Privacy Policy
Last updated: 2026-09-17
This page summarises what data TPIX (Typst Package Index & eXchange) stores and why. Your use of the Service is also governed by the Terms of Service.
Data we store
- Account data — your email address and username. If you sign in with a social provider, the provider identity (provider name and provider user ID) is stored so you can sign in again. A password hash — never the password itself — is stored only if you set a password.
- Published content — the packages, manifests, READMEs, licences, thumbnails and metadata you upload, together with who published each version.
- Operational data — audit logs of namespace and package operations, and aggregate request metrics (counts and timings, not request bodies).
What we do with it
This data is used solely to operate the registry: to authenticate you, serve and index packages, enforce namespace permissions, and keep the Service reliable. We do not sell your data or use it for advertising.
Retention and deletion
Account data and published content are retained while your account is active. A published package is visible within its namespace (and public namespaces are public), so copies may remain in other users' caches. To delete your account or request removal of your data, contact the administrators.
Contact
For privacy questions, reach the administrators via the Contact page.