ChatMD Studio

For IT

Deploy ChatMD Studio to your company’s PCs.

Install it everywhere with the Microsoft Store, manage it with the same Group Policy or Intune tools you already use, and see exactly what each PC sends over the network before you roll it out.

Install on many PCs

ChatMD Studio is a Microsoft Store app, and this guide only covers the Store route. Without our own code-signing certificate, a downloaded installer would trigger SmartScreen warnings and most IT deployment tools refuse an unsigned one outright — the Store needs no certificate of ours, which is why it is the one route offered here for 2.1.

Intune

Install ChatMD Studio from the Microsoft Store. In Intune, add it as a Microsoft Store app (new) with the install behaviour set to System, so it installs for everyone who signs in to the PC. Microsoft Store keeps it up to date.

A script, or winget

Or from a command prompt, with winget:

winget install --id 9N3KGMG61MMV --source msstore

Group Policy software installation

Not available for a Store app: Group Policy has no way to push the install itself, only the settings below once ChatMD Studio is on the PC.

ChatMD Studio in the Microsoft Store

Policies

ChatMD Studio reads its settings from the registry path below — the standard place Group Policy and Intune write application settings for a packaged app. It reads them before its window opens, when Settings is opened, and every 15 minutes while it runs. A setting that becomes stricter applies at once, letting a request already in flight finish; a setting that becomes looser waits until ChatMD Studio is started again.

HKLM\Software\Policies\ChatMD\Studio

HKCU at the same path is read too, but it can only make a setting stricter than what HKLM says — never looser, and never a different value. A copy-on-write per-user registry hive proves nothing about who wrote it, so it is never trusted to loosen anything, and it never carries the deployment code or the licence key below.

Download the policy templates (ADMX/ADML): the ADMX file, plus an ADML file for each of English, German, Spanish, French and Polish.

Set-ChatMDAIRules.ps1 writes settings files into other vendors’ system folders (C:\Program Files\ClaudeCode, C:\ProgramData\OpenAI\Codex, C:\ProgramData\gemini-cli). It must run elevated. It makes those apps more restrictive for every user and project on the PC, not only in vaults. It never writes Claude Code’s managed-mcp.json. It never sends anything anywhere.

Group Policy

Copy the ADMX file into your Group Policy Central Store's PolicyDefinitions folder, and each language's ADML file into its matching locale folder there (for example en-US). The policies then appear under Computer Configuration, Administrative Templates, ChatMD Studio.

Intune

Devices, Configuration, Import ADMX. Upload the ADMX file together with the English (en-US) ADML file — Intune's custom-ADMX import takes only one language file. Then create a profile from the imported template with the settings you want.

Every setting has a loosest value and a most restrictive one. A company's team page can only make a setting as strict as Windows policy already made it, never looser. A setting this build does not understand takes its most restrictive value and is reported in Settings, rather than being ignored.

Cursor Agent is not offered in this version of ChatMD Studio. The policy table still lists its code, so a setting that names it is read as before.

