For the curious, and the security-minded, here's how the reader gets its PDFs.
Open-access first
When you add a source without uploading a PDF yourself, Folio tries to resolve one in this order: a direct arXiv link, then bioRxiv or medRxiv, then an open-access PDF address already on the source's record, then the open-access location from Unpaywall (via the DOI), and finally a best-effort look at the source's own landing page for a linked PDF. We only fetch copies that are openly available; we don't bypass paywalls. When you upload your own PDF, Folio skips this search and keeps your file.
Downloaded server-side, stored privately
PDFs are fetched on our servers (never cross-origin in your browser), checked to be genuine PDFs and no larger than 25 MB, and stored in a private bucket. Nothing is public.
Served through short-lived signed URLs
When you open the reader, Folio mints a signed URL for your file, valid for one hour, after confirming you own the source. Links expire, and one user can never reach another's files.
Loaded same-origin
The PDF rendering engine is served from Folio itself rather than a public CDN, so the reader keeps working on restricted networks. Your PDF and the address of what you're reading never go to a third party. The one outside request is for shared font and character-map files the renderer needs for some PDFs, which load from a public CDN (unpkg.com) and carry nothing about your document.