Why we will not release software for Windows

Microsoft asked Rope Notes to accept responsibility for model output from inference services it does not operate or control. We will not add a reporting mechanism that promises a remedy we cannot provide.

We will not publish Rope Notes, or future products from this company, for Windows.

This is not a technical limitation. We refuse to mislead our users to pass Microsoft's compliance review.

We submitted Rope Notes to the Microsoft Store. In our certification correspondence, Microsoft applied its live generative AI policy because the app can display output from a model. The reviewer told us to add a way for users to report that output and to restrict the product on that basis.

We rejected those demands.

Rope Notes does not provide inference

Rope Notes is a client and an agentic workspace. You choose the model endpoint. That endpoint can be a hosted provider, a private server, or a model running on your own computer.

We do not operate an inference service. When a customer uses a local or private endpoint, our company does not receive the prompts or responses. We cannot remotely inspect output from a model running on a customer's machine, change that model, suspend it, or remove its output from someone else's system.

A report button would suggest that we can investigate the reported output and correct its source. In many configurations, we cannot do either. Accepting reports anyway would create the appearance of a safety process without the power needed to run one.

It would also create a new privacy problem. A useful report could contain model output, prompts, source code, file paths, or other project context. Rope Notes is designed to let users keep that material on hardware and infrastructure they control. We will not build a collection channel merely to satisfy a store review.

Microsoft's rule ignores who controls the model

The applicable rule is section 11.16 of the Microsoft Store Policies, version 7.19. It applies to products that contain dynamic content created by generative AI models in response to user input. The rule requires disclosure, an in-product reporting mechanism, and "appropriate actions" from the developer after a report.

Those duties make sense when the developer provides the model or operates the service. The developer can review a report, change a system prompt or filter, retrain a model, block an account, or remove hosted content.

Microsoft's policy does not distinguish that service from a general-purpose client connected to infrastructure chosen by the user. It assigns responsibility according to where output appears, not according to who generated it or who can change the system that produced it.

That is the category error at the center of this dispute.

Microsoft's own Store rules require accurate representation and prohibit misleading customers. We agree with that principle. A control labeled as a safety report would be misleading if the recipient has no access to the model and no authority over its output.

We will not pretend to govern a user's computer

We could add a button, send an automatic acknowledgment, and close each report with a canned response. That might satisfy a literal reading of the checklist. It would not make anyone safer.

We could also restrict every model connection to services we control. That would solve Microsoft's accountability problem by destroying the reason Rope Notes exists. Users would lose local inference, private endpoints, provider choice, and control over where their code goes.

We will do neither.

Rope Notes will keep honest boundaries. The app is responsible for its editor, tools, permissions, and execution paths. A model provider is responsible for the model service it operates. A person who runs a model locally controls that model and its data. We will describe those boundaries plainly instead of claiming authority we do not have.

The hypocrisy is hard to miss

Microsoft distributes its own AI products through Windows itself. Its current setup documentation says that new Windows 11 PCs should include Copilot by default and place it on the taskbar or Start menu. Microsoft can ship that product. We reject its decision to treat an independent client as though it has the same control over inference that Microsoft has over its own service and operating system.

Recall makes the double standard harder to ignore.

On May 3, 2024, Satya Nadella told Microsoft employees to prioritize "security above all else". The statement followed a U.S. Cyber Safety Review Board investigation that found Microsoft's security culture "inadequate". Seventeen days later, Microsoft announced Recall as a way to find almost anything a user had seen on a PC through a searchable collection of screen snapshots.

The first Recall design did not match the sensitivity of the archive it created. Independent testing found that Recall stored OCR text in a readily searchable local SQLite database. Malware running in the user's context could copy that database and transfer the user's recorded activity elsewhere. Ars Technica independently reproduced the exposure, and the TotalRecall proof of concept automated extraction of the captured data.

Microsoft changed the design after researchers and users objected. On June 7, 2024, Microsoft announced that Recall would become opt-in, require Windows Hello, use just-in-time decryption, and encrypt its search index. In September, Microsoft described a further redesign using TPM-backed keys and VBS enclaves. Those protections are substantial. They also show how much protection the original design lacked.

In December 2024, Tom's Hardware tested the enabled sensitive-information filter and found that Recall still captured test credit-card details, credentials, and a Social Security number in several ordinary contexts. Microsoft's current documentation says that the filter helps prevent sensitive captures. It does not promise that the filter catches all of them.

Signal had to defend its private conversations from capture by the operating system. In May 2025, Signal enabled Screen Security by default on Windows 11 to stop Recall from capturing those conversations. Signal reported that Windows offered no suitable granular privacy API, so it used a DRM screen-capture flag instead. That workaround also blocks legitimate screenshots and may interfere with accessibility software.

Microsoft says that Recall snapshots remain on the device and are not automatically uploaded to Microsoft. We will describe that claim accurately. Local storage does not make the design safe. Researchers proved that the original archive could be exfiltrated by malware, later testing found gaps in sensitive-data filtering, and Signal concluded that an encrypted messaging app had to hide its own window from the operating system.

Microsoft combines data from its own AI service with advertising and personalization, subject to settings that users can change. Microsoft's current consumer Copilot privacy controls say that people without a Microsoft 365 subscription may see ads selected from the current conversation. Personalized ads may use chat history, saved Copilot memories, and other permitted Microsoft data. The same page says that Copilot activity can personalize Bing, Edge, and MSN, while activity in those products can personalize Copilot.

Microsoft therefore understands that control, data custody, and product boundaries matter. Yet its Store review assigned Rope Notes responsibility for output from models that can run outside our servers and accounts, with no remote access by our company.

Calling that "responsible AI" does not fix the mismatch. It shifts responsibility to the party with the least control and asks that party to present a reporting process that cannot deliver the implied remedy.

This is a platform decision

Microsoft can set the terms of the Microsoft Store. We can refuse those terms.

We will not route around the dispute by offering a separate Windows download. Supporting an operating system is a long-term relationship. It requires packaging, testing, updates, security work, and confidence that the platform owner will not later demand product behavior we consider misleading. That confidence is gone.

This decision will disappoint people who use Windows. The decision is not a judgment of them. It is a judgment about the platform owner and the conditions under which Microsoft expects independent software to operate.

Rope Notes will remain available on platforms where we can state what the product does, preserve the user's control over inference, and stand behind every safety and privacy promise we make.

We would rather lose a market than promise a remedy we cannot provide. Microsoft can keep Windows.