Security and privacy
What is private by default, what a token can do, and what publishing actually means.
Contextaco holds working notes, which are often the most sensitive thing a team writes down — the decisions, the constraints, the things that did not work. This page states plainly what is protected and what is not.
Private by default
Everything you create is private. Publishing is a deliberate act, never a side effect of writing, sharing a link, or connecting a new agent.
A private taco returns not found to anyone else — not forbidden. Saying “this exists but you may not see it” is itself a disclosure, so the answer to someone not entitled to know is the same answer they would get for something that never existed.
What a published taco means
Anyone can read it and fork it, with no account. Treat it as irreversible in practice: a fork someone else made is theirs, and it stays theirs if you later make yours private again.
Connecting: two paths, and one is better
Your client registers itself, sends you through a sign-in, and you approve the connection once. Nothing is copied anywhere — there is no key to paste, lose, or leak into a shell history. Use this whenever the client supports it.
For CI, a headless machine, or a client with no connector support. A token is shown once, when created; if you lose it, revoke it and make another. There is no way to read it back, which is the property that makes revoking it meaningful.
What a token can and cannot do
A token acts as you. Be deliberate about which agent gets one.
| It can | It cannot |
|---|---|
| Read everything you own, including private work | Create or revoke credentials — that happens on the web only |
| Write, edit and delete notes | Delete a taco. It can only hand you a link; you finish it in the browser |
| Attach and delete files | Set or change your handle, which is chosen once, by you |
| Fork, and change a taco’s visibility — including making a private one public | Read anything you cannot read yourself |
| Act after you revoke it |
One token per agent. That is the whole point: it lets you cut off a single machine without disturbing anything else. A shared token turns every revocation into an outage.
History, deletion and what survives
- Deleting a note deletes it, along with every checkpoint version of it. There is no undo. That is a change from how this used to work: a checkpointed note was previously hidden rather than removed, which made the record tamper-evident but meant nothing could ever be taken back — on a product that meters and bills storage. What makes the record trustworthy is that a delete is explicit, per-note, and yours; not that removal is impossible.
- Files follow the same rule, and it matters more for them: deleting a file gives back its bytes, including when a checkpoint had frozen it. Deleting a note gives back its body and every checkpoint version of it too — just far fewer bytes, because text is cheap. What frees nothing is shortening a note: the longer version stays in the checkpoint that recorded it. If your storage is tight, files are where to look first.
- A whole taco can only be deleted by you, in the browser. It is the one action an agent cannot take — deleting a taco removes its notes, its files, its types and all of their checkpointed history at once, and there is no undo. An agent asked to clean up hands you a link to the taco’s page; you confirm there by typing its name.
- Deleting a file that a note still shows is refused, and the refusal names the notes, so you are never one command away from leaving a body pointing at nothing.
Where the data lives
Contextaco stores and serves. It makes no model calls of its own — your agent does the reasoning, so your content is not sent to a model by us as a side effect of being stored.
Full detail, including the operating entity and how to reach us: