Privacy Policy

Last updated: April 2026

1. Introduction

Pressa ("we", "us", "our") operates the pressa.dev website and the Pressa Compile-as-a-Service platform, including the REST API, CLI tool, and MCP server (collectively, the "Service"). This Privacy Policy explains how we collect, use, and protect your information when you use our Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address
  • Username
  • Hashed password (we never store plaintext passwords)

2.2 API Keys

When you generate API keys to access the compilation service, we store a cryptographic hash of each key. The full key is shown to you only once at creation time. We cannot retrieve your full API key after it has been generated.

2.3 Document Data

When you submit LaTeX source code or JSON data for compilation, this data is processed ephemerally. Source files are deleted immediately after compilation. Generated PDF files are stored temporarily and made available via signed URLs that automatically expire within 24 hours. After expiry, PDF files are permanently deleted.

2.4 Usage Data

We automatically collect:

  • Compilation counts and response times
  • API request metadata (endpoints called, status codes, timestamps)
  • IP addresses associated with API and web requests
  • Browser type and operating system (for web dashboard visits)

2.5 Billing Data

Payment processing is handled entirely by our payment provider, Polar. We do not store credit card numbers, bank account details, or other direct payment information on our servers. We may receive and store your subscription status, plan type, and billing email from Polar.

2.6 Saved Templates

Users on paid plans may save LaTeX templates to their account for reuse. When you save a template, we store its name, optional description, and LaTeX content in our database. Saved templates are accessible only via authenticated API requests owned by the same user. We retain this data until you delete the template or close your account, at which point it is permanently removed.

3. How We Use Your Information

We use the collected information to:

  • Provide, maintain, and improve the compilation service
  • Authenticate your identity and authorize API access
  • Monitor usage against your plan limits and enforce rate limiting
  • Process billing and manage subscriptions
  • Send transactional emails (account verification, password resets, billing receipts)
  • Detect, investigate, and prevent abuse or security incidents
  • Generate aggregated, anonymized usage analytics

We do not use your submitted LaTeX source code or generated PDFs for any purpose other than fulfilling your compilation request. We do not train machine learning models on your document data.

4. Third-Party Services

We use the following third-party services that may process your data:

ProviderPurposeData Shared
PolarPayment processingEmail, subscription details
Mailgun (Sinch)Transactional email deliveryEmail address, message content
SentryError tracking and monitoringError logs, IP addresses, browser metadata
CloudflareCAPTCHA verification (Turnstile), CDNIP address, browser metadata

Each third-party provider operates under their own privacy policy. We encourage you to review their respective policies.

5. Data Retention

  • Account data: Retained until you delete your account.
  • LaTeX source code: Deleted immediately after compilation completes.
  • Generated PDFs: Auto-deleted within 24 hours via signed URL expiry.
  • Saved templates: Retained until you delete them or close your account.
  • API usage logs: Retained for up to 90 days for debugging and billing reconciliation.
  • Error logs (Sentry): Retained per Sentry's default retention policy (typically 90 days).

6. Data Security

We implement the following security measures:

  • All data in transit is encrypted via TLS
  • API keys are stored as cryptographic hashes
  • LaTeX compilation runs in isolated workspaces with no-shell-escape enabled
  • Database backups are encrypted at rest
  • Access to production systems is restricted and audited

7. Cookies

We use essential cookies only for authentication and session management. We do not use third-party advertising or tracking cookies. Cloudflare Turnstile may set cookies necessary for bot detection during account registration.

8. Your Rights

You have the right to:

  • Access: Request a copy of your personal data.
  • Correction: Update inaccurate account information via your dashboard.
  • Deletion: Delete your account and all associated data.
  • API key revocation: Revoke any API key at any time from your dashboard.
  • Data portability: Request an export of your account data.

To exercise these rights, contact us at the email below or use the account settings in your dashboard.

9. International Data Transfers

Our servers may be located in different jurisdictions. By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence. We take reasonable steps to ensure your data is treated securely.

10. Children's Privacy

Pressa is a professional B2B service not directed at individuals under 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a minor, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on our website. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

12. Contact

Privacy questions or data requests? Contact us at [email protected]