← zrxiv

Privacy: what this site records about you

What zrxiv.dev records when you use it, as the service runs today: the website, the JSON API and the MCP endpoint.

Accounts are optional

Reading, searching and asking the reading assistant work without an account. Signing in is optional and uses Google. Each conversation you start with the reading assistant is kept so that you can find it again (see Your history, below); in a shared conversation you are shown to the others by your name instead of as a numbered guest; and you can share a conversation with only the people you invite. A conversation shared with invited people only opens only for the people invited, once they have signed in. Some assistant features, including private research artifacts, require sign-in; artifacts also require approval (see The reading assistant, below).

Signing in sets cookies on zrxiv.dev, and nothing else here does. One, zrxiv_session, keeps you signed in for up to seven days. Two more are security cookies of the sign-in itself, which hold random values and nothing about you: one stops another site from signing you in, is set when you start signing in and stays for up to a year; the other carries the sign-in across the visit to Google and stays for up to thirty days. If you never start signing in, no cookie is set. Signed in or not, the service serves no analytics or tracking scripts, and its pages load nothing from any other site; signing in goes through Google, under its own privacy policy.

Our sign-in service, which runs on our own servers, keeps an account for each person who has signed in: the email address Google has verified, the name on your Google profile, Google's identifier for your account, for a Google Workspace account the organisation's domain, and when the account was created. It also keeps a record of each sign-in: when it began, when it ends, and the browser and network address the sign-in request arrived with. It also keeps, encrypted, the sign-in token and the access token Google issued when you first signed in here. The sign-in token carries what Google states about you in it: your name, your email address and the address of your profile picture. If Google has not verified your email address, the sign-in is refused and no account is made, but the sign-in service records the refusal, with that address. No password ever reaches us: Google checks it and tells us only who you are. We have set no period after which an account, its tokens, its sign-in records or a recorded refusal are deleted.

In a shared conversation the other people see your name and never your email address. The name is the one on your Google profile when you first signed in here, reduced to letters, digits, spaces and the characters . ' -. If that leaves nothing usable, the part of your email address before the @ is shown instead. A later change of your name at Google does not reach us; to have it changed here, write to contact@zrxiv.dev. Your name is not sent to the language-model provider. The assistant is told a label that the service assigns you for that conversation (the word "member" and four random letters or digits), and that label is what the transcript the assistant keeps records (see The reading assistant, below). Conversations before 2 October 2026 were recorded with your name; those transcripts are deleted 30 days after the conversation's last message. Your email address is not sent to the model provider and is not in that transcript.

When you take part in a shared conversation while signed in, the assistant service writes your email address and your account's identifier to that conversation's file on its own storage, beside your name, so that it knows you when you come back. When you share a conversation with invited people only, the list of addresses and domains you invite is written to the same file; only you are shown that list. The file is deleted with the shared conversation: 30 days after the last message in it or the last time someone joined it, or when the person who shared it stops sharing, or when we remove it. A conversation you have not shared has no such file; what is kept of it is set out under Your history, below.

Your history. While you are signed in, each conversation you start with the reading assistant is kept so that you can find it and open it again: your questions, the assistant's replies and the list of papers, with your account's internal identifier and the name you are shown by. It is kept for 30 days after the conversation's last question, then deleted. There is a limit on how many conversations are kept at once: past it, a new conversation is not kept, and the research page says so. Of a very long conversation, the most recent part is kept. You can delete one conversation, or all of them, from the history panel on the research page at any time; a deleted conversation is removed from the assistant service's storage at once, and the transcript the assistant keeps of it (see The reading assistant, below) is deleted 30 days after the conversation's last message. Deleting your account deletes your history. When you ask about something from an earlier conversation, the assistant can search your own earlier conversations (never anyone else's, never ones you shared with other people, and never from inside a shared conversation), and what it finds is sent to the language-model provider like the rest of the conversation. If you are not signed in, nothing of this is kept.

Signing out ends the sign-in on that browser. To have your account deleted, write to contact@zrxiv.dev from the address you signed in with; we delete it by hand. That does not delete conversations other people shared and you took part in, which are deleted as described above.

