HomeSecurity at Read & Explain

Care behind the scenes.

Simple to use should still mean thoughtfully built. These are the protections in the current app and API.

Last updated September 8, 2026

Built with a smaller footprint

Your reading library stays on your device. Our API handles the online work without building a server-side photo library. Service credentials stay on the server.

Protection on your device

Saved readings and source photos are written to the app’s storage using Apple’s complete file protection. Your device passcode, operating system, and backup settings remain important parts of protecting that data.

Reading files are saved atomically to reduce the risk of a partial write. The app does not automatically sync your library to a Read & Explain cloud account. Sharing a reading creates a separate copy in the destination you choose.

Online requests

The app connects to the API over HTTPS. The API uses HTTPS for its connections to OpenAI, Microsoft, and Apple. This protects information in transit between those services; processing providers still need access to the content to perform the requested feature.

API credentials for AI processing, Microsoft access, and Apple verification are configured on the server. They are not shipped in the native app or this website. The API validates supported requests and applies size and timeout limits. Shared usage counters enforce the daily membership allowance across devices, with additional limits on rapid requests and total service use.

Membership verification

The app uses Apple’s StoreKit subscription flow. The API verifies signed transaction information and checks that the entitlement belongs to the expected app and subscription product and has not expired or been revoked.

Successful verification produces a temporary access token for protected features. Payment-card handling remains with Apple. TestFlight verification runs in a separate sandbox service. The website itself does not collect payments or ask for your Apple password.

Less information to retain

The application API does not save photos or reading results to S3 or a database. Its diagnostic log entries include a generated request ID, known route name, and status code, rather than request contents or access tokens.

We have signed zero-data-retention agreements covering OpenAI processing and Microsoft Immersive Reader. These services still process the selected content online. The privacy notice explains the data flow and provider details.

This website serves its own fonts and imagery and has no advertising trackers, analytics scripts, or photo-upload form.

Report a security issue

If you find a vulnerability, send us a private security report. Include the affected feature or URL, a description of the issue, steps to reproduce it, and its possible impact.

Use your own device and data. Please do not access other people’s information, send us real credentials, disrupt the service, or publish sensitive details before we have had a chance to investigate.

We will review the report and follow up using the contact details you provide. This is a reporting channel, not a guarantee of a bounty or a fixed response time.

A few useful habits

  • Keep iOS or iPadOS and the app up to date.
  • Use a device passcode and protect your Apple Account.
  • Choose photos carefully and crop out information you do not need to share.
  • Check AI-generated text against the original for important details.
  • Review device backups and copies you export or share.

Need help with an error or a purchase? The support page is the best place to start.