# MathBB Privacy Policy
**Effective date:** September 16, 2026
MathBB is a web app for writing and discussing mathematics. This policy explains
what personal data we collect when you use MathBB at mathbb.app, why, who else
handles it, how long we keep it, and the rights you have over it.
The short version: we collect what we need to run your account and store your
work. We don't sell your data, we don't show ads, we don't use analytics or
advertising trackers, and we don't use your content to train AI models. When you
use the AI assistants, the content they work on is sent to the AI provider that
powers them.
## 1. Who we are
MathBB is operated by **Rhombic Research, Inc.**, a Delaware corporation
("Rhombic Research", "we", "us"). For the purposes of the EU and UK General Data
Protection Regulation (GDPR), we are the **controller** of the personal data
described in this policy.
- Privacy contact: support@rhombicresearch.ai
---
## 2. Information we collect
### Account information
- **Username, display name and password.** Your password is stored only as a
salted hash; we can't read it.
- **Email address**, used to verify your account, reset your password, and send
you service messages (for example, when someone shares a notebook with you).
- **Account settings**, such as your AI model preferences and chat settings
profiles.
- **Guest accounts** are created without a name or email and are deleted
automatically after 24 hours unless you convert them to a full account.
- **Promo codes** you redeem at signup.
### Your content
Everything you create or upload is stored so that we can show it back to you and
to the people you share it with:
- notebooks, pages, folders, and uploaded files (images, PDFs, 3D models, text
files, interactive widgets, Lean files);
- conversations with the AI assistants (Dora and Relay), including the messages,
the actions the assistant took, and their results;
- messages in a notebook's collaborator chat;
- feedback messages you send us;
- code you run with the code-execution tool, and the files it produces;
- LaTeX manuscript settings and compiled output.
Your content is whatever you choose to write, so it may contain personal data
about you or others. Please don't upload special categories of data (such as
health information) that the service doesn't need.
### Credentials for other services
If you choose to add them, we store your **Anthropic API key**, **OpenAI API
key**, and **GitHub personal access token**. They are encrypted at rest, never
shown back to you or anyone else, and used only to make the requests you ask
for.
### Usage information
- When your account was created and when you were last active.
- How much AI compute you have used (a running total, plus hourly totals kept
for 30 days) and how many code-execution runs you have made, which we use to
apply free usage limits and plan capacity.
- Which notebook, page and chat tab you last had open, so the app can reopen
where you left off.
We don't record your IP address. Our hosting provider keeps MathBB's server
logs: the messages the app writes while it runs, which can include internal
identifiers such as your account ID, and a record of each request (the address
requested, when, and the result). These logs are kept for 14 days. Like any
network operator, our hosting provider also handles your IP address in order to
deliver your traffic to us.
### Information from connected services
- **Canvas / LTI.** If you reach MathBB through a course in Canvas or another
learning management system, that system sends us an identifier for you, your
name and email where the institution provides them, your course, and your role
in it. We record which course notebooks you have opened so your instructor can
see who has accessed them.
- **Telegram.** If you link a Telegram account, we store its Telegram
identifier and the state of your conversation with the MathBB bot.
- **GitHub.** If you connect GitHub backup, we store your GitHub username, the
repository and branch linked to each notebook, and the last commit synced.
---
## 3. Why we use it, and our legal bases
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing your account and the service: storing and showing your notebooks, sharing, chat, AI assistants, code execution, proof checking, LaTeX compilation | Account information, content, credentials, connected-service data | Performance of our contract with you |
| Service emails: verification, password reset, sharing notifications, and notices about your account or the service (such as changes to our terms or this policy, security incidents, or planned downtime) | Email address, username | Performance of our contract with you; legal obligation where the law requires us to notify you |
| Free usage limits and abuse prevention | Usage information | Legitimate interests: keeping the service available and affordable |
| Security, troubleshooting and capacity planning | Usage information, server logs | Legitimate interests: keeping the service secure and working |
| Answering feedback and support requests | Feedback messages, account information | Performance of our contract with you |
| Complying with legal obligations | As required | Legal obligation |
Where we rely on legitimate interests, you can object (§ 8). We don't make
decisions about you based solely on automated processing that have legal or
similarly significant effects.