SettingValue nameTypeAllowed valuesWhat it doesCan HKCU tighten it?
AIAI AIMode REG_SZ
  • any Any AI tool
  • local-only AI on this PC only
  • off Off
Which AI tools ChatMD Studio may use on this PC. Any AI tool: no restriction. AI on this PC only: only Ollama running on this PC, so nothing is sent to an AI service on the internet; Ollama may still download models, and that connection is made by Ollama, not ChatMD Studio. Off: every AI feature is off. Disabled or not configured: Windows policy does not restrict AI. Yes — only to make it stricter
AI tools allowedAI AllowedAIProviders REG_MULTI_SZ
  • anthropic Anthropic API key
  • openai OpenAI API key
  • xai xAI API key
  • claude-code Claude Code
  • codex Codex
  • antigravity Antigravity
  • cursor Cursor Agent
  • ollama Ollama on this PC
  • company Your organisation's AI
The AI tools ChatMD Studio may use, one per line, from: anthropic, openai, xai, claude-code, codex, antigravity, cursor, ollama, company. A tool that is not on the list cannot be used, and neither can another command chosen as the AI tool. A name this version does not know allows nothing and is listed in Settings. Disabled or not configured: no list applies. Yes — only to make it stricter
Another command as the AI toolAI AllowCustomAICommand REG_DWORD
  • 1 Allowed
  • 0 Blocked
Whether a person may choose another program as the AI tool (Settings, AI, Another command). Yes — only to make it stricter
AskAI AllowAsk REG_DWORD
  • 1 On
  • 0 Off
Ask: questions about the notes in a workspace, answered by the chosen AI tool. Yes — only to make it stricter
TeachAI AllowTeach REG_DWORD
  • 1 On
  • 0 Off
Teach: turning files and corrections into notes with the chosen AI tool. Yes — only to make it stricter
Brain digestAI AllowBrain REG_DWORD
  • 1 On
  • 0 Off
Brain digest: a summary of a whole workspace written by the chosen AI tool. Yes — only to make it stricter
Link and tag suggestionsAI AllowSuggestions REG_DWORD
  • 1 On
  • 0 Off
Link and tag suggestions made by the chosen AI tool. Yes — only to make it stricter
Catch me upAI AllowCatchUp REG_DWORD
  • 1 On
  • 0 Off
Catch me up: a summary of recent changes written by the chosen AI tool. Yes — only to make it stricter
Reading scans with my AIAI AllowAIOcr REG_DWORD
  • 1 On
  • 0 Off
Reading scanned pages with the chosen AI tool when converting documents. Yes — only to make it stricter
Editor assistAI AllowEditorAssist REG_DWORD
  • 1 On
  • 0 Off
Editor assist: rewriting and continuing text in the editor with the chosen AI tool. Yes — only to make it stricter
Web inside ChatMDAI AllowAIWebInChatMD REG_SZ
  • allow-always-ok Ask first; people may choose Always allow
  • ask Ask first
  • off Off
Web inside ChatMD: Claude Code may search the web and read web pages for Ask. allow-always-ok (the default): ChatMD asks the person before every search and every new site, and each person may choose Always allow in Settings › AI (web search, sites they name, or any site) and Apply without review for whole-note suggestions. ask: every search, every site and every suggested change is asked; Always allow and Apply without review are not offered. off: no web in Ask; Ask answers only from the notes. Yes — only to make it stricter
Semantic searchAI AllowSemanticSearch REG_DWORD
  • 1 On
  • 0 Off
Semantic search: an index of the notes, built by Ollama on this PC. Yes — only to make it stricter
What AI apps may do in vaultsAI AIRulesAccess REG_SZ
  • more Can also run programs
  • edit Can edit notes
  • read-only Read only
The most an AI app may do in a vault. ChatMD Studio writes it into each AI app's own files in the vault (AI rules): AGENTS.md, CLAUDE.md and the apps' settings files. Can also run programs: no limit beyond ChatMD Studio's own rules. Can edit notes: AI apps may read and change notes, but not run programs. Read only: AI apps may only read notes. A person may choose something stricter, never looser. Disabled or not configured: Windows policy does not limit it. Yes — only to make it stricter
AI rules in every vaultAI AIRulesInEveryVault REG_DWORD
  • 1 Every vault
  • 0 Your choice
Keep AI rules in every vault and team folder this PC opens, at the level AIRulesAccess sets. People cannot untick an AI app or remove the rules, and in a team folder these are the only rules ChatMD Studio writes. Yes — only to make it stricter
Web tools in AI apps (in vaults)AI AIRulesWeb REG_DWORD
  • 1 On
  • 0 Off
Web tools in AI apps, in vaults. On: ChatMD Studio writes nothing about the web, and each AI app searches and reads the web the way it normally does. Off: ChatMD Studio turns off each app's own web tools where the app has a setting a vault file can hold (Claude Code; Codex once a person trusts the folder) and tells every app not to go online. A person may turn it off, never on. Disabled or not configured: Windows policy does not limit it. Yes — only to make it stricter
Tools people add to AI apps (in vaults)AI AIRulesAddedTools REG_SZ
  • on On
  • ask Ask first
  • off Off
Tools people add to AI apps, such as MCP servers, in vaults. on: not limited by ChatMD Studio; at Read only and Can edit notes Claude Code asks before each use. ask: Claude Code asks before each use at every level; other apps are told to ask. off: ChatMD Studio writes a deny rule for them into Claude Code's vault settings; other apps are told not to use them. To allow only certain servers, use each AI app's own managed settings: Claude Code allowedMcpServers with allowManagedMcpServersOnly, VS Code ChatAllowedMcpServers, Codex requirements.toml mcp_servers, the Cursor Enterprise MCP Allowlist. Disabled or not configured: Windows policy does not limit it. Yes — only to make it stricter
AI rules for the whole PC (IT script)AI AIRulesMachineWide REG_DWORD
  • 1 On
  • 0 Off
Read by the deploy kit's Set-ChatMDAIRules.ps1, run as SYSTEM: it writes Claude Code's, Codex's and Gemini CLI's own machine-wide settings from AIRulesAccess, AIRulesWeb and AIRulesAddedTools. Those apply to every user and every project on the PC, not only vaults. It never writes Claude Code's managed-mcp.json. ChatMD Studio itself only shows this setting. Yes — only to make it stricter
Name staff seeYour organisation's AI CompanyAIName REG_SZ Free text — never a key or password The name staff see for your organisation's AI in ChatMD Studio, for example Contoso AI. Not configured: the address's host name is shown. No — read from the machine policy (HKLM) only
AddressYour organisation's AI CompanyAIEndpoint REG_SZ Free text — never a key or password The address of your organisation's AI: an Azure OpenAI or Foundry resource, your AI gateway, Amazon Bedrock or an AI company's API, for example https://contoso.openai.azure.com/openai/v1. It must start with https:// (http:// only to this PC), with no key, password or query in it. Each person confirms the address once on their PC, and again whenever it changes; nothing is sent before they do. No — read from the machine policy (HKLM) only
Request formatYour organisation's AI CompanyAIFormat REG_SZ
  • openai-chat OpenAI format (chat completions)
  • anthropic-messages Anthropic format (Messages)
How ChatMD Studio talks to the address. OpenAI format (chat completions): Azure OpenAI, Amazon Bedrock /openai/v1, AI gateways, OpenAI, xAI, Mistral. Anthropic format (Messages): Claude in Microsoft Foundry, Amazon Bedrock /anthropic, Anthropic. Not configured: OpenAI format. No — read from the machine policy (HKLM) only
Key headerYour organisation's AI CompanyAIKeyHeader REG_SZ Free text — never a key or password The header that carries each person's own key, for example api-key for Azure OpenAI or Ocp-Apim-Subscription-Key for Azure API Management. Not configured: Authorization (as a Bearer token) for the OpenAI format, x-api-key for the Anthropic format. No — read from the machine policy (HKLM) only
Fixed headersYour organisation's AI CompanyAIHeaders REG_MULTI_SZ Free text, one per line — never a key or password Extra headers sent with every request, one per line as Name: value, for example anthropic-workspace-id: wrkspc_… or OpenAI-Project: proj_…. Never a key: a header whose name suggests a key, token or password is refused, and the whole setting with it. No — read from the machine policy (HKLM) only
