Privacy Policy
This policy describes what the xRead service at https://www.xread.io (and related xread.io hosts) actually collects and processes when you use the Microsoft Word add-in or our website. Last updated: August 2026.
What xRead is
xRead helps you extract, verify, summarize, and discuss academic references. The Word add-in loads UI from our servers into Word’s task pane and reads the active document only in Word. We do not upload full documents automatically. Data is sent to our API when you take an action that requires processing (for example running citation tools, chat, or sync).
Data you send to xRead
Depending on the feature you use, requests to our servers may include:
- Text excerpts from your document (including selections, reference sections, or passages you paste).
- Structured citation lists and files or notes you attach to a request.
- Chat messages, optional conversation history your client sends, and sometimes an image URL you ask us to consider.
- Authentication tokens when you are signed in (see “Account data”).
Traffic is sent over HTTPS. Our backend may forward portions of that content to AI providers we contract with (or a provider you configure with your own key) and to scholarly or search APIs such as OpenAlex, Semantic Scholar, and where configured SerpAPI (xRead seat only), solely to fulfill the feature you invoked. We may change which models we use.
Account data we store
If you create an account, we store typical account records in our database, including:
- Your email address, a password hash (not your plain password), and session / refresh-token material for secure login.
- Optional institutional association if your organization provisions xRead.
- Saved references (“library”): citation strings and related metadata you save to your account.
- Persona and “skills” markdown you configure for Lux, and structured activity events (for example timeline or assistant events) tied to your user id for product features and diagnostics.
- Billing: if you subscribe or buy credit packs, we store Stripe customer and subscription IDs, invoice-grant records, and a credit-wallet ledger (balance and debit/grant entries). We do not store full card numbers; Stripe processes payments.
- Your API key (BYOK): if you save a key in System Controls, we store it encrypted so we can call your provider for complex tasks. We show only a hint (last characters) in the UI.
Word stores your session in the hosted task pane so you stay signed in.
Chat and “ephemeral” processing
Chat and similar endpoints process the payload you send to return an answer. We do not advertise a separate long-term “chat transcript” product in our database schema; treat chat content as sensitive and avoid pasting legally restricted or highly personal data. Standard server and cloud operational logs may exist for security and reliability and can briefly include request metadata.
Shared literature cache
To reduce duplicate external API calls, we maintain aggregated public scholarly metadata and derived summaries keyed by citation identifiers (for example DOI or normalized title). This cache does not need to retain your full manuscript; it stores reference-level enrichment that may be reused across users.
Local storage on your device
The Word add-in may cache results (for example summaries or UI state) in Office’s host environment so the product feels responsive. An API key you save in System Controls is stored encrypted on our servers (see Account data), not only on the device.
Support form
When you use support.html, your name, email, subject, and message are posted to our /api/support endpoint over HTTPS so our team can reply. Handle support messages like email: do not include secrets or full unpublished work unless you accept that we may need to read it to help you.
Retention and deletion
We retain account-linked data while your account exists and as needed for legal or security obligations. To request deletion or export of personal data, email support@xread.io from your registered address where possible.
Third-party services
- AI and search providers (for example Google, OpenRouter, Semantic Scholar, OpenAlex, SerpAPI — the set may change) act as sub-processors when we call them on your behalf. Review their policies for how they handle API traffic.
- Stripe is our payment processor for seats and credit packs. Stripe receives the billing details you enter at checkout.
- We do not sell your personal information to advertisers. We use data to run and improve xRead.
Contact
Questions about this policy: support@xread.io.