Legal
Privacy Policy
Last updated: July 11, 2026
The search index lives inside your vault and never leaves your machine through us. What happens to a chat message depends on how you run it: with your own key, Claude Code CLI, or a self-hosted endpoint, the request goes directly to your provider and we're not involved. On the paid subscription, your prompt and the relevant note excerpts are proxied through our backend to the AI provider — and, on that path, they are stored and logged.
1. Who we are
ZettelkastenAI ("we", "us") makes an Obsidian plugin that lets you chat with your vault, and operates the website zettelkasten-ai.com. For anything privacy-related, contact us at tarasov.slavas2002@gmail.com.
2. Your notes and vault content
This is the part that matters most, so it comes first.
- Indexing and retrieval run locally inside Obsidian. The search index is stored in your vault's plugin folder and never leaves your machine through us.
- Chat history is stored locally on your device only.
- When you send a message, the plugin gathers the relevant note excerpts and your prompt. How they reach the AI model depends on which plan you use — see below.
Where that request goes depends on your choice in the plugin:
- Paid subscription: your prompt and note excerpts are sent to our backend, which forwards (proxies) them to Z.ai (GLM models) under our account and returns the answer. On this path we store and log the request and response content — including your prompt and note excerpts — to operate the service, route between models, enforce quota, prevent abuse, and support and debug the product. Z.ai processes the forwarded request under Z.ai's privacy terms.
- Claude Code CLI: requests go through the official Claude CLI on your machine directly to Anthropic, under your own Anthropic account and Anthropic's privacy policy. They do not pass through our backend.
- Your own key / self-hosted: requests go directly to whatever endpoint you configured (e.g. a local Ollama server never leaves your machine at all). They do not pass through our backend, and we are not involved.
In short: the paid subscription is the only path where your prompt and note excerpts pass through — and are stored on — our servers. Every other way of running the plugin keeps that traffic between your machine and the provider you chose.
3. What we do collect
- Whitelist signups: your email address, the signup time, and your IP address (kept for abuse prevention and rate-limiting).
- Accounts: your email address and short-lived verification codes used for sign-in.
- Usage counters: message and token counts per account, used to enforce plan limits and detect abuse.
- Subscription request content: for messages you send on the paid subscription, we store and log the request and response — your prompt, the note excerpts included with it, and the model's answer — as described in section 2. This does not apply to the free tier, Claude Code CLI, or your-own-key/self-hosted usage, which never reach our backend.
- Payments: handled by our payment processor. We receive your subscription status, never your card details.
4. What we don't do
- No analytics scripts, ad trackers, or third-party cookies on this website.
- No selling or renting of personal data — to anyone, ever.
- No use of your stored prompts or note content to train our own AI models.
- No collection of note content on the free tier, Claude Code CLI, or your-own-key/self-hosted usage — that traffic never reaches our backend.
5. How long we keep data
- Whitelist emails: until launch outreach is done or you ask us to remove yours.
- Account data and usage counters: while your account exists, plus what bookkeeping and tax law require for billing records.
- Subscription request content and logs (prompts, note excerpts, responses): retained only as long as needed for the purposes in section 2 — operating the service, abuse prevention, and support/debugging — after which it is deleted. You can ask us to delete yours at any time.
- Everything local (index, chat history, settings): under your control — delete the plugin folder and it's gone.
6. Your rights
You can ask us at any time to access, correct, export, or delete the personal data we hold about you (in practice: your email, usage counters, and — for subscription users — the stored request content described in section 2). If you're in the EU/EEA, UK, or a jurisdiction with similar data-protection laws, these are your statutory rights and we honor them regardless of where you live. One email to tarasov.slavas2002@gmail.com is enough.
7. Security
Sign-in uses short-lived verification codes and signed tokens, and all traffic to our backend is encrypted with TLS. On the free tier, Claude Code CLI, and your-own-key/self-hosted usage, your note content is protected by the strongest measure available: we never receive it. On the paid subscription, where your prompt and note excerpts do pass through and are stored on our backend, we restrict access to that data and retain it only as described above.
8. Children
Our services are not directed at children under 16, and we do not knowingly collect their data.
9. Changes to this policy
If we change this policy in a way that matters, we'll update the date at the top and, for material changes affecting subscribers, notify you by email before they take effect.