← Back to home

Privacy Policy

Last updated: May 18, 2026

1. Introduction

Collabula (“we”, “us”, or “our”) operates getcollabula.com (the “Site”) and the Collabula collaborative LaTeX editor (the “Service”). This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.

2. Information We Collect

Information you provide

  • Email address, name, and profile picture when you create an account (via Clerk)
  • LaTeX documents, project files, and binary assets you create or upload
  • AI API keys you choose to store — encrypted at rest with AES-256-GCM; we never log or inspect the content of your AI requests or responses
  • Project collaboration data (invitations, shared access)

Information collected automatically

  • Vercel Analytics — anonymized, cookieless page-view data collected on every visit. No personally identifiable information is collected and no consent is required.
  • PostHog (with your consent) — page views, referrers, geographic region, and device type to help us understand how the Site is used. For signed-in users on the /projects and /editor pages, session recordings may be captured to help us identify usability issues; all form inputs and text fields are masked before transmission. PostHog data is processed on servers in the European Union and retained for up to one year. You can withdraw consent at any time via the cookie settings on the Site.
  • Cookies — strictly necessary session cookies for authentication (provided by Clerk). No tracking or advertising cookies are set without your consent.

Information we do NOT collect

  • We do not read or analyze the content of your LaTeX documents
  • LaTeX compilation runs entirely in your browser via WebAssembly — document content is never sent to our servers for compilation
  • AI requests are proxied directly to your chosen provider; we do not store prompts or responses
  • Session recordings never capture document content or API keys — all inputs are masked

3. How We Use Your Information

  • Provide, maintain, and improve the Collabula service
  • Authenticate your identity and secure your account
  • Store and serve your LaTeX documents and project files
  • Enable real-time collaboration between project members
  • Send transactional emails (account confirmation, collaboration invites)
  • Improve the Site based on anonymized usage analytics and session recordings

We do not sell, rent, or share your personal data with third-party advertisers.

4. Cookies

We use strictly necessary cookies for authentication and session management (provided by Clerk). These cannot be disabled as the service cannot function without them.

With your consent, we use analytics cookies (PostHog) to understand how visitors interact with the Site and to capture session recordings on the editor and projects pages for signed-in users. Session recordings help us identify usability issues; all form inputs and text fields are masked and never transmitted. You can manage your cookie preferences at any time using the cookie settings on the Site.

5. Third-Party Services

  • Clerk — authentication and user management (privacy policy)
  • Supabase — database and file storage, hosted in EU-West-1 (privacy policy)
  • Vercel — hosting and cookieless analytics (privacy policy)
  • PostHog — product analytics and session recordings, EU-hosted (privacy policy). Only active with your consent. Session recordings are limited to the editor and projects pages for signed-in users; all inputs are masked.
  • Liveblocks — real-time collaboration infrastructure (privacy policy)
  • AI providers (BYOK) — when you provide your own API key, requests are proxied to your chosen provider (e.g., OpenAI, Anthropic). Their privacy policies apply to those interactions.

6. Data Storage & Security

Your data is stored on servers in the European Union (Supabase EU-West-1). We use industry-standard security measures including:

  • TLS encryption for all data in transit
  • AES-256-GCM encryption for stored AI API keys
  • Row-Level Security (RLS) on all database tables
  • Service role keys never exposed to client-side code

7. Your Rights (EU/EEA Users)

Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (“right to be forgotten”)
  • Export your data in a portable format (download your projects as ZIP)
  • Withdraw consent for non-essential data processing at any time
  • Lodge a complaint with a supervisory authority

To exercise any of these rights, contact us at legal@getcollabula.com.

8. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where required by law. Vercel Analytics data is anonymized and retained per Vercel’s policy. PostHog analytics and session recording data is retained for up to one year, after which it is automatically deleted.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on the Site. Your continued use of the Service after changes constitutes acceptance of the updated policy.

10. Contact

If you have questions about this Privacy Policy, contact us at legal@getcollabula.com.