Hi, team. Question regarding Bear Web: is access to a user’s notes via the web opt-in or opt-out?
If for example a user doesn’t have any interest in using Bear Web, will they have to manually disallow web access to their library (opt out) or do you have to have created that web account (opt in)? And in either case can that access be later revoked if desired?
So far, the web access can’t be opted out. Mind Bear web requires the same iCloud credentials you use on your device, and if someone tries to access your data, all the security notifications provided by Apple are triggered and notify you as on iCloud.com.
You can also enable two-factor authentication on your iCloud account, so confirmation from one of your Apple devices is required.
Tied to the opt in/out question, what’s the data model for
web access?
You mentioned in your reply that it’s using iCloud credentials, but does the data stay in a users iCloud account? Or is it being moved to a different data store permanently?
Obviously the web layer is going to need access, but how is the data handled?
The data is stored only in iCloud, within the user’s account. Apple provides an API to give access to this data via the web (similarly to the way the web apps at icloud.com work), and that is what Bear Web uses to retrieve notes, tags and files; when any of those are updated locally (for example if the user edits the text of a note), Bear Web uses those same API to upload the edited items back to the iCloud storage.