Your file · Your assistant

Your assistant,
reading your file.

NOTANOTR is an iPhone app. Almost nobody runs Claude or ChatGPT on a phone. They run them on a laptop, at a desk. So connecting the two is one code: made in the app, typed on the computer. Nothing to carry between devices except eight characters you can read out loud.

01 · Three steps

  1. 01Make a code in the app. On your phone: You, then Claude & ChatGPT, then New code. Face ID confirms it is you. Name it “My assistant”, or your coach’s name. Choose whether it may only look or may also propose changes, and how long it lasts: a day, a month, three months, or until you revoke it.The code is eight characters, shown once, and stored only as a hash. If it is lost, revoke it and make another.
  2. 02Add the address to your assistant. In Claude or ChatGPT, add NOTANOTR as a connector and give it the address below. Nothing else goes in that dialog: the address is the same for everybody and carries no code. Where each of them keeps that dialog is under the address.A credential in a URL ends up in a browser history, a referrer header and a proxy log, so ours is never in one.
  3. 03Type the code on the page that opens. Your assistant opens a NOTANOTR page. It asks for one thing, your code, and then it is done. There is no sign-in, no password and no list of checkboxes, because you already answered that question in the app.Capitals do not matter and the hyphen is optional.

The address

https://mcp.notanotr.com/mcp/v1

This address changes if the relay moves to a domain of its own, and the Codes screen in the app always shows the one that works today.

  • Claude. On the web or in the desktop app: Customize, then Connectors, then Add custom connector. Or let this link open the dialog with the name and the address filled in. The Claude page has the rest: the way in from the app and from Claude's directory, what Claude may and may not do, and prompts to start with.
  • ChatGPT. On the web, on a paid plan, with developer mode. In Settings, open Security and login and switch Developer mode on. Then open Plugins, click +, then Create MCP App: name it NOTANOTR, paste the address as the connection, choose OAuth, and create it. The NOTANOTR page opens for the code. In a chat, add NOTANOTR from the tools menu. ChatGPT asks before it sends a proposal, and the proposal still waits in the app.
Customize, Connectors, Add custom connector.
Customize, Connectors, Add custom connector.
Settings, Security and login, Developer mode. Then Plugins, +, Create MCP App.

02 · What it can read

A code carries what you chose when you made it, and never more. The page your assistant opens cannot widen it and neither can the assistant. The code’s row in the app always shows what it carries.

For the first seven days of your account a code works without a membership, so you can set up. After that it works while your membership is active, and a call without one is refused with a line that says so.

  • Your numbers. The plan, the trend, the measured maintenance, how consistent you have been, where your lifts stand.
  • Your rows. Weigh-ins, food, training sessions and sets, habits, tape measurements.
  • Three more, only if you switch them on. Blood work, protocol and check-in photos are off on every code. You switch each one on by itself, for one code, when you make it. A code made without them never gains them afterwards.
  • Blood work. Every lab result and vital reading as logged, with dates and units.
  • Protocol. Compounds, doses and injection sites exactly as logged. No advice travels with them.
  • Check-in photos. Dates and angles and a count. Never the photos themselves, never the notes.
  • Never, whatever you switch on. Your conversations with the coach are never readable, by anything.

03 · What it can propose

If you chose look and propose changes, the assistant can also send proposals: a whole program with its schedule, a meal plan for training and rest days, your calorie and macro targets, one change to an exercise, or a note.

It cannot change anything. A proposal waits in the app, on Today under Review, with who asked and why. You read it and tap Apply, or you do not, and until you do, nothing in your file has moved. Nothing can log food, a weigh-in or a dose, or touch blood work, photographs or your profile, and nothing is going to: those are the things the app checks against your own words, and an outside assistant has none of that to check against.

04 · Taking it back

One code per assistant, so you can end one without touching the others. The Codes screen lists every code you have made, what it may do, when it runs out and when it was last used. A code that has been out for a month and never touched is one to revoke.

Revoke is one tap, and it says the honest thing rather than the comfortable one: it stops the next read, and it cannot un-read what has already been read. A code you revoke also ends whatever was connected with it, on that connection’s next call rather than whenever its session would have run out. Revoking a code revokes everything it carried, including anything you switched on for it.

The same screen keeps a log of what was read and when, and which of the three items a read used when it used one. What it said is not recorded, here or anywhere.

05 · Giving a coach access

The same code, named for them. Make one called “My coach”, choose whether they may only look or may also propose, choose how long, and give them the eight characters. They add the address to their own assistant and type the code when the page asks for it: exactly the three steps above, done by somebody who is not you.

They never sign in to anything of yours, they never see your email, and what they can read is what you chose. You end it the same way you end any other code.

06 · What this changes about your data

Nothing leaves your phone that could not already. An assistant with a code reads the encrypted copy your account already keeps, through the same relay your coach messages already go through. What a code changes is who may read that copy, a permission rather than a new flow. So the list on the privacy page of everything that can ever leave your phone is unchanged, and still complete.

Codes · 29 September 2026