Version of 3 October 2026
This is an earlier version of our Privacy Policy, published on 3 October 2026. It applied to every account from 3 October 2026 to 9 October 2026. The current version is here, and every version is listed here.
This page says what TeXType knows about you, where it keeps it, who can see it, and how to make it go away. There is no advertising, no tracking across sites, and nothing is sold or shared for advertising. Your documents are yours: we look at one only for the few reasons listed under “Who can see what”, and we never use them to train AI models.
TeXType is run by TEXTYPE LLC, a Massachusetts limited liability company (“we”, “us”). We are responsible for the information described here (under European law, the “controller”). This policy covers textype.io and everything it offers (our “Services”).
You can reach us at hello@textype.io, or by post at TEXTYPE LLC, 82 Wendell Ave, Suite 100, Pittsfield, MA 01201, U.S.A.
Your account. When you sign in with Google, GitHub or Microsoft, we receive and store your email address and your name, from Google and GitHub the address of your profile picture, and we note when the account was created. From GitHub, the address is your primary one, and only if GitHub has verified it; if your GitHub profile has no name, your GitHub username is used as your name. From Microsoft, the address is used only if Microsoft confirms it: a personal Microsoft account’s always, and a work or school account’s only when the organisation has proven it owns the address. We keep no access to your GitHub or Microsoft account afterwards. Nothing else from your Google, GitHub or Microsoft account is requested. If you sign in with more than one using the same email address, they reach the same account.
Your projects. The files in each project, every saved version of them, and the comments and suggestions made on them. Each version records who made it, by name and email address, and when. Text deleted from a file stays in the project’s version history, so it can be restored. Each project’s last compiled PDF and its log are kept with it. Comments and suggestions are kept with the project but not in its version history, so restoring an earlier version of the text does not change them. Their past shapes from the last 30 days, and at least the 20 most recent whatever their age, are kept so a wiped conversation can be put back. Comments and suggestions made before 26 September 2026 were also saved in the version history, and stay there.
Who is in a project. Which projects you own, which you’ve been invited to and with what role, the invitations you’ve sent, and the invite links an owner has made. When you join a project through an invitation, your email address is recorded as admitted, so you can sign in again later.
Your plan and payments. Which plan you’re on and until when, the Stripe customer number that links your account to your subscription, and what Stripe tells us about the subscription: its price, when it started, when it renews, and any discount and when it ends. Your card details go to Stripe and never reach us.
A request for an account, if you made one. Before anyone could sign up, people could ask for an account. For a request, we hold the name and email address the sign-in provider confirmed, which provider it was, the note added, when it was made, and the network address it came from (to slow down automated requests).
Messages you send us. What you write through the support page or by email, the address to reply to, the topic, and the network address it came from (to slow down automated messages).
Refunds and bank disputes. When a payment is refunded or disputed with your bank, a record of it, so the refund rules in our Terms can be applied.
Interest in Pro. If you press “Upgrade to Pro” when you can’t subscribe yet, we note that you did and whether monthly or yearly, so we can tell you when you can.
What you’ve seen. For each project, when you last looked at its comments and suggestions, so the list can tell you what’s new.
A git mirror, if an owner sets one up. The repository address and the access token provided. The token is stored encrypted and never shown again, and it’s used only to sync with the repository chosen: to check which account it belongs to and when it expires, to list the repositories it can reach, to test the connection, to push the project, and to pull changes back. Commits pulled from the repository bring their authors’ names and email addresses into the project’s history, including people who don’t use TeXType.
A reference manager, if you link one. Your Zotero API key, or the token Mendeley issues when you sign in there, stored encrypted and never shown again, and your name on that service. It is used only to read the libraries it can reach: to list them, and to import or refresh a bibliography you or your collaborators keep in a project. The entries imported become part of that project.
Access tokens, if you make them. The name you give each, the project it reaches, what it may do, when it expires, and when and from which network address it was last used. The token itself is shown to you once and kept only in a form that cannot be turned back into it; its first characters are kept so you can tell it apart.
Security events. When something looks wrong, such as repeated refused requests from one address or an account used from many addresses at once, we record what happened, the account involved and the network address, and keep it for 90 days to investigate. Administrators’ actions are recorded the same way.
Server logs. Each request to the server is logged with its network address, for security and troubleshooting.
In your browser. Your colour theme, how the projects table is arranged, the sizes of the editor’s panes, and which files you had open live in your browser’s local storage, not on our server. So does text you type while the connection is down, until it reaches the server; signing out removes it from that browser. On a shared computer, sign out when you finish. Whether you’ve seen the walkthrough is stored with your account.
