Security and your notes
What Antescript keeps and where, and what decides who may open a page, read a file or act through a token. This is how the product works today, stated plainly.
Where your data lives
What you keep in Antescript, and where each part of it is held:
- Your account
- The name, email address and picture Google’s sign-in gives Antescript, and your sessions. Antescript never sees your Google password.
- Your pages
- Each page’s content and its snapshots, in a room of its own; the page tree, who may see what, comments, and a plain-text copy of each page for search and previews, in Antescript’s database.
- Your files
- Images and attachments, in private storage under a random name.
- Payments
- Taken on Stripe’s checkout page, if you pay for a plan. Stripe holds your card details; Antescript never sees or stores a card number.
- Invitations, shares, notices and receipts go out through a mail delivery service, which sees the address and the message, and tracks neither opens nor clicks.
- Agents
- If you connect an agent through the MCP server, you sign in with Antescript and MCPCloud keeps the access you grant, using it only to make the calls you allowed; the agent never holds it.
No data is sold, and none is used to train anything. There is no advertising, no analytics and no tracking pixel; the cookies are a session for sign-in and two preferences, your theme and whether the sidebar is open. The privacy page says what is stored and for how long.
Who can open a page
- The workspace’s members, by their role: the owner, editors who write and viewers who read.
- Anyone you share one page with by address, to edit it or only to view it. They get that page and nothing else.
- Nobody else, in a private group. Its pages are seen by the person who made it and by whoever they share a page with, and by no one else, the workspace’s owner included. A private page can’t be published.
A workspace’s owner also decides who may invite people, who may share pages by address, and whether agents may read and write there, only read, or nothing.
How that is enforced
- Each page’s content lives in a room of its own. The room lets a browser in only with a short-lived token signed for that page, that person and their role, and checks it before the connection opens.
- A viewer’s changes are dropped by the room, not just disabled in the browser, so read-only holds on the server.
- The room refuses writes once a token lapses. Removing someone, changing their role, revoking a share, trashing a page or making it private closes their open connections at once.
- Every list, the sidebar, search, Recent, Favorites, the comments inbox and the API alike, leaves out what you can’t open.
- Other sites can’t put the app in a frame, so nobody can be led to click through it unseen.
Files
Images and attachments are stored under a random name, and a page links to them only through Antescript. Each read is checked against the page and answered with a signed address that lasts an hour, so a file is served only to someone who can open its page, or to anyone while the page is published. An upload is signed only for someone who may add a file to that page, and counted at the size storage reports, not the size the browser claims.
API tokens and agents
A token is shown once, when you make it; Antescript keeps only its SHA-256 hash, so it can’t be shown again or read back from storage. It reads, or reads and writes, as the person who made it, and no further. Through the MCP server you don’t make one: you sign in with Antescript and name the agent, Antescript keeps only hashes of the hour-long access and the refresh it hands MCPCloud, and the agent never sees either; the connection works as you, under the same scopes, and Disconnect under Agents ends it at once. Each call is logged with its token or connection, the call and the page, and the log is purged after 30 days. Revoke a token under Agents the moment you think it leaked. Agents has the scopes and limits.
Sign-in and sessions
Sign-in is with Google alone, so there is no Antescript password to guess or leak. Account lists every session you’re signed in with, and signs any of them out.
Reporting abuse
Every published page has Report this page at its foot, which needs no account; or write to compliance@antescript.app. Every report is read. A page that breaks the terms can be taken off the web, and an account suspended: it can’t sign in, its tokens stop working, and the pages published from its workspaces come down.
Keeping, exporting and deleting
Export a page, or the whole workspace as markdown and files, at any time and on every plan. The trash keeps a page for 30 days; then, or when you delete it forever, the page goes with its files, snapshots and content. Snapshots thin out with age: every one for a day, hourly for a week, daily for ninety days, then monthly. Delete account, on the Account page, removes your account and the workspaces you own.
Questions about any of this go to support@antescript.app.