Privacy policy
This policy covers this website and the AXXA Agent plugin for Obsidian, both made by AXXA Lab™. In short: we don’t collect your data. The website sets no cookies and runs no analytics, and the plugin has no telemetry.
01Who is responsible
AXXA Lab™, the developer of AXXA Agent, based in Brazil, is the data controller for this website. Write to contato@axxalab.com.br for any privacy question. That address is the privacy channel; as a small processing agent, AXXA Lab™ has not appointed a data protection officer (ANPD Resolution 2/2022, art. 11).
02This website
- It is a static site. It has no forms, no accounts, no cookies, no analytics and no advertising.
- Everything it shows (text, fonts, styles, images) is served from this domain. It loads no third-party fonts, scripts or trackers.
- The site is hosted on GitHub Pages, and Cloudflare answers the DNS lookups for its domain. Like any web server, GitHub receives the technical data your browser sends to load a page (such as your IP address and browser type) and may keep it in logs for security and to deliver the site. That processing is governed by the GitHub General Privacy Statement, and DNS by the Cloudflare Privacy Policy. We don’t use those logs. The legal basis is legitimate interest in keeping the site available and secure (LGPD art. 7, IX).
03The AXXA Agent plugin
- The plugin runs on your device, inside Obsidian. It has no telemetry and sends nothing to us.
- When you use an AI provider (OpenAI, Anthropic, Google Gemini, OpenRouter, NVIDIA NIM, ElevenLabs, or your own Ollama server), your device sends your messages, attachments and the note excerpts the plugin uses directly to that provider, with the API key you configured. Each provider handles that data under its own terms and privacy policy.
- In Vault Q&A and Agent conversations, a per-chat switch starts on: excerpts of the notes that match your message are sent with it to the chat provider. In Chat it starts off.
- Answers are shown as Markdown, so an image link inside an answer is loaded from wherever it points, and that server sees your IP address. Web pages are fetched only when you ask.
- Your API keys are stored on your device, in your operating system’s keychain through Obsidian’s secret storage.
- Chats, the Vault Q&A index, skills and reports are saved as files in your vault.
- The full list of what the plugin sends, and to whom, is in the Disclosures section of its README.
04GitHub and the Obsidian directory
If you open an issue, start a discussion or install the plugin from the Obsidian community directory, those services handle your data under their own policies (GitHub, Obsidian).
05Your rights
Under Brazil’s General Data Protection Law (LGPD) and similar laws, you can ask whether we hold data about you, and ask for access, correction or deletion. Because neither this website nor the plugin sends personal data to us, we normally hold none. If you contact us, we use your message only to answer it (legal basis: LGPD art. 7, IX) and delete it when the conversation is no longer needed. You can also file a complaint with Brazil’s data protection authority (ANPD).
06Changes
If this policy changes, the new version will be posted on this page with a new date. If a paid option is added in the future, this page will be updated before it launches, to explain what the payment provider processes.
07Contact
Email contato@axxalab.com.br. You can also write in GitHub Discussions, or report a security problem privately through GitHub’s private reporting.