← Back to MechatronicSurge Live · iPhone + Web + MCP

Synapstack OS

A personal journaling system with an API. Capture on the phone, review on the web, and let an AI assistant read and write the same entries — no export step, no copy-paste.

Why it exists

Journals are write-only. That's the bug.

Years of notes are worth nothing if the only way to use them is scrolling. Synapstack OS treats the journal as a database with a proper API, then hands an AI assistant a scoped key to it. Ask a question in Claude and it searches the actual entries. Tell it something worth keeping and it writes the entry itself.

Synapstack OS iPhone app
iPhone app assets/images/synapstack-app.png
Synapstack OS web companion
Web companion assets/images/synapstack-web.png
Architecture

Three clients, one edge backend

Everything lands in the same D1 database. The MCP server is a second Worker with its own auth, so an AI client never touches the app's session.

CLIENTS iPhone app Expo · React Native Web companion Static SPA Claude / MCP client Desktop · web · mobile CLOUDFLARE EDGE synapstack-api REST + sync engine invite code · Google · Apple synapstack-mcp Streamable HTTP · OAuth 7 tools · no delete STORAGE D1 entries · tags · people R2 photos · media session auth oauth 2.1 + pkce Apple Journaling Suggestions picker ships as a local Swift module inside the iPhone app. WAF rate limiting sits in front of the auth endpoint. No secret is ever committed to the repo. Diarium importer backfills years of existing journal history into D1.
MCP Surface

Seven tools, and deliberately not an eighth

Read tools work with a read-only grant. Write tools require read-write. There is no delete tool in v1 — an agent that can't delete can't quietly erase a decade of entries during a bad reasoning chain.

search_entries
Full-text and semantic search across every entry
get_entry
Pull one entry in full, by id
list_entries
Browse by date range, tag, or person
list_tags
Enumerate the tag and people vocabulary
create_entry
Write a new entry — read-write grant only
append_to_entry
Add to today without clobbering what's there
update_entry
Revise an existing entry in place
Engineering Notes

Decisions worth defending

Secrets never touch the repo

The working tree lives in OneDrive, so a committed .env would sync straight to someone else's cloud. Worker tokens live only in Cloudflare; API keys live only in the iOS Keychain. The rule is the point — the gitignore is just enforcement.

Auth is the app's job, not the gate's

The web companion runs its own invite code plus Google or Apple sign-in. A separate edge access gate on top of that was redundant, so it came off — with a one-click restore path kept in place.

Rate limiting at the edge and in the app

A WAF rule throttles credential hammering at the door. The real fix — failed-attempt lockout with exponential backoff — belongs in the Worker, where there are no plan limits on the counter.

One database, many front doors

Phone, browser, and AI assistant all read the same D1 rows through the same sync engine. Nothing is a mirror or an export, so nothing drifts.

Status

Where it stands

Platform
iPhone (Expo SDK 57) · web companion · remote MCP server
Backend
Cloudflare Workers · D1 · R2
Availability
Private beta — running daily on the author's own journal
Next
Multi-user auth, app-side lockout, broader importer coverage
hello@mechatronicsurge.com