Privacy Policy
What TypesetOS processes, where it is stored, and how it is used to provide the service.
Effective 3 September 2026
Controller and scope
TypesetOS, Shah Jamal, Lahore, Punjab 54000, Pakistan, is responsible for the personal information described in this policy. This policy applies to the TypesetOS website, document-formatting service, preview, account features, purchases, revision access, and optional website analytics.
Information we process
- Document files, filenames, and the information contained in files you upload.
- The formatting preset you select, job status, document identifiers, preview information, and technical document fingerprints used to operate revision eligibility.
- Browser session information needed to keep a document associated with your session.
- When you request a university standard, the institution, country, email address, optional program, official-guidance URL, notes, referring page, and campaign tags you choose to submit. This request form does not accept thesis or dissertation files.
- When you sign in, the account information and authentication status provided through Clerk.
- When payment is available through Paddle, transaction and entitlement information needed to unlock a document and its Thesis Pass. Paddle, not TypesetOS, handles payment-card details.
- Operational request, performance, and error metadata needed to host, secure, monitor, and troubleshoot the service. TypesetOS does not intentionally place manuscript text or payment credentials into operational telemetry.
- If you choose to allow optional analytics, website routes and product-funnel milestones such as document selection, formatting submission/completion, university-request viewing/submission, preview viewing, checkout opening, confirmed Thesis Pass purchase, download, and reformat activity. Our analytics event layer does not send document contents, filenames, document IDs, Clerk IDs, Paddle transaction IDs, presigned links, payment credentials, university-request email addresses, institution names, guidance URLs, program text, or notes.
How document processing works
The public website is delivered through Cloudflare Pages. Uploaded .docx files, formatted results, preview assets, and bounded audit artifacts are stored in Cloudflare R2. The TypesetOS backend and formatting workers run on Oracle Cloud Infrastructure. The formatting engine reads the document, applies the selected formatting preset, creates a formatted .docx result, and creates watermarked WebP page previews for review before download.
Temporary local copies used during processing are removed after the job. The original R2 upload is deleted after formatting completes. The formatted document and its preview assets are stored separately from the original upload.
How we use information
We use this information to process and deliver your formatted document, generate the preview, authenticate users, administer purchases and refund requests, enforce Thesis Pass revision eligibility, review demand for additional university standards, follow up about a submitted university request, secure the service, diagnose failures, operate the website, and, where you have allowed analytics, understand traffic sources and where visitors move through or leave the product funnel.
Service providers
- Cloudflare provides website delivery, network services, and R2 object storage for uploaded files, results, previews, and related service artifacts.
- Oracle Cloud Infrastructure provides the compute environment that runs the TypesetOS backend and document-processing workers.
- Neon stores application records, including sessions, document metadata, university requests, checkout intents, and entitlements.
- Clerk provides account authentication and profile management.
- Paddle processes supported payments as Merchant of Record.
- Resend provides transactional email delivery, including internal university-request notifications and document or purchase notifications.
- Google Analytics is used only when you choose to allow optional analytics, to measure website usage and product-funnel events. TypesetOS keeps Google advertising storage, advertising user data, and advertising personalization disabled in this implementation.
Retention
Original uploads are deleted after formatting completes. For an unpaid document, the application records a 48-hour availability period for the formatted result and preview. For a paid Thesis Pass, the application records the six-month revision window and retains the paid result for at least that entitlement period plus an additional seven-day safety period.
University requests are retained while needed to assess demand, research possible standards, and follow up with the requester. You may ask us to delete or correct a request through the contact process below.
Automatic lifecycle deletion of every stored result, preview, and related artifact is still being finalized. We therefore do not represent a shorter automatic-deletion deadline than the application actually enforces. Payment and transaction records may be retained as needed for accounting, fraud prevention, disputes, and legal obligations. Google Analytics applies its own configured data-retention controls to analytics data collected with your permission.
Your choices and requests
You may manage or delete your account through available Clerk profile settings. Deleting a Clerk account removes its link to TypesetOS sessions; it does not erase payment records that must be retained for accounting, and it does not override the document-retention position described above.
Optional Google Analytics does not load until you choose to allow analytics. You can change that choice later through “Analytics settings” in the site footer. Declining analytics does not prevent you from formatting, previewing, purchasing, downloading, or managing a thesis.
To request access, correction, or deletion of personal information held by TypesetOS, contact [email protected]. We may need to verify your identity before acting on a request.
International processing and security
Our providers may process information outside Pakistan. We use providers and technical measures intended to protect the service, including scoped, time-limited links for file access, server-side ownership checks, payment-webhook verification, and isolated document-processing controls. No internet service can guarantee absolute security.
Please do not send passwords, payment-card details, or other unnecessary sensitive information in a document or support email.
Changes and contact
We will publish an updated effective date when this policy changes. For privacy questions or requests, contact [email protected].