Privacy policy
Last updated 25 September 2026
This policy covers the hosted mdreview service at app.mdreview.space, and the mdreview MCP server and Claude connector when they are pointed at that service. If you run mdreview yourself, your data stays on your machine and this policy does not apply.
What we store
Your account. Your email address, when the account was created, and whether it is active. You sign in with a one-time link sent to that address.
What you put into reviews. Documents (markdown or LaTeX), every past round of a document, comments and replies, feedback notes, and files you attach. This is the service, so we keep it until you delete it.
Sign-in and security records.
- For each browser session: when it started and was last used, the IP address, and the browser's user agent. You can see and end your sessions on the Account page.
- Agent tokens and connector tokens: a keyed hash of each token, never the token itself. You can revoke them on the Account page.
- A security log of sign-in events: the event, the time, the account, the email and the IP address.
- For sign-in emails: the address and requesting IP of each send, kept for two days to stop abuse, then deleted.
- The web server's standard access logs: IP address, time and requested path.
We use no analytics, no advertising and no tracking cookies. The cookies we set are for signing you in.
Who can see your reviews
- You. Every review belongs to the account that created it. Only the owner can edit or delete it.
- People you share with. A named share lets one person view it, or view and comment. A public link lets anyone with the link view it, but not comment. You can revoke shares.
- Your agents and connectors. An agent token, or an app you connect such as Claude, acts as you and has your access. You approve each connector on a consent screen and can revoke it on the Account page.
- The operator, rarely. The service administrator can read a specific review for support or abuse handling. That access is read-only, off by default, one document at a time, and every use is recorded in an audit log.
We do not sell your data, use it to train AI models, or share it with anyone else except as the law requires.
Services we rely on
| Service | What it gets | Why |
|---|---|---|
| Hostinger (virtual server in Germany) | Everything above, stored on its disks | Running app.mdreview.space |
| Microsoft Azure Communication Services | Your email address and the sign-in link | Sending sign-in emails |
| GitHub Pages | Standard request logs | Hosting mdreview.space (this site and the docs, not the app) |
Keeping and deleting
Reviews, comments and attachments stay until you delete them. The dashboard and the delete_review
tool both remove a review. There is no self-serve account deletion yet: email
rana.waqas.works@gmail.com and we will delete your account and
everything it owns within 30 days.
Contact
Questions or requests: rana.waqas.works@gmail.com.
We will post changes to this page and update the date at the top.