Last updated: August 1, 2026
Privacy Policy
PaperDock is a web LaTeX workspace for collaborative research writing. This policy explains how we handle information when you use paperdock.dev, the PaperDock web app, collaboration tools, LaTeX compilation, and AI agent integrations through MCP.
Public Website Communications
The public website can open your email app when you request product updates or send feedback. We receive the email address and message content only when you choose to send that email. Browsing the public website does not require a PaperDock account.
Account Information
When you create an account or sign in to the web app, we may process your email address, authentication provider information, account identifier, profile details, session data, and basic account metadata needed to authenticate you and operate your account.
Project and Collaboration Content
PaperDock stores and processes the project files, assets, project metadata, document revisions, comments, comment replies, chat messages, collaborator and invitation details, and other content you create, upload, or share in a web workspace. Project members can access this information according to their assigned roles and permissions.
When you compile a project, PaperDock may process the selected source revision and store compilation status, logs, PDFs, SyncTeX data, and related artifacts needed to provide and troubleshoot compilation.
AI Agent and MCP Information
When you connect an AI agent through MCP, PaperDock may process authorization metadata, permission scopes, token hashes, tool requests, change proposals, and records needed to apply or review agent actions. Agent access is limited by the connected account's current project role, granted scopes, and PaperDock's safety controls.
An AI agent or MCP client you choose may receive project information that you authorize it to read or modify. That provider processes information under its own terms and privacy policy, so review its settings before connecting it to a PaperDock account or project.
PaperDock minimizes MCP tool responses to information needed for the requested action. Connection checks do not return account profile identity. Collaboration responses label authors as a person or AI agent without returning collaborator names, email addresses, or internal user identifiers. Internal storage paths and raw database records are not returned. Short-lived asset and PDF links are provided only when a tool explicitly reads that asset or compile result.
Technical Information
We may process request metadata, timestamps, browser and device information, error and diagnostic details, rate-limit events, and security signals to keep PaperDock reliable, investigate failures, and prevent abuse. We aim to redact credentials and other secrets from diagnostic data.
How We Use Information
We use information to authenticate users; provide projects, collaboration, version history, compilation, invitations, and agent integrations; respond to support and update requests; improve reliability; enforce permissions and limits; and protect PaperDock and its users. We do not sell your personal information.
How Information Is Shared
We share project information with collaborators you or a project owner authorize and with AI agents or integrations you choose to connect. We may also disclose information when required by law or when reasonably necessary to protect users, PaperDock, or the public.
Service Providers
PaperDock uses service providers for hosting, authentication, databases, storage, realtime collaboration, email delivery, and security. These may include Cloudflare, Supabase, Resend, and authentication providers such as GitHub. Optional reference integrations and user-selected AI agents or MCP clients process information under their own terms and policies.
Data Retention and Deletion
The periods below describe PaperDock's current application database and storage cleanup rules. When a period ends, the affected data becomes eligible for scheduled cleanup; deletion work may complete after that point. Service-provider backups and infrastructure security logs may age out under the provider's own operational schedule.
Account information. Authentication details, account settings, and account-level usage records are retained while your account remains active. When an account is deleted, account-scoped settings and credentials linked to it are deleted, and projects owned by that account are deleted. Content contributed to a project owned by someone else may remain as part of that shared project, with the deleted account's author reference removed where the database relationship is designed to preserve shared history.
Project and collaboration content. Project files, binary assets, memberships, invitations, comments, replies, chat messages, and related project metadata are retained while the project exists. When a project owner deletes a project, PaperDock removes its active database records and queues the project's stored assets and compile artifacts for deletion.
Document version history. Current file content remains while the file and project exist. General visible history is kept for up to 30 days and up to 30 checkpoints per file. Compile-related history is kept for up to 7 days and up to 10 checkpoints per file. Operational revision updates are compacted on a 7-day window. The most recent visible checkpoint may remain as a recovery point, and deleting the file or project removes its associated revision records.
Compilation logs, PDFs, and artifacts. Full compile input snapshots are cleared when a job reaches a terminal state. Successful compile logs are retained for 24 hours; failed, canceled, or expired logs are retained for 72 hours. Older successful PDF and SyncTeX results are limited to the three most recent results and a 7-day window. The latest successful PDF and SyncTeX result may remain until a newer successful result is created or the project is deleted. Terminal compile job metadata is retained for 30 days, except that the latest successful job may remain until it is replaced or the project is deleted.
MCP OAuth tokens and approval information. PaperDock stores token hashes, not raw MCP access or refresh tokens. OAuth authorization codes expire after 10 minutes, and their records become eligible for daily cleanup after they have been expired for one day. Account-switch approval intents expire within 15 minutes and are deleted with their linked source token or account. Access tokens expire after one hour. Refresh tokens rotate on use and expire after 90 days of inactivity. Disconnecting or revoking a connection invalidates its token family; expired or revoked access and refresh token records become eligible for cleanup 30 days after expiration or revocation. Deleting the account also deletes its linked OAuth codes and token records.
Security and usage records. Project synchronization events are retained for up to 30 days. Detailed compile request metric events are retained for the latest eight UTC days. Hash-only API rate-limit buckets become eligible for cleanup one day after their rate-limit window expires. PaperDock also keeps daily aggregate compile and MCP tool counts that contain no user, project, token, request argument, project content, or error-detail fields. The current application schema does not assign a fixed expiry to these anonymous aggregate totals, so they may remain after an account or project is deleted.
You can delete projects you own through PaperDock, disconnect or revoke an MCP connection through the connected client or PaperDock's OAuth revocation flow, and contact us at [email protected] to request account or personal data deletion. A project member who is not the owner can ask the project owner to remove shared project content or membership.
Security
We use reasonable technical and organizational safeguards, including access controls and permission checks, to protect information. No online service can guarantee absolute security. Keep your account and connected-agent credentials secure, and grant project access only to people and services you trust.
Changes to This Policy
We may update this policy as PaperDock changes. If we make material changes, we will update the date above and, when appropriate, provide additional notice.
Contact
For privacy questions or data requests, contact PaperDock at [email protected].