Model namesYour organisation's AI CompanyAIModels REG_MULTI_SZ Free text, one per line — never a key or password The model or deployment names staff may choose, one per line; the first is the default. Azure OpenAI and Amazon Bedrock need them, because their names are yours. Not configured: ChatMD Studio asks the address for its model list. No — read from the machine policy (HKLM) only
SecretsSecrets AllowSecrets REG_DWORD
  • 1 Allowed
  • 0 Off
Secrets: the locker that keeps API keys and passwords on this PC. When it is turned off, stored items are kept but cannot be used. Yes — only to make it stricter
AI tools asking Secrets for keysSecrets AllowSecretsBridge REG_DWORD
  • 1 Allowed
  • 0 Off
Whether AI tools may ask Secrets for a stored key. Yes — only to make it stricter
Stored keys for AskSecrets AllowStoredKeysForAsk REG_DWORD
  • 1 Allowed
  • 0 Off
Whether Ask may use an API key stored in Secrets. Yes — only to make it stricter
Secrets protectionSecrets RequireSecretsProtection REG_DWORD
  • 1 Required
  • 0 Not required
Whether Secrets must be protected by Windows Hello or a password. Yes — only to make it stricter
Key health checksSecrets AllowKeyHealthChecks REG_DWORD
  • 1 Allowed
  • 0 Off
Key health checks: asking each provider whether a stored key still works, by hand or by the daily automatic check. Yes — only to make it stricter
Web clippingInternet AllowWebClipping REG_DWORD
  • 1 Allowed
  • 0 Off
Web clipping: saving a web page, a post on X or a Reddit thread as a note from its address. Yes — only to make it stricter
Picture downloadsInternet AllowPictureDownloads REG_DWORD
  • 1 Allowed
  • 0 Off
Downloading a picture from the web when a person pastes it into a note. Yes — only to make it stricter
Local historySafety KeepLocalHistoryOn REG_DWORD
  • 1 Always on
  • 0 Your choice
Local history: snapshots of every workspace on this PC. When it is enforced, a person cannot turn them off. Yes — only to make it stricter
Showing who has a note openTeam folders AllowPresence REG_DWORD
  • 1 Allowed
  • 0 Off
Showing colleagues who has a note open in a shared team folder. When it is turned off, this PC neither shows nor shares that information. Yes — only to make it stricter
Showing and copying the licence keyLicence AllowShowLicenceKey REG_DWORD
  • 1 Allowed
  • 0 Off
Whether a person may show or copy the licence key in Settings. Yes — only to make it stricter
Removing the licence keyLicence AllowRemoveLicenceKey REG_DWORD
  • 1 Allowed
  • 0 Off
Whether a person may remove the licence key from this PC. Yes — only to make it stricter
Deployment codeLicence EnrollmentCode REG_SZ Free text — the code or key itself, typed or pasted by IT A deployment code from your team page. ChatMD Studio uses it when it starts, to add this PC to your organisation's licence. Read from the machine policy only. No — read from the machine policy (HKLM) only
Licence key from Windows policyLicence LicenceKey REG_SZ Free text — the code or key itself, typed or pasted by IT A licence key, for PCs that cannot reach the internet. Every user of this PC can read it; where the PC is online, a deployment code is safer. ChatMD Studio reads it when it starts. Read from the machine policy only. No — read from the machine policy (HKLM) only
Personal ChatMD accountsChatMD account AllowPersonalAccounts REG_DWORD
  • 1 Allowed
  • 0 Off
Signing in to a personal ChatMD account on this PC. An account is optional: ChatMD Studio, its notes and a licence key all work without one. When it is turned off, nobody can sign in to a personal account here, and one already signed in is signed out. Yes — only to make it stricter
Signing in for StudioChatMD account AccountSignIn REG_SZ
  • optional Optional
  • required-for-studio Required for Studio
Whether a person must be signed in to a ChatMD account to use Studio features on this PC. Optional: no sign-in is needed. Required for Studio: Studio features stay locked until someone signs in with an account this PC accepts; the free editor, opening and saving files, and Settings never need a sign-in, so nobody is locked out of their own files. A PC that has been offline longer than the sign-in lasts treats the person as signed out for Studio. Disabled or not configured: Windows policy does not require it. Yes — only to make it stricter
If a PC loses its team settingsChatMD account LostTeamSettings REG_SZ
  • keep-last Keep the last good copy
  • lock-studio Lock Studio until it checks in
What a PC does when the team settings it received from your team page are missing or damaged, until it next checks in with your organisation. Keep the last good copy: it uses the last team settings it verified; if it has none, AI and internet features stay at their strictest, but Studio is not locked and nobody is signed out. Lock Studio until it checks in: every team setting is at its strictest and Studio features stay locked until the PC checks in again; the free editor, opening and saving files, and Settings are never locked. Disabled or not configured: Windows policy does not decide; the team page may, and Keep the last good copy is the default. Yes — only to make it stricter
Accounts that may sign inChatMD account AllowedAccountIdentities REG_MULTI_SZ
  • entra: and your Microsoft Entra tenant id
  • google: and your Google Workspace domain
  • oidc: and your sign-in service’s https issuer address
  • email: and a domain (a proven address only)
The ChatMD accounts that may sign in on this PC, one per line: entra: and a Microsoft Entra tenant id, google: and a Google Workspace domain, oidc: and the https issuer address of another company sign-in service, or email: and a domain, which matches only an address the person has proven with an emailed code. A company sign-in matches its service (entra:, google: or oidc:); any other sign-in matches only email:. An account that matches no line is not kept, and one already signed in is signed out. A line this version does not understand lets nobody sign in, and Settings says so. Disabled or not configured: any account may sign in. Yes — only to make it stricter
Ways of signing inChatMD account AllowedSignInMethods REG_MULTI_SZ
  • passkey Passkey
  • password Password
  • password-2step Password and authenticator code
  • email-code Emailed code
  • google Google
  • microsoft Microsoft
  • company Company sign-in
The ways a person may sign in to a ChatMD account on this PC, one per line, from: passkey, password, password-2step (a password and an authenticator code), email-code, google, microsoft, company. A sign-in made any other way is not kept. Disabled or not configured: every way is allowed. Yes — only to make it stricter
Longest a sign-in lasts (days)ChatMD account MaxSignInDays REG_DWORD A whole number of days, 1 to 90 The longest a sign-in to a ChatMD account lasts on this PC, in days, from 1 to 90. After that the person is signed out and signs in again. Disabled or not configured: Windows policy sets no limit; the team page or your organisation's company sign-in may still set one. Yes — only to make it stricter
Company to sign in withChatMD account SignInHint REG_SZ Free text — your verified email domain or your organisation id from the team page Your organisation's verified email domain or its organisation id from the team page. Sign in with your company then goes straight to your organisation's sign-in instead of asking for a work address. Read from the machine policy only, when ChatMD Studio starts. No — read from the machine policy (HKLM) only
Sending PC names and versions to the team pageReporting AllowPCDetailsReporting REG_DWORD
  • 0 Off (the team page cannot loosen this)
  • — not set (delete the value): the team page decides
Enabled: this PC never sends its name and ChatMD Studio version to the team page, whatever the team page asks. Disabled or not configured: the team page decides. Yes — only to make it stricter

