# Privacy, permissions, and AI boundaries

Hjarni is the knowledge base. ChatGPT, Claude, and other clients only get access when you connect them. This page explains what is stored where, what a connection allows, and what the boundaries are.

## Who does what

Hjarni

Stores notes, containers, tags, links, files, versions, and AI instructions.

ChatGPT / Claude

Act as clients that read and write through MCP after you connect them.

You

Choose what gets saved, which assistant gets connected, and when access is revoked.

A connected assistant is not your permanent memory by itself. If you want something to be available later, save it to Hjarni.

## Connections and tokens

- OAuth connections create a revocable MCP session tied to your Hjarni account. These reach everything the account can reach; an MCP session cannot currently be limited to one folder.
- Manual API tokens default to full account access, but you can limit one when you create it: to a single folder and everything nested under it, to all of your personal notes, or to a team folder. Choose it under **Limit to** in **Settings > Connections**.
- Scoping controls which notes and folders a token can reach through the REST API. It does not make the token read-only: inside its scope it can still create, update, and delete.
- You can review and revoke tokens or MCP sessions from **Settings > Connections**.
- Revoking a token immediately breaks access for the app or client using it.

## What a connected assistant can do

### Can do

- Read notes, containers, tags, and AI instructions in the spaces you can access.
- Create and update notes, tags, links, and containers through MCP.
- Use team spaces you belong to and shared containers you can access.
- Follow instruction inheritance when a container or team has AI rules.

### Cannot do

- Access Hjarni before you connect it.
- Bypass Hjarni ownership or sharing rules.
- Read personal or team spaces that your account itself cannot access.
- Keep memory outside what you save in notes or instructions.

Some clients may ask for confirmation before destructive actions, but the real enforcement boundary is still Hjarni's permissions model.

## Teams and shared spaces

### Personal and team spaces are separate

A team has its own notes, containers, tags, and team instructions. Your personal brain remains separate.

### Shared containers have narrower permissions

Collaborators can work inside shared containers, but some owner-only actions remain restricted, including modifying the shared container itself.

### Instructions still apply

If a team or container has AI instructions, connected assistants receive them and are expected to follow them.

## Public folder links

A public folder link is a different sharing mode. Anyone with the URL can read the folder and the notes inside. No login. No Hjarni account.

Visitors only see what's inside that one folder. Your other folders, your account, your edit history, and your AI instructions stay private. Disable the link from **Edit folder > Public Link** to revoke access. Re-enabling generates a fresh URL, never the old one.

For details, see [Share a folder publicly](https://hjarni.com/docs/public-sharing).

## Exports, deletion, and portability

You can export your knowledge base as a ZIP of Markdown files with the folder structure preserved. Attachments are included alongside their notes.

Archived notes can be restored. Deleted notes go to Trash and stay recoverable for 30 days; restore one any time before then, after which it is permanently removed. If you revoke a token or disconnect an MCP client, it no longer has access.

For the exact export behavior, see [Export and data ownership](https://hjarni.com/docs/export-and-ownership). For the legal privacy policy, see [Privacy Policy](https://hjarni.com/privacy).

## Account security

Your account can ask for a second factor at sign-in: a six-digit code from an authenticator app such as 1Password, Google Authenticator or Authy, on top of your password or your Google, Apple or GitHub sign-in. It is optional and off by default.

Turn it on under **Settings > Two-factor authentication > Enable**. Scan the QR code with your app, enter the code it shows, and save the ten recovery codes you are given. Each recovery code signs you in once if you lose your phone; you can generate a new set from Settings at any time, and turning two-factor authentication off deletes them.

For setup, recovery codes and what to do if you lose your phone, see [Two-factor authentication](https://hjarni.com/docs/two-factor-authentication).

You can also add a passkey and sign in with Face ID, Touch ID, a fingerprint or your device PIN instead of a password. A passkey only works on hjarni.com and counts as both factors, so it does not ask for a two-factor code. Add or remove one under **Settings > Passkeys**; Hjarni emails you either way. See [Passkeys](https://hjarni.com/docs/passkeys).

Two-factor authentication protects the sign-in to hjarni.com and the mobile apps. API tokens and MCP connections are separate credentials with their own lifecycle: they keep working while it is on, and you revoke them from **Settings > Connections**.

## Related docs

[Use Hjarni with ChatGPT](https://hjarni.com/docs/chatgpt) | [Use Hjarni with Claude](https://hjarni.com/docs/claude) | [MCP reference](https://hjarni.com/docs/mcp) | [Export and data ownership](https://hjarni.com/docs/export-and-ownership) | [Share a folder publicly](https://hjarni.com/docs/public-sharing) | [Hjarni vs ChatGPT Projects](https://hjarni.com/compare/hjarni-vs-chatgpt-projects)

Questions about privacy or permissions?

Email [evert@hjarni.com](mailto:evert@hjarni.com)