Reading

The service keeps no request log: its per-request logging is switched off, so it does not record your IP address, the pages you read, your searches or your MCP calls. If a request makes it fail, the error is written to its log, without your IP address. It answers from what it already holds, with three exceptions: the MCP tools lit_search, zrxiv_locate and zrxiv_reading_context (for a work whose text it does not serve) look your query or identifier up, live, in public metadata indexes (OpenAlex, Crossref, Europe PMC, arXiv, PubMed and Unpaywall). Those requests are sent from our server and carry only what you asked about, never your IP address. Their answers are kept in the service's memory for up to an hour, so a repeat is not asked again. Nothing else is fetched on your behalf.

The address /artifact/sha256:… answers which published work a file is a copy of, from a catalogue of file digests. No file is uploaded: only the file's SHA-256 digest is sent, as part of the address. Like every address you ask for, it passes through Cloudflare (below). This service does not write it to a log. It passes the digest, and nothing about who is asking, to the catalogue, which runs on our own servers and does not log it either. The service keeps the answer in its memory for up to 10 minutes. Lookups there are counted per client, by the IP address Cloudflare reports for you, in the service's memory only. If a file was issued to you personally (a download stamped with your name or with an identifier of its own), its digest belongs to that copy alone and can identify the copy, and so you, to whoever issued it.

Cloudflare

Every request reaches us through Cloudflare, which runs the edge of this site: your connection ends at Cloudflare, which passes the request on to our server. Cloudflare processes your IP address and the request (including any search terms, which are part of the address you ask for) to do that and to protect the site, under its own privacy policy.

Requests to add a work

If you ask us to add a work (POST /doi/…, POST /arxiv/…, the MCP tool zrxiv_request, or by opening the /doi/… or /arxiv/… page of a work we do not hold yet), we store the request: the identifier you sent, the depth you asked for, and when. We do not store who sent it: no IP address or other identifier of yours is written with the request. The request and its outcome sit in a working queue inside the service, which is cleared whenever the service is redeployed, and the identifier also appears in the log of the process that works through the queue. The work itself, once added, becomes part of the public corpus. A request may fetch and store an openly licensed copy of the work from the lawful location that states its licence; nothing else is fetched, and nothing about you travels with that fetch.

To stop one client filling the queue, requests to add a work are counted per client, by the IP address Cloudflare reports for you (twice for zrxiv_request, which has a slower ceiling of its own). Those counts are kept only in the service's memory, never written to disk, and are gone when the service restarts. Reading is never counted, except the MCP tools' lookups in outside indexes (lit_search, zrxiv_locate and zrxiv_reading_context) and the page of a work we do not hold yet (/doi/…, /arxiv/…), which looks it up in the same indexes; those are counted per client in the same way.

A request zrxiv's reading assistant makes for you is counted instead by an identifier of the conversation that its relay derives with a secret key: this service never sees your session, your IP address or anything it could tie back to you. Its lookups in outside indexes for you are counted by the same identifier. Those counts, too, are kept only in memory and are gone when the service restarts.

The reading assistant

The chat window on the home page and on each paper's page is a separate service from the rest of this site. What you type there goes to our assistant service, which runs on our own servers, and from there to a language-model provider that writes the reply.

The chat needs no sign-in. When you open the chat window it gets a random conversation id, kept only in that browser tab (its session storage, never a cookie): it is still there after a reload or when you open a paper from the conversation, and it is gone when you close the tab. If you are signed in, the conversation itself is also kept in your history, where you can open it again or delete it (see Your history, under Accounts, above). The assistant does not receive your name or your IP address, whether you have signed in or not (see Accounts, above), and the service that relays your messages keeps the link between the page and the conversation in memory only, for up to an hour of inactivity, unless the conversation has been shared (see below) or it is kept in your history.

The assistant keeps a transcript of each conversation, your messages and its replies, so that it can follow what was said: the most recent 200 turns of a conversation. Transcripts of conversations are kept on our servers and deleted 30 days after a conversation's last message. The people who run this service can read them. We do not use them to train any model. Please do not type anything into the chat that you would not want kept.

The assistant can read one part of the page you have open: the block with the paper's title, authors, year, DOI, record id and whether we serve its text. Nothing else on the page, and never the text of a work. The chat window shows each time it does.

On the research page a conversation can be shared. Sharing makes a link. Anyone who has the link can read the whole conversation, ask in it, and pass the link on; there is no list of who may open it. A person who is signed in can instead share with invited people only: that link opens only for the people they listed, by email address or by domain, and only after those people have signed in; the person who shared can change the list at any time, and anyone it no longer covers is put out of the conversation. Each person in a shared conversation is shown to the others as a numbered guest ("guest 2"), not by name or address. A person who has signed in is shown by their name instead (see Accounts, above). The secret part of the link comes after the "#", which a browser does not send to a server when it opens a page; it reaches our assistant service when a browser joins the conversation.

