Privacy & terms

Last updated 17 September 2026. Written in plain language on purpose; if anything is unclear, ask us and we will fix the text.

The short version

  • Your documents are yours. We claim no rights to them.
  • We never sell your data, never share it with advertisers, and never use your documents to train AI models.
  • Your projects are stored in the EU (Ireland). They are only visible to you and the people you share them with.
  • Samskrift is run by two private individuals. We can technically reach the database, and we only do so to fix a problem or keep the service running, never to read your work for its own sake.
  • AI features send only what the feature needs (the text you selected, the image you uploaded, the compile log) to the model provider, and only when you trigger them. You can turn the AI features off in your account settings.
  • Compiling sends your project files to our own compile server and nowhere else. Public backup compile services exist but are off unless you turn them on yourself.
  • Fonts, dictionaries and everything else the app needs are served from samskrift.com itself. Your browser talks to no third-party content network.
  • Delete a project and it is gone from our database and file storage. Delete your account yourself under Account → Settings and everything you own goes with it, immediately.

Who runs Samskrift

Samskrift is built and run by two private individuals in Stockholm, Sweden, as a hobby project (you meet them on the About page). There is no company behind it, no employees and no contractors, and nobody outside the two of us has administrative access to the service. Under EU data protection law (GDPR) the two of us are joint controllers of the personal data described here; either of us can handle any request about it.

Contact us through the and include your email address if you want a reply. We answer requests about your data within one month, as GDPR requires; in practice usually within a few days.

What we store

Your account
Your email address, a display name and an avatar colour. If you sign in with Google we receive your name, email address and profile picture from Google. Passwords are never stored in readable form.
Your projects
Everything you put in a project: LaTeX source, bibliographies, images and other uploaded files, the compiled PDF (cached so it is there when you come back), version history snapshots, comments, track-changes data, the project chat, and the labels and settings you give the project.
Collaboration data
Who is a member of which project and with which role, share links you have created, invitations you have sent (the invited email address), and which projects you have opened, so we can show you what changed since your last visit.
Activity records
For each compile: which project, which engine, how long it took and whether it succeeded. For each AI request: which feature, which model, how many tokens it used and what it cost. These records contain no document text and exist so we can keep the service reliable and the AI budget fair. They are deleted after 12 months.
Feedback
The message you send through the feedback form, the page you sent it from and, if you chose to give one, your email address. To stop spam we keep a salted one-way hash of the sending network address for 7 days, never the address itself.
Technical analytics
Our hosting platform records basic technical analytics for the site: page views, page load performance and error reports, together with the browser type and the country the request came from. There are no advertising trackers and no third-party marketing scripts on Samskrift.

Where it lives, where it is processed

The database and file storage run on Lovable Cloud in the EU (Ireland, the AWS eu-west-1 region), on Amazon Web Services infrastructure. That is where your projects are stored at rest.

Processing is a different matter. The server code that serves the site runs on Lovable's hosting platform, built on Cloudflare's global network, so a request is handled close to where you are. Compiles run on short-lived sandbox machines provided by the same platform, and AI requests go to the model providers listed below; neither is guaranteed to happen inside the EU. So: stored in Ireland, processed wherever the compile or AI request is served, for the duration of that request.

Transfers outside the EU rest on the mechanisms GDPR recognises. Cloudflare (hosting network and compile sandboxes), Google (AI models and sign-in) and Amazon Web Services (storage) are each certified under the EU-U.S. Data Privacy Framework. OpenAI processes API data under the European Commission's Standard Contractual Clauses (its data processing addendum, section 4.1). Our AI requests are relayed through Lovable's AI gateway, so the direct contracts with OpenAI and Google are Lovable's; Lovable publishes its sub-processors and security documentation at trust.lovable.dev. The optional backup compile services below are unrelated public services with no agreement with us and no transfer mechanism, which is exactly why they are off by default.

