Lektava
Legal

Privacy

Last updated

Lektava is a catalogue for the books you own. It needs an account to know whose shelves are whose, and it needs the catalogue itself to be of any use. Beyond that it measures only which pages get used, without cookies and without advertising. Your reading is never shared for marketing; sharing within a library is described below.

01 Who runs Lektava

Lektava is an independent product built and operated by Oshan Mudannayake. For anything in this policy — questions, corrections, a request to export or delete your account — write to oshan.ivantha@gmail.com.

02 What is stored

Four kinds of thing, and nothing else:

  • Your account. Email address, and a display name if you set one. Optionally a short bio, a profile picture, and a profile slug if you choose to make a public profile page. Library owners can also store managed household profiles: a name, a built-in avatar and an optional birth year. These profiles have no email or sign-in; their owner manages their reading and borrowing.
  • How you sign in. If you use a password, only a hash of it is stored — never the password itself. If you use Google Sign-In, your Google account identifier and the tokens needed to keep the session valid. If you use a passkey, only its public key and credential id. Active sessions record the user agent, platform, device name and last-seen time so you can review them and sign out one device or every device in Profile's Security settings. An account-scoped digest of a random device identifier remains after sign-out to recognize returning devices; it is removed when the account is deleted. If you enable phone notifications, the push provider, device token and registration time are attached to your sign-in session. The server removes that registration when you sign out, the session expires or the provider reports the token is no longer valid.
  • Your catalogue. Everything you put into it — books, authors, publishers, genres, series, shelves, tags, notes, reviews, loans, reading sessions, reading goals, wishlist entries — plus an activity log of changes made in each library, and any cover images you upload.
  • How the app is used. Which pages are opened, and a short list of named actions — a book added, a library created, an invitation accepted, a checkout started. Once you are signed in these carry your numeric account id and your plan, so the picture is per-account rather than a crowd average. They never carry your email, your name, or anything about which books are in your catalogue. This runs on PostHog (see 06) and stores nothing on your device (see 04).

A visitor may request a book from a public library that has opted into borrowing, providing a name and email visible only to the current library owner. Requests are kept privately until review; acceptance records the contact on a loan, while decline, moving or trashing the book, or trashing the library removes the pending contact. Availability is public; visitor contacts and loan details are not. Requests arrive as in-app notifications without copying visitor contacts into notification history; no automatic request or decision email is sent.

A lender may record a borrower’s name and email even when the borrower has no account. For libraries with paid email reminders, that address receives due-date reminders and a private link. Borrower links expire after 30 days and show only that borrower’s outstanding book titles and due dates in one library. Anyone holding the link can see those loans and ask the lender for more time; the request does not change the due date. These pages have no analytics. Changing the recorded email invalidates earlier links for those loans. The lender should share a link only with its intended borrower.

When you cancel a subscription, you can optionally choose a reason and write a short comment. After you confirm cancellation, that feedback is recorded in private operational logs with your account and subscription identifiers, plan and billing cycle so the founder can understand why readers leave. It is not shared with library members, sent to analytics, or included in Paddle’s cancellation request. Leaving both fields blank does not prevent cancellation.

03 What is not stored

  • No card details. Payments are handled entirely by Paddle (see 06). Card numbers never reach Lektava’s servers. What is kept is a Paddle customer and subscription identifier, the plan, the billing cycle, and the renewal date.
  • No advertising, and no recording. There is no advertising network and no tracking pixel. Nothing records your screen or replays your session, nothing captures your clicks or keystrokes automatically, and nothing builds a behavioural profile of you. The usage measurement described in 02 is a fixed list of named actions and nothing more. Your catalogue and your reading are never sold, rented, or shared for marketing.

04 Cookies

Lektava sets one cookie and keeps small functional settings in your browser’s local storage (on your device, in the apps). It also saves an offline catalogue and the web app’s static files. Desktop apps keep the update-check settings described below. All of them are strictly functional. There are no advertising or analytics cookies, which is why there is no cookie banner.

