Privacy Policy

Last updated: September 26, 2026

The short version

Markdown Preview has no accounts and your documents never leave your device. We use Microsoft Clarity and Google Analytics for anonymous usage analytics and PostHog to hear about crashes; your document content is never uploaded.

Your documents

Everything you type, upload or import is rendered entirely in your browser and saved locally using browser storage (IndexedDB and localStorage) so your tabs and view settings (theme, font, text size and layout) survive a reload. Nothing is uploaded to our servers. Clearing site data for this domain permanently removes all locally saved documents.

The same browser storage also keeps a few notes that make the app's guidance work: that you have seen the welcome tour, so it is shown once; which app features and kinds of markdown syntax (such as tables or math) you have used, so the occasional "Did you know" tip suggests something you have not tried; when the last tip was shown and how often each one has been shown, so tips stay rare; and whether you turned tips off. These notes stay on your device and are never sent to us.

You can also open a file from your device and save your changes straight back to it. Your browser asks you to pick that file, and the app can only read and write the files you choose, nothing else on your disk. We remember which file a tab came from so you can save it again later, and that reference is stored in your browser too. Saving to a file happens only when you ask for it, and the file never leaves your device. Firefox and Safari do not support writing files this way, so there saving downloads a copy instead.

Importing from a URL

When you import a document from a URL, your browser fetches that file directly from the host you entered (for example GitHub). That request is subject to the destination's own privacy policy; we never see the URL or the content.

A document opened this way remembers, in your browser alongside the document itself, the address it came from, so the preview can show where it came from and offer a link that opens it again. That address is never sent to us, and you can remove it from the document with the close button on that bar.

The same applies to the README preview tool: pasting a repository or file URL there makes your browser fetch it straight from GitHub, GitLab or Bitbucket, with no credentials and without passing through us. Text you paste into that tool, or into the markdown table generator, stays in your browser exactly like a document in the editor.

Images and embeds in documents

When a document shows an image, a video or an embed that is hosted somewhere else (for example a picture linked from GitHub, or a YouTube video), your browser loads it straight from that host, the same as any web page would. That host sees your IP address and that the file was requested, under its own privacy policy; we are not involved. Embedded videos run in a sandbox and cannot use your camera, microphone or location. Images you paste or drop into the editor are stored inside the document itself and are not loaded from anywhere.

Feedback you send us

The optional in-app feedback form is the one place where something you type is sent to us: the message you write and, if you choose to include it, your email address, along with your browser's user-agent string and an approximate location (country and city, derived from your network by our hosting provider, your IP address itself is not stored). We store this in our own database (hosted by Neon) and use it only to improve the app and, when you left an email, to reply. Nothing is sent unless you press Send, and feedback is never linked to your documents. To have a submission deleted, ask through the feedback form itself (include the email you originally left so we can find it).

Analytics

We use Microsoft Clarity and Google Analytics to understand how the app is used, such as page views, clicks, scrolling and general session activity. These services may set cookies and collect telemetry like device type and approximate location, processed under the Microsoft Privacy Statement and Google Privacy Policy. Clarity session recordings are configured to mask text, so the content of your documents is not captured; your documents are never sent to either service.

On top of that, the app sends Google Analytics a few named events so we can see which features people find and which they miss: how far someone gets through the welcome tour (which step was shown, whether it was tried or skipped, whether the tour was finished, and which feature was opened from its last page); which app features are used, and whether it was the first time (for example zen mode, export, search, opening a file or importing from a URL); which kinds of markdown syntax you start using (for example that a document now has a table or math); and whether a tip was shown, acted on, dismissed or turned off. Each event carries only a feature's name. It never includes your document's text, a file name, the address of a URL you imported, or the table or the math itself.

To switch analytics off in your browser, open any page with ?analytics=off at the end of the address. Neither service is loaded again in that browser until you open a page with ?analytics=on or clear the site's data.

Error reports

When the app crashes or hits an error it did not expect, it sends a report to PostHog so we can find and fix the bug. A report holds the error message, where in the code it happened (the stack trace), the page path, your browser and operating system, and your approximate location (country and city, which PostHog works out from the connection). PostHog does not keep your IP address. It is used here for error reports only: no page views, no click tracking, no screen recordings, and nothing is stored in your browser. Addresses are cut down to the page path before sending, so the address of a document you imported never goes along, and your documents, file names and feedback messages are never part of a report.

Hosting

The static application files are served by our hosting provider, which may keep standard technical server logs (such as IP address and request time) to operate and secure the service. Fonts are served from our own domain; apart from the analytics scripts above, no third-party scripts are loaded at runtime. The footer shows a Product Hunt badge, an image served by Product Hunt; loading it shares your IP address with Product Hunt like any image request. The same goes for the "Featured on" badges on the About page, images served by the directories that list the app (Uneed, TinyLaunch, AlternativeTo, StartupBase, Turbo0, Smol Launch, Fazier and Twelve Tools). They are plain images and links: none of these sites runs a script here.

Changes

If this policy changes, the new version will be published on this page with an updated date above.