Who can see your work

  • You and your collaborators. Access is enforced by permission rules in the database itself, per project and per role (owner, editor, viewer), not just in the user interface.
  • Anyone with a share link, if you have turned on link sharing for a project. Editor links let people edit, viewer links let people read. You can turn links off at any time.
  • Everyone, if you publish a project as a public template. Only projects you explicitly publish are public.
  • The two of us, technically. Running a service means having access to its database, and our admin overview shows aggregated usage: signups, compile counts and timings, AI spend, and project names next to failed compiles. We do not browse people's documents. We open a document only when it is needed to investigate a problem you have reported or a failure we can see in the logs, and we keep that to the minimum needed.

We do not sell, rent or share your documents or personal data with anyone, and we do not use them for advertising or for training AI models. The only parties that ever process your data are the services listed next, and only in order to run Samskrift for you.

Services that process your data

Lovable Cloud (hosting)
Runs the database, file storage, sign-in, transactional email (sign-up confirmation, password reset, project invitations sent from notify.samskrift.com) and the isolated machines our compile server runs on. Lovable's staff can in principle access infrastructure they operate; they do so only for operating the platform, under their own terms.
Our compile server (TeXpress)
Every compile sends the project's files to TeXpress, a compile service we built and run ourselves. It runs TeX Live inside isolated, short-lived sandbox machines rented from Lovable's platform (the same company that hosts the rest of Samskrift). A machine lives for at most four hours and is replaced when idle. While it is alive it keeps a copy of your project's files and the resulting PDF, tagged to your project, so repeat compiles are fast; that copy is removed three hours after it was last used, and in any case with the machine. TeXpress also keeps a record of each compile (project, engine, timing, outcome) for 30 days, including an excerpt of the LaTeX log, which can quote the lines of your document near an error. Compiled PDFs are returned to Samskrift and cached in your project's storage.
Backup compile services (off by default)
Two public LaTeX services, latex.ytotech.com and texlive.net, can take over a compile when our own server is down. They are third parties outside our control, outside the EU, with no agreement with us, so we never use them unless you have turned on "Backup compile services" under Account → Settings. With it on, your source files are sent to one of them for that one compile only (texlive.net never receives images or other binary files), and the compile log says so every time. With it off (the default), a compile simply fails with a clear message while our server is unavailable. For anonymous visitors compiling through a share link, the project owner's setting applies.
AI model providers
AI features are served through Lovable's AI gateway by models from OpenAI and Google. See the AI section below for exactly what is sent and when.
Google (sign-in)
If you choose to sign in with Google, Google knows that you signed in to Samskrift, and we receive your name, email and profile picture. Email-and-password sign-in involves no third party.
Nothing else
Web fonts, spell-check dictionaries, symbol data and every script the app runs are served from samskrift.com itself. Your browser never contacts a third-party content delivery network, so no outside party sees your IP address just because you opened the editor. Spell-checking and symbol drawing run entirely in your browser.

AI features

Nothing is sent to an AI model unless you trigger a feature. When you do, we send only what that feature needs:

  • Inline edit and AI assist: the text you selected, your instruction and enough surrounding lines for context.
  • Try to fix: the compile log and the parts of your files the agent needs to understand the error.
  • Image-to-LaTeX: the image you uploaded.
  • Symbol search: the words you typed. Drawing a symbol is recognised entirely on your device; your sketch is only sent to a model if you press "Ask AI".

Requests go through Lovable's AI gateway to OpenAI and Google models under their API data-use terms, which do not permit using API requests to train their models. We never use your content to train anything either. We keep a record of the model, token counts and cost of each request for 12 months, not its content. Every AI feature can be switched off under Account settings.

AI assistants connected via MCP

If you connect an AI assistant (Claude, ChatGPT, Codex or another MCP client) to Samskrift, you sign in with your Samskrift account and the assistant acts with exactly your permissions. It can read, edit and compile the projects you can, and whatever it reads is sent to that assistant's provider under their terms, not ours. Disconnect it from the assistant's own settings whenever you like; signing out of Samskrift everywhere also ends its access.

Cookies, local storage and offline mode

Samskrift uses your browser's storage for things the app needs to work: your sign-in session, editor preferences (theme, layout, keyboard mode), draft state, and, when offline editing is on, a local copy of your projects so you can keep working without a connection. That copy lives on your device and syncs back when you reconnect. There are no advertising or cross-site tracking cookies, which is why there is no cookie banner.

