Cloud boundary
Public integrations operate on cloud-backed data. They do not turn device-only state into hosted state.
| Data or behavior | Integration boundary |
|---|---|
| Free personal data stored only on a device | Not visible to REST, MCP, Event Log, or webhooks |
| Cloud-backed Tasks and Lists | Visible only when the exact connection, scope, ownership, membership, and entitlement checks pass |
| Shared Lists | Hosted by the owner’s entitlement; membership does not grant the owner’s historical event stream |
| Attachment metadata | Available only through an authorized generated operation |
| Attachment bytes | Delegated with signed URLs when supported; never assumed to flow through MCP or REST |
| Local reminders and notifications | Remain device behavior unless a generated hosted operation says otherwise |
| Geofence monitoring | Remains device behavior |
Event snapshots are deliberately thin. They exclude Notes, comment bodies, attachment filenames and storage keys, collaborator identity and email, precise location details, OAuth material, and mutation actor or source attribution.