TeXTypeTeXType
AboutPricingFAQ
Sign inStart free

Privacy Policy

Version of 3 October 2026

This is an earlier version of our Privacy Policy, published on 3 October 2026. It applied to every account from 3 October 2026 to 9 October 2026. The current version is here, and every version is listed here.

This page says what TeXType knows about you, where it keeps it, who can see it, and how to make it go away. There is no advertising, no tracking across sites, and nothing is sold or shared for advertising. Your documents are yours: we look at one only for the few reasons listed under “Who can see what”, and we never use them to train AI models.

Who we are and what this policy covers

TeXType is run by TEXTYPE LLC, a Massachusetts limited liability company (“we”, “us”). We are responsible for the information described here (under European law, the “controller”). This policy covers textype.io and everything it offers (our “Services”).

You can reach us at hello@textype.io, or by post at TEXTYPE LLC, 82 Wendell Ave, Suite 100, Pittsfield, MA 01201, U.S.A.

What we hold

Your account. When you sign in with Google, GitHub or Microsoft, we receive and store your email address and your name, from Google and GitHub the address of your profile picture, and we note when the account was created. From GitHub, the address is your primary one, and only if GitHub has verified it; if your GitHub profile has no name, your GitHub username is used as your name. From Microsoft, the address is used only if Microsoft confirms it: a personal Microsoft account’s always, and a work or school account’s only when the organisation has proven it owns the address. We keep no access to your GitHub or Microsoft account afterwards. Nothing else from your Google, GitHub or Microsoft account is requested. If you sign in with more than one using the same email address, they reach the same account.

Your projects. The files in each project, every saved version of them, and the comments and suggestions made on them. Each version records who made it, by name and email address, and when. Text deleted from a file stays in the project’s version history, so it can be restored. Each project’s last compiled PDF and its log are kept with it. Comments and suggestions are kept with the project but not in its version history, so restoring an earlier version of the text does not change them. Their past shapes from the last 30 days, and at least the 20 most recent whatever their age, are kept so a wiped conversation can be put back. Comments and suggestions made before 26 September 2026 were also saved in the version history, and stay there.

Who is in a project. Which projects you own, which you’ve been invited to and with what role, the invitations you’ve sent, and the invite links an owner has made. When you join a project through an invitation, your email address is recorded as admitted, so you can sign in again later.

Your plan and payments. Which plan you’re on and until when, the Stripe customer number that links your account to your subscription, and what Stripe tells us about the subscription: its price, when it started, when it renews, and any discount and when it ends. Your card details go to Stripe and never reach us.

A request for an account, if you made one. Before anyone could sign up, people could ask for an account. For a request, we hold the name and email address the sign-in provider confirmed, which provider it was, the note added, when it was made, and the network address it came from (to slow down automated requests).

Messages you send us. What you write through the support page or by email, the address to reply to, the topic, and the network address it came from (to slow down automated messages).

Refunds and bank disputes. When a payment is refunded or disputed with your bank, a record of it, so the refund rules in our Terms can be applied.

Interest in Pro. If you press “Upgrade to Pro” when you can’t subscribe yet, we note that you did and whether monthly or yearly, so we can tell you when you can.

What you’ve seen. For each project, when you last looked at its comments and suggestions, so the list can tell you what’s new.

A git mirror, if an owner sets one up. The repository address and the access token provided. The token is stored encrypted and never shown again, and it’s used only to sync with the repository chosen: to check which account it belongs to and when it expires, to list the repositories it can reach, to test the connection, to push the project, and to pull changes back. Commits pulled from the repository bring their authors’ names and email addresses into the project’s history, including people who don’t use TeXType.

A reference manager, if you link one. Your Zotero API key, or the token Mendeley issues when you sign in there, stored encrypted and never shown again, and your name on that service. It is used only to read the libraries it can reach: to list them, and to import or refresh a bibliography you or your collaborators keep in a project. The entries imported become part of that project.

Access tokens, if you make them. The name you give each, the project it reaches, what it may do, when it expires, and when and from which network address it was last used. The token itself is shown to you once and kept only in a form that cannot be turned back into it; its first characters are kept so you can tell it apart.

Security events. When something looks wrong, such as repeated refused requests from one address or an account used from many addresses at once, we record what happened, the account involved and the network address, and keep it for 90 days to investigate. Administrators’ actions are recorded the same way.

Server logs. Each request to the server is logged with its network address, for security and troubleshooting.

In your browser. Your colour theme, how the projects table is arranged, the sizes of the editor’s panes, and which files you had open live in your browser’s local storage, not on our server. So does text you type while the connection is down, until it reaches the server; signing out removes it from that browser. On a shared computer, sign out when you finish. Whether you’ve seen the walkthrough is stored with your account.