---
## 4. AI features
When you use **Dora** or **Relay**, the assistant reads what it needs to answer
you. That can include your message, the pages and files in the open notebook,
and earlier messages in the conversation. That content is sent to:
- **Anthropic** (Claude models), for Dora, for Relay agents that use Claude, and
for figure and 3D-model generation;
- **OpenAI**, only for Relay agents set to use OpenAI models, and only with an
OpenAI API key you have supplied.
These providers process the content to generate a response. Under their terms
for API customers, as of September 2026:
- **Anthropic** doesn't use API inputs or outputs to train its models. It
deletes them within 30 days, except where the law requires otherwise or it
finds a violation of its usage policy, in which case it may keep the inputs and
outputs for up to 2 years (and safety classification scores for up to 7 years).
Figure generation runs code in Anthropic's code-execution environment, whose
files are kept for up to 30 days.
- **OpenAI** doesn't use API data to train its models. It keeps inputs and
outputs for up to 30 days for abuse monitoring, unless the law requires
longer. Relay also stores each OpenAI response with OpenAI for 30 days, so that
an agent's next step can build on it.
These terms are set by the providers and can change; see
[Anthropic's](https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data)
and [OpenAI's](https://developers.openai.com/api/docs/guides/your-data) own
documentation. When you use your own API key, your use is also covered by your
own agreement with that provider.
Don't put anything into a chat that you wouldn't want sent to these providers.
---
## 5. Service providers
We use the following companies to run MathBB. They process personal data on our
behalf, under contracts that require them to protect it and use it only to
provide their service. Each name links to that company's own privacy policy:
| Provider | What they do | Data involved |
|---|---|---|
| [Render](https://render.com/privacy) | Hosting, database, file storage | All account data and content; server logs |
| [Amazon Web Services](https://aws.amazon.com/privacy/) | Sandboxed code execution; Lean proof checking; nightly backups | Code you or an assistant runs, with its files and output; Lean files checked; an encrypted backup copy of all account data and content |
| [Anthropic](https://www.anthropic.com/legal/privacy) | AI models | Content sent to the AI features (§ 4) |
| [OpenAI](https://openai.com/policies/privacy-policy/) | AI models (Relay only, with your own key) | Content sent to those Relay agents |
| [Zoho](https://www.zoho.com/privacy.html) | Sending email | Your email address and the message |
| [GitHub](https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement) | Notebook backup (optional, at your request) | Notebooks you choose to back up |
| [Telegram](https://telegram.org/privacy) | Chat bot (optional, at your request) | Messages you send the MathBB bot and its replies |
The software libraries MathBB's pages use are served from our own servers, not
from third-party content networks. The exception is a page that embeds a YouTube
video: the video is loaded from YouTube, in its privacy-enhanced mode, so YouTube
receives your IP address and basic browser information when you view that page.
---
## 6. International transfers
Rhombic Research is based in the United States, and MathBB runs there: our
servers, database and file storage are hosted by Render in Oregon, and code
execution, proof checking and our nightly backups run on Amazon Web Services,
also in Oregon. If you
use MathBB from the EU, EEA, UK or Switzerland, your personal data is processed
in the United States.
Our service providers process personal data for us under data processing
agreements, which protect
data they handle or pass on outside the EEA, UK and Switzerland:
- **Render**, **Amazon Web Services** and **GitHub** are certified under the
[EU–U.S. Data Privacy Framework](https://www.dataprivacyframework.gov/list),
its UK Extension and the Swiss–U.S. Data Privacy Framework, and their
agreements also include the European Commission's Standard Contractual
Clauses ([Render](https://render.com/dpa),
[AWS](https://aws.amazon.com/compliance/gdpr-center/),
[GitHub](https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement)).
- **Anthropic**'s [agreement](https://www.anthropic.com/legal/data-processing-addendum)
includes the Standard Contractual Clauses, with the UK and Swiss addenda.
- **OpenAI**'s [agreement](https://openai.com/policies/data-processing-addendum/)
includes the Standard Contractual Clauses with the UK Addendum; data from the
EEA and Switzerland is handled by its Irish entity.
- **Zoho**'s [agreement](https://www.zoho.com/gdpr.html) and its agreements
between Zoho companies are based on the Standard Contractual Clauses.
You can ask us for a copy of the relevant safeguards.
---
## 7. Who can see your content
- **You**, and no one else by default.
- **People you share with.** Collaborators you add can view or edit a notebook
and read its collaborator chat. Anyone with a public link can read a shared
page or notebook, with no account needed. Course share links make a notebook
available to students in a course.
