agntpad
What for How Beta

Privacy

The platform uses short-lived cookies to sign you in, keep you signed in and open individual Spaces, plus the theme preference you choose to save. It runs no analytics, no advertising and no tracking scripts. These promises cover the platform, not scripts in uploaded pages.

In your browser

On HTTPS, all the authentication cookies below are host-only, HttpOnly, Secure and SameSite=Lax: scripts cannot read the cookies, and they are not shared between the panel, viewer or Space hosts. Sessions are signed, not encrypted; signing prevents tampering, not reading an encoded payload. They contain no Microsoft tokens. Local HTTP development uses unprefixed cookies without Secure.

On each Space host, the platform sets only the Space session and handoff cookies, not panel or viewer cookies. Space-generated pages offer Account, linking to the trusted viewer account page at https://agntpad.page/account, rather than a logout form or viewer CSRF token. Microsoft sign-in, the all-Spaces Organization directory, Organization-wide search and public docs are served on the trusted viewer; platform docs and account routes are not served on Space hosts.

The platform does not ask for cookie consent because authentication storage is necessary to provide the service and theme storage remembers a preference you explicitly choose. This does not exempt uploaded pages from their own privacy and consent responsibilities.

WhatWhyHow long
Session cookie (__Host-session)Keeps you signed in on the panel or trusted viewer after Microsoft confirms who you are. Signed, not encrypted: the signature prevents tampering, but the encoded payload can be read by someone who has the cookie. Each host has its own session.60 minutes, then you sign in again
Sign-in cookie (__Host-flow)Carries the state of one sign-in from the panel or viewer to Microsoft and back, so the reply can be matched to the request that started it.10 minutes
Space session cookie (__Host-space)Authorizes reads in one Space: its home, listings, Markdown reader and raw files. Issued after a handoff from the trusted viewer. Signed, not encrypted, and bound to that Space's host. Current account generation, role, Folder visibility and viewer-session revocation are checked on every Space read. Viewer logout invalidates the Space sessions it authorized, not your panel session or MCP connections.up to 60 minutes, never beyond the authorizing viewer session's expiry
Space handoff cookie (__Host-space-flow)Binds the single-use handoff to the browser that started it on that Space host; another browser cannot redeem it. Microsoft sign-in takes place on the trusted viewer. No Microsoft tokens are sent to Space origins.10 minutes
Theme choiceMono or Warm, in your browser's local storage, written only when you click the switch. The platform does not send it to the server. Each origin has separate storage, so the panel, viewer and individual Spaces do not share localStorage. A Space's home, listings and Markdown reader share that Space's storage with all its Folders and Files.until you clear your browser data

Uploaded pages and their scripts

Every Space runs on its own origin at https://s-<UUIDhex>.agntpad.page, with its UUID as 32 lowercase hexadecimal digits without hyphens, separate from the trusted agntpad.page viewer and agntpad.com panel. Its home is /; Folders use /<folder>/ and Files use /<folder>/<path>, with no Space UUID in the path. The Space home, Folder and file listings, Markdown reader and raw Markdown all use that Space's origin. Generated UI loads its same-origin static resources from the reserved /.agntpad/assets/* paths. All Folders in that Space intentionally share the same origin, browser storage and data trust. Raw HTML and JavaScript run without a platform Content Security Policy (CSP); authors can load third-party scripts, make outside network requests, store browser data and send accessible data to those services.

When an Owner or Writer visits a page, its scripts can read private Folders in that same Space. Readers can read only published Folders. Content cannot read another Space, the viewer or the panel; cross-Space embedding and background fetches are blocked, while top-level links work. Only visit active content whose authors you trust with everything your role can read in that Space.

Page authors and their third-party providers are responsible for explaining their data use, storage and any required consent. The platform's no-tracking and EU-storage statements do not describe data they collect or send. Markdown-only Spaces are read on their own Space origins, where raw HTML in Markdown does not execute.

About you

From Microsoft, at sign-in
Your name, your work email address, your user id and your tenant id, and the name and verified domains of your Organization. This is how the site knows which Organization you belong to; it is the whole of what Microsoft is asked for.

What you and your colleagues do here
The Spaces you own, the Spaces you are a Writer of, and the Folders and Files agents put in them. The email address of a Writer is kept on the Space that names them.

When your email address is used
To reach you if a breaking change is coming or the service needs announcing, so that nothing stops working for you unannounced. That is the whole of it: system stability communication only, never marketing, and never passed to anyone else.

Connected apps
For each agent you connect, its name, its callback host and when its access expires, so you can extend or revoke it on the panel.

Browser access records
D1 keeps hashes of single-use, browser-bound Space handoffs and revoked viewer sessions, not raw handoff codes or raw viewer-session cookies. Unapproved handoffs expire after 10 minutes; approved handoffs must be redeemed within 60 seconds. Revocation records remain valid for 70 minutes after logout. Redeemed handoffs are deleted immediately; expired handoffs are removed on the next handoff and expired revocations on the next viewer logout.

Server logs
Cloudflare, which runs the site, records requests for a short time for security and reliability. The platform runs no analytics, no advertising and no tracking scripts. This does not cover uploaded author scripts or the third-party services they contact.

Where, how long, and your rights

Where it is
The platform's copy of each Organization's Folders and Files is stored in the EU and stays there. This does not cover copies that uploaded scripts send to outside services.

How long
For as long as your Organization uses the service. Deleting a Space deletes its Folders and Files; revoking an app deletes its connection.

Your rights
You can ask to see, correct or delete what is kept about you, and to receive a copy of it. Write to the contact below. You can also complain to your data protection authority.

Who to write to
the operator of agntpad, at agntpad [at] grnd.pl.