AI and MCP

MCP Security and Privacy

Remote MCP is deliberately separate from Elasticnote's normal notebook and Calendar backing storage.

Explicit scopes

Notebook permissions and Calendar permissions are independent. The user explicitly chooses which notebooks may be projected. OAuth grants separately restrict notebook access. Calendar requires calendar.read and local Calendar changes require calendar.write; a Calendar-only client does not need a notebook grant.

Temporary encrypted projections

Eligible text documents, notebook metadata and the local Calendar snapshot are encrypted at rest with an MCP-specific key. The local-first workspace remains canonical. With backing storage, Calendar remains canonical in .calendar; otherwise it remains in browser storage. MCP reads do not extend projection lifetime; only a successful Elasticnote browser synchronization does.

Provider Calendar entries are read from Elasticnote's normalized provider cache. MCP responses do not expose provider OAuth tokens, storage credentials or provider ETags used for direct provider conflict control.

Write back safety

AI-created, updated, appended, moved, renamed or deleted notebook text becomes a pending mutation. Kanban task mutations rewrite the same canonical board document through that conflict-safe path. Local Calendar create/update/delete operations also become pending mutations. An Elasticnote client validates stable identity and optimistic hashes before applying changes to canonical local storage. A mismatch becomes a conflict instead of overwriting newer work.

Calendar MCP does not directly write provider-managed Google or Microsoft events. Provider write-back, when separately enabled in the Calendar UI, remains behind the provider-specific OAuth and conflict controls.

Logs

MCP operational logs are designed to record items such as client/grant identity, tool name, status, duration and byte counts. They do not need note bodies, event descriptions or the text of search queries.

Revocation and purge

You can revoke a connected client, disable Remote MCP or purge the temporary projections from Settings. Backing-provider and Calendar-provider OAuth credentials are never shared with MCP clients.