How and why we use it

We use this information to run TeXType and for nothing else: to sign you in, show you your projects, let the people in a project see each other’s edits and names, compile your documents, keep their history, bill for Pro, email you about your account, keep the service secure, and back all of it up. When a compile runs, your files are sent to a compiler with no network access, which returns the PDF. It keeps a temporary in-memory cache of recently compiled files, overwritten as it fills and erased when it restarts.

We may scan files uploaded to TeXType, automatically, for malware and for content that breaks our Terms, to protect the people who open them and the service. Today, nothing scans them. If we start, we’ll say so here, and if a provider does the scanning for us, we’ll add it to the list below. A person looks at a file a scan flags only as “Who can see what” describes.

We don’t use your documents to train AI models, don’t build advertising profiles, and don’t send marketing email.

Legal bases (EEA, UK and Switzerland). We use your information because it’s necessary to provide the Services you asked for under our Terms (everything above, including billing); because we have a legitimate interest in keeping TeXType secure and working (security events, logs, backups, error reports); and where the law requires it (for example, keeping records of payments).

Where it lives, and who else handles it

We share information with the providers and services below, and in the other cases this section lists.

Providers that work for us. Each handles information only to provide its service to us, under its terms with us:

  • The server is a virtual machine on Amazon Web Services in the United States. All account and project data is there.
  • Cloudflare sits in front of it and handles the connection, so it sees your network address and the pages you request. It also provides our page-view counts, using a script that sets no cookies and doesn’t identify you, and passes email sent to hello@textype.io on to our mailbox.
  • Backups are taken nightly, encrypted with a key that is kept offline and never on any server, and stored with Backblaze in the United States. We keep the last 14 nightly copies and the last 6 monthly ones. Amazon Web Services also keeps a daily snapshot of the server for 7 days.
  • Server logs are copied off the server every hour, encrypted the same way, and deleted after 30 days, the copies included.
  • Errors and security alerts are reported to Sentry so that they get fixed. An error report contains what went wrong and where in the code, the page you were on, your browser type, and your network address. A security alert contains what happened, the account involved and the network address. Neither ever contains the contents of a document.
  • Email we send (about your account, your subscription or payments, your access, your projects, or a support message reaching us) goes through Resend, in the United States, which handles the message and its addresses to deliver it.
  • Google hosts our mailbox: email to hello@textype.io, including messages from the support page, reaches a Gmail inbox, where we read and answer it.

Services you use alongside TeXType, under their own policies. These decide for themselves what they do with what they receive, under their own privacy policies:

  • Stripe, in the United States, handles payments for Pro, and Pro is sold to you through Link, Stripe’s payment service, as the merchant of record. They keep their own records of payments and invoices, as the law requires of them.
  • Your sign-in provider (Google, GitHub or Microsoft) confirms who you are when you sign in with it.
  • A git host. If an owner mirrors a project to GitHub or another git host, a copy of it, including its history and everyone’s commit names and addresses, goes to that host under whatever terms the owner has with them.

The people in your projects see what the next sections describe.

We’ll disclose information if the law requires it, and will tell you when we’re allowed to. If TEXTYPE LLC is ever sold or merged, your information would pass to the new owner under this policy, and we’d tell you first.

Where it’s stored. Everything we hold is stored in the United States. If you use TeXType from another country, what you send comes to us there.

Cookies

TeXType sets two cookies, both its own. One keeps you signed in: it expires after 12 hours without activity and after 7 days regardless. The other lasts only for the few minutes it takes to complete a sign-in with Google, GitHub or Microsoft. There are no advertising or cross-site cookies. If Cloudflare ever challenges a request that looks automated, it may set a short-lived cookie of its own to remember that you passed. Stripe’s checkout and billing pages are on Stripe’s own site, under its cookie policy.

Who can see what

The people in a project see its contents, its history, and the names and email addresses of the others in it. An invite link admits anyone who has it, for 30 days or until an owner revokes it, so whoever an owner gives one to can join and see the project too. If an owner mirrors a project to a git host, whoever that repository is visible to there can see what is pushed. Otherwise, nobody outside a project can see into it.

We can access the server and the database in order to run them. Most of what happens to your documents is automatic: the compiler turns them into PDFs, and limits on compile time and storage are enforced without anyone reading your work. A person at TeXType looks at the contents of a specific project only:

  • when you ask us to help with a problem in it;
  • to investigate abuse, an attack on the service, or a breach of our Terms (for example, a document built to break out of the compiler’s sandbox, or a file a scan flagged);
  • when it’s needed to keep the service working for everyone (for example, a project whose compiles keep exhausting the compiler); or
  • when the law requires it.