That holds even though the app measures its own usage. The analytics described in 02 is configured to keep nothing on your device — no cookie, no local storage, no session storage — so there is nothing to ask your permission to store. The trade is that it cannot recognise a returning visitor who is not signed in, and that is the intended trade.

  • A session cookie, so you stay signed in. It is HTTP-only and unreadable by page scripts. The apps keep the same sign-in in the device’s secure storage instead.
  • A random device identifier, kept in an HTTP-only cookie for up to one year on the web and in local app preferences on native devices. It recognizes a returning sign-in, survives sign-out, and cannot grant access. New-device security emails go only to verified addresses and cannot be switched off.
  • A last-library preference, so that opening Lektava returns you to the library you were last using.
  • A catalogue display preference, so your library opens in the layout, cover size and page size you last chose. It holds those settings and nothing else.
  • A signed-in marker, so the home page can take you straight to your library. It says only that you are signed in, not who you are.
  • Accessibility preferences remember your text size and reduced-motion choices on this device. They are not shared with other devices or sent to the server.
  • A reading timer draft keeps the book and reader identifiers, starting page, and start and stop times on this device so timing survives backgrounding or restarting the app. Saving sends the elapsed minutes and pages you enter as a reading session. Saving, discarding the timer or signing out removes the local draft. Timers are not synchronized between devices.
  • Desktop apps keep the last update-check time, the latest release version they found, and the version of any update notice you dismissed. Automatic checks contact lektava.com at most once every 24 hours, without sending account details. When you choose Install update, the app checks the release again and downloads the update from our Google Cloud Storage download bucket. macOS uses Sparkle; Windows uses our installer; Linux AppImages use zsync to download changed parts. These requests do not include your sign-in token or account details. The update replaces the app in its existing location and keeps its saved sign-in. Other installation formats open the download page when you choose to view it. Failed Windows updates can leave local installer logs until you remove them.
  • Native apps may temporarily save pending crash diagnostics on this device for delivery after restarting or reconnecting. These reports are filtered by Lektava before they reach Sentry. Error reporting is separate from usage measurement and does not record screens.
  • An offline catalogue, so you can check your books without a connection: the libraries you can see, their books and entities, front-cover thumbnails and your last verified account details. The web uses IndexedDB; native apps use their local application storage. This copy is not separately encrypted. It contains no passwords or session tokens and is removed when you sign out or change accounts. A local account marker coordinates this copy between browser tabs; it contains only your account identifier. Reconnecting removes libraries you can no longer access. While disconnected, it reflects your last verified access. Offline use is read-only; changes are not queued.
  • The web app saves its generic application shell and static assets in a browser cache so an installed copy can reopen offline. That cache contains no account or catalogue data and may remain after sign-out.

05 Where it lives

  • The database is Neon (PostgreSQL), hosted in AWS us-east-2 in the United States.
  • The application runs on Google Cloud Run in us-central1, and cover images are held in a private Google Cloud Storage bucket. The app checks that you have access to a library before issuing a read-only image link that expires within five minutes. Book images are delivered directly from Cloud Storage and are not stored in shared caches. If access is removed, a link already issued can still be used until it expires. The one exception to library access is a library whose public page you turn on: while it is on, anyone with the link sees its books’ front covers. Back covers and attachments stay private. Public library link previews also show its name and a mosaic of front covers, rendered by the API and cached there while the catalogue is unchanged. Preview requests recheck that the library is public and are not stored in shared caches.

If you are outside the United States, using Lektava means your data is transferred there and stored there.