Enrolling PCs

To add the PCs to this licence without typing anything, create a deployment code from your team page's Deploy section and set it as the EnrollmentCode value under HKLM\Software\Policies\ChatMD\Studio. Each PC redeems it when ChatMD Studio starts and takes a free seat.

Anyone who can sign in to a PC can read that policy value, so a copied deployment code could add another PC until you withdraw it. For PCs that cannot reach chatmdstudio.com, the key itself can go in the LicenceKey value instead, but then every user of that PC can read the key.

Our website records up to 30 activations and daily checks for each key an hour, or twice the key’s seats if that is more. A PC past that still starts Studio, and is counted at its next check.

Honest limit: both routes rely on Windows policy being the strictest thing set. A person who can edit files in their own profile — not the registry, which needs an administrator — can still remove the team page's settings on their own PC and fall back to whatever Windows policy alone enforces. For a PC where an AI feature must never run even once, set it through Windows policy, not the team page alone.

What each PC sends over the network

This is the same list ChatMD Studio shows on the PC itself, under Settings › Privacy, generated here from the app's own source so it cannot silently gain an undeclared destination. The Closed by column names the setting above that can turn a destination off; where it is blank, no policy closes that connection, and it is listed here rather than left unsaid.

Cursor Agent is not offered in this version of ChatMD Studio. Its row stays in this list so the list matches the policy table.

