Legal
Privacy Policy
This policy describes how the Syncer Obsidian plugin (“Syncer”, “the plugin”) accesses, uses, stores, and shares user data, including Google user data.
Who we are
Syncer is open-source software maintained by Daniel Simpson. It is a local desktop plugin. There is no Syncer company backend that receives your vault or provider data.
Questions: GitHub Issues.
No Syncer servers
Syncer does not run a Syncer backend, proxy, or hosted API. OAuth and API traffic goes from your Obsidian install to the provider you connected (Google, Microsoft, Todoist, or Azure DevOps). Firefox Bookmarks sync reads a local Firefox profile on your machine and does not use a cloud account.
What is stored on your device
-
OAuth tokens and Azure DevOps personal access tokens are stored in
Obsidian plugin settings (
data.jsonin your vault’s plugin folder). - Synced item titles, links, and completion state are written into the Markdown note you configure.
- Disconnecting an integration clears that integration’s stored credentials from plugin settings.
Google user data
When you use Connect Google Tasks or Connect Gmail Starred, Syncer requests access to your Google Account and calls Google APIs from the plugin.
Google Tasks (if connected):
- Reads incomplete tasks from lists you select (identifiers, titles, status, and Google-provided links).
- Optionally writes completion or deletion back to Google Tasks when you enable those settings.
Gmail Starred (if connected):
-
Lists messages with the STARRED label and fetches
format=metadatafor the Subject and From headers only. Syncer does not request message bodies. - Optionally adds or removes the STARRED label when completion sync is enabled.
OpenID, email, and profile scopes identify which Google account is connected. Tokens are sent only to Google’s OAuth and API endpoints.
The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Other providers
If you connect Microsoft, Todoist, or Azure DevOps, Syncer reads the items needed to list references in your note (for example task titles, flagged-mail subjects, or work-item identifiers) and, where you enable it, writes completion or flag/star state back to that provider. Data stays on your device and at that provider. Syncer does not receive a copy.
Sharing
Syncer does not sell, rent, or share Google user data or other provider data with third parties. It does not use that data for advertising, analytics, or credit decisions. It does not transfer data to a Syncer server because none exists.
Telemetry and ads
Syncer does not include client-side telemetry, analytics SDKs, or ads.
In-product notice
Plugin settings also describe network use and storage. This page is the canonical Privacy Policy linked from the Google OAuth consent screen.
Last updated 14 August 2026.