We only look at that which is required to address the issues directly above. We do not look at the contents of your work for any other purpose.

Security

No online service is perfectly secure, but we work hard to protect your information, and our Security page describes exactly how: from encryption and backups to monitoring and how we respond to incidents. If a breach affects your information, we’ll tell you within 72 hours of confirming it, with what happened and what you can do, and tell the authorities where the law requires it.

How long we keep it

Everything is kept for as long as your account exists, except as listed here. While it exists:

  • a project moved to the trash can be restored by any of its owners for 30 days, and is then deleted for good;
  • a project’s version history, including text later deleted from its files, is kept for as long as the project exists;
  • past shapes of a project’s comments and suggestions are kept for 30 days, and at least the 20 most recent of each kind are kept whatever their age;
  • a request for an account is deleted 12 months after it was made, or when you delete your account, whichever comes first;
  • security events expire after 90 days and logs after 30.

When you delete your account:

  • your account record is deleted immediately, and so are the projects you own, unless they have another owner, who becomes their owner;
  • projects in your trash with no other owner are deleted at once, without waiting for the 30 days;
  • when a project with other members is deleted, we email them to say so;
  • you’re removed from every project you were invited to, and any Pro subscription is cancelled;
  • your name and email address remain on the versions you made in other people’s projects, because their history has to stay whole, and your name stays on the comments and suggestions you made in them;
  • messages you sent through the support page are kept for at least three years, and deleted from our systems after four; email correspondence with us stays in our mailbox for as long as we need it to help you;
  • records of refunds and bank disputes are kept for at least three years, so the refund rules in our Terms can be applied and our accounts kept; after that we review them and delete what we no longer need;
  • server snapshots age out after 7 days, and backups on the schedule above, so the last trace is gone within 6 months;
  • Stripe keeps its payment records for as long as the law requires of it;
  • any copy pushed to a git mirror stays with that host; deleting or keeping it is up to whoever controls the repository.

Your choices and your rights

Wherever you live, you can:

  • Take your data. Every project can be downloaded as a zip of its source at any time, and its full history mirrored to a git repository you control.
  • See or correct it. Write to hello@textype.io for a copy of everything we hold about you, or to correct it.
  • Delete it. Delete your account from your account page (it asks you to type your email address), or ask us to.
  • Disconnect a mirror. Removing the mirror from a project’s sync settings deletes the stored token. You can also revoke the token at the host that issued it.
  • Disconnect a reference manager. Disconnecting Zotero or Mendeley on your account page deletes the stored key. You can also revoke it at zotero.org or in your Mendeley account.
  • Revoke a sign-in service’s connection: from your Google account’s security settings; on GitHub under Settings → Applications → Authorized GitHub Apps; or for Microsoft at myapps.microsoft.com (work or school accounts) or account.live.com/consent/Manage (personal ones). You won’t be able to sign in that way again until you reconnect.

People in the EEA, the UK and Switzerland have these as legal rights, along with the rights to object to or restrict our use of their information, and to complain to their data protection authority. Residents of U.S. states with privacy laws have similar rights, including not being treated differently for using them. We don’t sell or share personal information for advertising, so there’s nothing to opt out of. We give everyone the same rights, whether or not a law requires it.

We answer requests within 30 days, and may need to confirm it’s you first (usually by replying from the email address on your account). If we turn a request down, we’ll say why, and you can ask us to reconsider by replying to that email.

Children

Our Services are not directed to children. You’re not allowed to access or use our Services if you’re under the age of 13 (or 16 in Europe), and we don’t knowingly collect or hold personal information about anyone under those ages. If you think we do, tell us and it will be removed. If you’re under 18 years of age (or the legal age of majority where you live), you can only use our Services under the supervision of a parent or legal guardian who agrees to our Terms of Service.

Changes

We may change this policy, for example when the Services or the law change. When we do, the date at the top will move, and we keep the earlier version, which we’ll send you if you ask. If a change matters, we’ll also tell you at least 30 days before it takes effect, by email and on the sign-in page.

This policy’s structure and parts of its text are adapted from Automattic’s Privacy Policy, used under the Creative Commons Attribution-ShareAlike 4.0 license, and have been changed substantially. This page is available under the same license.

TeXTypeTeXType© 2026 TEXTYPE LLC, Massachusetts
ProductAboutPricingFAQ
TrustSecurityPrivacyTerms
HelpSupporthello@textype.io