Privacy Policy
What stays here. What connects, and when.
The Boundary Check, answered in full. Core AI runs on your Apple device. Setup, storage, and connected features can use services such as Plaid or iCloud. Their defaults vary by app. The public website uses Google Analytics to measure aggregate traffic. A blanket privacy claim is not a boundary, so here is the specific version.
Effective September 14, 2026
Privacy at a glance
Processing
On your device
Core AI features run on your Apple hardware, not on our servers.
Storage
Product-specific
Apps store content locally; some also use your private iCloud database. Sync defaults are described below.
Connections
Setup and features
Downloads, purchases, storage services, and connected features have distinct roles and defaults.
1. Scope of this policy
This policy covers the Obsidian Ridge Labs website and our published applications. Product pages and help guides provide additional detail for individual features. Practices for products still in development will be confirmed before those products are released.
The approach is local-first, not network-blind. Data movement is reduced wherever the product can do the job locally, and the cases where a feature genuinely needs a connection are named rather than buried.
2. Core AI processing and local content
Core AI features are designed to process your content on supported Apple hardware using Apple on-device frameworks or local models. We do not send your recordings, transcripts, financial history, journal entries, tasks, or decision content to an external AI API for inference.
App content is held inside the operating system's app sandbox. Some products also use a private iCloud database, including Mettle and Cove by default when available. Our apps do not require an Obsidian Ridge Labs account, contain advertising, or use advertising identifiers. We do not sell your app content or use it to build advertising profiles.
Some on-device models require a one-time download before they can work offline. A model download requests model files; it does not include the private content you created in the app.
3. Optional and product-specific connections
Some connections support setup, purchase verification, or a product's default storage; others are features you choose. Disabling an optional feature does not move core AI processing to a remote service. Development-product descriptions below refer to the current implementation; release practices will be confirmed before availability.
Echo Chamber
Recording, transcription, and transcript intelligence run on-device. Recordings and transcripts are stored locally. Echo Chamber may connect for model setup, purchase verification, and usage checks. Optional iCloud sync is off by default and uses your Apple account when enabled. Exporting or sharing creates a copy at the destination you choose. Obsidian Ridge Labs does not operate a recording server for Echo Chamber.
On Mac, Echo Chamber can request Screen & System Audio Recording permission to capture the audio of a meeting running in another app, such as Zoom, Teams, or Slack. This captures audio only, never screen contents, and it necessarily includes the voices of other meeting participants, not just the device owner. Separately, optional Calendar access lets Echo Chamber read event details, including titles, attendees, and agenda items, to enrich a transcript. Both the audio of other participants and any calendar attendee information used by the app are processed locally. Optional iCloud sync and deliberate export or sharing can move associated records through those destinations; they are not uploads to an Obsidian Ridge Labs AI service.
If you record a meeting or call, you are responsible for complying with the laws that apply to you, including any requirement to notify or obtain consent from other participants before recording them.
Vault
Vault is in development. Manual tracking, statement and receipt import, local categorization, forecasting, and core AI coaching run on-device. If you enable bank sync, you sign in through Plaid's interface. Vault does not see or store your bank username or password. Plaid receives the information needed to connect your institution, and transaction and balance data passes through Plaid and a relay to reach your device. The relay handles connection tokens needed for this path. Premium connected categorization can also send merchant information, transaction amount, currency, and a pseudonymous identifier for Plaid enrichment. That connection is separate from local calculations and manual tracking.
Vault also offers diagnostics that are off by default. If you opt in, they contain limited event-name counts and a hashed identifier, not account balances, amounts, merchants, categories, or coach conversations. Financial records are stored locally without automatic iCloud record sync. Exported CSV and password-encrypted backups follow the destination you choose.
Mettle and Cove
Both apps are in development. Coaching in Mettle, and reflection and search in Cove, run on the device. Their records use your private iCloud database when available, with a local fallback if that storage cannot be initialized. This is the current default, not an in-app opt-in sync switch. Optional Health access uses Apple's permission controls. Cove can index dates, summaries, and themes in Spotlight; that setting can be disabled.
Other apps in development
Mise, Trove, and Wove offer optional Plus private iCloud record sync, off by default. Trove and Wove store image files locally; complete cross-device photo sync is not being claimed. Mise recipe import fetches the page you choose and may fetch its image from a separate host. Wove can request approximate location for an Apple WeatherKit forecast, with cached or seasonal context when unavailable.
