1. Scope
This policy applies to the Explixit Chrome extension, PDF reader, account service, and connected APIs. It does not apply to other websites that you visit in the browser or replace the privacy rules of the website that supplied a PDF.
2. When PDF processing begins
Installing the extension or detecting a PDF does not upload the document. You must sign in first. Processing begins only after you enter the Explixit Reader and use a feature that needs document content. You can leave reading mode for the current PDF and return to Chrome's native PDF reader.
- 01After signing in, you open a remote or local PDF and enter the Explixit Reader.
- 02The extension calculates a content hash in the browser. The API records document metadata and your ownership relationship.
- 03When you use a document AI feature, the request includes the current complete PDF. The API verifies the hash, ownership, and file limits.
- 04The API loads the current conversation history from PostgreSQL and sends the PDF, history, and request to the configured model provider.
- 05The result returns to the reader and is stored only where the feature requires it. The API releases the PDF bytes after the request and does not write them to the database, a file directory, or object storage.
3. Data we process
Account and authentication
- Username, display name, verified email address, irreversible password hash, and email-verification or password-reset state.
- A stable Google subject, verified email, name, and image when you use Google sign-in, plus OAuth credentials encrypted on the server.
- Independent Website and Extension sessions, single-use session handoffs, login times, and account state.
- Request-rate data and a client IP supplied by a trusted proxy for abuse prevention.
Documents and reading content
- PDF bytes processed during a request, plus persisted filename, content hash, document ID, and page-count metadata.
- Summaries, keywords, page translations, selections, formulas, question context, and model output.
- Highlights, comments, notes, explanation records, and conversation history.
Subscriptions and usage
- Free or Pro entitlement, billing period, document counts, AI request counts, and translated-page counts.
- Stripe customer, subscription, billing-period, and webhook identifiers when Stripe is enabled.
- Explixit does not store full payment-card numbers. Stripe processes card information.
Local extension data
Chrome Storage keeps the device session managed by the Extension Background, reading-mode state, and interface preferences. It does not store passwords, email codes, or Google OAuth tokens. The current tab holds the active PDF in memory. Accounts, document ownership, conversations, and feature results are also stored in server-side PostgreSQL and are not local-only.
4. Why we use this data
- Build the current PDF context and provide page translation, summaries, and grounded questions and answers.
- Associate highlights, comments, notes, explanations, and conversations with the correct user and document.
- Operate authentication, session security, usage limits, subscriptions, and billing.
- Diagnose failures, prevent abuse, protect the service, and recover actions that you requested.
The landing page does not load advertising, behavioral analytics, chat widgets, conversion tracking, or related non-essential cookies.
5. Third-party processors
- Model providers: requests that need paper context receive the current complete PDF and may receive it again during later questions. Retention, training, and deletion depend on the provider contract and configuration; Explixit does not make an absolute claim without evidence.
- Text-model gateway: minimized text operations, such as translating a selection, may send only the selected content to a configured text-model gateway.
- Stripe: processes Checkout, Billing Portal activity, payments, receipts, refunds, and subscription state.
- Authentication email service: sends registration codes, password-reset links, and account-security notices. It is configured separately from Stripe billing email and does not use remote tracking images.
- Google: handles OAuth authorization when you choose Google sign-in and returns a stable account identifier, verified email, and basic profile. Explixit does not request Gmail, Google Drive, or offline business access.
- Stripe email: Stripe may send payment and subscription messages according to Stripe Dashboard settings.
- Hosting and database: the service runs in server-side Docker and PostgreSQL and is exposed over HTTPS. New native-PDF requests do not persist PDF bytes to a file directory.
Processors may handle data outside your region. We will update this policy when suppliers, models, or hosting arrangements materially change.
6. Storage and retention
Accounts, document ownership, metadata, conversations, translations, and personal records remain while the account exists or while needed to provide the feature. New native-PDF requests do not persist PDF bytes. Deleting an account removes directly linked data through database cascades. Unreferenced legacy files are handled by the compatibility cleanup policy.
Production database backups are currently retained for 14 days and then expire automatically. Stripe billing, refund, dispute, fraud-prevention, and legally required records may remain longer. Operational logs follow the server rotation policy.
7. Security measures
- Model-provider API keys stay on the server and are not bundled in the Chrome extension.
- Signed bearer credentials, document ownership checks, and user-scoped queries isolate data.
- Sign-in and registration use basic rate limits; authentication emails share a per-email cooldown and hourly cap, and production requires secure cookies and trusted origins.
- Registration codes and session handoffs are stored only as hashes and have short expirations, attempt limits, or single-use consumption rules.
- A successful password reset revokes old Website and Extension sessions.
- Stripe webhooks require signature verification and verified events are recorded.
No system can promise absolute security. A discovered issue should lead to containment, investigation, and notification as required by applicable rules.
8. Deletion and your rights
You can delete your account from the account area on the pricing page after cancelling any active Pro subscription in Stripe Billing Portal. See Account and data deletion.
Send access, correction, deletion, restriction, or complaint requests to the public support address.
9. Children
Explixit is not directed to children under 13. Where a higher minimum age or guardian consent applies, use the service only after satisfying the local requirement.
10. Contact and changes
For privacy, access, deletion, or security questions, contact explixitai@outlook.com.
We will update the version and date, and provide reasonable notice, when data uses, processors, or retention rules materially change.