06 Who else touches it

Lektava relies on a small number of external services. Each receives only what it needs to do its job:

  • Neon — database hosting. Holds everything described in 02.
  • Google Cloud — application hosting and book-image storage.
  • Paddle — payments. Paddle is the merchant of record and collects your billing details directly, under its own privacy policy.
  • PostHog — the usage measurement in 02, on their United States cloud. Receives the pages opened and the named actions listed there, together with your numeric account id and plan once you are signed in. It does not receive your email, your name, or any part of your catalogue. Requests go through lektava.com rather than to PostHog directly.
  • Sentry: error diagnosis, when enabled. Receives error types, code stack traces, application version and commit, and the deployment environment. App reports go through lektava.com, where account identity, device identifiers, IP addresses, request bodies and headers, exception messages, catalogue contents and breadcrumbs are removed before forwarding. Screenshots, session replay, performance traces and attachments are not sent.
  • Resend — email delivery, and a deliberately short list of it: address verification, password resets, new-device sign-in alerts, email-change confirmations and old-address notices, account-deletion confirmations, loan reminders, being added to or removed from a library, and up to three getting-started tips during your first week. Tips are skipped for steps you have already completed and for imported libraries, and can be turned off under Getting started in your Profile's Notifications settings. There is also one optional follow-up per library three days after an import leaves books waiting on a Free account. That follow-up names the number waiting, links to billing, and includes an unsubscribe link for its notification preference. Paid owners can also receive one monthly library summary with books added, their own pages read, current loans and pooled book and media usage. Monthly library summary email can be turned off in Profile's Notifications settings, independently of its in-app copy. Other notification details stay in the app and are never emailed. Receives your email address and the content of that message. No other marketing email is sent.
  • Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM) — optional phone alerts. When you enable phone notifications, Apple (iOS) or Google (Android) receives your device token and the generic alert "You have a new notification. Open Lektava for details." We send no book titles, borrower names, library details, email address or account identifier in that alert. Android also uses Firebase installation identifiers to register the device; Firebase Analytics is not enabled. Your in-app notification switches also control these alerts. Email-only getting-started tips and import follow-ups do not trigger push alerts. Signing out removes the server registration and asks the device to stop receiving alerts; an alert already accepted by a provider cannot be recalled.
  • Google Books — metadata lookups when you add or enrich a book, or search for a cover. Receives the title, author or ISBN being looked up, not your identity. Results are cached so the same lookup is not repeated.
  • Open Library — book metadata lookups, series volume lists and requested title/author cover searches. Receives the ISBN, title, author or series name being looked up from the API server, not your identity or your list of owned books. Results are cached to avoid repeating the same lookup.
  • ISBNdb — a further book metadata source when configured. Receives the ISBN, title or author being looked up from the API server, not your identity or your library. Metadata sources are tried in order and their results are cached. Cover previews load from the sources’ image servers, which receive your device’s IP address and the image address. Choosing a cover stores a copy through Lektava’s API.
  • Google Sign-In — only if you choose it. Lektava receives your email address, name and profile picture from Google.
  • Google Fonts — the web app fetches font files from fonts.gstatic.com: a default font when it starts, and any it needs to draw an emoji or a script it does not bundle itself. Those requests carry nothing about your account or your library; like any web request, they show Google your IP address.

07 Who can see your library

A library is private to you and to the people you invite into it. Members you invite can read it, and can change only what you allow them to. Nobody else can, and Lektava does not read your catalogue.

When the library owner is on Pro or a higher plan, Insights shows current members each member’s finished-book count, the page totals of those books and their top genres. Only finished books are counted in this breakdown; it does not include in-progress activity, session details or ratings. Marking a book finished records your finish, and choosing another reading status removes it from your breakdown. These member breakdowns are never public.

Two things are public only if you deliberately turn them on: a library’s public page, and your public profile page. Both are off by default, both can be turned off again at any time, and once off the content stops being reachable. Your public profile shows your name, bio, personal reading statistics, favourites and recent reviews. You can separately opt in to showing up to ten currently reading titles, ten recent dated finishes, and a preview of one curated shelf from a library you own. These extra sections are off by default. Opting in shares titles and authors even from private libraries, and finish dates for recent finishes. It does not share your notes, page progress, images, acquisition details or private catalogue links. Clearing an option stops publishing that section.

