Privacy Policy
Clear about what stays local.Precise about what connects.
Obsidian Ridge Labs builds its core AI experiences to run on your Apple device. Some optional features use services such as Plaid or iCloud. The public website uses Google Analytics only to measure aggregate traffic. This policy names those connections instead of hiding them behind a blanket claim.
Effective August 21, 2026
Privacy at a glance
Core AI
On-device
Product content is processed locally for core AI features.
Default storage
Local-first
Your content begins in the app sandbox on your device.
Network features
Disclosed
Optional connections are explained where they are offered.
1. Scope of this policy
This policy covers the Obsidian Ridge Labs website and our published applications. Product pages and help guides provide additional detail for individual features. Practices for products still in development will be confirmed before those products are released.
Our approach is local-first, not network-blind: we reduce data movement wherever the product can work locally and identify the cases where a feature needs a connection.
2. Core AI processing and local content
Core AI features are designed to process your content on supported Apple hardware using Apple on-device frameworks or app-bundled models. We do not send your recordings, transcripts, financial history, journal entries, tasks, or decision content to an external AI API for inference.
App content is stored locally by default inside the operating system's app sandbox. Our apps do not require an Obsidian Ridge Labs account, contain advertising, or use advertising identifiers. We do not sell your app content or use it to build advertising profiles.
Some on-device models require a one-time download before they can work offline. A model download requests model files; it does not include the private content you created in the app.
3. Optional and product-specific connections
The following connections are limited to the feature you choose to use. Disabling an optional feature does not move core AI processing to a remote service.
Echo Chamber
Recording, transcription, summaries, transcript chat, search, and translation run on-device. Audio stored by Echo Chamber is encrypted at rest using AES-256-GCM. Echo Chamber may connect to download a speech model. If you enable iCloud sync, audio is encrypted on your device before it is stored in your iCloud account; iCloud sync is off by default. Obsidian Ridge Labs does not operate a recording server for Echo Chamber.
Vault
Manual tracking, statement and receipt import, financial categorization, forecasting, and AI coaching are designed to run locally. If you enable bank sync, you sign in through Plaid's interface. Vault does not see or store your bank username or password. Plaid receives the information needed to connect your institution, and transaction and balance data passes through Plaid and a secure relay to reach your device.
Vault also offers anonymous diagnostics that are off by default. If you opt in, they contain limited event-name counts and a hashed identifier, not account balances, amounts, merchants, categories, or coach conversations. An optional local AI model download requests model files without including your financial data.
Apple system services
Features you deliberately send to Apple Reminders or Calendar may sync through your iCloud settings. Apple also processes App Store downloads, subscription verification, and purchases. Those services are governed by your Apple account settings and Apple's privacy terms.
4. App diagnostics
Our applications do not include third-party behavioral analytics SDKs. Where an app offers first-party diagnostics, as Vault does, the control is off by default and the app explains what is included before you enable it. App diagnostics are separate from the public website measurement described in section 5.
5. Public website traffic measurement
The public Obsidian Ridge Labs website is not an account product and does not receive content stored in our apps. Recordings, transcripts, finances, journals, tasks, and similar in-app material are not sent to this website or to Google Analytics.
To measure how the website itself is used in the aggregate, we load Google Tag Manager (container ID GTM-PGQDN8FM), which loads Google Analytics 4 (measurement ID G-FNL2K6W19T). These services are provided by Google LLC. We use them solely to produce aggregated website statistics, such as approximate counts of visits and page views, which pages are requested, coarse geographic region, referring site or campaign, and general device or browser category.
We do not use Google Tag Manager or Google Analytics to identify you by name, email address, or account; to create a marketing, remarketing, or advertising profile; to measure or target ads on other sites or apps; to combine website traffic with app content; or to sell personal information. We do not share website analytics for cross-context behavioral advertising. We do not assign a Google Analytics user ID, do not enable Google Signals or Google's advertising features for this property, and do not authorize Google to use this property's Analytics data for Google's advertising products.
Google may process technical information that is necessary to generate those aggregate reports. That information can include the pages requested and related timestamps, a cookie or similar client identifier used to distinguish sessions for counting, the referring URL, user-agent or device characteristics, and Internet Protocol address information that Google uses to estimate approximate location. We review Analytics in aggregated form. We do not attempt to re-identify a visitor from those reports, and we do not collect additional personal information through the website for analytics purposes.
Independently of Google Analytics, the service that hosts this website may process ordinary request logs required to deliver pages securely and reliably. Hosting logs do not include content stored inside our apps.
You can limit or delete cookies and similar storage in your browser settings. Google also provides a Google Analytics opt-out browser add-on. Google's processing of information is further described in the Google Privacy Policy, how Google uses information from sites that use Google services, and Google's commitments for Google products. Questions about our use of these tools can be sent to the contact address in section 11.
6. Purchases
Purchases and subscriptions are processed through Apple's StoreKit and the App Store. Apple handles your payment credentials and billing relationship. Our apps receive the transaction or receipt information needed to verify a purchase and unlock the relevant features; Obsidian Ridge Labs does not receive your full payment-card number or billing address from Apple.
7. Security
Local content benefits from Apple's app sandbox, device passcode protections, and the security controls available on your device. Individual apps may add Face ID access or feature-specific encryption. Encryption details are stated per product rather than as a blanket claim across every kind of data.
No device, network, or storage system is immune to every risk. Keep your operating system current, use a strong device passcode, and review optional sync settings in the relevant app.
8. Your controls and deletion
You can delete local content from the app or remove the app from your device. Where offered, you can turn off diagnostics, disable iCloud sync, or disconnect a Plaid-linked bank. Product help guides explain the controls available in each app. Website traffic measurement is described in section 5, including browser cookie controls and Google's Analytics opt-out add-on.
Removing an app does not automatically delete information already managed by a service you enabled, such as iCloud, Plaid, or the App Store. Use the controls provided by that service where applicable.
9. Children's privacy
Our products are not directed to children under 13, and we do not knowingly request personal information from children through our apps. If you believe a child has provided information to us through a support interaction, contact us so we can review the request.
10. Policy changes
We may update this policy as products and optional services change. The effective date at the top of this page identifies the current version. Material product-specific changes will also be reflected in the relevant product documentation.
11. Contact
Questions about this policy or a product's data handling can be sent to support@obsidianridgelabs.com. Because app content is generally stored on your device rather than in an Obsidian Ridge Labs account, we may not possess a copy that we can retrieve for you.