access, and on Creem for future subscription billing. Those providers process information under their own privacy terms.
5. Legal bases and purposes
Depending on where you live, we process information to perform the service you request, pursue legitimate interests such as security and product improvement, comply with legal obligations, or act with your consent. This section is a draft and must be finalized for the regions in which the Service is offered.
6. Sharing
We do not sell your personal information. We may share limited information with infrastructure, authentication, billing, security, and support providers where necessary to run the Service; when required by law; or as part of a business transaction subject to appropriate safeguards.
7. Retention
We keep account and saved-content information while your account is active and as needed to provide the Service. Security, billing, and legal records may be kept longer where reasonably necessary. We will define specific retention periods before commercial launch.
8. Your choices and deletion
You can stop saving new material at any time by no longer mentioning the bot or by disabling the plugin. You may request access, correction, account unlinking, or deletion of your account and Service-stored content by emailing support@save2obsidian.com.
Deleting Service-stored content does not delete files already synced into your local Obsidian vault. You control and can delete those files directly.
9. Security
We use reasonable technical and organizational measures designed to protect account and saved-content information. No system is perfectly secure. Keep your API key private and contact us promptly if you believe it has been exposed.
10. International processing
Our providers may process information in countries other than the one where you live. Where required, we will use appropriate safeguards for international transfers.
11. Children
The Service is not directed to children under 13, or the higher minimum age required in their jurisdiction. We do not knowingly collect personal information from children in violation of applicable law.
12. Changes and contact
We may update this policy as the Service changes. The revised policy will be posted here with a new “Last updated” date. Privacy questions and requests may be sent to support@save2obsidian.com.