DestinationWhyWhenWhat is sentClosed by
chatmdstudio.comOver the internet Show the purchase page in a window the app owns instead of sending the person out to a browser. The app only ever loads its own buy page; what happens after that is the payment provider navigating its own page, and the window can reach nothing in this app. Only after Buy on chatmdstudio.com is pressed, and only for as long as the window is open. The one-time pickup token for that purchase, in the address of our own buy page. No file, note, vault path or account detail. Card details are entered on the payment provider’s page and never pass through this app. The window keeps nothing on disk: its session lives in memory and ends when the window closes. Nothing closes this: it keeps working even under “Keep everything on this PC”, so buying and licensing never lock you out.
chatmdstudio.comOver the internet Ask whether a launch offer on Studio is running, so the purchase screen can show the offer price, what it becomes, how many are left at that price and when it ends. If the answer is missing, slow or not understood, the screen shows the regular price; what is charged is decided by the checkout, not by this answer. Only when the Studio purchase screen opens, once each time, waiting at most two seconds. Never while “Keep everything on this PC” is on. Nothing but the request itself. No file, note, vault path, licence key, PC code or account detail.
  • Daily licence check not a Windows policy: set from the team page, or “Keep everything on this PC” on that PC
chatmdstudio.comOver the internet Collect the licence key for a purchase the person started inside the app, so they never have to copy one. Asked only while that purchase is in flight; silent on every failure. Only after Buy on chatmdstudio.com is pressed, and only until the key arrives, the offer closes or fifteen minutes pass; right after a code from an administrator — typed, or set by IT in Windows policy — is accepted, to collect the key it unlocks; and right after Add to this PC in Settings › Account, to collect that key. The one-time pickup token minted for that purchase, code or Add to this PC. No file, note, vault path, account detail or identifier of the PC. Nothing closes this: it keeps working even under “Keep everything on this PC”, so buying and licensing never lock you out.
chatmdstudio.comOver the internet Add this PC to an organisation’s licence with a code its administrator created. The website checks the code, takes one of the licence’s seats for this PC and files the key for the app to collect; the key itself never travels in this answer. When someone types a code from their administrator in Settings › Account and presses Add this PC; or, when IT has set a deployment code in Windows policy and this PC has no business key yet, once, a random 0–10 minutes after launch, with a few spaced retries if the website cannot answer. Never again for a code that was accepted or refused for good. The code, a one-time pickup token minted for it, and a one-way code for this PC, which contains neither the PC name nor the user name. No file, note, vault path or account detail. Nothing closes this: it keeps working even under “Keep everything on this PC”, so buying and licensing never lock you out.
chatmdstudio.comOver the internet One call when a licence key is entered, so a refunded key can be refused on new installs, installs can be counted, and this PC takes one of the key’s seats. It fails open: if it cannot be made, the key is accepted. Only at the moment a licence key is applied — typed, collected after a purchase or a code, or set by IT in Windows policy and not yet applied on this PC, which happens at launch — or Use Studio on this PC is pressed. The licence key and a PC code: a one-way code made from the PC name and the Windows user name together with the licence key — it contains neither name and cannot be worked out from the names alone. If the website has not yet confirmed that it knows this PC by that code, the app also sends the code earlier versions sent, made from the two names alone, so the PC keeps its place. After Add to this PC in a company sign-in, for a business licence, also the one-time token received for it, so that a licence counting seats per person counts this PC under you. No file, note, vault path or account detail. Nothing closes this: it keeps working even under “Keep everything on this PC”, so buying and licensing never lock you out.
chatmdstudio.comOver the internet Check that this PC is still one of the PCs a licence key is active on, because a key works on a limited number of PCs at a time. Only a signed answer that the key moved can turn Studio off here; if the check cannot be made, nothing changes. Only while a licence key is stored on this PC: shortly after launch, then once a day while the app runs, and never more than once every twelve hours on the timer. Also at once when someone presses Refresh in Settings › Managed settings, and right after a business key is accepted without a free seat. “Keep everything on this PC” switches the timer off for a personal key; a business key keeps checking, because the check carries the company’s team settings. The licence key and a PC code: a one-way code made from the PC name and the Windows user name together with the licence key — it contains neither name and cannot be worked out from the names alone. If the website has not yet confirmed that it knows this PC by that code, the app also sends the code earlier versions sent, made from the two names alone, so the PC keeps its place. For a business key, also the number of the team settings this PC has applied and — only when the team page has turned it on and no Windows policy forbids it — the PC’s name and the ChatMD version. No file, note, vault path or account detail.
  • Daily licence check not a Windows policy: set from the team page, or “Keep everything on this PC” on that PC
chatmdstudio.comOver the internet Give a business licence’s seat back when you sign out of your ChatMD account on this PC, where that licence counts seats per person and this PC was counted under you. The key comes off this PC at once; the seat is freed when this call arrives. Only when Sign out of this PC is pressed on a PC counted under you by a licence that counts seats per person — or, if it could not be sent then, at the next launch and with each daily licence check until it arrives. The licence key and the one-time token this PC received when the licence was added to it. No file, note, vault path, PC code or account detail. Nothing closes this: it keeps working even under “Keep everything on this PC”, so buying and licensing never lock you out.
account.chatmdstudio.comOver the internet Sign in to an optional ChatMD account. With an emailed code, the app sends what is typed straight to the account website; with a password, it sends only a one-time exchange worked out from it on this PC, never the password; with Google, Microsoft or a passkey, the browser signs in there and the app exchanges the one-time code it brings back. Either way the answer is this PC’s own sign-in to that account. A sign-in made through your organisation’s own sign-in service is the organisation’s: “Keep everything on this PC” and AllowPersonalAccounts = 0 end every other sign-in, not that one. Only after Sign in is pressed (Settings › Account, first-run setup, or the account badge): each step typed in the app as it is sent, or once the browser comes back with the code. Signing in inside the app: the email address, and the emailed code, authenticator code or recovery code typed there, each sent once over an encrypted connection and kept by the app nowhere; for a password, never the password itself — two one-time messages worked out from it on this PC (OPAQUE), which prove it once and cannot be reused; and a one-way code for this PC, which contains neither the PC name nor the user name. Signing in through the browser: the one-time code the browser brings back, the proof made for that sign-in (PKCE), and the same one-way code for this PC. No file, note, vault path or AI conversation.
  • Personal ChatMD accounts AllowPersonalAccounts
account.chatmdstudio.comOver the internet Keep a signed-in ChatMD account current: renew this PC’s sign-in, fetch the address, sign-in method and licence endings Settings shows, and tell the website when this PC signs out. A sign-in made through your organisation’s own sign-in service is the organisation’s: “Keep everything on this PC” and AllowPersonalAccounts = 0 end every other sign-in, not that one. Only while an account is signed in on this PC: when ChatMD starts, then about once a day, and when Sign out is pressed (or at a later start, if it could not be sent then). This PC’s sign-in token for the account, or on sign-out the token being ended. The answer carries the account’s address, how it signed in, the last characters of its licence keys and a signed statement of who is signed in. No file, note, vault path or AI conversation.
