LeLibrary
Home Account Privacy –/4 Configure Addon
Privacy Policy

No tracking.
No ads. No nonsense.

The LeLibrary account area stores the bare minimum needed to run your library: your sign-in identity, the keys you choose to save, and your library itself. Sensitive data is encrypted at rest, nothing is sold or shared for marketing, and deleting your account wipes everything.

Last updated: 7 September 2026  ·  Applies to lelibrary.uk (hosted service)
Analytics
None
Trackers / Ads
None
Data Sold
Never
// the short version

If you read nothing else, read this.

01
🔐

What we store

Your sign-in basics from GitHub or Google (name, email, avatar), any API keys you save with us (encrypted before they touch disk), optional platform connections, your collections, and your saved addon setups.

02
🚫

What we don't

No analytics, no advertising, no trackers, no fingerprinting, no IP address logs, no profiling. There is no telemetry anywhere in LeLibrary. We couldn't sell your data even if we wanted to, because we barely collect any.

03
📤

Where data goes

Only where you point it: your debrid provider, TMDB metadata lookups, watchlist services you connect, and Nuvio or Stremio when you push to them. The full third-party list is below.

// what we collect

Everything the account area keeps, item by item.

ACCOUNT BASICS
👤

Sign-in identity

You sign in with GitHub or Google OAuth. We receive and store your name, email address, avatar URL, and your provider account id so we can recognise you on return. The OAuth access tokens used during sign-in are used once to fetch that profile and are not kept. The hosted sign-in page also uses Cloudflare Turnstile, a privacy and abuse-prevention service, to help distinguish genuine sign-in attempts from automated abuse. Turnstile may process limited technical information, such as browser and network signals, for that security check; it is not used by LeLibrary for advertising or tracking.

name email avatar provider id
CREDENTIALS
🔑

Your API keys

If you save provider keys with us (TorBox, Real-Debrid, AllDebrid, Premiumize, plus optional TMDB, MDBList, OMDb, Fanart.tv, RPDB and ERDB), every key is encrypted with AES-256-GCM before storage and is only decrypted in memory when answering your addon's requests.

CONNECTIONS
🔗

Platform connections

Connecting Trakt or Simkl stores their OAuth tokens (encrypted) so we can read your watchlist. Connecting Nuvio or Stremio stores their credentials (encrypted) so collection pushes and addon syncs keep working while you're away from the browser.

SAVED SETUPS
💾

Addon setups

Saved installs get a random unguessable id and store your preferences: enabled providers, language, catalog toggles, sort order, and a label you choose. API keys are deliberately stripped out of these saves; they live only in encrypted storage. We also note when a setup was last used.

YOUR LIBRARY
🎬

Collections

Names, descriptions and sort order of collections you create, plus the items inside them: public IMDb/TMDB ids, titles, years, and poster references. Nothing here is shared with anyone unless you push it to your own Nuvio or Stremio profile.

SECURITY
🍪

Sessions

A random opaque session cookie and a matching CSRF cookie keep you signed in securely. Accepting cookies keeps the account signed in for up to 30 days; denying uses a one-day account session instead. No IP addresses, device fingerprints or browser histories are stored anywhere. Rate limiting counts request IPs in memory for about a minute purely to stop abuse, then forgets them.

// hard rules

What we never do, full stop.

no analytics no advertising no trackers no ip logging no fingerprinting no data sales no ad cookies no profiling no spam emails
COOKIES
🍪

Four first-party cookies. No tracking.

LeLibrary uses an opaque session id, its CSRF security partner, a short-lived OAuth state cookie, and a cookie that remembers your consent choice. Selecting “Accept” keeps you signed in for up to 30 days and remembers that choice for six months. Selecting “Deny” uses only the required account-security cookies and expires both the choice and your login after 24 hours. The OAuth state cookie lasts 10 minutes. None track you across sites or support advertising or analytics, and the catalog/meta/stream endpoints set no cookies at all. Cloudflare Turnstile may also use temporary security mechanisms when an abuse-prevention check runs.

LOGS
📝

No request logs tied to you

The application keeps no access logs with usernames, session ids or decrypted keys. Error messages may mention a media title if something goes wrong mid-match, but never your credentials. Reverse-proxy transport logs exist briefly for operating the site, as with any web server, and are not tied into the account system.