- **MathBB Commons.** If you propose a notebook for MathBB Commons and it's
accepted, it's listed publicly with the title, description and byline you
gave. Revoking the notebook's public link removes it from the listing.
- **Instructors.** If you open a notebook through a course, its instructor can
see that you did.
- **Our administrators.** A small number of people who operate MathBB can access
account data and content, only as needed to run the service, respond to
support or feedback, investigate abuse or security problems, or comply with
the law.
- **When required by law.** We may disclose information if the law requires it,
or where necessary to protect the rights, safety or property of our users, the
public, or Rhombic Research.
- **If MathBB changes hands.** If MathBB is transferred as part of a merger,
acquisition or sale, personal data may transfer with it, subject to this
policy, and we'll tell you before that happens.
---
## 8. Your rights
If you are in the EU, EEA or UK, the GDPR gives you the right to:
- **access** the personal data we hold about you and receive a copy of it;
- **rectify** inaccurate data;
- **erase** your data;
- **restrict** our processing of it;
- **data portability**: receive the data you gave us in a machine-readable form;
- **object** to processing based on legitimate interests;
- **withdraw consent** at any time where we rely on consent, without affecting
earlier processing;
- **lodge a complaint** with your local data protection authority.
Much of this you can do yourself in the app:
- download any notebook, with its pages, files and folder structure, as a ZIP;
- change your display name, email address and password in Settings;
- delete individual notebooks, chat sessions and files, or your whole account
(Settings → Security → Delete Account);
- remove API keys, disconnect GitHub and unlink Telegram at any time.
For anything else, including a full copy of your data or erasure from our
backups, email support@rhombicresearch.ai. We'll respond within one month, which
we may extend by two further months for complex requests, telling you why. We may
need to confirm your identity first.
Wherever you live, you can ask us to access, correct or delete your data, and
we'll honor the request as far as the law allows.
---
## 9. Retention
- **Your content and account information** are kept while your account exists,
or until you delete them.
- **Deleting your account** permanently removes your account, notebooks,
uploaded files, AI chat transcripts and code-execution workspaces from our live
systems. We keep only an anonymous record that an account was deleted, with no
identifying information. Notebooks owned by others that you collaborated on
are not deleted.
- **Guest accounts** are deleted automatically after 24 hours.
- **Hourly AI usage records** are deleted after 30 days.
- **Server logs** are kept for 14 days.
- **Backups.** We keep backup copies of our database and files so we can recover
from failures: our hosting provider keeps recovery copies for about a week,
and we keep an encrypted nightly copy with Amazon Web Services for 30 days.
Each is then deleted automatically. Data you delete can remain in backups
until they expire. Backups aren't used for anything except recovery, and if we
ever restore one, we re-apply every deletion made since it was taken before the
restored data is used again.
- **Copies outside MathBB** aren't affected by deleting your account: GitHub
repositories you backed up to, files you downloaded, and data held by the AI
providers under their own retention policies.
---
## 10. Cookies and browser storage
MathBB only uses cookies that are strictly necessary for the service you asked
for, so they don't require consent:
| Cookie | Purpose | Lasts |
|---|---|---|
| Session | Keeps you logged in and protects forms against forgery | Until you close your browser |
| Remember me | Keeps you logged in between visits | 30 days |
We don't use analytics, advertising or tracking cookies. If that ever changes,
we'll ask for your consent first.
The app also saves display preferences (pane widths, font sizes, whether the
sidebar is collapsed, drawing colors) in your browser's local storage. These stay
on your device and aren't sent to us.
---
## 11. Children
MathBB is not directed to children. You must be at least 16 to create an
account, unless you use MathBB through your school or university, which is
responsible for any consent required. If we learn we have collected personal
data from a child without the consent the law requires, we'll delete it.
---
## 12. Security
We protect your information with measures that include encrypted connections
(HTTPS), hashed passwords, encryption at rest for stored API keys and access
tokens, and isolated, network-restricted sandboxes for running code. No system is
perfectly secure. If a breach puts your personal data at risk, we'll notify the
relevant authority within 72 hours where the law requires, and tell you without
undue delay if the risk to you is high.
---
## 13. Changes to this policy
We'll update this page when our practices change and revise the effective date
above. If a change is significant, we'll notify account holders by email or in
the app before it takes effect.
---
## 14. Contact
Rhombic Research, Inc.
support@rhombicresearch.ai