AREX Reader Privacy Notice
AREX Reader Privacy Notice
Effective date: August 26, 2026
This notice explains how Beijing Academy of Artificial Intelligence ("BAAI", "AREX", "we", or "us") handles data when you use the AREX Reader Chrome extension. It supplements the AREX Privacy Policy and Terms of Service. If this notice and the general privacy policy differ for AREX Reader data practices, this more specific notice controls for the extension.
1. What AREX Reader does
AREX Reader helps you understand the webpage, video, or research paper you are actively reading through source-grounded summaries, explanations, translations, and chat.
The extension runs an on-page launcher and selection toolbar on sites you visit. Simply browsing a regular webpage does not automatically upload its page body. AREX Reader transmits source data only when you deliberately open or use a reading action, such as asking a question, requesting an explanation or translation, or generating an overview.
2. Data handled by the extension
Depending on the action you choose, AREX Reader may handle:
- Account and authentication data: your phone number, account identifier, profile name if provided, authentication session tokens, registration status, and plan eligibility. The raw access key used by an internally provisioned account is used only for sign-in and is not stored by the extension after the authentication exchange.
- Website and browsing context: the current page URL, title, site name, page text needed for the requested action, and identifiers such as an arXiv ID, YouTube video ID, or Bilibili bvid/cid/page. Before transmission, the extension removes URL fragments and query parameters whose names commonly indicate credentials or secrets.
- Selected and nearby text: text you select and a bounded amount of nearby page text when you ask AREX to explain, translate, or discuss a passage.
- User-generated content: your prompts, chat messages, language choice, and feedback you choose to submit.
- Generated and operational data: AREX responses, conversation identifiers, timestamps, request status, quota events, and security or reliability logs such as IP address, browser type, and error information.
- Local extension settings: interface language, window position and size, disabled-site settings, reader mode, source-session pointers, and the authenticated session returned by AREX. These values are stored in Chrome's extension-private local or session storage.
The extension does not request access to Chrome browsing history, cookies, contacts, email, files, camera, microphone, precise location, payment information, or health information. Because AREX Reader can operate on arbitrary webpages, page content you deliberately send may itself contain sensitive information. Do not invoke AREX Reader on private or sensitive material that you do not want processed.
3. How the data is used
We use this data only to:
- authenticate your AREX account and enforce access and usage limits;
- extract and bind the source you deliberately ask AREX to read;
- generate summaries, explanations, translations, paper or video overviews, and source-grounded chat responses;
- save and reload your account's conversation history and source context;
- remember extension settings on your device;
- moderate input and output, prevent abuse, diagnose failures, and keep the service secure and reliable; and
- comply with applicable law and enforce our terms.
We do not sell extension user data, use it for personalized advertising, use it to determine creditworthiness or eligibility for lending, or use page content and conversations to train or fine-tune models.
4. Service providers and source services
AREX processes extension requests through AREX-operated servers. Only the data needed for a requested feature is transferred to a provider:
- DeepSeek processes bounded prompts, source material, and generated-content requests for chat and overview generation.
- Alibaba Cloud supports SMS authentication and performs input/output safety screening. Safety screening may receive the text needed to assess a request or generated response.
- Supadata receives YouTube video identifiers to retrieve an existing native transcript when required. It does not receive your AREX login credential or arbitrary webpage body from this flow.
- TikHub receives Bilibili video identifiers to resolve page and subtitle information when required. It does not receive your AREX login credential or arbitrary webpage body from this flow.
- Google/YouTube Data API, YouTube, Bilibili, and arXiv may receive public source identifiers when AREX retrieves metadata, transcripts, or paper material needed for the feature you requested.
- If you ask AREX to search or browse the web, relevant search/content services and public websites may receive the query or target URL needed to return results. Requests are made by AREX services rather than by granting those services access to your Chrome profile.
Providers may process data only to deliver, secure, or support the requested AREX feature, subject to our agreements and applicable law. Current model and safety-provider details are also listed in the third-party model agreements and third-party service list.
5. Storage and retention
- Authentication tokens and preferences are stored in extension-private Chrome storage. Signing out removes the persisted AREX authentication session; locally saved display preferences may remain until you clear extension data or uninstall the extension.
- Ordinary page and arXiv source snapshots submitted for a conversation, your prompts, and AREX responses may be stored with that conversation so later turns use the same source.