Ownership

You own everything you write and upload. By using Samskrift you give us only the permission we need to provide the service: to store your files, show them to you and your collaborators, compile them, and, when you ask, pass parts of them to the AI and compile services above. That permission ends when you delete the content. You are responsible for having the right to upload what you upload.

How long we keep things

Deleting is under your control; everything else expires on a schedule. Every period below is enforced automatically.

Projects, files, history, comments, chatUntil you delete them. Deleting from the trash is immediate and permanent.
Cached PDFReplaced on every compile; deleted with the project.
Your accountDeleted immediately when you delete it (Account → Settings).
Compile records (Samskrift)12 months, then deleted automatically.
Compile records on our compile server (TeXpress), including the log excerpt30 days, then deleted automatically.
Copies of your files and PDF on a compile machineRemoved 3 hours after last use, and always when the machine is replaced (at most every 4 hours).
AI usage records (model, tokens, cost)12 months, then deleted automatically.
Feedback: network-address hash7 days.
Feedback: message, page, optional email12 months, or sooner once handled.
Database backups (hosting provider)Daily, kept up to 14 days, then expire.
Hosting platform request logs and technical analyticsKept by the hosting platform under its own retention policy; we do not control the period.
  • Files and projects: deleting a file removes it from the database and file storage. Deleting a project moves it to the trash; deleting it from the trash removes the project with all its files, history, comments, chat and cached PDFs. A collaborator's own copies (downloads, offline copies) are theirs.
  • Your account: open Account → Settings → Delete account. It removes your account, every project you own (with files, history, comments, chat and cached PDFs), your templates and your personal data immediately; there is no waiting period and no way back. Projects owned by others that you collaborated on remain theirs; your membership is removed. Activity records are detached from your account at the same moment and expire on the schedule above. If you cannot sign in, ask us through the from the email address on the account and we do it for you.
  • Backups exist for disaster recovery only. A deleted project or account is gone from the live service at once and disappears from the backups within 14 days.

Your rights

Under GDPR you can ask us at any time what personal data we hold about you, have it corrected, exported or deleted, and object to or restrict how we use it. A full export of any project is one click away (Download ZIP) and needs no request. For anything else, use the and include your account email. If you believe we are handling your data wrongly you can complain to the Swedish Authority for Privacy Protection (IMY) or the supervisory authority in your own country.

Our legal basis for processing is performing the service you asked for (your account and projects), our legitimate interest in keeping the service secure and reliable (activity records, technical analytics, spam protection), and your consent where you turn on an optional feature (AI, Google sign-in, backup compile services). Consent can be withdrawn at any time by turning the feature off again.

Minimum age

You must be at least 13 years old to create a Samskrift account, which is the age at which you can consent to online services yourself under Swedish law. Younger students are welcome to work in a project that a teacher or parent owns and shares with them through an editor link, which needs no account. If we learn that an account belongs to someone under 13 we delete it.

Security

All traffic is encrypted in transit (TLS) and data is encrypted at rest by our hosting provider. Access rules are enforced inside the database for every table, so a bug in the interface cannot expose another person's project. Passwords are hashed by the sign-in service and checked against known leaked-password lists. Anonymous endpoints (feedback, public links) are rate limited. If you find a security problem, please tell us through the first so we can fix it before it is public.

Terms of use

Samskrift is free to use. In return we ask for a few things, and we want to be clear about what we can and cannot promise.

  • Use it for writing. Do not use it to store or distribute illegal content, to attack the service or other users, or to run automated compile or AI workloads that degrade it for everyone. We may limit, suspend or remove accounts and content that do.
  • It is provided as is. We run it carefully and keep version history for you, but we are two people with day jobs: we cannot guarantee uptime or that data is never lost, so keep your own copies of anything irreplaceable (Download ZIP does this).
  • Features may change. We note every user-visible change on the changelog. If we ever had to shut the service down we would give notice and time to export your projects.
  • Swedish law applies. Samskrift is a free service run by private individuals; to the extent the law allows, our liability is limited to what is mandatory.

Changes and contact

When this page changes in a way that matters we update the date at the top and add a changelog entry. Questions, corrections and requests: use the and include your email address so we can answer.