Privacy Policy
Last updated: April 2025
Overview
Vault Therapist is an Obsidian plugin that runs entirely on your device. It does not have its own server that reads your notes. Your privacy depends entirely on which AI provider you choose — if you use a cloud provider, your notes travel to that provider's servers under their privacy policy. If you use Ollama, nothing leaves your machine at all.
Network Requests
Vault Therapist makes two and only two categories of outbound network requests:
- Your chosen AI provider — Ollama, OpenAI, Anthropic, or OpenRouter. Note content is sent here for analysis. Which provider you use is your choice, and each has its own data handling practices.
- api.vaulttherapist.com — License key validation only. This endpoint receives your license key and device identifier. It never receives note content, file names, or vault metadata of any kind.
There are no other outbound connections — no analytics pings, no error reporting services, no telemetry.
What We Collect
Via the license validation endpoint, we store:
- License key — to verify your subscription
- Activation timestamp — when your license was first activated
- Device count — how many machines the license is active on
That is the complete list. We collect no analytics, no telemetry, no crash reports, and absolutely no note content — ever.
AI Providers & Your Data
When you use a cloud AI provider, your note content is transmitted to that provider and subject to their privacy policy. Review the policy for whichever provider you choose:
- Ollama — ollama.com. Runs entirely locally. Zero data leaves your machine.
- OpenAI — openai.com/privacy
- Anthropic — anthropic.com/privacy
- OpenRouter — openrouter.ai/privacy
If privacy is your top priority, use Ollama. It runs models locally and no data of any kind leaves your machine.
Offline Grace Window
If the license validation server is unreachable — due to network issues, downtime, or offline travel — the plugin continues to work normally for 24 hours without phoning home. After that window, validation will be reattempted on next use.
Data Deletion
To request deletion of your license record (key, activation timestamp, and device count), email support@vaulttherapist.com. We will delete your record within 30 days of the request.
Contact
Questions about this policy? Reach us at support@vaulttherapist.com.