Product privacy policy

Effective date: 29 August 2026

Version: 1.1

This policy describes personal-information processing by the Seller identified on the product page, at checkout, on the invoice, or in the order confirmation. That Seller is the controller for processing it determines. A storefront, merchant of record, payment processor, email provider, or support provider may be a separate controller or processor under its own notice.

The Seller’s legal identity, geographic address, and privacy contact are provided on the product page, at checkout, in the order confirmation, or at the point where information is collected.

Scope

This policy covers information processed by the Seller for:

  • purchasing and delivering Lifebase;
  • issuing and administering a license, authenticating an installation, and restoring access;
  • checking entitlement and delivering an authorized release or update;
  • customer support and refund handling;
  • fraud, abuse, security, accounting, and legal compliance; and
  • product announcements or marketing when the recipient has consented or another lawful basis applies.

It does not replace the privacy notices of Obsidian, community plugins, AI providers, synchronization or backup services, Git hosts, checkout providers, or other services selected by the User.

Local vault content

Lifebase is distributed as a local file-based workspace. The Seller does not automatically receive notes, journals, tasks, attachments, profiles, or other vault contents merely because the User runs Lifebase.

The Lifebase CLI keeps the one managed vault’s absolute path in the operating system’s local configuration directory so it can return to that installation and detect when its folder is missing. It sends only the license, installation, release, and security metadata described below. It does not upload the vault path, note names, file contents, hashes derived from vault files or local baselines, local change lists, merge decisions, or AI prompts.

User Content may reach a third party when the User chooses an AI, synchronization, backup, Git, plugin, or other external service. The third party’s terms and privacy notice govern that processing.

If the User voluntarily provides a vault excerpt or file for support, the Seller will use it only for the support request and related security or legal needs. The User should remove unrelated personal and sensitive information before sending it.

Information processed

Depending on the sales and support channels, the Seller may process:

  • identity and contact information, such as name, email address, country, and organization;
  • order information, such as product edition, license tier, date, currency, price, tax, order number, and access status;
  • limited payment and fraud information made available by the checkout provider;
  • support messages, requested attachments, issue history, and resolution records;
  • records of consent to the EULA, immediate digital delivery, marketing, and policy versions; and
  • license and entitlement information, such as a license-key lookup HMAC, a separately encrypted recovery copy and final four characters of the key, license status, license tier, and authorized version range;
  • installation information, such as a randomly generated installation identifier, an optional device label, operating system, CLI version, installed Lifebase version, locale and release channel, and activation or deactivation timestamps;
  • authorized download information, such as the requested release version, artifact purpose, result, size, timestamp, and the official release archive’s SHA-256 when a user-supplied release ZIP is confirmed; and
  • technical and security information generated by the Seller-controlled sales or support surface, such as IP address, browser information, timestamps, access logs, and limited administrator audit records.

The installation identifier is generated by the CLI and is not based on a hardware serial number, advertising identifier, or a scan of the User’s files.

Full payment-card or bank credentials are generally collected by the payment provider rather than the Seller. The checkout notice controls where a provider or Seller uses a different arrangement.

The Seller processes information as necessary to:

  • perform a contract, deliver the product, maintain access, and provide requested support;
  • comply with tax, accounting, consumer, sanctions, and other legal obligations;
  • pursue legitimate interests in preventing fraud, protecting the product, securing services, handling disputes, and improving support, where those interests are not overridden by the individual’s rights; and
  • send optional marketing or use optional technologies when valid consent is required and obtained.

Consent may be withdrawn at any time for future processing. Withdrawal does not affect processing already lawfully completed.

Sharing

Information may be shared only as reasonably necessary with:

  • storefronts, merchants of record, payment and fraud-prevention providers;
  • hosting, email, download-delivery, analytics, and support providers selected by the Seller;
  • professional advisers, auditors, insurers, and prospective business successors under appropriate confidentiality obligations; and
  • courts, regulators, tax authorities, law enforcement, or other parties when disclosure is legally required or necessary to protect legal rights.

The Seller does not sell vault contents. If other personal information is sold or shared in a manner that creates a statutory opt-out right, the Seller provides the required notice and opt-out method at collection.

International transfers

Sales and support providers may process information outside the User’s country. Where law requires a transfer mechanism, the Seller or responsible provider will use an applicable adequacy decision, contractual safeguard, certification, or other lawful mechanism and make required information available.

Retention

Information is kept only as long as reasonably necessary for the purpose collected, including:

  • order, license, tax, and accounting records for the legally required period;
  • active license, entitlement, installation, and terms-acceptance records while needed to deliver the purchased access and document the applicable terms;
  • device sessions until they expire after 90 days of inactivity, are replaced, or are revoked;
  • download and installation-confirmation events for up to 180 days unless a longer period is reasonably required for an active security incident or legal obligation;
  • limited administrator audit records for up to 365 days unless a longer period is reasonably required for an active security incident or legal obligation;
  • support and dispute records while needed to resolve and document the matter;
  • security logs for a proportionate security period; and
  • marketing records until consent is withdrawn or the information is no longer needed, while retaining minimal suppression information where necessary to honor an opt-out.

When retention is no longer necessary, information is deleted, anonymized, or securely isolated as law permits.

Individual rights

Depending on applicable law, an individual may have rights to:

  • obtain information and a copy of personal information;
  • correct inaccurate information;
  • request deletion or restriction;
  • object to certain processing;
  • receive portable information;
  • withdraw consent;
  • opt out of marketing or legally defined sale or sharing; and
  • complain to a competent privacy or data-protection authority.

Requests should be sent to the privacy contact shown on the product page or order confirmation. The Seller may verify identity and may retain information where law requires or permits it.

Security

The Seller uses measures appropriate to the nature and risk of the information under its control. No storage or transmission method is completely secure. Users should not send credentials, complete vaults, or unrelated sensitive files through support channels.

Children

Lifebase is not directed to children who cannot lawfully enter into the applicable purchase. A parent or legal guardian must make and manage any permitted purchase for a minor.

Changes

The effective date and version identify this policy. Material changes apply prospectively and will be presented through the sales, account, or support channel where required. A prior policy remains available for processing governed by that version when law or the order requires it.

Contact

The controller’s legal identity, geographic address, and direct privacy contact are the details displayed on the product page, at checkout, in the order confirmation, or at the point where information is collected. Privacy requests may be sent through that contact method.