What ChatGPT Sees When It Reads Your Voice Notes Through SpeakPen
You've thought about pointing an AI at your notes for a year. What stops you isn't the setup. It's that "connect your account" pages never say what actually happens next. Can it edit things? Does it get the audio? Will it quietly keep access after you've forgotten it exists?
This post answers those questions for one specific connection: ChatGPT reading your SpeakPen voice notes over MCP. It's written from the server code, not from marketing copy, and it ends with how to check each claim yourself.
The request path, end to end
When ChatGPT has the SpeakPen plugin and you ask about your notes, here's what happens:
- ChatGPT sends a request to
https://speakpen.app/mcpwith an access token. - SpeakPen checks the token: is it valid, is it unexpired, was it issued for this server (
/mcp) and with thenotes:readscope? - If yes, SpeakPen runs one of three tools against your notes only and returns JSON.
- If no, it returns 401 and ChatGPT has to send you to sign in again.
No browser session cookie ever authorizes an MCP call. Being signed in to speakpen.app in another tab doesn't give ChatGPT anything; only the token you approved does.
What each tool returns, field by field
There are exactly three tools. All three are marked read-only, non-destructive and idempotent, and they really are: none of them has a code path that writes to a note.
Recent notes returns up to 50 notes (default 20), newest first, optionally between two dates. For each note:
-
id,title -
url, a link to that note in the SpeakPen web app (it opens only for you, signed in) created_at-
snippet, the beginning of the AI summary
Search takes a query, matches it against titles, summaries and transcripts, and returns up to 10 notes in the same shape.
Read a note returns one note in full:
-
title, the fulltext(the transcript, or the summary if there's no transcript) -
summary,category,created_at,duration_seconds
Only completed notes are visible. A recording still being transcribed doesn't exist yet as far as ChatGPT is concerned.
What it never returns
Audio. The response shape is a whitelist, and the audio URL isn't on it. That's deliberate twice over: audio is the most sensitive thing you've given SpeakPen, and the storage links for it are presigned URLs that expire within hours anyway. A model reading your notes has no use for either.
Other people's notes. Every query starts from the signed-in user's own notes. There's no tool that takes a user id.
Your Obsidian vault. ChatGPT talks to SpeakPen's server, not to your vault. If you use the SpeakPen Sync plugin, your vault receives notes; nothing in this connection reads from it.
What it can't do
- Write. There's no create, edit or delete tool. Your notes are exactly as they were, however the conversation goes.
- Run forever. Calls are limited to 60 per minute per account, and the MCP endpoint also has a per-IP ceiling.
- Outlive your decision. An access token lasts one hour. Refresh tokens rotate on every use and expire after 30 days. When you disconnect, both are revoked on the server.
The sign-in step, and why it's OAuth
When you add the plugin, ChatGPT registers itself with SpeakPen as an OAuth client named "ChatGPT", using a redirect back to chatgpt.com. You sign in on speakpen.app, not inside ChatGPT, so ChatGPT never sees your password or Google login. The consent screen says "ChatGPT wants to read your SpeakPen notes" and spells out the limit: it can read titles, summaries and transcripts, and can't change or delete anything. You press Allow; ChatGPT receives a code and swaps it for a token bound to https://speakpen.app/mcp.
The same flow works for local tools. Codex or Claude Code use a redirect to 127.0.0.1 on your own machine instead. That's why their "Authentication complete" page looks like a bare text file: it's served by the tool on your computer, not by SpeakPen.
About ChatGPT's "high risk" label
Developer mode in ChatGPT carries a red high risk badge, and the plugin form asks you to confirm you trust the server. The warning is generic. It covers every custom MCP server, including ones whose tools can change or delete data. Read it in that light: the question to ask of any server is "what can its tools do?". For SpeakPen the answer is above, three read-only tools, and you can confirm it in the next section.
Check it yourself
You don't have to take this post's word for any of it:
- See the connection. In SpeakPen, open Settings → Connections → AI assistants. ChatGPT is listed with when it connected and when it was last used.
- See the tools. Ask ChatGPT: "Which SpeakPen tools do you have, and can any of them change my notes?" It sees the same three tools and their read-only flags that this post lists.
- Watch it fail to write. Ask ChatGPT to "rename my last SpeakPen note". It has no tool for that and will tell you so.
- Cut it off. Press Disconnect in Settings → Connections. Ask ChatGPT about your notes again: the request is refused until you sign in and allow it again.
What this is good for
Once the boundaries are clear, the use is simple. You capture by voice when the thought happens. Later, ChatGPT can search and read those notes as source material: group a week of ideas, find where you contradicted yourself, pull the to-dos out of twenty rambling recordings. Your notes stay as you said them; what ChatGPT makes from them stays in the chat.
Next step
Set it up in five minutes, then open Settings → Connections and confirm what you just read.
Setup guide for ChatGPT, Claude and coding agents: https://speakpen.app/connect
Top comments (1)
Some comments may only be visible to logged-in visitors. Sign in to view all comments.