Privacy Policy
Effective 1 August 2026.
calmcontacts keeps your Obsidian vault on our servers and mirrors it to a GitHub repository you own. This policy explains what we collect, how we use it, and the control you have — consistent with the Australian Privacy Act 1988 (Cth). By using the service you agree to the handling of information described here.
What we store
- Your email address — used to sign you in (a one-time code is emailed to you; there is no password).
- Your vault — the notes and files you sync from Obsidian, plus any contacts and journal entries you add. These are stored on our servers so they are available across your devices and can be mirrored to GitHub.
- Your GitHub connection — if you enable backup, we store only the GitHub App installation identifier for the repository you chose. We never store a GitHub password or personal access token; we mint short-lived, repository-scoped tokens as needed to write to your repo.
- Device sync passwords — the WebDAV passwords you create for Obsidian are stored only as salted one-way hashes (bcrypt). We cannot recover them; you can revoke any of them at any time.
- Session data — an authentication token (held in an HttpOnly cookie for the web app) that keeps you logged in.
- Log data — standard technical logs such as IP address, request time, and error diagnostics. Verification codes and credentials are never written to logs.
How your data moves
- Obsidian talks to our server over WebDAV, authenticated with a device password, over HTTPS only.
- When GitHub backup is enabled, your vault is committed to your own GitHub repository. From that point GitHub also holds a copy, under your GitHub account and GitHub's terms — you control and can delete that repository.
- Each user's vault is isolated; one account cannot access another's files.
- All traffic is encrypted in transit (HTTPS/TLS).
Third parties
We keep third parties to the minimum needed to run the service:
- Linode (Akamai), our cloud host, where the service and your vault are stored. Data may be hosted in the United States and other countries.
- SendGrid, to deliver your login codes and occasional notification emails.
- GitHub, only if you enable backup, and only for the repository you choose.
These providers process data on our behalf and, to the extent permitted by law, are obligated not to use it for any other purpose.
Your control
- Export your contacts anytime as CSV; your vault is plain markdown you already hold in Obsidian and (if enabled) in your GitHub repo.
- Disconnect GitHub to remove the stored installation link (also uninstall the app on GitHub to complete revocation).
- Revoke device passwords individually.
- Wipe all your data — this also deletes your GitHub connection, your device passwords, and your server-side vault.
- Delete your account entirely.
Retention and deletion
Deleted content is removed from your active data immediately and may persist in encrypted backups for up to 30 days for disaster recovery, after which it ages out. Deleting your account removes your records from the active system on the same basis.
Security
We protect your data with HTTPS/TLS in transit, hashed device credentials, and per-user access isolation, and we deliberately avoid storing long-lived third-party credentials (there is no GitHub token at rest). No system is perfectly secure, and we cannot guarantee absolute security.
Children's privacy
The service is not directed to anyone under 13, and we do not knowingly collect their personal information.
Access
You may request access to the personal information we hold about you at any time, by using our contact details below. We will promptly acknowledge your request for access and let you know when we will provide you with the requested information. If we refuse access, we will provide you with a written notice which sets out (unless the law allows us not to specify a reason) the reasons for the refusal and how you can complain about our refusal. We may recover our reasonable costs for giving access to your personal information.
Correction
We seek to ensure that the personal information we hold is accurate, up-to-date, complete and, in the case of use and disclosure, relevant.
Where we believe that the information we hold is inaccurate, out-of-date, incomplete, irrelevant or misleading, we will take reasonable steps to correct that information and (if you ask and it is reasonable and practicable for us to do so) to notify that correction to third parties that may have received the incorrect information from us. If you believe that information we hold about you should be corrected, you may also request that we do so, by using our contact details below.
If we do not agree with the corrections you have requested, we are not obliged to alter your personal information. Instead, we will give you a written notice which sets out (unless the law allows us not to specify a reason) the reasons for our refusal and how you can complain about our refusal. You can also ask us to associate a statement with the relevant information that puts your view that it is inaccurate, out-of-date, incomplete, irrelevant or misleading. We will not charge you for making a correction request, for correcting your information or for associating a statement with your information.
Enquiries and complaints
If you have any enquiries, concerns or complaints about this privacy policy, our handling of your personal information or our compliance with the Australian Privacy Act 1988 (Cth) or any related codes, please contact us at admin@calmcontacts.com.
We usually respond in writing within 30 days, unless we need further information to respond to your enquiry, concern or complaint.
If you would like to make an enquiry or complaint about how we handle your personal information, you can also contact the Office of the Australian Information Commissioner on 1300 363 992 or via email at enquiries@oaic.gov.au.
Changes
We regularly review this policy and may make changes to it from time to time, without notice to you. An up-to-date copy is always posted on this page.
This policy is effective as of 1 August 2026 and was last amended on 14 August 2026.
Contact
Questions? Email admin@calmcontacts.com.