Privacy Policy
Last updated: July 9, 2026
1. Who we are
LetX is a collaborative LaTeX editing platform operated by Shahriar Labs, based in Dhaka, Bangladesh ("LetX", "we", "our", or "us"). This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights you have. It applies to letx.app and related services.
2. Information we collect
Information you provide:
- Account: name, email address, and (for email sign-up) a hashed password. If you sign in with Google or GitHub, we receive your name, email, and avatar from that provider.
- Profile & onboarding: to tailor the product and understand our users, we ask for your role, field, university or company, and how you write, and optionally your title, a work/portfolio link, gender, and how you heard about us. You can edit or clear these in settings.
- Your content: the LaTeX documents, files, images, and project data you create, upload, or collaborate on.
- Communications: messages, feedback, and support requests you send us.
Information collected automatically:
- Usage & device data: IP address, approximate location derived from IP, browser and device type, pages viewed, and actions taken.
- Cookies: a small number of strictly-necessary cookies for authentication (including an HttpOnly session cookie) and preferences. See §7.
Payments: when paid plans launch, card details will be handled directly by our payment processor (e.g. Stripe or Paddle); we do not store full card numbers.
3. How we use your information
- Provide, operate, secure, and improve LetX (including compiling your documents and syncing real-time collaboration).
- Authenticate you and protect against abuse, fraud, and security incidents.
- Understand who our users are and how they use LetX, so we can prioritise features (analytics and product research).
- Send you service and account emails (verification, password reset, invitations, important notices). Marketing emails are optional and you can opt out.
- Comply with legal obligations and enforce our Terms.
Legal bases (GDPR): we process data to perform our contract with you (providing the service), for our legitimate interests (improving and securing LetX, product analytics), with your consent (optional profile fields, AI features, marketing), and to comply with law.
4. AI features & your documents
AI assistance in LetX is opt-in. Unless you explicitly enable an AI feature, your documents are not sent to any AI model. When you do use an AI feature, the relevant text is sent to third-party model providers (via our AI gateway) solely to generate your result. We choose providers that do not use inputs from our API to train their models and that offer limited or zero data-retention options where available; retention and processing practices vary by provider and may change, and we update our sub-processors from time to time.
We never sell your work, and we never use your private documents to train AI models without your explicit, opt-in consent. If we ever offer to use your content to improve or train our own models, that will be a separate, clearly-labelled choice you can decline, and we would use anonymised or aggregated data wherever possible.
Aggregated & de-identified data. We may create and use aggregated, anonymised, or de-identified information — which does not identify you and cannot reasonably be used to identify you — for any lawful purpose, including operating, analysing, securing, improving, and promoting LetX. Such data is not treated as your personal information.
5. How we share information (sub-processors)
We do not sell your personal data. We share it only with service providers who process it on our behalf, under appropriate confidentiality and data-protection obligations. Our providers may change as the Service evolves; the current key sub-processors are:
- Amazon Web Services (AWS) — cloud hosting, file storage, database, and transactional email (SES).
- Cloudflare — DNS, CDN, and delivery of the web app and public assets.
- Google and GitHub — optional sign-in (OAuth), if you use them.
- Zoho — our business email/support inbox.
- AI model providers (via our AI gateway) — only when you use an opt-in AI feature (see §4).
- Payment processor (e.g. Stripe or Paddle) — only once paid plans launch, to process payments.
We may also disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition (with notice where required).
6. Data retention
We keep your information for as long as your account is active or as needed to provide the service. When you delete your account, we delete or anonymise your personal data and documents within a reasonable period, except where we must retain some data to meet legal, accounting, or security obligations.
7. Cookies
We use only strictly-necessary cookies: an HttpOnly cookie to keep you signed in and rotate your session, short-lived cookies for the OAuth sign-in flow, and local storage for your preferences (such as theme). We do not use third-party advertising cookies.
8. Security
We use appropriate technical and organisational measures to protect your data: encryption in transit (HTTPS/TLS), encryption at rest for stored data, hashed passwords, role-based access controls, and private, signed access to your files. No method of transmission or storage is completely secure, but we work to protect your information and to notify you of material incidents as required by law.
9. International transfers
We are based in Bangladesh and use cloud infrastructure located in various regions (including Asia-Pacific). Your information may be processed in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
10. Your rights & choices
Depending on your location (including under GDPR and similar laws), you may have the right to:
- Access, correct, or delete your personal information.
- Export your documents and data.
- Object to or restrict certain processing, and withdraw consent (e.g. AI features, optional fields, marketing).
- Lodge a complaint with your data protection authority.
To exercise any of these, email us at [email protected].
11. Children
LetX is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their data. If you believe a child has provided us information, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will update the date above and, where appropriate, notify you. Continued use of LetX after changes means you accept the updated policy.
13. Contact us
Questions or requests? Contact Shahriar Labs at [email protected] (support & privacy) or [email protected] (Shahriar Labs, Dhaka, Bangladesh).