Privacy Policy.

Effective date: August 25, 2026  ·  Last updated: August 25, 2026

LatexScribe is a Google Docs add-on that renders LaTeX equations into images inside your document. It is operated by ONESTOPML LIMITED, a company registered in England and Wales, of 320 Firecrest Court, Centre Park, Warrington, England, WA1 1RG ("we", "us").

LatexScribe runs in your browser. Your document is read there, and nothing of it is sent to our servers: not its text, not its title, not its identity. The equations you render pass through our image service briefly, as finished images on their way into your document, and are deleted right after insertion, with an automatic one-day cleanup as a backstop. We never read or keep them. Beyond that, we store only your email address (with your consent), your plan, and a count of how many equations you render.

We designed LatexScribe to handle as little of your data as technically possible. The short version:

  • We never store your documents or any document content on our servers. There is no database of user content.
  • Rendering happens in your own browser. Your document is read and edited using your own Google account, directly between your browser and Google.
  • The count of how many equations you render is recorded on our backend, keyed to an identifier for your Google account, and kept for about 90 days. It contains no document content.
  • With your consent on the in-app setup screen, we keep your email address and account settings (including your marketing-email choice). If you subscribe to a paid plan, we also keep your plan and subscription status. Payments are handled by Stripe; we never see your card details.

The rest of this policy explains that in detail.

1. What LatexScribe does with your document

When you click Render, the add-on:

  1. Reads the text of the currently open document (using your Google access, in your browser) to find LaTeX equations.
  2. Renders each equation to an image locally in your browser. The LaTeX is not sent to a rendering server.
  3. Uploads each rendered image briefly to our image host (hosted at Cloudflare) so Google Docs can fetch it.
  4. Instructs Google Docs (again using your Google access, from your browser) to insert the images into your document. Google copies the image into your document.
  5. Deletes the uploaded images from our storage as soon as Google has copied them into your document. For a short time after that, a copy may still sit in Cloudflare's delivery network before it clears; as a safety net, anything not deleted is automatically removed by a storage lifecycle rule within 1 day.

Two things are worth spelling out:

  • The rendered images pass through our storage transiently. A rendered equation image (a PNG) exists in our Cloudflare-hosted storage for the seconds it takes Google to fetch it. The image's web address is not opaque: by design it carries that one equation's LaTeX (see the next point). The stored image is then deleted, though a copy may sit briefly in Cloudflare's delivery network before it clears. We keep no copy, and we never read, mine, or reuse your equations.
  • Your equation's LaTeX source is stored in your document, not with us. So that you can convert an equation image back to editable text later ("De-render"), the LaTeX source is encoded into the image's web address, and Google stores that address inside your document as part of the image. It travels with your document (in Google's storage, under your control), not in any system of ours.

De-render (turning an equation image back into text) reads that stored source from your own document. Again, this happens between your browser (or Google's Apps Script infrastructure) and Google, not through our servers.

2. Google account data and OAuth scopes

Your LatexScribe account is keyed to your Google account (see section 4): you sign in only with Google, and there is no separate password. The add-on requests these Google OAuth scopes:

  • https://www.googleapis.com/auth/documents: to read the open document (to find equations) and to edit it (to insert equation images or restore equation text). This is the add-on's core function.
  • https://www.googleapis.com/auth/script.container.ui: to show the add-on's sidebar inside Google Docs.
  • https://www.googleapis.com/auth/script.external_request: lets the add-on contact our backend (for example, to check your plan). On Google's consent screen this appears as "Connect to an external service".
  • openid: identifies your Google account to our backend so your plan and usage can be keyed to you.
  • https://www.googleapis.com/auth/userinfo.email: shows you which account you are signed in with, and, with your consent, lets us keep your email address for account and billing support.

Your Google access token is used only to talk to Google. It is used from your own browser (and Google's Apps Script environment) to call Google's Docs API. It is never sent to our backend, our image host, or any third party, and we never log or store it.

Limited Use disclosure: LatexScribe's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Google user data (your document content) only to provide the equation-rendering features you invoke; we do not transfer it to others except as necessary to provide those features (the transient image hosting described above); we do not use it for advertising; and no humans read it (your document's text stays between your browser and Google; the only content that reaches our systems is each rendered equation on its way into your document, transiently, as described above, and we never read or keep it).