  • Personal ChatMD accounts AllowPersonalAccounts
account.chatmdstudio.comOver the internet Put a licence the signed-in ChatMD account holds on this PC, with Add to this PC in Settings › Account. The account website files that key for this PC and answers a one-time token; the app then collects the key from chatmdstudio.com with it and applies it like a typed key. A sign-in made through your organisation’s own sign-in service is the organisation’s: “Keep everything on this PC” and AllowPersonalAccounts = 0 end every other sign-in, not that one. Only when Add to this PC is pressed beside one of the account’s licences, while an account is signed in on this PC. This PC’s sign-in token for the account and the last 12 characters of that licence key. The answer is a one-time token to collect the key. No file, note, vault path, PC code or AI conversation.
  • Personal ChatMD accounts AllowPersonalAccounts
127.0.0.1Stays on the PC While a sign-in is open, listen on this PC for the one address the browser is sent back to with the one-time code (RFC 8252). Nothing leaves the PC on this connection. A sign-in made through your organisation’s own sign-in service is the organisation’s: “Keep everything on this PC” and AllowPersonalAccounts = 0 end every other sign-in, not that one. Only from Sign in until the browser comes back, the sign-in is cancelled, or ten minutes pass. Nothing is sent. The browser delivers the one-time code and the check value to this PC.
  • Personal ChatMD accounts AllowPersonalAccounts
The Microsoft Store licence service, through WindowsA program ChatMD starts Ask Windows whether this installation owns the Studio add-on bought earlier in the Microsoft Store. ChatMD starts Windows PowerShell, which asks the Store; Windows makes the connection, not ChatMD. At start, when a Studio feature is used, and when Refresh, Restore purchase or a purchase asks. An answer that Studio is owned stands until ChatMD restarts; any other answer is asked again only when something needs it, and no more often than every 30 seconds. There is no timer. The Store is not asked while a stored licence key verifies. The Store purchase path has no button in this version. Nothing from ChatMD. Windows answers with this installation’s Store licence; ChatMD keeps the result and the time in its own data folder. Nothing closes this: it keeps working even under “Keep everything on this PC”, so buying and licensing never lock you out.
127.0.0.1Stays on the PC Let an AI tool on this PC ask Secrets for a key, only when the person turned on the AI-tools setting in Secrets. A random port and a random token; every request is shown to the person first. Only while the AI-tools setting in Secrets is on, Secrets is on, and the organisation allows it. Nothing leaves the PC. A key is handed to a program on this PC only after the person approves that request.
  • Secrets AllowSecrets
  • AI tools asking Secrets for keys AllowSecretsBridge
127.0.0.1Stays on the PC Talk to the Ollama service running on this PC for Ask, local embeddings, setup, and model downloads. Only when Ollama is selected or its setup/model controls are used. Ask and embedding calls can contain note text, but the connection is literal HTTP loopback. Model downloads are performed onward by Ollama, without note text.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
[::1]Stays on the PC Allow the explicit IPv6-loopback form of the same local Ollama service. Only when Ollama is selected and CHATMD_OLLAMA_HOST explicitly uses IPv6 loopback. The same local Ollama request data as the IPv4 entry; the address cannot route off this PC.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
api.anthropic.comOver the internet Use an Anthropic key directly for Ask and whole-note suggestions, list available models, or check whether the key is accepted. Only after the person stores an Anthropic key and explicitly uses its Ask, whole-note suggestion, model-list, or key-check action — or, if the person turned on the daily automatic key check in Secrets (off by default), about once a day while the app runs. Ask sends the displayed question/context, which may include selected note text, plus the key in a request header. Whole-note suggestions send the whole open note and the instruction, after the person confirms. Model-list and key-check requests send the key but no notes.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
  • Secrets AllowSecrets
  • Stored keys for Ask AllowStoredKeysForAsk
  • Key health checks AllowKeyHealthChecks
api.openai.comOver the internet Use an OpenAI key directly for Ask and whole-note suggestions, list available models, or check whether the key is accepted. Only after the person stores an OpenAI key and explicitly uses its Ask, whole-note suggestion, model-list, or key-check action — or, if the person turned on the daily automatic key check in Secrets (off by default), about once a day while the app runs. Ask sends the displayed question/context, which may include selected note text, plus the key in a request header. Whole-note suggestions send the whole open note and the instruction, after the person confirms. Model-list and key-check requests send the key but no notes.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
  • Secrets AllowSecrets
  • Stored keys for Ask AllowStoredKeysForAsk
  • Key health checks AllowKeyHealthChecks
api.x.aiOver the internet Use an xAI key directly for Ask and whole-note suggestions, list available models, or check whether the key is accepted. Only after the person stores an xAI key and explicitly uses its Ask, whole-note suggestion, model-list, or key-check action — or, if the person turned on the daily automatic key check in Secrets (off by default), about once a day while the app runs. Ask sends the displayed question/context, which may include selected note text, plus the key in a request header. Whole-note suggestions send the whole open note and the instruction, after the person confirms. Model-list and key-check requests send the key but no notes.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
  • Secrets AllowSecrets
  • Stored keys for Ask AllowStoredKeysForAsk
  • Key health checks AllowKeyHealthChecks
The address your organisation set for its AI (Windows policy or the team page)Over the internet Send AI requests to your organisation’s own AI service — its Azure resource, its AI gateway or its account with an AI company — instead of any other provider. Only after your organisation has set its AI address, you have confirmed that address in Settings › AI, and an AI feature is used, its model list is refreshed or Test connection is pressed. Never before you confirm, and never after the address changes until you confirm the new one. The request and the note text the feature needs (and, for reading a scan, the picture), plus your own key from Secrets in the header your organisation named, and any fixed headers it listed. Nothing is sent to ChatMD.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
  • Secrets AllowSecrets
api.github.comOver the internet Check whether a GitHub key stored in Secrets is accepted by GitHub. Only when the person presses the provider-check action for that GitHub key — or, if the person turned on the daily automatic key check in Secrets (off by default), about once a day while the app runs. The GitHub key in an authorization header. No note text is sent.
  • Secrets AllowSecrets
  • Key health checks AllowKeyHealthChecks
generativelanguage.googleapis.comOver the internet Check whether a Google AI key stored in Secrets is accepted by Google. Only when the person presses the provider-check action for that Google key — or, if the person turned on the daily automatic key check in Secrets (off by default), about once a day while the app runs. The Google AI key in a request header. No note text is sent.
  • Secrets AllowSecrets
  • Key health checks AllowKeyHealthChecks
api.fxtwitter.comOver the internet Read the text of an X (Twitter) post whose address the person pasted into Teach. api.fxtwitter.com is a third-party service run by the open-source FxEmbed project, not by X or ChatMD. Only when the person asks ChatMD to clip an X/Twitter post URL. The public post account name and post ID from the pasted URL. No vault note text is sent.
  • Web clipping AllowWebClipping
The public host in the URL the person pastedOver the internet Fetch a web page or Reddit post the person explicitly asked Teach to clip. Only when the person pastes a web URL and presses the clip/add action. An HTTP GET for that URL. The URL and normal request metadata reach that site; vault note text is not added to the request. Private, local, and cloud-metadata addresses are refused and redirects are rechecked.
  • Web clipping AllowWebClipping
