SECURITY NOTES · LAST UPDATED JULY 26, 2026

Small boundaries. Visible choices.

Framnova is designed around selected captures, explicit delivery, read-only MCP tools, and credentials that stay under your control.

Scope: this page describes the intended and currently implemented product boundaries. It is not a certification, penetration-test report, uptime promise, or guarantee that a security incident can never occur.

01

Local by default

The browser capture queue is stored in the user’s Chrome profile by default. After website access is granted, a lightweight Framnova content script can load on regular pages so the optional quick dock and explicit capture actions are available; it does not continuously scan browsing history. Chrome permissions and the dock setting can be reviewed or revoked by the user.

02

Explicit delivery boundaries

WEB AI

User-initiated attachment

The selected originals are prepared for the supported AI website the user chooses. The destination provider then controls its own processing.

LOCAL MCP

User-selected workspace

The capture set is exported locally to the folder chosen by the user; it does not require hosted Direct MCP storage.

DIRECT MCP

Explicit sync

A selected set crosses the network only when the user syncs it or separately enables automatic sync in extension settings.

AI CLIENT

Read-only retrieval

The MCP tools expose stored capture-set material for retrieval and inspection; they are not designed to control the browser or edit the source webpage.

03

Pro Token handling

The Pro Token is shown once after successful payment and is used as a Bearer credential. The billing service stores a one-way SHA-256 representation for entitlement lookup rather than the original Token. The Token itself should be stored locally in a password manager or a client’s secure secret facility.

  • Never paste a real Token into an AI conversation, issue, screenshot, or support request.
  • Never commit a Token to mcp.json, shell history, or a public repository.
  • If a Token is exposed or lost, stop using it and contact support with a checkout or receipt identifier.
04

Transport and hosted infrastructure

Direct MCP endpoints use HTTPS. Hosted service components run on Cloudflare infrastructure. These controls reduce risk in transit but do not make confidential data suitable for upload by default. Users should redact secrets and sync only what is needed.

05

Payment separation

Stripe hosts checkout and handles payment-card entry. Framnova receives billing references, subscription status, plan, and provider identifiers needed to activate and manage Pro; it does not receive or store full payment-card numbers through this flow.

06

Retention and deletion

Local captures stay in the Chrome profile or selected workspace until the user removes them. Direct MCP capture sets are stored in the Token-scoped hosted workspace needed for retrieval. A precise default hosted-retention schedule has not yet been published; do not sync material that requires a retention guarantee. The self-service deletion page authenticates with the Pro Token and deletes only the specified capture-set ID, including unfinished staging for that ID.

07

Responsible reporting

When the active security mailbox is published, reports should include the affected URL or component, reproduction steps, impact, and a safe proof of concept. Do not access other users’ material, disrupt the service, publish Tokens, or include confidential capture content.

support@framnova.example Security-contact placeholder · replace when the verified mailbox is supplied · not monitored