Security and Privacy
Understand PressedNotes permissions, Notion tokens, API keys, AI provider data, and frontend content exposure.
Screenshot placeholder: PressedNotes settings with Notion, AI, and API secrets hidden.
Access Model
Admin routes are authenticated WordPress REST routes. License actions require nonce checks and settings-management permissions. Notes use WordPress post capabilities.
External Services
Notion OAuth tokens, AI provider keys, API keys, and collaboration secrets should be treated as sensitive. AI workflows can send selected note content to the configured provider.
Public Content
Published pressed_note entries are public WordPress content. Review content before publishing or embedding it on the frontend.