Memora, Molehill, and Kith currently have no app-managed cloud sync. Their local records can still appear on enabled system surfaces, such as widgets or Spotlight. Chosen exports, communication handoffs, and operating-system backups have their own destinations and settings. Model setup and Apple purchases may require a connection even when an app's core workflow operates offline.
Apple system services
Features you deliberately send to Apple Reminders or Calendar may sync through your iCloud settings. Apple also processes App Store downloads, subscription verification, and purchases. Those services are governed by your Apple account settings and Apple's privacy terms.
4. App diagnostics
Our applications do not include third-party behavioral analytics SDKs. Where an app offers first-party diagnostics, as Vault does, the control is off by default and the app explains what is included before you enable it. App diagnostics are separate from the public website measurement described in section 5.
5. Public website traffic measurement
The public Obsidian Ridge Labs website is not an account product and does not receive content stored in our apps. Recordings, transcripts, finances, journals, tasks, and similar in-app material are not sent to this website or to Google Analytics.
To measure how the website itself is used in the aggregate, we load Google Tag Manager (container ID GTM-PGQDN8FM), which loads Google Analytics 4 (measurement ID G-FNL2K6W19T). These services are provided by Google LLC. We use them solely to produce aggregated website statistics, such as approximate counts of visits and page views, which pages are requested, coarse geographic region, referring site or campaign, and general device or browser category.
We do not use Google Tag Manager or Google Analytics to identify you by name, email address, or account; to create a marketing, remarketing, or advertising profile; to measure or target ads on other sites or apps; to combine website traffic with app content; or to sell personal information. We do not share website analytics for cross-context behavioral advertising. We do not assign a Google Analytics user ID, do not enable Google Signals or Google's advertising features for this property, and do not authorize Google to use this property's Analytics data for Google's advertising products.
Google may process technical information that is necessary to generate those aggregate reports. That information can include the pages requested and related timestamps, a cookie or similar client identifier used to distinguish sessions for counting, the referring URL, user-agent or device characteristics, and Internet Protocol address information that Google uses to estimate approximate location. We review Analytics in aggregated form. We do not attempt to re-identify a visitor from those reports, and we do not collect additional personal information through the website for analytics purposes.
Independently of Google Analytics, the service that hosts this website may process ordinary request logs required to deliver pages securely and reliably. Hosting logs do not include content stored inside our apps.
You can limit or delete cookies and similar storage in your browser settings. Google also provides a Google Analytics opt-out browser add-on. Google's processing of information is further described in the Google Privacy Policy, how Google uses information from sites that use Google services, and Google's commitments for Google products. Questions about our use of these tools can be sent to the contact address in section 11.
6. Purchases
Purchases and subscriptions are processed through Apple's StoreKit and the App Store. Apple handles your payment credentials and billing relationship. Our apps receive the transaction or receipt information needed to verify a purchase and unlock the relevant features; Obsidian Ridge Labs does not receive your full payment-card number or billing address from Apple.
7. Security
Local content benefits from Apple's app sandbox, device passcode protections, and the security controls available on your device. Individual apps may add Face ID access or feature-specific encryption. Encryption details are stated per product rather than as a blanket claim across every kind of data.
No device, network, or storage system is immune to every risk. Keep your operating system current, use a strong device passcode, and review optional sync settings in the relevant app.
8. Your controls and deletion
You can delete local content from the app or remove the app from your device. Where offered, you can turn off diagnostics, disable iCloud sync, or disconnect a Plaid-linked bank. Product help guides explain the controls available in each app. Website traffic measurement is described in section 5, including browser cookie controls and Google's Analytics opt-out add-on.
Removing an app does not automatically delete information already managed by a service you enabled, such as iCloud, Plaid, or the App Store. Use the controls provided by that service where applicable.
9. Children's privacy
Our products are not directed to children under 13, and we do not knowingly request personal information from children through our apps. If you believe a child has provided information to us through a support interaction, contact us so we can review the request.
10. Policy changes
We may update this policy as products and optional services change. The effective date at the top of this page identifies the current version. Material product-specific changes will also be reflected in the relevant product documentation.
11. Contact
Questions about this policy or a product's data handling can be sent to support@obsidianridgelabs.com. Because app content is generally stored on your device rather than in an Obsidian Ridge Labs account, we may not possess a copy that we can retrieve for you.