Privacy Policy

How ReadmeX handles your account, community content, AI conversations and connected services.

On this page

Who we are

ReadmeX operates ReadmeX. This policy explains the information we process when you browse the site, create an account, participate in communities or use AI and project integrations.

Information we process

Account information includes your email, display name, username, avatar, profile details and linked sign-in identities. Email registration uses a password hash, verification records and login sessions. Invitation, points and badge features also store the records needed to provide them.

We process content you submit, including posts, comments, messages, uploads, searches, AI prompts and project feedback, along with follows, community memberships, saved items and reports. Public sources may also provide articles, author information and repository content shown on ReadmeX.

Our application and infrastructure may process IP addresses, browser or device information, request times, authentication events and security or diagnostic logs to deliver the service, prevent abuse and investigate errors.

When you choose an integration, we receive the identity and permissions you authorize. GitHub integrations may include repository access, authorization credentials and project activity. CNBlogs verification may include your blog identity, account tenure and membership status. Enabled mobile push services use device identifiers to deliver notifications.

Why we use this information

We use information to create and secure accounts, display content, deliver messages and notifications, personalize feeds from your follows and activity, provide AI assistance, run authorized project tasks and manage invitations, badges and points.

Where applicable law requires a legal basis, we process information needed to provide the service you request, protect our legitimate interests in service security and reliability, comply with legal obligations, or act on consent where required. Optional integrations, subscriptions and permissions can be declined or withdrawn; features that depend on them may then be unavailable.

Public content and messages

Your username, profile details, public posts, comments, community activity and displayed badges may be visible to other users and, when public access is enabled, to visitors and search engines. Community administrators and moderators can access information needed to manage their communities.

Direct messages are available to conversation participants. Community chat is available according to the community's access rules. Authorized service operations, security investigations and moderation may require access to stored messages; chats do not provide end-to-end encryption.

When you submit feedback for GitHub issue creation or an authorized repair task, the relevant problem description, evidence and proposed changes may be sent to GitHub. Issues and pull requests on public repositories are public. Avoid including passwords, access keys or unrelated personal information in content you submit.

AI assistance and shared summaries

AI features send your prompt and relevant context to the configured AI provider. Depending on the feature, this may include recent conversation messages, selected content, followed activity, repository source code or task evidence. Communities with enabled AI or project automation may use chat context to answer questions or identify feedback. Authorized repair tasks also process relevant code and task logs in an execution environment.

Summaries of public topics may be cached and reused for other readers. Personal conversations and summaries of your followed activity are handled under the associated account and access rules. AI providers have their own retention and data-use terms; this policy does not promise that a provider never retains inputs or uses them to improve its services.

Cookies and browser storage

We use cookies and browser storage for login, language and theme preferences, invitation flows, read markers, drafts and chat continuity. Installed web apps cache application assets and preferences. Business content is requested from the server so the current access rules can be checked.

You can clear cookies and local storage in your browser. Doing so may sign you out or remove local preferences and drafts. Email subscriptions can be managed in settings or through the unsubscribe link; mobile notification permissions can be changed in your device settings.

Service providers and integrations

The services below may process the information needed for an enabled feature. Their own policies also apply when you interact with them. We may disclose information when required by law or necessary to investigate abuse and protect the service and its users.

  • Google: optional sign-in and One Tap; identity, email, profile and information processed by Google's sign-in components. Provider privacy policy
  • GitHub: optional sign-in, repository authorization, source access and issue or pull request creation. Provider privacy policy
  • Cloudflare: network delivery and protection, Turnstile human verification, and configured storage or task execution services. Provider privacy policy
  • Resend: delivery of verification, recovery and subscription emails, including recipient addresses and email content. Provider privacy policy
  • DeepSeek: AI inputs and relevant context when DeepSeek is the configured provider. Provider privacy policy
  • OpenAI: AI inputs and relevant context when OpenAI is the configured provider. Provider privacy policy
  • Alibaba Cloud: configured hosting, database and cache infrastructure used to store and process service data. Provider privacy policy

Turnstile Privacy Addendum

Other optional integrations include CNBlogs identity and membership verification, SMTP email delivery and Getui mobile push. Data is sent when the corresponding integration is enabled and used.

Retention and account deletion

Retention depends on the purpose of the information: operating your account and conversations, maintaining project history, investigating abuse, resolving disputes, meeting legal obligations and recovering from failures. Different records and providers have different retention rules. This policy does not specify a universal automatic deletion deadline.

You can delete your account in Settings. The current deletion flow ends sign-in sessions, removes linked sign-in accounts and profile contact information, revokes API tokens and clears selected follows, saved items and memberships. Public contributions remain attributed to a deleted account. Stored messages, project history, points or badge records, moderation and audit records, backups and previously published GitHub content may remain; deleting an account does not erase every historical record or third-party copy.

Your choices and rights

You can edit your profile, manage sign-in sessions and subscriptions, delete supported posts or comments, disconnect supported integrations and delete your account through the available settings. Repository authorization can also be revoked on GitHub.

Depending on applicable law, you may request access, a copy, correction or deletion of your personal information, object to processing, request restrictions or withdraw consent. Contact us using the details below; we may need to verify your identity and consider legal obligations and the rights of others. You may also raise a complaint with the relevant data protection authority.

Security and international processing

We use access controls, password hashing, protected authorization storage and HTTPS on the production site to reduce risks. Authorized personnel and service providers may access data for their responsibilities. Security measures cannot remove every risk.

Hosting and service providers may process information outside your country, including in the United States and China depending on the infrastructure and AI provider used. Protections and applicable laws may differ between countries. Contact us for information about the processing and safeguards relevant to your request.

Children's information

ReadmeX is intended for developer and technology communities and is not directed at children. If you believe a child has provided personal information inappropriately, contact us so we can review the situation and take appropriate steps.

Changes to this policy

Updates are published on this page with a revised date. Where required, material changes will receive additional notice or consent. Review this page when deciding whether to use a newly introduced feature.

Contact and privacy requests

Account controls are available in Settings. The contact address for other privacy requests will be published here.