Privacy & permissions
Privacy and permissions
When you use a cloud model, PeriCode sends it the content needed for your request. Your permission settings control what tools can do in your vault.
What reaches your AI provider
Your provider receives your requests, relevant conversation history, attachments and tool results. If PeriCode reads a note to answer a question, that note can be sent too. A model running on your own machine can keep these requests local. Other connections you enable may still use the network.
What is stored locally
Conversations, drafts, tool history, memory and audit records are stored locally. API keys saved in plugin settings and saved conversations are currently unencrypted. Vault sync, backups, other trusted plugins and anyone with access to these files may also have access to that data.
Research and Agent modes
- Research: read notes and navigate supported views in Obsidian. Tools that change files are unavailable.
- Agent: create, edit, move or trash notes when your permission settings allow it.
- Permission policy: PeriCode checks each tool request before running it. Depending on your settings, a request may run automatically, ask for approval or be blocked. Deleting files always needs confirmation. Lockdown asks before every tool request, including reads. Dry run mode executes no tools.
Review changes and stop requests
Revision preview lets you inspect a suggested edit before accepting it. Press Stop or Escape in chat to cancel a request. Cancellation does not undo completed actions, and an external tool already running may need to finish.
Connections you enable
Provider apps handle their own login details and may store data outside your vault. MCP servers are separate programs that can have access beyond the vault; their tool requests need approval. PeriCode cannot restrict what other Obsidian plugins or external programs do.
Read the details
Storage, network access and data removal - Security implementation and limits - Report a vulnerability