The public host a picture in a paste points atOver the internet Download, once, a web picture that was inside something the person pasted into a note — from a web page, Word or Outlook — so the note links a copy saved in the folder instead of a web address, which the app never loads. Only at the moment the person pastes into a Markdown note, once for each web picture in that paste; never when a note is opened or shown. An HTTP GET for each picture address. That site sees the address, this PC’s IP address and the time; no cookies, credentials, note text or vault path are sent. Private, local and cloud-metadata addresses are refused and redirects are rechecked.
  • Picture downloads AllowPictureDownloads
Windows Package Manager (winget)A program ChatMD starts Install Ollama or a command-line AI tool with one button instead of a download page. ChatMD starts winget.exe; winget, not ChatMD, downloads and checks the package. Only when the person presses Install for Ollama, Claude Code, Codex or Antigravity. ChatMD passes winget only the name of the package. winget looks it up in its own source and downloads the installer; no note, vault path or account detail is involved.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
Anthropic’s web search, through Claude CodeA program ChatMD starts Let Claude Code search the web for an Ask conversation, after the person allows each search, allows searches for that conversation, or chose to always allow web search in Settings › AI. Only in an Ask conversation with Web switched on, and only after the person answers Allow in the approval box — or with no box when they chose to always allow web search in Settings › AI. The search words Claude Code chose — shown to the person in the box before anything is sent, or, when they chose to always allow web search, listed in the conversation. They go to Anthropic as part of the person’s own Claude Code session; results come back as titles and addresses.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
  • Ask AllowAsk
  • Web inside ChatMD AllowAIWebInChatMD
The web site the person allowed, through Claude CodeA program ChatMD starts Let Claude Code read a web page for an Ask conversation, after the person allows that page once, that site for the conversation, or that site (or any site) always in Settings › AI. Only after the person answers Allow for that address or site, or when that site (or any site) is always allowed in their Settings › AI. Claude Code downloads the page from this PC (that site sees this PC’s IP address and the address). Claude Code first sends the site’s name, not the address, to api.anthropic.com for Anthropic’s safety check, then sends the page’s text to Anthropic to read.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
  • Ask AllowAsk
  • Web inside ChatMD AllowAIWebInChatMD
OpenAI’s web search and the pages it opens, through CodexA program ChatMD starts Let Codex search the web and open pages for an Ask conversation, after the person allows the list Codex showed first — once, for that conversation, or always in Settings › AI. Only in an Ask conversation with Web switched on and Codex chosen, and only after the person allows the list Codex showed — or with no box when everything on it is already allowed for that conversation or in Settings › AI. ChatMD stops the answer if Codex looks up anything that is not on the list. The search words Codex chose and the addresses of the pages it opens, shown in the box before the answer runs. They go to OpenAI as part of the person’s own Codex session; OpenAI runs the searches and opens the pages on its own servers.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
  • Ask AllowAsk
  • Web inside ChatMD AllowAIWebInChatMD
Google’s web search, and the sites of the pages Antigravity opensA program ChatMD starts Let Antigravity search the web and open pages for an Ask conversation, after the person allows the list it showed first — once, for that conversation, or always in Settings › AI. Only in an Ask conversation with Web switched on and Antigravity chosen, and only after the person allows the list Antigravity showed — or with no box when everything on it is already allowed. ChatMD stops the answer if Antigravity looks up anything else, and stops any web use it starts when the web is not allowed. The search words Antigravity chose and the addresses of the pages it opens, shown in the box before the answer runs. The searches go to Google as part of the person’s own Antigravity session; Google runs them on its own servers. Antigravity downloads each allowed page on this PC, so the site sees this PC’s address, and sends the page’s text to Google to read. Google records these interactions to improve its products, and people at Google may review them; ChatMD turns Antigravity’s own sharing setting off, which ChatMD has not verified on Google’s side.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
  • Ask AllowAsk
  • Web inside ChatMD AllowAIWebInChatMD
The web search of Anthropic, OpenAI or xAI, through a stored keyOver the internet Let a stored key’s provider search the web and open pages for an Ask conversation, after the person allows the list the AI showed first — once, for that conversation, or always in Settings › AI. Only in an Ask conversation with Web switched on and a stored key chosen, after one confirmation of the key for that question, and only after the person allows the list the AI showed — or with no box when everything on it is already allowed. Anything looked up that was not on the list is named in the answer. The search words the AI chose and the addresses of the pages it opens, shown in the box before the answer runs. The provider runs the searches and opens the pages on its own servers, charged to the person’s key (about $0.01 a search at Anthropic and OpenAI).
  • AI AIMode
  • AI tools allowed AllowedAIProviders
  • Ask AllowAsk
  • Web inside ChatMD AllowAIWebInChatMD
  • Secrets AllowSecrets
  • Stored keys for Ask AllowStoredKeysForAsk
127.0.0.1Stays on the PC While an AI session runs, listen on this PC for Claude Code’s permission requests, so ChatMD can ask the person. Nothing leaves the PC on this connection. Only from the start of an Ask-with-web or whole-note editor-assist session until it ends; one address and key per session. Nothing is sent. Claude Code tells ChatMD which tool it wants and with what input; ChatMD answers allow or not.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
Claude CodeA program ChatMD startsChatMD passes the requested prompt/context to Claude Code. Claude Code, not ChatMD, chooses and makes its own network connections.Only when selected for an AI action.Owned by that program, not ChatMD.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
CodexA program ChatMD startsChatMD passes the requested prompt/context to Codex. Codex, not ChatMD, chooses and makes its own network connections.Only when selected for an AI action.Owned by that program, not ChatMD.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
AntigravityA program ChatMD startsChatMD passes the requested prompt/context to Antigravity. Antigravity, not ChatMD, chooses and makes its own network connections. Google records what is sent to Antigravity and what comes back to improve its products, and people at Google may review it. ChatMD turns Antigravity’s own sharing setting off for every run it starts; what Google does with that setting on its servers is not documented, and ChatMD has not verified it.Only when selected for an AI action.Owned by that program, not ChatMD.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
Cursor AgentA program ChatMD startsChatMD passes the requested prompt/context to Cursor Agent. Cursor, not ChatMD, chooses and makes its own network connections, and authenticates with your Cursor account.Only when selected for an AI action.Owned by that program, not ChatMD.
  • AI AIMode
  • AI tools allowed AllowedAIProviders
Another commandA program ChatMD startsChatMD passes the requested prompt/context to the person-chosen executable. Its destinations and behaviour are unknowable to ChatMD.Only when the person configures and selects that command.Owned by that program, not ChatMD.
  • AI AIMode
  • Another command as the AI tool AllowCustomAICommand
  • AI tools allowed AllowedAIProviders
The http, https, or mailto link the person choseOpened by WindowsChatMD asks Windows to open the URL. The default browser—not ChatMD Studio—then owns any connection.Only when the person opens a note link, help/support/privacy page, provider install page, or presses Sign in or Manage account for a ChatMD account.Not made by ChatMD Studio.Not a ChatMD control: it is whatever opens that link.
Microsoft Store or Windows SettingsOpened by WindowsChatMD asks Windows to open its own Store or Settings handler; Electron does not fetch a page.Only when the person presses the matching Store or Startup-settings action.Not made by ChatMD Studio.Not a ChatMD control: it is whatever opens that link.

