Obsidian Second Brain
Terms and product disclosure
What gets installed on your computer, what leaves it, and what your licence covers.
Version obsidian-mac-2026-08-11
The short version
- This is a one-time purchase covering up to 3 computers. Activating a computer registers it against that limit; re-running the installer on the same computer reuses its existing slot, and if you hit the limit the error points you at the recovery page where you can free one.
- Everything the product captures — your Claude Code and Codex conversations, session notes and memory files — is written to a folder on your own computer. None of it is uploaded to us.
- Two things do leave your computer. Activation sends your license token, a device fingerprint, this Mac's hostname and its OS version to our activation server. Separately, once a day at most, the product asks https://obsidian-setup.fly.dev/version whether a newer version has been published — that request carries only a fixed product-and-platform query, no license token and nothing identifying your machine. It never downloads anything, and an unreachable server is treated as no update at all.
- Captured text is scanned for known secret and personal-data shapes (API-style keys, credential-style key=value pairs, email, phone, SSN, card numbers) and matches are replaced before writing. That is pattern matching against known shapes, not a guarantee every secret is caught — and some fields are written as-is, including the session-end note and Codex note metadata such as absolute file paths, which can contain your Mac username.
- A separate lane mirrors your per-project Claude memory files into the vault byte-for-byte with no masking, on its own hourly schedule, whether or not capture is switched on. Replaced copies are snapshotted and kept at least 90 days. The product reads Anthropic's source memory files but never modifies them.
- The installer sets up Obsidian, a vault folder, and background helpers that run on your computer, and may download one Obsidian plugin (Auto Note Mover) from GitHub while it does. You can remove all of it; the notes it has written stay yours either way.
- After the installer finishes it hands you a prompt to paste into Claude Code or Codex CLI, and that assistant completes the setup. What that assistant does on your computer is governed by your own approvals in that tool.
The full version
Below is the disclosure exactly as your installer will show it, word for word — quoted rather than rewritten, so what you agree to here and what your Mac shows you are the same text. It is written for somebody already running the installer, which is why it opens by asking about capture and closes by naming an example vault folder.
Before you decide whether to enable capture, read this disclosure in full: One fact first: this version has four capture lanes. Three share one on/off switch (capture_enabled): Claude Code sessions from ~/.claude/projects, Codex CLI sessions from ~/.codex/sessions/**/rollout-*.jsonl, and a short note (date, project name, machine name, agent, tags, duration, working directory, up to 20 changed filenames) written to /Users/Example/ObsidianVault/Sessions/ when each Claude Code session ends. Claude Code markdown goes to /Users/Example/ObsidianVault/conversations/; Codex markdown, including this conversation, goes to /Users/Example/ObsidianVault/conversations/Codex/. Captured text and command input/output are checked against a fixed set of patterns (AWS and other vendor API-style keys, credential-style key=value pairs, email, phone, SSN, 16-digit card numbers) and matches are replaced before writing; this is pattern matching against known shapes, not a guarantee every secret is caught. Codex notes include command output; Claude Code notes omit it. Codex note metadata -- its session ID, timestamps, machine name, and the source file's absolute path -- is written as-is and is not covered by this masking; an absolute path can include your Mac username. The session-end note above is NOT masked; its fields are written as-is. A fourth lane, not covered by the capture_enabled switch, mirrors your per-project Claude memory files from ~/.claude/projects/*/memory/* into /Users/Example/ObsidianVault/ClaudeMemory/<this Mac's name>/<project name>/, copied byte-for-byte with no masking. It runs on its own hourly schedule regardless of that switch. When a mirrored memory file changes or is removed at the source, its previous vault copy is written to that project's _snapshots folder with a timestamped filename before the live mirror is updated or removed. It is kept at least 90 days, then pruned on a later sync. The product reads Anthropic's source memory files but never modifies them. - For automatic tagging, the installed default checks a literal loopback Ollama endpoint. When local Ollama is present, tagging is processed by Ollama on this Mac; configured Ollama and embedding URLs outside literal loopback are refused before a request and the product uses its visible local fallback instead. This is the only ongoing network activity the capture engine itself makes. - Separately, this installer program (not the capture engine) contacts two destinations of its own. It sends your license token, a device fingerprint, this Mac's hostname, and its OS version to our activation server -- once per attempt, so a failed and retried activation sends it again. It also may download the Auto Note Mover plugin from GitHub during the post-install steps above; that download is skipped if a valid copy is already present, and is not guaranteed to succeed. Activation registers this Mac against your license's 3-machine limit. Re-running on this same Mac reuses its fingerprint-based slot. If the limit is reached, the activation error shows the recovery page where you can free a slot. Once a day at most, this product checks https://obsidian-setup.fly.dev/version?product=obsidian-second-brain&os=mac for the latest published version. It sends only that fixed product/os query -- no license token, no machine identity. The response is a version number and a release date, nothing else: it never returns or redirects to a URL, and this product never downloads anything from it. If you're told about an update, it always points you to the same fixed page, https://dontsleeponai.com/obsidian-claude-code, never anywhere the server names. A slow, unreachable, or erroring server is treated as "no update" and never delays or affects capture. Selected vault: /Users/Example/ObsidianVault
Questions before you buy? Email support@dontsleeponai.com. The site's general terms, privacy policy and refund policy apply to this purchase as well.