Privacy Policy
Undertwig (“we”, “us”) is a browser-based LaTeX workspace available at undertwig.com. This policy explains what information is involved when you use the service.
Summary
Undertwig is designed to run in your browser. Your project files are stored on your device by default. Optional Google sign-in unlocks collaboration and free Google Cloud project storage in your Google account. We do not intentionally collect the contents of your documents for advertising or profiling.
Information stored on your device
The editor saves your current project in your browser’s local storage
(under a key such as undertwig-latex-project-v1) so your work
can persist between visits on the same browser and device. That data stays
on your device unless you export it, clear site data, or otherwise share it.
If you sign in, a minimal account session is stored in local storage under a key
such as undertwig-auth-v2: Google subject identifier, verified email,
display name, optional profile image URL, and an expiry time. The raw Google ID
token is verified in the browser and is not kept after sign-in.
Generated PDFs are created locally in your browser and are not uploaded to Undertwig servers as part of local conversion.
Google account sign-in
Collaboration and related signed-in features require a Google account. Sign-in uses Google Identity Services in your browser. When you choose “Continue with Google,” Google authenticates you and may share with Undertwig basic profile details such as your name, email address, and profile picture, subject to your Google account settings and Google’s own policies.
Undertwig verifies the Google ID token’s signature against Google’s published signing keys, checks issuer, audience, expiry, email verification, and a one-time nonce, then keeps only the minimal profile fields needed to show your signed-in state. Sign-in sessions expire when the Google credential expires. Logging out clears the local session and attempts to revoke Google grants for this site. We do not offer other sign-in providers. Google’s handling of your account is governed by Google’s Privacy Policy.
Google Cloud project storage
When you are signed in, Undertwig can store your LaTeX project (file names and contents, including uploaded assets) in an Undertwig folder in your Google Drive. You own that project. Access uses a Google OAuth token with the Drive file scope. Sign-in also requests Drive access, so the editor connects automatically afterward (no separate Connect click in the usual case). The access token is kept in session storage for the current browser tab session so later saves can sync without repeated prompts. Logging out clears the local session and attempts to revoke the token. You can also remove app access from your Google Account permissions page.
Local editing without signing in continues to use browser storage only. If browser storage is too small for a project, Undertwig may prompt you to sign in to use Google Cloud storage instead.
Collaboration invitations
When you are signed in, you can invite another person by email from the Collaborate
control. Undertwig shares your Drive project with that Google account (editor access)
and asks Google for permission to send email through your Gmail account
(gmail.send). The invitation is sent from your address and includes a
link to open that shared project. The invitee edits your Google Drive project; you
remain the owner. Undertwig does not operate a
separate mail server for these invites. Recipient addresses you type are used only
to create the Drive share and send that invitation.
Information processed to provide the service
- Hosting and delivery. The website is hosted on GitHub Pages. Like most websites, the hosting provider may process standard technical request data such as IP address, user agent, and request timestamps in server logs for security, reliability, and abuse prevention.
- Google sign-in and cloud storage. The login page loads Google Identity Services. During sign-in verification, the browser may request Google’s public signing keys. When cloud storage is used, the editor requests a Google OAuth access token and reads/writes project data via the Google Drive API (Undertwig folder / shared project files). Collaboration invites may share a Drive file with the recipient and request Gmail send access to deliver an invitation from your account. Logging out may contact Google to revoke grants for this site.
-
Optional package fetching. When a document needs TeX packages
that are not already available in your project, the local compiler may
request package resources from a third-party TeX Live endpoint
(currently
texlive.texlyre.org). Those requests are made by your browser and may include technical request metadata. - Source repository. If you visit our public GitHub repository or open issues there, GitHub’s own privacy terms apply to that activity.
Cookies and similar technologies
Undertwig does not use advertising cookies or third-party analytics cookies. The app relies on browser local storage (and normal browser/session mechanisms) to keep your project and optional sign-in session available on your device. Google’s sign-in flow may set or read cookies on Google domains according to Google’s practices.
How we use information
Technical hosting data, where processed by our hosting provider, is used only to operate, secure, and maintain the website. Google profile details from sign-in are used to identify your session for signed-in features such as collaboration access controls. We do not sell personal information, and we do not use your document contents for advertising.
Data retention
Project data in local storage remains until you clear it, log out (for session data), or your browser removes it. Cloud project data stored in your Google Drive Undertwig folder remains until you delete it in Drive, revoke app access, or remove it via Google Account controls. Hosting provider logs are retained according to that provider’s practices.
Children
Undertwig is a general-purpose tool and is not directed at children under 13 (or the equivalent minimum age in your jurisdiction).
International visitors
Because the site is delivered over the internet, technical request data may be processed in the United States or other locations used by GitHub Pages, Google Identity Services, and any package endpoint your browser contacts.
Your choices
- Use Undertwig without signing in for local editing and conversion.
- Log out from the account control in the editor to clear the local sign-in session.
- Clear site data in your browser to remove locally stored projects and session data.
- Export or copy your files before clearing data if you want to keep them.
- Use network controls in your browser if you prefer to block third-party package requests.
- Manage Google account permissions in your Google account settings.
Contact
Questions about this policy can be raised via the project’s GitHub repository: github.com/martino-vic/undertwig.
Changes
We may update this policy as the service evolves. The “Last updated” date at the top will change when we publish revisions.