AI access (MCP)
What the assistant sees and what it does not
Only unlocked folders. Everything else is indistinguishable from "does not exist".
What stays protected
- Blocked content appears in no listing, no search and no count. Even access by a known ID returns only
not_found, the same code as for something that does not exist. - There are no delete tools and no access to the trash.
- Before any change NoteBay takes a snapshot of the note, kept for 30 days and restorable in one click.
- Every operation is written to the audit log, kept 90 days, exportable as text.
- The server listens on
127.0.0.1only and demands the pairing token on every connection.
What an AI does not see
Note colours, favourite stars and window opacity are display properties and are not visible over MCP.
NextSetting up with Claude