We use this information to run TeXType and for nothing else: to sign you in, show you your projects, let the people in a project see each other’s edits and names, compile your documents, keep their history, bill for Pro, email you about your account, keep the service secure, and back all of it up. When a compile runs, your files are sent to a compiler with no network access, which returns the PDF. It keeps a temporary in-memory cache of recently compiled files, overwritten as it fills and erased when it restarts.
We may scan files uploaded to TeXType, automatically, for malware and for content that breaks our Terms, to protect the people who open them and the service. Today, nothing scans them. If we start, we’ll say so here, and if a provider does the scanning for us, we’ll add it to the list below. A person looks at a file a scan flags only as “Who can see what” describes.
We don’t use your documents to train AI models, don’t build advertising profiles, and don’t send marketing email.
Legal bases (EEA, UK and Switzerland). We use your information because it’s necessary to provide the Services you asked for under our Terms (everything above, including billing); because we have a legitimate interest in keeping TeXType secure and working (security events, logs, backups, error reports); and where the law requires it (for example, keeping records of payments).
We share information with the providers and services below, and in the other cases this section lists.
Providers that work for us. Each handles information only to provide its service to us, under its terms with us:
Services you use alongside TeXType, under their own policies. These decide for themselves what they do with what they receive, under their own privacy policies:
The people in your projects see what the next sections describe.
We’ll disclose information if the law requires it, and will tell you when we’re allowed to. If TEXTYPE LLC is ever sold or merged, your information would pass to the new owner under this policy, and we’d tell you first.
Where it’s stored. Everything we hold is stored in the United States. If you use TeXType from another country, what you send comes to us there.
TeXType sets two cookies, both its own. One keeps you signed in: it expires after 12 hours without activity and after 7 days regardless. The other lasts only for the few minutes it takes to complete a sign-in with Google, GitHub or Microsoft. There are no advertising or cross-site cookies. If Cloudflare ever challenges a request that looks automated, it may set a short-lived cookie of its own to remember that you passed. Stripe’s checkout and billing pages are on Stripe’s own site, under its cookie policy.
The people in a project see its contents, its history, and the names and email addresses of the others in it. An invite link admits anyone who has it, for 30 days or until an owner revokes it, so whoever an owner gives one to can join and see the project too. If an owner mirrors a project to a git host, whoever that repository is visible to there can see what is pushed. Otherwise, nobody outside a project can see into it.
We can access the server and the database in order to run them. Most of what happens to your documents is automatic: the compiler turns them into PDFs, and limits on compile time and storage are enforced without anyone reading your work. A person at TeXType looks at the contents of a specific project only:
We only look at that which is required to address the issues directly above. We do not look at the contents of your work for any other purpose.
No online service is perfectly secure, but we work hard to protect your information, and our Security page describes exactly how: from encryption and backups to monitoring and how we respond to incidents. If a breach affects your information, we’ll tell you within 72 hours of confirming it, with what happened and what you can do, and tell the authorities where the law requires it.
Everything is kept for as long as your account exists, except as listed here. While it exists:
When you delete your account:
Wherever you live, you can:
People in the EEA, the UK and Switzerland have these as legal rights, along with the rights to object to or restrict our use of their information, and to complain to their data protection authority. Residents of U.S. states with privacy laws have similar rights, including not being treated differently for using them. We don’t sell or share personal information for advertising, so there’s nothing to opt out of. We give everyone the same rights, whether or not a law requires it.
We answer requests within 30 days, and may need to confirm it’s you first (usually by replying from the email address on your account). If we turn a request down, we’ll say why, and you can ask us to reconsider by replying to that email.
Our Services are not directed to children. You’re not allowed to access or use our Services if you’re under the age of 13 (or 16 in Europe), and we don’t knowingly collect or hold personal information about anyone under those ages. If you think we do, tell us and it will be removed. If you’re under 18 years of age (or the legal age of majority where you live), you can only use our Services under the supervision of a parent or legal guardian who agrees to our Terms of Service.
We may change this policy, for example when the Services or the law change. When we do, the date at the top will move, and we keep the earlier version, which we’ll send you if you ask. If a change matters, we’ll also tell you at least 30 days before it takes effect, by email and on the sign-in page.
This policy’s structure and parts of its text are adapted from Automattic’s Privacy Policy, used under the Creative Commons Attribution-ShareAlike 4.0 license, and have been changed substantially. This page is available under the same license.