A shared conversation is no longer kept in memory only: the assistant service writes its questions, replies and list of papers to its own storage, so that the link still works the next day. It is kept there until 30 days after the last message in it or the last time someone joined it, or until the person who shared it stops sharing, which a guest can do only from the browser tab they shared it from, and a person who was signed in when they shared from any browser where they are signed in. Stopping ends the link and deletes that copy; the transcript the assistant keeps of every conversation is kept as described above. A conversation that a signed-in person started also stays in that person's history, shared or not, until they delete it there or its period ends (see Your history, under Accounts, above); deleting it there ends the link too. After a guest's tab is closed, nobody in the conversation can stop that sharing. To have a shared conversation removed, write to contact@zrxiv.dev and include its link. Do not put anything in a conversation you share that you would not want everyone with the link to read.

When the assistant reads the page that someone in a shared conversation has open, only that person's browser is asked. The assistant's answer is in the shared conversation, though, and can say which paper that is.

Web search. If you are signed in, the assistant can search the web and read web pages to answer you. Both are done from our servers, not from your browser. The words of a search are sent to the services our search service asks: Wikipedia and its sister projects (the Wikimedia Foundation), Wikidata, Hacker News (through Algolia), GitHub, Stack Overflow and arXiv. A page is fetched by our web gateway, so the site that is read sees our server's address and not yours; when the assistant reads the Internet Archive's copy of a page, the Internet Archive is asked for it from our servers. The search words, the addresses read and the text of the pages read are part of the conversation: they are kept with it for as long as it is, and sent to the language-model provider like the rest of it. Our web gateway keeps a copy of each page it fetched for at most 2 days, and its log records only the name of each site it contacted, never a page's full address or the words of a search. Beside the conversation, the pages the assistant read are listed with the time each was read and a link to look the page up in the Internet Archive, which may not have a copy; we do not ask the Internet Archive to save a page. What a web page says is that page's, not ours and not a paper's: the assistant is told to say what kind of source it is, and it can be wrong.

Private research artifacts. Artifacts are an alpha feature, not a production service, available only to approved signed-in accounts. Only the owner of an existing, unexpired private conversation can open its artifacts while their account remains approved. We store the artifact's title and content on our servers and its reference with the conversation. We support plain text, Markdown source and CSV, not HTML or executable pages. Artifacts are retained with their conversation; deleting it or reaching its retention limit immediately removes read access, and stored artifact copies are deleted by cleanup, retried if storage is unavailable. A conversation with artifacts cannot be shared. Downloads you keep yourself are not deleted by us. Artifact tool arguments may also remain in the assistant's separate brain transcript until its existing retention sweep; deleting a conversation does not erase that separate transcript. The transcript policy above still applies, including operator access and processing by the language-model provider.

Before a reply is shown, it is checked for how much of any one work it quotes. That check keeps a record of what it measured (which works, how many words, where in them, and what it decided), without the text of the reply or of your message. We keep that record for 90 days, then delete it.

To write a reply, the conversation is sent to a language model reached through OpenRouter. Every request asks OpenRouter to use only providers that keep no copy of it (zero data retention). When the first model is busy or fails, the request goes to another model, also through OpenRouter and under the same rule; no other provider is called.

Counts

This site publishes a few totals about its own use at /stats/launch, so that anyone can see how the service is doing: for each of the last seven days (UTC), how many times the MCP tool zrxiv_request was called and with what result, how many requests to add a work were finished, and, when a log of quote checks is kept, how many checks ran, what they decided and how long they took. These are totals per day only. They say nothing about who made a request, what was asked for or which conversation a check was for.

The zrxiv_request totals are kept in the service's memory and are gone when it restarts. The other totals are worked out, when the page is asked for, from the request queue and the quote-check log described above; they add nothing to either.

The service that relays the chat also keeps totals per day: how many chat windows were opened, how many conversations went past one reply, how many replies there were and how long they took, and what the quote check decided. It keeps them in memory and may write one small file of the day's totals, kept for up to 35 days. Those totals are for the people who run the service and are not published; like the others, they are counts per day, not records of any conversation.

What will change this page

This page will be revised whenever what an account or the assistant keeps changes.

Questions: contact@zrxiv.dev. The terms of use are at terms.