3. The data we actually hold

Today, the complete list of data we hold or process about you is:

DataWhere it livesWhyHow long
Rendered equation images (PNGs)Our image storage (Cloudflare, transient)So Google Docs can fetch and insert them into your documentDeleted as soon as Google has copied them into your document; a copy may sit briefly in Cloudflare's delivery network; 1-day automatic deletion as a backstop
Usage metering records (pseudonymous: an identifier for your Google account, run identifiers, and equation counts)Our backend (Cloudflare)To apply your plan's limit and to support corrections if a count ever looks wrongAbout 90 days, then deleted automatically; contains no document content
Account record (your email address, your marketing-email choice with its timestamps, your plan and subscription status)Our backend (Cloudflare)Account identification, billing, and support (details in section 4)While your account exists; deleted on request
A local copy of your account settings (including your marketing-email choice)Google's per-user add-on storage (PropertiesService), managed and partitioned by GoogleSo the add-on knows your setup is complete without a network callWhile the add-on is installed
Standard connection data (e.g. your IP address) when your browser contacts our backendCloudflare's network, transiently, as part of serving any web requestDelivering the service; security and abuse preventionWe do not log or store request contents, document IDs, or user identifiers on our backend, beyond the account, entitlement, and metering records described in sections 3 to 5

That's the full list. Specifically, we do not:

  • store your documents, your equations, or any document content on our servers;
  • keep any database of user content (the account and metering records above contain no document content);
  • use analytics, advertising, or tracking tools in the add-on (there is no analytics code in the product today; if we ever add privacy-respecting product metrics, we will update this policy first);
  • sell or share your data with anyone for advertising or any unrelated purpose.

4. Your account, email, and marketing consent

The first time you use LatexScribe, the add-on shows a setup screen. Your account exists only after you confirm there, and no account data leaves the add-on before that.

What we collect. When you confirm, we keep: your Google account's email address; your marketing-email choice, with a record of when you made or changed it and the exact wording you agreed to; your plan and subscription status; and the pseudonymous usage records described in section 3.

What we use it for. Identifying your account; billing and support; essential service emails (for example, about a billing problem or a material change to these terms); and marketing emails ONLY if you opted in. Service emails stay purely administrative; they are never marketing in disguise.

Legal bases. Contract, for account identification, billing, and essential service email. Consent, for marketing email: it is off by default, you can withdraw it at any time, and every marketing email includes an unsubscribe link. Withdrawing consent stops marketing email and nothing else.

Where it lives, and for how long. Account and consent records live on our backend; billing runs through Stripe (section 5). We keep account data while your account exists and delete it on request, subject to legal retention of billing records.

Deletion and help. Email support@latexscribe.com to close your account, delete its data, or change your email preferences. Closing your account never touches your documents.

This section applies only if and when you buy a paid subscription. Until then, none of the data in this section exists.

LatexScribe offers paid plans with higher rendering limits. When you subscribe:

  • Stripe processes your payment. You check out on Stripe's payment page. Your card details go to Stripe, not to us. We never see or store them. Stripe acts as our payment processor.
  • We keep an entitlement record: an identifier for your Google account, your plan (e.g. Pro or Max), and your subscription status, stored on our backend so the add-on knows your tier and retained while your paid plan is active. If your subscription ends, this shrinks to a billing record of exactly three items: your Stripe customer identifier, your subscription identifier, and your subscription status, kept so that if you subscribe again you keep the same Stripe customer instead of a duplicate. It contains no plan, price, or card details, and it is kept until you ask us to delete it (see Your rights below).
  • Stripe will hold the billing information it needs (such as your email and payment history) as part of processing payments and, where required, as an independent controller for its own compliance obligations. Stripe's handling of your data is governed by Stripe's Privacy Policy.

