Privacy Policy
editor.pub is a collaborative text editor at app.editor.pub, operated by Adam Koszek (“we”, “us”). This policy explains what we collect when you use it, why, who else sees it, and what you can ask of us.
The short version
- A document you create without signing in is shared by link: anyone who has its URL can read and edit it, and it is listed on the home page. A document you create while signed in is private to you until you share it with people by email, or switch it to “anyone with the link”.
- When you ask the agent or a reviewer for suggestions, the text of that document is sent to an AI model provider to produce the answer. Nothing is sent unless you click.
- Signing in is optional. If you sign in with Google or GitHub we store the name, email address and avatar they give us, and nothing else from your account.
- We do not sell data and we do not run advertising.
What we collect
Documents. The text you and your collaborators type, together with the edit history needed to synchronise everyone’s copies (the document is stored as a log of changes), pending suggestions, and reviews produced by the agent. For a document created while signed in we also store who owns it, whether it is private or open by link, and the email addresses the owner has shared it with. Documents are stored on our server until deleted.
Presence. While a document is open, the nickname and colour you chose, your cursor and selection position, and your connection status are shared live with everyone else in that document. The nickname lives in your browser session and is not tied to an account.
Account information. If you sign in with Google or GitHub, we receive and store your name, email address, avatar URL and the provider’s identifier for your account, so we can recognise you next time. We never see your password. We do not request access to your email contents, repositories or contacts.
Session cookie. A signed-in session is kept with a cookie. It holds a random session identifier and nothing else.
Submissions. If you join the waitlist or send feedback through the site, we keep the email address and message you submit.
Server logs. Like every web server, ours records the request path, time, IP address and browser user agent for each request. We use this to run the service, diagnose problems and block abuse, and keep it for a limited period.
How we use it
To operate the editor, keep documents in sync between collaborators, produce suggestions when you ask for them, let you sign in, answer your messages, and keep the service secure. That is all.
Who else sees your data
- AI model providers. When you run the agent, a check, or a critic, the text of the proposed document is sent to OpenRouter, which routes it to the model named on the page; our requests are restricted to providers that commit to zero data retention. As a fallback we may send it directly to Anthropic. We send only the document text, never your account details.
- Sign-in providers. Google and GitHub handle authentication when you choose to sign in, under their own privacy policies.
- Infrastructure. The site runs on a server operated by OVH and is fronted by Cloudflare, which sees traffic metadata as part of serving the site. The editor loads its JavaScript libraries from the esm.sh content delivery network, which receives your IP address when your browser fetches them.
- Backups. Our database is replicated continuously to encrypted off-site storage so documents survive a server failure.
We do not share your data with anyone else, and we do not sell it.
Retention and deletion
Documents stay until they are deleted. The owner of a signed-in document can delete it from the document’s sharing panel. Anonymous documents have no owner; email us the link and we will remove them. Deleted documents disappear from backups within the backup retention window. Account records stay until you ask us to delete them. Logs are kept for a limited period and then discarded.
Your rights
You can ask us at any time to see, correct or delete the information we hold about you, including documents you created. Email [email protected]. If you are in the EU, the UK or California, the rights under GDPR, UK GDPR and the CCPA apply and we will honour them regardless of where you are.
Children
editor.pub is not directed at children under 13 and we do not knowingly collect their information.
Changes
If this policy changes in a way that matters, we will update the date at the top and, for signed-in users, mention it on the site.