This Privacy Policy explains how MDVIEW (“MDVIEW”, “the App”, “we”, “us”) handles information when you use the application to upload, preview, and share Markdown documents, including the optional feature to view Google Drive documents. By using the App you agree to the practices described here.
MDVIEW is a lightweight Markdown preview tool operated by its developer. For any privacy question or request, contact us at riloaw@gmail.com.
When you upload a Markdown file, its contents are stored on the server hosting the App (in a single upload directory) so the App can render a preview and generate a shareable link. Uploaded files remain available until they are removed by the operator of the server.
If you choose to view a Google Drive document, you sign in with Google (OAuth). We request read-only access to your Google Drive (the drive.readonly scope) solely to:
Documents are rendered live and are not stored by the App. We only access the specific file you request; we do not browse, index, or copy your other Drive files. Because access uses your own Google credentials, you can only view documents you already have permission to access.
After you sign in with Google, the resulting OAuth token is held in the server’s memory and referenced by a session cookie (mdp_sess). Tokens are not written to a database and are discarded when you log out or when the server restarts. We use short-lived cookies during the sign-in flow to protect against cross-site request forgery.
Your theme (light/dark) and zoom preferences are stored in your browser’s localStorage on your device only. They are never sent to the server.
We do not run advertising or third-party analytics/tracking, and we do not sell or rent any information. The App does not intentionally collect names, contact lists, or other personal data beyond what is described above.
The App communicates with Google APIs to authenticate you and fetch the documents you request. The preview page also loads the Mermaid diagram library from a public CDN (jsDelivr) to render diagrams in your browser. We do not otherwise share your information with third parties.
Uploaded files persist on the host server until deleted by the operator. Google OAuth tokens persist only in server memory for the duration of your session and are cleared on logout or server restart. Browser preferences persist locally until you clear them.
We use HTTP-only session cookies and rely on Google’s OAuth for authentication. However, no method of transmission or storage is completely secure. You are responsible for keeping your device and Google account secure, and for the sensitivity of any file you upload.
The App is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect their data.
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date above. Continued use of the App after changes constitutes acceptance of the updated policy.
Questions about this Privacy Policy: riloaw@gmail.com.