Privacy Policy
Last updated: April 2026
1. Introduction
Pressa ("we", "us", "our") operates the pressa.dev website and the Pressa Compile-as-a-Service platform, including the REST API, CLI tool, and MCP server (collectively, the "Service"). This Privacy Policy explains how we collect, use, and protect your information when you use our Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Username
- Hashed password (we never store plaintext passwords)
2.2 API Keys
When you generate API keys to access the compilation service, we store a cryptographic hash of each key. The full key is shown to you only once at creation time. We cannot retrieve your full API key after it has been generated.
2.3 Document Data
When you submit LaTeX source code or JSON data for compilation, this data is processed ephemerally. Source files are deleted immediately after compilation. Generated PDF files are stored temporarily and made available via signed URLs that automatically expire within 24 hours. After expiry, PDF files are permanently deleted.
2.4 Usage Data
We automatically collect:
- Compilation counts and response times
- API request metadata (endpoints called, status codes, timestamps)
- IP addresses associated with API and web requests
- Browser type and operating system (for web dashboard visits)
2.5 Billing Data
Payment processing is handled entirely by our payment provider, Polar. We do not store credit card numbers, bank account details, or other direct payment information on our servers. We may receive and store your subscription status, plan type, and billing email from Polar.
2.6 Saved Templates
Users on paid plans may save LaTeX templates to their account for reuse. When you save a template, we store its name, optional description, and LaTeX content in our database. Saved templates are accessible only via authenticated API requests owned by the same user. We retain this data until you delete the template or close your account, at which point it is permanently removed.
3. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve the compilation service
- Authenticate your identity and authorize API access
- Monitor usage against your plan limits and enforce rate limiting
- Process billing and manage subscriptions
- Send transactional emails (account verification, password resets, billing receipts)
- Detect, investigate, and prevent abuse or security incidents
- Generate aggregated, anonymized usage analytics
We do not use your submitted LaTeX source code or generated PDFs for any purpose other than fulfilling your compilation request. We do not train machine learning models on your document data.
4. Third-Party Services
We use the following third-party services that may process your data:
| Provider | Purpose | Data Shared |
|---|---|---|
| Polar | Payment processing | Email, subscription details |
| Mailgun (Sinch) | Transactional email delivery | Email address, message content |
| Sentry | Error tracking and monitoring | Error logs, IP addresses, browser metadata |
| Cloudflare | CAPTCHA verification (Turnstile), CDN | IP address, browser metadata |
Each third-party provider operates under their own privacy policy. We encourage you to review their respective policies.
5. Data Retention
- Account data: Retained until you delete your account.
- LaTeX source code: Deleted immediately after compilation completes.
- Generated PDFs: Auto-deleted within 24 hours via signed URL expiry.
- Saved templates: Retained until you delete them or close your account.
- API usage logs: Retained for up to 90 days for debugging and billing reconciliation.
- Error logs (Sentry): Retained per Sentry's default retention policy (typically 90 days).
6. Data Security
We implement the following security measures:
- All data in transit is encrypted via TLS
- API keys are stored as cryptographic hashes
- LaTeX compilation runs in isolated workspaces with no-shell-escape enabled
- Database backups are encrypted at rest
- Access to production systems is restricted and audited
7. Cookies
We use essential cookies only for authentication and session management. We do not use third-party advertising or tracking cookies. Cloudflare Turnstile may set cookies necessary for bot detection during account registration.
8. Your Rights
You have the right to:
- Access: Request a copy of your personal data.
- Correction: Update inaccurate account information via your dashboard.
- Deletion: Delete your account and all associated data.
- API key revocation: Revoke any API key at any time from your dashboard.
- Data portability: Request an export of your account data.
To exercise these rights, contact us at the email below or use the account settings in your dashboard.
9. International Data Transfers
Our servers may be located in different jurisdictions. By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence. We take reasonable steps to ensure your data is treated securely.
10. Children's Privacy
Pressa is a professional B2B service not directed at individuals under 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a minor, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on our website. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
12. Contact
Privacy questions or data requests? Contact us at [email protected]