Privacy Policy
Last updated: December 2025
1. Overview
Thetapad is designed with privacy in mind. Your documents are stored locally in your browser by default, giving you full control over your data.
2. Data We Collect
Local Storage: Your LaTeX documents and projects are stored in your browser's IndexedDB. This data never leaves your device unless you explicitly sync or export.
Account Data: When you sign in with Google or GitHub, we collect:
- Email address (for authentication and account recovery)
- Name (for personalization)
- Profile picture URL (for display purposes)
Usage Data: We may collect anonymous usage statistics to improve the service. This does not include document content or personal information.
3. Legal Basis for Processing (GDPR)
We process your data based on:
- Contract: To provide the service you signed up for
- Legitimate Interest: To improve our service and prevent abuse
- Consent: For optional features like analytics (when applicable)
4. Data Retention
Local Data: Stored indefinitely in your browser until you clear it.
Account Data: Retained while your account is active. Upon account deletion, your data is permanently removed within 30 days.
Logs: Server logs are retained for 90 days for security and debugging purposes.
5. Your Rights (GDPR)
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Delete your account and associated data
- Portability: Export your data in a machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to certain processing activities
To exercise these rights, contact us via our GitHub repository or delete your account through the settings page.
6. Cookies
We use essential cookies for:
- Authentication session management
- Security (CSRF protection)
These cookies are strictly necessary for the service to function and do not require consent under GDPR.
7. Third-Party Services
We integrate with:
- GitHub: For repository sync (optional, subject to GitHub's privacy policy)
- Google: For authentication (subject to Google's privacy policy)
- Vercel: For hosting (subject to Vercel's privacy policy)
8. Data Security
We implement industry-standard security measures including:
- HTTPS encryption for all data in transit
- Secure authentication via OAuth 2.0
- Rate limiting to prevent abuse
- Regular security updates
9. Children's Privacy
Thetapad is not directed at children under 13. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this policy from time to time. Significant changes will be announced via the application or email.
11. Contact
For privacy-related questions or to exercise your rights, please open an issue on our GitHub repository.