Privacy
Last updated 24 August 2026
Lektava is a catalogue for the books you own. It needs an account to know whose shelves are whose, and it needs the catalogue itself to be of any use. Beyond that it collects nothing — no analytics, no advertising, no third-party tracking of any kind.
01Who runs Lektava
Lektava is an independent product built and operated by Oshan Mudannayake. For anything in this policy — questions, corrections, a request to export or delete your account — write to oshan.ivantha@gmail.com.
02What is stored
Three kinds of thing, and nothing else:
- Your account. Email address, and a display name if you set one. Optionally a short bio, a profile picture, and a profile slug if you choose to make a public profile page.
- How you sign in. If you use a password, only a hash of it is stored — never the password itself. If you use Google Sign-In, your Google account identifier and the tokens needed to keep the session valid. If you use a passkey, only its public key and credential id. Active sessions are recorded so you can be signed out of them.
- Your catalogue. Everything you put into it — books, authors, publishers, genres, series, shelves, tags, notes, reviews, loans, reading sessions, reading goals, wishlist entries — plus an activity log of changes made in each library, and any cover images you upload.
03What is not stored
- No card details. Payments are handled entirely by Paddle (see 06). Card numbers never reach Lektava’s servers. What is kept is a Paddle customer and subscription identifier, the plan, the billing cycle, and the renewal date.
- No analytics or advertising. There is no Google Analytics, no advertising network, no session recorder, no behavioural profiling, and no tracking pixels. Nothing about your reading is sold, rented, or shared for marketing.
04Cookies
Lektava sets two cookies, both strictly functional. There are no advertising or analytics cookies, which is why there is no cookie banner.
- A session cookie, so you stay signed in. It is signed, HTTP-only, and unreadable by page scripts.
- A last-library preference, so that opening Lektava returns you to the library you were last using.
05Where it lives
- The database is Neon (PostgreSQL), hosted in AWS us-east-2 in the United States.
- The application runs on Google Cloud Run in us-central1, and cover images are held in a private Google Cloud Storage bucket. Covers are never public: every image is served through the app, which checks that you have access to that library first.
If you are outside the United States, using Lektava means your data is transferred there and stored there.
06Who else touches it
Lektava relies on a small number of external services. Each receives only what it needs to do its job:
- Neon — database hosting. Holds everything described in 02.
- Google Cloud — application hosting and cover-image storage.
- Paddle — payments. Paddle is the merchant of record and collects your billing details directly, under its own privacy policy.
- Resend — transactional email only: address verification, password resets, loan reminders and notification digests. Receives your email address and the content of that message. No marketing email is sent.
- Google Books — optional metadata lookups when you add a book. Receives the title, author or ISBN being looked up, not your identity. Results are cached so the same lookup is not repeated.
- Google Sign-In — only if you choose it. Lektava receives your email address, name and profile picture from Google.
07Who can see your library
A library is private to you and to the people you invite into it. Members you invite can read it; owners can change it. Nobody else can, and Lektava does not read your catalogue.
Two things are public only if you deliberately turn them on: a library’s public page, and your public profile page. Both are off by default, both can be turned off again at any time, and once off the content stops being reachable.
08Getting your data out, and deleting it
You can export your catalogue at any time, on every plan including the free one — every book, note, loan and review.
To delete your account, write to oshan.ivantha@gmail.com. Your account, your libraries and their contents, and your uploaded covers are removed. Backups are cycled out within 30 days. Records that must be kept for accounting purposes — the fact and amount of a payment — are retained where the law requires it.
Depending on where you live you may also have rights to access, correct, or object to the processing of your data. The same address handles those requests.
09How long it is kept
Your catalogue is kept for as long as your account exists, because it is the thing the account is for. Sign-in sessions expire on their own. Deleting your account removes the rest, as described in 08.
10Children
Lektava is not directed at children under 13, and accounts are not knowingly created for them. If you believe a child has created an account, write to the address above and it will be removed.
11Changes to this policy
If this policy changes in a way that materially affects what is collected or who it is shared with, the date at the top changes and account holders are notified by email before it takes effect. Smaller clarifications are made in place.