Privacy, permissions, and AI boundaries
Hjarni is the knowledge base. ChatGPT, Claude, and other clients only get access when you connect them. This page explains what is stored where, what a connection allows, and what the boundaries are.
Who does what
Stores notes, containers, tags, links, files, versions, and AI instructions.
Act as clients that read and write through MCP after you connect them.
Choose what gets saved, which assistant gets connected, and when access is revoked.
A connected assistant is not your permanent memory by itself. If you want something to be available later, save it to Hjarni.
Connections and tokens
- OAuth connections create a revocable MCP session tied to your Hjarni account. These reach everything the account can reach; an MCP session cannot currently be limited to one folder.
- Manual API tokens default to full account access, but you can limit one when you create it: to a single folder and everything nested under it, to all of your personal notes, or to a team folder. Choose it under Limit to in Settings > Connections.
- Scoping controls which notes and folders a token can reach through the REST API. It does not make the token read-only: inside its scope it can still create, update, and delete.
- You can review and revoke tokens or MCP sessions from Settings > Connections.
- Revoking a token immediately breaks access for the app or client using it.
What a connected assistant can do
Can do
- Read notes, containers, tags, and AI instructions in the spaces you can access.
- Create and update notes, tags, links, and containers through MCP.
- Use team spaces you belong to and shared containers you can access.
- Follow instruction inheritance when a container or team has AI rules.
Cannot do
- Access Hjarni before you connect it.
- Bypass Hjarni ownership or sharing rules.
- Read personal or team spaces that your account itself cannot access.
- Keep memory outside what you save in notes or instructions.
Some clients may ask for confirmation before destructive actions, but the real enforcement boundary is still Hjarni's permissions model.
Teams and shared spaces
Personal and team spaces are separate
A team has its own notes, containers, tags, and team instructions. Your personal brain remains separate.
Shared containers have narrower permissions
Collaborators can work inside shared containers, but some owner-only actions remain restricted, including modifying the shared container itself.
Instructions still apply
If a team or container has AI instructions, connected assistants receive them and are expected to follow them.
Public folder links
A public folder link is a different sharing mode. Anyone with the URL can read the folder and the notes inside. No login. No Hjarni account.
Visitors only see what's inside that one folder. Your other folders, your account, your edit history, and your AI instructions stay private. Disable the link from Edit folder > Public Link to revoke access. Re-enabling generates a fresh URL, never the old one.
For details, see Share a folder publicly.
Exports, deletion, and portability
You can export your knowledge base as a ZIP of Markdown files with the folder structure preserved. Attachments are included alongside their notes.
Archived notes can be restored. Deleted notes go to Trash and stay recoverable for 30 days; restore one any time before then, after which it is permanently removed. If you revoke a token or disconnect an MCP client, it no longer has access.
For the exact export behavior, see Export and data ownership. For the legal privacy policy, see Privacy Policy.
Account security
Your account can ask for a second factor at sign-in: a six-digit code from an authenticator app such as 1Password, Google Authenticator or Authy, on top of your password or your Google, Apple or GitHub sign-in. It is optional and off by default.
Turn it on under Settings > Two-factor authentication > Enable. Scan the QR code with your app, enter the code it shows, and save the ten recovery codes you are given. Each recovery code signs you in once if you lose your phone; you can generate a new set from Settings at any time, and turning two-factor authentication off deletes them.
For setup, recovery codes and what to do if you lose your phone, see Two-factor authentication.
You can also add a passkey and sign in with Face ID, Touch ID, a fingerprint or your device PIN instead of a password. A passkey only works on hjarni.com and counts as both factors, so it does not ask for a two-factor code. Add or remove one under Settings > Passkeys; Hjarni emails you either way. See Passkeys.
Two-factor authentication protects the sign-in to hjarni.com and the mobile apps. API tokens and MCP connections are separate credentials with their own lifecycle: they keep working while it is on, and you revoke them from Settings > Connections.
Related docs
Questions about privacy or permissions?
Email evert@hjarni.com
Give your AI a memory. Free.
Connect Claude or ChatGPT to notes they can actually read and write.
Give your AI a memory. Free.