Privacy policy
This policy explains what information Libram collects, how it is used, and the choices you have. It is written to be read, not skimmed past — it's short because we collect little.
Who this covers
Libram is self-hostable software. This policy applies to the services we operate: this website (libram.dev), the public demo workspace (demo.libram.dev), the sign-in relay (auth.libram.dev), and any other Libram workspace we run ourselves.
If you use a Libram workspace that someone else hosts on their own Cloudflare account, that operator controls the data in it and is responsible for their own privacy practices. Our sign-in relay may still be involved in getting you signed in to such a workspace (see below), and this policy covers that step.
Information we collect
When you sign in with Google or GitHub
Libram has no passwords; you sign in with an existing account. We request only basic profile information:
| Provider | What we ask for | What we receive |
|---|---|---|
The openid, email, and profile scopes | Your Google account ID, email address (if verified by Google), display name, and profile picture URL | |
| GitHub | The read:user and user:email scopes | Your GitHub user ID, username, display name, avatar URL, and verified email addresses |
We do not request, and cannot access, anything else in your Google or GitHub account — no files, mail, calendar, contacts, repositories, or activity. We do not store the access or refresh tokens these providers issue; they are used once, during sign-in, to fetch the profile above, and then discarded.
We use this information to:
- create and identify your user account in the workspace you're signing into;
- show your name and picture to other members of that workspace, and attribute your edits, comments, and suggestions to you;
- link your Google and GitHub identities to the same account when they share a verified email address, so you can sign in with either;
- decide whether you're allowed into the workspace (by invitation, an allowed email domain, or an allowlist), and send the email invitation that got you there.
The sign-in relay (auth.libram.dev)
Instances we operate share a single Google and GitHub app registration. To make that work, the sign-in round trip runs on auth.libram.dev, which then passes a short-lived, signed identity (the profile fields above) to the workspace you're signing into. The relay has no database: it stores nothing about you beyond the cookies needed to complete a single sign-in, which expire within minutes. It only delivers identities to origins on an explicit allowlist.
Content you create
Documents, comments, suggestions, uploaded files, folder structure, and the activity log that records who changed what. This is the product; storing it is the point. It is stored in the Cloudflare account that hosts the workspace, and is visible to the other members of that workspace.
Docs you deliberately publish are visible to anyone with the link, and may be indexed by search engines. Files you upload are served at unguessable URLs so that they can be embedded in published docs; anyone who has such a URL can open the file.
Automatic summaries
Libram generates short summaries and keywords for docs and folders to make search and navigation better. To do this, document content is processed by a language model running on Cloudflare Workers AI, within the same Cloudflare account as the workspace. Summaries are generated automatically and are not editable. This feature can be turned off by the workspace operator.
Agents and integrations you connect
Libram exposes a REST API and an MCP (Model Context Protocol) server so that AI tools can work with your docs. Those tools act only with credentials you create — a personal API token, or an OAuth authorization you grant in the browser with a scope you choose (read, comment, or write). What a connected tool then does with the content it reads is governed by that tool's own privacy policy. You can revoke a token or authorization at any time from the workspace settings, and every action taken through one is attributed in the activity log as automated, so it's always clear what a person did and what a tool did.
Technical information
Like any web service, our servers see your IP address, browser type, and the pages you request. Cloudflare, our hosting provider, processes this to serve the site and defend against abuse. We do not run third-party analytics or advertising trackers on these sites.
Cookies
We use a session cookie to keep you signed in to a workspace, and short-lived cookies to protect the sign-in flow against forgery. No cookies are used for tracking or advertising.
How we share information
We do not sell your information, and we do not share it with third parties for their own marketing. Your information is disclosed only:
- to other members of your workspace, as described above;
- to our service providers, who process it on our behalf: Cloudflare (hosting, database, file storage, email delivery, and Workers AI), and Google and GitHub (sign-in);
- to tools you authorize through API tokens or OAuth grants;
- when required by law, or to protect the rights, safety, and security of Libram or its users.
Google API Services — Limited Use
Libram's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: we use the Google profile information above only to provide and improve the sign-in and collaboration features of Libram that you see; we don't use it for advertising, we don't sell it, and humans don't read it except with your consent, for security purposes, to comply with the law, or in aggregated, anonymized form.
Retention and deletion
- The demo workspace at demo.libram.dev is reset on a schedule. Everything in it — accounts included — is deleted at each reset. It is also marked
noindexso its short-lived pages stay out of search engines. - Other workspaces we operate keep your account and content for as long as you're a member. Deleted docs go to a trash from which they can be restored, and are then removed.
- To delete your account and the profile information we hold from Google or GitHub, email privacy@libram.dev from the address on the account. We'll confirm the deletion within 30 days. Content you contributed to shared docs may remain, attributed to a deleted user, because removing it would alter other people's documents.
- You can also revoke Libram's access to your Google account at any time from your Google account permissions page, or to your GitHub account from your GitHub authorized apps. Doing so stops future sign-ins; it does not by itself delete the data already in a workspace.
Security
All traffic to our services is encrypted in transit. Data is stored on Cloudflare's infrastructure, which is encrypted at rest. Session cookies are HTTP-only and secure. API tokens are stored only as hashes. Sign-in identities passed between the relay and a workspace are signed and single-use.
Children
Our services are not directed to children under 13 (or the age of digital consent where you live), and we don't knowingly collect information from them.
International transfers
Cloudflare operates a global network, so your information may be processed in countries other than your own. Cloudflare maintains appropriate safeguards for these transfers.
Changes
If we change this policy in a way that matters, we'll update the date at the top and, for changes that affect how we use your information, notify workspace members. Continued use after a change means you accept it.
Contact
Questions or requests about your information: privacy@libram.dev.