TheoremDB
TheoremDB
Last updated August 24, 2026

Privacy

How TheoremDB handles the data behind the website, the API, and the MCP connectors.

What TheoremDB receives

Search and record retrieval work without an account. Those calls process the search text and record identifiers needed to answer them, and search text never becomes a research record.

An account may hold a display name, handle, email address, authentication provider identifier, an optional public profile image, a password verifier for legacy sign-in, OAuth grants, and account activity. Tokens are stored as hashes, never as reusable plaintext.

If an authentication provider verifies a .edu address, the public profile may display an “Academic email” badge. The address and its domain remain private. The badge does not certify a person’s identity, affiliation, or current academic standing.

Profile-image uploads accept JPEG, PNG, or WebP. The service crops and re-encodes the image as a 256-pixel WebP file, which removes embedded metadata before publication.

A public contribution holds the submitted mathematics, its provenance, status, attribution, review history, and evidence. An MCP or API request carries only the fields the client sends. The rest of a conversation with an agent stays with that client unless a user or model puts it in a request.

A feedback message can include an optional reply email or other contact text supplied by the sender. Buying usage credits gives TheoremDB the Stripe checkout and payment-intent identifiers, account, package, credit quantity, amount, currency, payment status, refund or dispute state, and fulfillment timestamps needed to credit the account and reconcile the purchase. Stripe keeps the payment-card details.

Service and security data

Network addresses, timestamps, requested paths, client headers, and error details are processed for security and operations. Rate-limit identifiers are stored as keyed hashes in short windows. Hosting providers keep their own access and security logs under their published policies.

Anonymous audience measurement

The website counts page paths and uses a random first-party browser identifier to estimate its audience. The identifier rotates after 30 days. Each tab receives a separate session identifier, which resets after 30 minutes without activity. The API transforms both identifiers with a keyed hash before storage.

A session summary can hold its entry and latest page, the hostname of an external referring site, the Fly.io network edge region that accepted the request, page count, and time while the page was visible. TheoremDB also keeps the ordered page paths in a session and named product actions such as opening TheoremDB Researcher or TheoremDB Problem Creator in ChatGPT. It excludes raw network addresses, user-agent strings, full referrer URLs, query strings, and individual cursor or keystroke activity. Session summaries and their journey events are deleted 90 days after their last activity and are excluded from database backups.

Browsers that send Global Privacy Control or Do Not Track are excluded. You can also change this browser’s setting here. Disabling measurement removes its local anonymous identifiers.

Checking this browser’s setting.

Research workflow measurement

The agent workflow records append-only retrieval impressions so its search and duplicate checks can be evaluated. An impression can hold a digest of the query, up to 64 normalized query terms, the resolved problem identifier, candidate record identifiers, the workflow stage, its decision, retrieval health, and the selected approach key. A laterrecord_result call can link its public record to that impression.

Operator reports aggregate where sessions stop and how often retrieval is degraded. They exclude raw query text, network addresses, and user-agent strings. Query terms and identifiers stay in the append-only research audit log so retrieval decisions can be reproduced.

How the data is used

To return search results, maintain research records, attribute contributions, prevent duplicate writes, operate OAuth, enforce quotas, review submissions, investigate abuse, improve retrieval quality, respond to support and feedback, fulfill usage-credit purchases, and reconcile refunds or payment disputes.

TheoremDB does not sell personal data and runs no behavioral advertising.

Service providers

Hosting
Infrastructure providers run the API and the website.
Sign-in
Google or GitHub processes social sign-in when you choose one of them.
Agent clients
A third-party client you connect processes your activity under its own terms.
Feedback
Tally displays and processes the public feedback form. Linear receives the resulting issue, message, page context, and any optional reply email for triage. When you open the form while signed in, TheoremDB sends a Tally-specific opaque subject and a short-lived signed proof. Tally does not receive your internal account ID, password, session token, or API token.
Submission review
A configured model provider can review a submitted problem, packet candidate, validation report, source metadata, or uploaded research image. Image review uses a short-lived private preview. The provider does not receive your TheoremDB password, session, API token, or payment details. Its handling of review inputs follows its own service terms and TheoremDB’s provider agreement.
Payments
Stripe processes the checkout and payment-card details when you buy usage credits. TheoremDB receives the transaction identifiers, amount, currency, status, and later refund or dispute updates needed to fulfill and reconcile the purchase.

Each provider receives the data it needs to perform its part and no more.

Retention and public records

Account and authentication
The account and its private sign-in records remain while the account is open. Sessions and OAuth grants carry recorded expiration times, with current issuance capped at 30 days, and revocation can end them earlier. Account deletion removes sessions, grants, provider identities, API tokens, step-up grants, notification settings, and the stored profile image. It replaces the public identity with a random deletion tombstone and keeps the deletion receipt needed to prevent credential or identity recreation.
Security records
Rate-limit buckets and risk assessments remain until each row's recordedexpires_at time, then the cleanup job removes them. Infrastructure access and security logs follow the hosting provider's published retention policy.
Submission and provider review
Submitted problem, packet, asset, validation, decision, and provider-receipt records remain with the public research and review history. A private image-review URL expires after five minutes. A review provider's copy of an input follows its service terms and TheoremDB's provider agreement.
Feedback
The Tally identity proof expires after 15 minutes, and TheoremDB does not store the webhook proof as an account mapping. A locally submitted message, its page and category, and any optional reply address stay in the operator mailbox for triage history. There is no automatic fixed deletion period. Tally and Linear keep their copies under their own retention policies, and a fulfilled privacy request can remove the optional contact information where the sender can identify the record.
Payments and usage credits
Stripe transaction identifiers, package, amount, currency, payment status, refunds, disputes, fulfillment times, and the associated credit entries remain with the append-only usage-credit ledger. They are kept for balance reconstruction, payment reconciliation, disputes, and accounting obligations. Stripe retains payment-card data under its own policy.
Retrieval audit
Retrieval impressions, their normalized query terms, candidate identifiers, decisions, and linked feedback remain in the append-only research audit log. They stay for the life of that audit record so a published result's retrieval and duplicate checks can be reproduced. Raw query text is not stored in these impressions.

Public mathematical contributions and their revision history stay as part of the research record. Moderation can hide content while keeping a tombstone, attribution, or audit event.

A profile image remains public until the account replaces or removes it. Account deletion removes the stored image while preserving public mathematical records under the deletion policy above.

Public profile image responses use Cache-Control: no-store. Conforming browsers and shared HTTP caches fetch them again for each request, so a replacement or removal applies to the next fetch. Copies saved outside normal HTTP caches remain outside TheoremDB’s control.

Your choices

Revoke OAuth grants on the account page. Send requests to access, correct, or delete account data through Support. A public research contribution may be kept in de-identified or tombstoned form where the integrity of the mathematical record requires it.

The public feedback form is provided by Tally and routed to Linear for triage. The Tally script and form frame load on Support and public statement pages where the form can open.

Report a problem

Your ChatGPT account

Opening ChatGPT

ChatGPT is opening in a new tab.