- Video transcripts and paper/video overviews may be stored as shared source assets. They contain source material and generated summaries, not your raw access key.
- Selection translation uses a separate temporary session. The extension requests deletion after returning the result, and the server purges any surviving translation-session tree within one hour.
- Other account, conversation, security, and service data is retained only for as long as necessary to provide the service, satisfy security and legal requirements, resolve disputes, or as otherwise described in the general AREX Privacy Policy.
6. Your choices and controls
You can:
- avoid sending page content by not invoking a reading action;
- hide AREX on the current page or disable its on-page surfaces for specific sites in Reader settings;
- sign out to remove the extension's authenticated AREX session;
- delete data through AREX where deletion controls are available, or request deletion of account data; and
- contact us at arex@baai.ac.cn to exercise access, correction, deletion, or withdrawal rights described in the general privacy policy.
7. Security
AREX Reader sends service requests over HTTPS. Authentication tokens are kept in extension-private storage and are not injected into the host webpage. Page content is treated as untrusted source material and kept separate from the user's prompt at the service boundary. No security measure is absolute, so avoid submitting secrets or information you are not authorized to share.
8. Chrome Web Store Limited Use
AREX's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We use this information only to provide or improve AREX Reader's user-facing reading features. We do not transfer it for personalized advertising, data brokerage, creditworthiness, or other unrelated purposes. We do not allow humans to read it except with the user's explicit consent for a specific support case, when necessary for security, to comply with law, or when data is aggregated and anonymized for permitted internal operations.
9. Changes and contact
We may update this notice when AREX Reader's data practices change. Material changes will be disclosed through the extension, its Chrome Web Store listing, or the AREX website as appropriate. Questions and privacy requests may be sent to arex@baai.ac.cn.
AREX Reader 浏览器扩展隐私说明
生效日期:2026年8月26日
本说明用于解释北京智源人工智能研究院(简称“智源研究院”“AREX”或“我们”)在您使用 AREX Reader Chrome 扩展时如何处理数据,是《AREX隐私政策》和《AREX服务协议》的补充。如果本说明与通用隐私政策对 AREX Reader 数据处理的说明不一致,以本说明中更具体的扩展规则为准。
1. AREX Reader 的用途
AREX Reader 通过有来源依据的速览、解释、翻译和对话,帮助您理解当前正在阅读的网页、视频或研究论文。
