Privacy Policy

Obsidian Tasks Sync · last updated 2026-08-26

Who this covers

Obsidian Tasks Sync ("the app") is a personal utility operated by a single individual for their own Google account. It has no other users, no customers and no operator other than that individual. This policy describes what the app does with data, so that anyone authorising it understands exactly what they are agreeing to.

What the app accesses

With the user's explicit consent, the app requests the Google OAuth scope https://www.googleapis.com/auth/tasks. This grants read and write access to the task lists and tasks in the user's Google Tasks account. Specifically, the app reads and writes:

The app requests no other scope and accesses no other Google product.

How the data is used

Solely to mirror tasks between Google Tasks and a local Obsidian vault on the user's own computer. Data is used for no other purpose: it is not analysed, profiled, used for advertising, used to train any model, or used to build any product.

Where the data is stored

On the user's own computer only. Task content is written to Markdown files inside the user's Obsidian vault. A small synchronisation snapshot is kept in the user's local state directory. The OAuth refresh token is stored in a separate local file readable only by the user's own account.

There is no server, no database and no cloud component belonging to the app. This website is static and collects nothing; it exists only because Google requires a published privacy policy for OAuth applications.

Who the data is shared with

Nobody. Data is never transmitted to any third party. The only network connection the app makes is directly to Google's own API endpoints, to fetch and update the user's tasks.

The app's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Retention and deletion

Data persists on the user's machine for as long as the user keeps their own notes. Deleting the local vault files and the state directory removes every copy. Access can be withdrawn at any time from Google Account permissions; revoking access immediately and permanently prevents further reads or writes.

Security

The refresh token is stored with file permissions restricting it to the owning user account and is never committed to version control. All communication with Google uses HTTPS.

Children

The app is a personal tool and is not directed at children.

Changes

Any change to this policy will be published on this page with an updated date above.

Contact

Questions about this policy: ты@почта