API Key Safety Guide
Companion Reader's member plan lets you use your own AI API Key. This page explains the Key's purpose, cost, risks and safety principles.
1. What Is the API Key Used For
After configuring an API Key, Companion Reader can use your chosen AI service for chat, summaries, chapter extraction, categorization and correction. Users without a Key can still read, underline, highlight, note and collect quotes.
2. Who Pays
When "User API" is shown, AI calls use your own Key — cost and quota are between you and the AI provider. Membership fees cover Companion Reader's product, sync, limits and maintenance, not third-party AI costs.
3. How We Protect Your Key
- Transport:All API Key requests use HTTPS.
- Storage:Server-side encryption, never stored in plain text.
- Display:Frontend never shows the full Key — only the last digits or masked.
- Logs:Error, access and debug logs never record the full Key.
- Access:Only backend processes that need it can read the decrypted Key.
- Deletion:Users can delete, update or deactivate their Key anytime.
4. What to Watch Out For
- Never share your Key or show it in screenshots, group chats or public docs.
- Create a dedicated Key for Companion Reader and set a budget limit with your AI provider.
- If you suspect a leak, delete or reset the Key immediately with your AI provider.
- When using AI features, text excerpts, notes or your input may be sent to the AI provider.
5. System API vs User API
If System API is offered later, users may use some AI features without configuring a personal Key. The interface will clearly label "System API" or "User API" in AI areas, settings and quota pages.
6. What If Something Goes Wrong
If you notice abnormal charges, calls, Key leaks or AI errors, delete the Key immediately and contact us. We'll help check our side, but third-party AI bills must be verified with the provider.