Privacy, Control, Continuity
Trust
Trust starts with the Workspace boundary
People, settings, content, permissions, provider context, and billing decisions belong to a specific Workspace. Queries, jobs, downloads, exports, search, citations, meters, and assisted runs should remain tenant scoped from beginning to end.
Global platform administration and Workspace administration are separate responsibilities. Membership in one Workspace should never imply access to another.
Preserve the original
Files are intended to remain private, Note-owned original assets. Derived text, previews, titles, Tags, summaries, Briefs, and assisted artifacts may make a source easier to use, but they should not silently replace the authoritative material.
Uploaded source, HTML, SVG, archive contents, or retrieved webpage code should be treated as untrusted content rather than executable instructions. Downloads and retrieval paths require authorization.
Fail without taking the evidence with you
Capture and preservation come before optional enrichment. A failed extraction, preview, index, summary, or provider request should leave the original asset and its Note context intact.
When a safety ceiling or allowance is reached, the intended response is to pause the affected feature, explain what happened, and preserve provider-free and ordinary Workspace functions.
Make assisted use explicit
Provider transmission depends on the selected capability, Workspace policy, consent, configuration, payer route, allowance, and the operation the user requested. Not all saved content is automatically sent to a provider.
Grounded, Hybrid, and Research each have a different information boundary. Citations, source preservation, and clear distinctions between evidence and broader model knowledge make the result more inspectable.
Keep people authoritative
Suggestions can accelerate titles, Tags, placement, summaries, Briefs, rewrites, and research. Final placement, wording, sharing, and destructive action remain controlled by people. Public-sharing actions should be explicit and reversible where practical.
Continuity matters
AI entitlement or provider availability should not hold customer content hostage. Notes, Projects, Tasks, Files, Links, Drawings, search, reading, downloads, and eligible exports remain the durable foundation of the Workspace.
Practical safeguards
- Validate file type, detected content, size, page or pixel limits, batch size, and processing duration.
- Authorize every retrieval, download, export, and sharing path.
- Use bounded rates and safety ceilings for provider-funded and BYOK execution.
- Record useful operational evidence without unnecessarily logging secrets or customer content.
- Keep destructive actions explicit and preserve recovery paths where practical.
Claim boundary
This page describes product principles and implemented design boundaries. It is not a claim of a named compliance certification, guaranteed data residency, zero risk, or a service level. Any such commitment requires separate legal, technical, and operational evidence.