What ChatMD writes into a shared team folder

In a team folder, ChatMD writes small files into the folder’s hidden .chatmd folder, and your sync service carries them like any other file. Nothing in them reaches ChatMD.

One file for each PC shows who has a note open: the person’s display name, the PC’s name, which notes are open (as codes made from their paths) and the time, refreshed every two minutes. The Showing who has a note open control turns it off.

Each person’s save journal records every save made in ChatMD: the time, the note’s path and a fingerprint of its contents, plus the display name and the PC’s name while showing who has a note open is on. Your sync service may keep earlier versions of these files.

Claude Code on the web, inside ChatMD

With Claude Code as the AI tool, Ask can search the web and read web pages, and whole-note editor assist can suggest changes. Claude Code asks ChatMD before each search, each new site and each change, and ChatMD asks the person. Each person may choose to always allow web search, named sites or any site, and to apply suggestions without review, in Settings › AI on their PC; every use is still listed in the conversation. The Web inside ChatMD setting above (AllowAIWebInChatMD) decides how far they may go: allow-always-ok (the default) lets them choose; ask keeps every search, site and change asked, with no always and no apply without review; off turns the web off, and Ask answers from notes only.

ChatMD answers Claude Code through a small helper that listens on this PC only (127.0.0.1, a new port and key for each conversation), under the path /chatmd-session/. Where Claude Code’s managed-mcp.json is deployed, Claude Code cannot load that helper, so web in Ask and whole-note suggestions are unavailable on those PCs; Ask still answers from notes and editor assist still works on a selection.

Where Claude Code’s managed settings allow only listed MCP servers, add this entry for ChatMD’s helper:

{"serverUrl": "http://127.0.0.1:*/chatmd-session/*"}

Settings at each AI company that affect ChatMD Studio

Each person’s AI runs under their own account or key, so your organisation’s settings at each AI company decide what works. These are the ones we know of, from each company’s own documentation as read on 3 October 2026. They change, so when something stops working, check the source under each heading.

OpenAI API keys

A restricted key needs read access to models (api.model.read) for the model list and for “Check at provider” in Secrets. Ask needs only one more permission: Responses: Write (measured on 4 October 2026 with a restricted key; Chat completions is not needed). Every other permission can stay at None.

OpenAI answers 429 for a reached spend limit, for credit that has run out and for a usage limit, each with its own error code, as well as for too many requests at once. Trying again in a moment helps only with too many requests at once.

A project with data residency, for example in Europe, is reached at its own regional address, such as eu.api.openai.com. A key stored in Secrets always goes to api.openai.com, so for such a project set Your organisation’s AI to https://eu.api.openai.com/v1 in OpenAI format instead. Projects that need mutual TLS (mtls.api.openai.com with a client certificate) are not supported.

ChatMD Studio asks OpenAI not to store conversations (store: false), with a stored key and through Your organisation’s AI on an OpenAI address. This does not change how long OpenAI keeps requests for abuse monitoring.

Source: developers.openai.com/api/docs

xAI API keys

xAI keys are deny-by-default: a key can do only what its own permissions allow. Listing models is a permission of its own (models). A key with only the Chat endpoint answers Ask, web search included (measured on 4 October 2026); without Models, the model list and “Check at provider” in Secrets cannot work. xAI’s mutual-TLS address (mtls.api.x.ai) is not supported.

Source: docs.x.ai

Claude API keys

A key that is not tied to one workspace must name a workspace on every request, or Anthropic refuses it. Create each person’s key inside one workspace. Through Your organisation’s AI, you can instead send the workspace as a fixed header:

anthropic-workspace-id: wrkspc_…

Fable and Mythos need 30-day data retention, so an organisation with zero data retention cannot use them.

Source: platform.claude.com/docs

Codex in a ChatGPT workspace

A workspace admin must turn on “Allow members to use Codex locally”, or Codex will not run on members’ PCs, ChatMD Studio’s runs included.

Your workspace’s Codex requirements override the settings ChatMD Studio passes to Codex. Where they do not allow what ChatMD asks for, such as its approval or web search setting, Codex falls back to a setting they allow.

GPT-6.1 Sol, GPT-6 Sol and Luna are off by default in Enterprise and Edu workspaces.

Codex’s documentation has moved: the old developers.openai.com/codex pages now lead to learn.chatgpt.com/docs.

Source: learn.chatgpt.com/docs

Claude Code on managed PCs

Three of Claude Code’s managed settings can change or stop what ChatMD Studio runs through it:

  • allowManagedPermissionRulesOnly: Claude Code ignores the permission rules ChatMD sets for its runs and follows only yours, including whether it asks before reading a web page.
  • Managed hooks run inside ChatMD’s runs too, and ChatMD cannot turn them off. A hook that answers permission requests can answer before ChatMD asks the person.
  • disableSideloadFlags: Claude Code exits instead of starting a conversation that loads ChatMD’s helper (passed with --mcp-config), so web in Ask and whole-note suggestions stop working on that PC.

Source: code.claude.com/docs

Antigravity

Google says Antigravity is for personal Google accounts. Google’s terms may not allow another company’s app, such as ChatMD Studio, to use Antigravity’s sign-in, and Google may suspend an account it finds breaking them. To keep Antigravity off company PCs, leave antigravity out of AI tools allowed (AllowedAIProviders).

Source: antigravity.google/terms

Verify on one PC before rolling out further

Before applying a policy across your fleet, confirm it reaches an actual ChatMD Studio window: an ordinary registry write does not by itself prove a packaged Store app can see it.

  1. As an administrator, run: reg add "HKLM\Software\Policies\ChatMD\Studio" /v AIMode /t REG_SZ /d off /f
  2. Start ChatMD Studio from the Start menu. Starting the installed program file directly skips the Store identity and would pass this check either way.
  3. Open Settings › Privacy. A Managed settings section should list AI, set to Off by Windows policy.
  4. Remove the test value: reg delete "HKLM\Software\Policies\ChatMD\Studio" /v AIMode /f, then start ChatMD Studio again. The Managed settings section should be gone.

Import the policy templates into a test Group Policy object, or a test group of one device in Intune, and repeat this check there before pointing either at every PC.

Updates and uninstalling

Updates come through the Microsoft Store, the same as any other Store app; ChatMD Studio has no update setting of its own. Whatever already controls Store updates for your organisation, through Intune or Group Policy, controls updates for ChatMD Studio too.

In the Microsoft Store version, uninstalling removes the application and its own data. A vault is an ordinary folder of files, wherever a person chose to open it, never inside the app's own install or profile folder, so removing ChatMD Studio does not touch it.