08 Getting your data out, and deleting it

You can export your catalogue at any time, on every plan including the free one — every book, note, loan and review.

Deleting a book or library moves it to Trash for 30 days. It is hidden from the catalogue, public sharing and usage counts while its images and history are retained for recovery. Restore books from Library settings and libraries from Manage libraries before their deadline. After 30 days, recovery ends and daily cleanup permanently removes the retained contents and images.

Delete your account from Profile > Delete account after confirming your password or a passkey. You are signed out on every device, with a seven-day grace period: signing in before the deadline cancels deletion. After that, your Paddle subscription is canceled before your account, owned libraries, archives, Trash, their stored images and managed profiles are removed. Reviews, borrower records and activity in other people's libraries retain anonymous history; your private reading data and notes are removed. We email a confirmation of the scheduled deletion. You can also contact oshan.ivantha@gmail.com for help. Backups are cycled out within 30 days. Records that must be kept for accounting purposes — the fact and amount of a payment — are retained where the law requires it.

Depending on where you live you may also have rights to access, correct, or object to the processing of your data. The same address handles those requests.

09 How long it is kept

Your catalogue is kept for as long as your account exists, because it is the thing the account is for. Sign-in sessions expire on their own. Deleting your account removes the rest, as described in 08.

The usage records in 02 are held separately by PostHog and outlive the account, because they are what the totals for past months are made of. They are keyed to a numeric account id that no longer resolves to anyone once the account is gone; ask at the address above if you would rather they were erased outright.

10 Your rights over this data

Wherever you live, you can ask for a copy of what is held about you, ask for it to be corrected, or ask for it to be deleted. Most of it you can do yourself and without asking: the export in 08 gives you the whole catalogue in a machine-readable file on every plan, including the free one, and account deletion is available in Profile as described in 08.

If you are in the UK, the EU, or the EEA, the UK GDPR and the GDPR give you specific rights: access to your data, rectification of anything wrong, erasure, restriction of processing, portability, and the right to object to processing carried out on the basis of legitimate interests. Write to oshan.ivantha@gmail.com and you will get an answer within one month. You can also complain to your national data protection authority — in the UK, the Information Commissioner’s Office.

The lawful bases relied on are narrow, and there are only three:

  • Performance of a contract — your account, your catalogue, and everything in 02 that makes the service work. Without this data there is no service to provide.
  • Legitimate interests — the usage measurement in 02, to see which parts of the product are used and which are not. It is deliberately narrow: no advertising, no profiling, no session recording, and nothing about the contents of your catalogue. You can object to it at the address above.
  • Legal obligation — records Paddle keeps for tax and accounting on purchases, which are its responsibility as merchant of record rather than Lektava’s.

Lektava is run from Sri Lanka and hosted in the United States, as set out in 05, so using it involves an international transfer. Neither country has an EU adequacy decision, so that transfer relies on the appropriate safeguards in the sub-processors’ own terms — Google Cloud, Neon, Paddle, PostHog, Resend and Sentry each publish a data processing agreement incorporating the Standard Contractual Clauses. Ask at the address above if you need the current list in writing.

11 Children

Lektava accounts are for people old enough to manage an account. Account holders can create managed profiles for household members, including children, to record reading and borrowing. These profiles cannot sign in or publish a public profile. Only their library owner can edit them, and the optional birth year is visible only to that owner. Attach an email for an account upgrade only once the person meets the account age requirements. The minimum age is 16 in the UK and the EEA, or 13 where local law sets it lower — the age floors differ by country, so the higher one applies unless yours says otherwise. If you believe a child has created an account, write to the address above and it will be removed.

12 Changes to this policy

If this policy changes in a way that materially affects what is collected or who it is shared with, the date at the top changes and account holders are notified by email before it takes effect. Smaller clarifications are made in place.