For users in the UK, EU, and other GDPR-style jurisdictions, our legal bases are:

  • Performance of a contract, covering everything in sections 1 to 5: rendering your equations, identifying your account, applying usage limits, essential service emails, and managing your subscription are the service you asked for.
  • Consent: keeping your email address for your account, and marketing email (section 4). Marketing consent is off by default, withdrawable at any time, and every marketing email includes an unsubscribe link.
  • Legitimate interests: basic security and abuse prevention on our backend (e.g. rate limiting), and keeping minimal records needed to run the business.
  • Legal obligation: retaining billing records where tax or accounting law requires it.

We do not use analytics or tracking in the add-on, and we do not sell your data. The only optional processing is marketing email, and it happens only with your consent.

For document content, the honest technical picture is that we barely touch it: it stays between your browser and Google. To the extent the transient image hosting involves personal data at all, we are the controller of that momentary processing: it happens only when you invoke a render, and nothing is retained.

7. Sub-processors and recipients

We use these providers to run LatexScribe:

ProviderRoleData involved
Google (Google Ireland Ltd / Google LLC)The platform LatexScribe runs on: Google Docs, Apps Script, and the per-user add-on settings storageYour documents (in your own Google account); a local copy of your account settings (including your marketing-email choice)
Cloudflare (Cloudflare, Inc.)Backend hosting and transient image storage; account, entitlement, and usage metering storageTransient rendered images (each image's web address carrying that equation's LaTeX); connection metadata; account records (email, consent); entitlement records; pseudonymous usage metering records
Stripe (Stripe, Inc. / Stripe Payments Europe)Payment processing (paid plans only)Billing and payment details you give at checkout

These providers may process data outside the UK/EEA (notably in the United States). Where they do, transfers are protected by recognized safeguards: adequacy decisions (including the UK-US Data Bridge / EU-US Data Privacy Framework where applicable) and/or standard contractual clauses in the providers' data processing terms (for transfers from the UK, the UK Addendum to those clauses or the ICO's International Data Transfer Agreement).

We do not share your data with anyone else, except if we are legally compelled to (and given how little we hold, there is very little to compel).

8. Your rights

Under UK GDPR (and equivalent laws), you can ask us to access, correct, delete, or export the personal data we hold about you, object to or restrict processing, and complain to a regulator.

In practice, because we hold so little, here is what that means:

  • Usage records: they live on our backend, keyed to an identifier for your Google account, and expire automatically after about 90 days. You can ask us to explain or correct your count; if it ever looks wrong, email us and we will put it right.
  • Account record: email us to access, correct, or delete your email address and consent record (deletion is handled by support at launch). You can change your marketing choice at any time from the add-on or by email.
  • Rendered content: we have none to delete. It is in your own Google Doc, which you control.
  • Subscription record (paid users): contact us to access or delete it (subject to legal retention of billing records). Cancelling your subscription is covered in the Terms of Service.

To exercise any right, email support@latexscribe.com. We will respond within one month. If you are unhappy with our answer, you can complain to the UK Information Commissioner's Office (ico.org.uk) or your local data protection authority.

9. Children

LatexScribe is a general-audience tool for writing documents with math. It is not directed at children under 13, and we do not knowingly collect personal data from them. (Given the design above, we barely collect personal data from anyone.) Use through a school-managed Google Workspace account is subject to the school's and Google's own controls.

10. Security

  • Rendering happens in your browser; your Google token never leaves the Google ecosystem.
  • Uploads to our image host use short-lived, single-purpose signed URLs; stored images are deleted after insert, with the delivery-network caveat and the 1-day automatic deletion described in section 1.
  • Our backend does not log document content, document IDs, or user identifiers. The stored identifiers are the account, entitlement, and usage metering records described in sections 3 to 5; none of them contain document content.
  • Secrets and access keys are stored in the hosting platform's secret storage, never in code.

No system is perfectly secure, but our main security measure is structural: we hold almost nothing, so there is almost nothing to breach.

11. Changes to this policy

If we change this policy, we will post the new version at this address and update the effective date. For material changes (for example, if we ever start holding new categories of data), we will give notice in the add-on before the change takes effect.

12. Contact

  • Operator: ONESTOPML LIMITED
  • Mailing address: 320 Firecrest Court, Centre Park, Warrington, England, WA1 1RG
  • Email: support@latexscribe.com

We are the data controller for the (minimal) personal data described in this policy.