We understand that your books are your most valuable assets. Here is exactly how we protect them, in plain language, not legal boilerplate.
Your book content is stored in a vector namespace exclusive to your account (pub_{your_id}_book_{book_id}). No other publisher, no QuantumRead employee, and no system process can query your namespace.
We convert your text into mathematical vector embeddings, numerical representations that cannot be reverse-engineered back to the original words. The AI answers questions about your content; it cannot output paragraphs or chapters from your book.
The AI model we use is a third-party API (OpenRouter). Your book content is sent as temporary context for each question, then discarded. It is never used to fine-tune, train, or update any model, ours or anyone else's.
Click Delete on any book in your dashboard and its vector data is removed immediately. No 30-day grace period, no backup retention window. We also honor deletion requests via email within 24 hours.
All data is transmitted over TLS 1.3. Vector store data is encrypted at rest using AES-256. API keys are hashed using SHA-256 and never stored in plaintext, not even we can recover your key.
Each widget request must present a valid, active API key tied to your account. You can revoke a key instantly. Rotating keys takes under 30 seconds and does not require any code changes.
When you upload a PDF or ePub, here is exactly what happens, step by step:
Publishers already upload full book content to distribution platforms. QuantumRead is not a new risk, it is a more controlled one.
| Platform | Holds full content | Isolated to you | Delete on demand |
|---|---|---|---|
| Amazon KDP | Shared infrastructure | Slow process | |
| Apple Books | Shared infrastructure | Slow process | |
| Google Books | Shared infrastructure | Slow process | |
| Scribd / Overdrive | Shared infrastructure | Slow process | |
| QuantumRead |
We are happy to sign a Data Processing Agreement (DPA) before you upload any content. This is standard practice for enterprise publishers and provides legal binding for all the guarantees on this page.
Our DPA covers: data isolation, retention limits, sub-processor disclosure, breach notification timelines, and your right to audit. Most publishers receive a signed DPA within 48 hours of request.
Request a DPAQuestions about security? security@quantumread.space