// data flows out

Where your data goes, exactly.

These services receive data only when you use the related feature. Each one processes your data under its own privacy policy.

SIGN-IN
GitHub & Google
Verify who you are and hand us your profile basics (name, email, avatar). Their own privacy terms cover the login itself.
DEBRID
TorBox · Real-Debrid · AllDebrid · Premiumize
Every library listing and stream link call authenticates directly to your provider with your key. They see the requests coming from our server, authenticated as you.
METADATA
TMDB
Title searches and detail lookups use your TMDB key. Requests contain media titles and ids, never anything about you beyond the key itself.
WATCHLISTS
Trakt · Simkl · MDBList
When connected, we pull your watchlist titles (ids, titles, years) with your stored token or key. We only read lists; we don't scrobble, rate or write anything back.
PUSH
Nuvio
Pushing installs the addon into your Nuvio profile using your stored token, syncs your collection folders and home rows, and includes a pseudonymous origin id so pushes can be attributed. Only happens when you press push or enable auto-sync.
SYNC
Stremio
Connecting updates which addons are installed in your Stremio account via their official API, authenticated with your auth key.
ARTWORK
Fanart.tv · OMDb · RPDB · ERDB · BetterPosters
Optional artwork and rating providers. If configured, requests carry the relevant key and the title being looked up.
STREAMS
Stream addons (Torrentio · Comet · Meteor · MediaFusion…)
On discovery rows, these addons are asked which sources exist for a title, so they see the title id being resolved. Your debrid keys are never forwarded to them.
// retention

How long we keep things.

Sign-in sessions
One day after denying cookies or up to 30 days after accepting them. Expired sessions are purged automatically. Signing out deletes the authentication session immediately.
1 or 30 days
OAuth state cookie
Short-lived handshake value used during GitHub/Google login, then gone.
10 minutes
Cookie duration choice
Remembers whether you accepted or denied persistent cookies so the login screen can respect your choice.
1 day or 6 months
Watchlist caches
Cached watchlist results keyed by a pseudonymous hash of your keys, so repeated views stay fast without re-hitting Trakt/Simkl.
~15 minutes
Metadata caches
Shared title-to-metadata mappings. Contain media titles and ids only, never personal data.
hours to days
Rate limit counters
IP-based abuse counters held in process memory only. Never written to disk, database or logs.
~1 minute
Encrypted backups
Daily database backups kept for operational safety, then deleted on rotation.
30 days
Everything else
Your profile, keys, connections, collections and saved setups are kept until you delete them or delete your account.
until deletion
// gdpr rights

You're in control. Here's how.

01

See everything

The account settings page shows every record we hold: your profile, connected platforms, saved keys by service name, tokens, sessions and collections. No hidden fields, no request forms needed.

02

Fix anything

Edit or replace your keys, rename collections, relabel setups and disconnect platforms at any time from settings. Changes take effect immediately.

03

Delete everything

The Delete Account button removes your entire account in one go: profile, encrypted keys, connections, collections, saved setups and sessions. Immediate cascade deletion, no grace period, no soft-delete copies.

04

Talk to us

Questions, export requests or complaints: open an issue on GitHub or post on the subreddit. EU/UK residents have statutory rights of access, portability, rectification, erasure and objection, and we honour all of them.

// the fine print

Legal bits, in human words.

Who is responsible

LeLibrary (lelibrary.uk) is an open-source project run as a hobbyist community service. For this hosted instance, the controller is the operator of lelibrary.uk. Contact: GitHub issues or r/LeLibrary.

Why we process data (legal basis)

To provide the service you signed up for: running your library, storing your preferences and serving your streams (performance of a contract). To protect the service from abuse: short-lived IP rate limiting (legitimate interests). Optional connections such as watchlists and platform pushes happen only with your consent, which you withdraw by disconnecting them or deleting your account.

International transfers

Some providers listed above (GitHub, Google, TMDB and others) process data outside the UK/EU. Using those features necessarily involves those transfers under each provider's own safeguards.

Self-hosting

This policy covers the hosted service at lelibrary.uk. If you self-host LeLibrary, all data stays on hardware you control and this policy doesn't apply; you become the data controller instead.

Changes to this policy

If this policy changes materially, the updated date above will change and notable differences will be summarised on the home page or release notes. Continued use after changes means you accept the updated version.