扩展会在您访问的网站中运行网页入口和划词工具栏。仅浏览普通网页不会自动上传网页正文。只有当您主动打开或使用阅读功能,例如提问、解释、翻译或生成速览时,AREX Reader 才会发送完成该操作所需的来源数据。
2. 扩展处理的数据
根据您主动选择的功能,AREX Reader 可能处理:
- 账号与认证数据:手机号、账号标识、您主动提供的昵称、认证会话令牌、注册状态和套餐资格。内部配置账号使用的原始登录码仅用于登录交换,扩展不会在认证完成后保存该原始登录码。
- 网站与浏览语境:当前页面地址、标题、网站名称、完成请求所需的网页文字,以及 arXiv ID、YouTube video ID、Bilibili bvid/cid/page 等来源标识。发送前,扩展会移除 URL 片段以及参数名中通常表示凭据或密钥的查询参数。
- 选中文字与邻近文字:当您要求解释、翻译或讨论某段内容时,发送您选择的文字及有长度限制的少量前后语境。
- 用户生成内容:您的提示词、对话消息、语言选择以及您主动提交的反馈。
- 生成与运行数据:AREX 回复、会话标识、时间戳、请求状态、配额事件,以及 IP 地址、浏览器类型、错误信息等安全与可靠性日志。
- 本地扩展设置:界面语言、窗口位置和大小、停用网站、阅读器模式、来源会话指针,以及 AREX 返回的认证会话。这些数据保存在 Chrome 扩展私有的本地或会话存储中。
扩展不会申请 Chrome 浏览历史、Cookie、通讯录、电子邮件、文件、摄像头、麦克风、精确位置、支付信息或健康信息权限。由于 AREX Reader 可以在任意网页上工作,您主动发送的网页内容本身可能包含敏感信息。请勿在您不希望被处理、或您无权分享的私密敏感材料上调用 AREX Reader。
3. 数据使用目的
我们仅将这些数据用于:
- 验证 AREX 账号并执行访问与用量限制;
- 提取并绑定您主动要求 AREX 阅读的来源;
- 生成摘要、解释、翻译、论文或视频速览及有来源依据的对话回复;
- 保存并恢复账号对应的对话历史和来源语境;
- 在设备上记住扩展设置;
- 审核输入和输出、防止滥用、诊断故障并保障服务安全稳定;以及
- 遵守适用法律并执行服务条款。
我们不会出售扩展用户数据,不会将其用于个性化广告、信用评估或贷款资格判断,也不会使用网页内容和对话训练或微调模型。
4. 服务商与来源服务
扩展请求通过 AREX 运营的服务器处理。我们只向服务商传输完成您所请求功能所必需的数据:
- DeepSeek:处理对话和速览生成所需的有限提示词、来源材料和生成请求。
- 阿里云:提供短信认证与输入/输出安全检测;安全检测可能接收判断请求或生成结果所需的文字。
- Supadata:在需要时接收 YouTube 视频标识,以读取已经存在的原生字幕;该流程不会向其提供 AREX 登录凭据或任意网页正文。
- TikHub:在需要时接收 Bilibili 视频标识,以解析分 P 与字幕信息;该流程不会向其提供 AREX 登录凭据或任意网页正文。
- Google/YouTube Data API、YouTube、Bilibili 与 arXiv:当 AREX 获取功能所需的元数据、字幕或论文材料时,可能接收公开来源标识。
- 如果您要求 AREX 搜索或浏览网络,相关搜索/内容服务及公开网站可能接收返回结果所需的查询或目标地址。请求由 AREX 服务发出,不会因此获得您的 Chrome 个人资料访问权。
服务商只能按照我们与其之间的约定及适用法律,为交付、保障或支持您所请求的 AREX 功能处理数据。当前模型与安全服务商信息也可在三方模型服务协议清单和第三方合作伙伴清单中查看。
5. 存储与保留
- 认证令牌和偏好设置保存在 Chrome 扩展私有存储中。退出登录会移除持久化的 AREX 认证会话;本地显示偏好可能保留到您清除扩展数据或卸载扩展。
- 普通网页与 arXiv 对话提交的来源快照、您的提示词和 AREX 回复可能随对话保存,使后续追问继续使用同一来源。
- 视频字幕和论文/视频速览可能作为共享来源资产保存,其中不包含您的原始登录码。
- 划词翻译使用独立临时会话。扩展在返回结果后请求删除,服务端会在一小时内彻底清理任何残留的翻译会话树。
- 其他账号、对话、安全与服务数据仅在提供服务、满足安全和法律要求、解决争议所必需的期限内保留,或按照通用《AREX隐私政策》处理。
6. 您的选择与控制
您可以:
- 不调用阅读功能,从而不发送网页内容;
- 隐藏当前页面上的 AREX,或在 Reader 设置中为特定网站停用网页入口;
- 退出登录,移除扩展中的 AREX 认证会话;
- 通过 AREX 已提供的删除功能删除相应数据,或申请删除账号数据;以及
- 通过 arex@baai.ac.cn 联系我们,行使通用隐私政策中说明的查阅、更正、删除或撤回同意等权利。
7. 安全措施
AREX Reader 通过 HTTPS 发送服务请求。认证令牌保存在扩展私有存储中,不会注入宿主网页。网页内容在服务边界被视为不可信来源材料,并与用户提示词分开处理。任何安全措施都无法保证绝对安全,请避免提交密钥或您无权分享的信息。
8. Chrome Web Store Limited Use
AREX 对从 Chrome API 获得的信息的使用遵守 Chrome Web Store User Data Policy,包括 Limited Use 要求。我们仅将这些信息用于提供或改进 AREX Reader 面向用户的阅读功能,不会将其用于个性化广告、数据经纪、信用评估或其他无关用途。除非用户针对具体支持事项明确同意、出于安全所必需、为遵守法律要求,或数据已聚合匿名并用于政策允许的内部运营,否则我们不会允许人工读取这些信息。
9. 更新与联系我们
当 AREX Reader 的数据处理实践发生变化时,我们可能更新本说明。重大变化将视情况通过扩展、Chrome Web Store 页面或 AREX 网站进行说明。如有问题或隐私权请求,请联系 arex@baai.ac.cn。