The LeLibrary account area stores the bare minimum needed to run your library: your sign-in identity, the keys you choose to save, and your library itself. Sensitive data is encrypted at rest, nothing is sold or shared for marketing, and deleting your account wipes everything.
Your sign-in basics from GitHub or Google (name, email, avatar), any API keys you save with us (encrypted before they touch disk), optional platform connections, your collections, and your saved addon setups.
No analytics, no advertising, no trackers, no fingerprinting, no IP address logs, no profiling. There is no telemetry anywhere in LeLibrary. We couldn't sell your data even if we wanted to, because we barely collect any.
Only where you point it: your debrid provider, TMDB metadata lookups, watchlist services you connect, and Nuvio or Stremio when you push to them. The full third-party list is below.
You sign in with GitHub or Google OAuth. We receive and store your name, email address, avatar URL, and your provider account id so we can recognise you on return. The OAuth access tokens used during sign-in are used once to fetch that profile and are not kept. The hosted sign-in page also uses Cloudflare Turnstile, a privacy and abuse-prevention service, to help distinguish genuine sign-in attempts from automated abuse. Turnstile may process limited technical information, such as browser and network signals, for that security check; it is not used by LeLibrary for advertising or tracking.
If you save provider keys with us (TorBox, Real-Debrid, AllDebrid, Premiumize, plus optional TMDB, MDBList, OMDb, Fanart.tv, RPDB and ERDB), every key is encrypted with AES-256-GCM before storage and is only decrypted in memory when answering your addon's requests.
Connecting Trakt or Simkl stores their OAuth tokens (encrypted) so we can read your watchlist. Connecting Nuvio or Stremio stores their credentials (encrypted) so collection pushes and addon syncs keep working while you're away from the browser.
Saved installs get a random unguessable id and store your preferences: enabled providers, language, catalog toggles, sort order, and a label you choose. API keys are deliberately stripped out of these saves; they live only in encrypted storage. We also note when a setup was last used.
Names, descriptions and sort order of collections you create, plus the items inside them: public IMDb/TMDB ids, titles, years, and poster references. Nothing here is shared with anyone unless you push it to your own Nuvio or Stremio profile.
A random opaque session cookie and a matching CSRF cookie keep you signed in securely. Accepting cookies keeps the account signed in for up to 30 days; denying uses a one-day account session instead. No IP addresses, device fingerprints or browser histories are stored anywhere. Rate limiting counts request IPs in memory for about a minute purely to stop abuse, then forgets them.
LeLibrary uses an opaque session id, its CSRF security partner, a short-lived OAuth state cookie, and a cookie that remembers your consent choice. Selecting “Accept” keeps you signed in for up to 30 days and remembers that choice for six months. Selecting “Deny” uses only the required account-security cookies and expires both the choice and your login after 24 hours. The OAuth state cookie lasts 10 minutes. None track you across sites or support advertising or analytics, and the catalog/meta/stream endpoints set no cookies at all. Cloudflare Turnstile may also use temporary security mechanisms when an abuse-prevention check runs.
The application keeps no access logs with usernames, session ids or decrypted keys. Error messages may mention a media title if something goes wrong mid-match, but never your credentials. Reverse-proxy transport logs exist briefly for operating the site, as with any web server, and are not tied into the account system.
These services receive data only when you use the related feature. Each one processes your data under its own privacy policy.
The account settings page shows every record we hold: your profile, connected platforms, saved keys by service name, tokens, sessions and collections. No hidden fields, no request forms needed.
Edit or replace your keys, rename collections, relabel setups and disconnect platforms at any time from settings. Changes take effect immediately.
The Delete Account button removes your entire account in one go: profile, encrypted keys, connections, collections, saved setups and sessions. Immediate cascade deletion, no grace period, no soft-delete copies.
Questions, export requests or complaints: open an issue on GitHub or post on the subreddit. EU/UK residents have statutory rights of access, portability, rectification, erasure and objection, and we honour all of them.
LeLibrary (lelibrary.uk) is an open-source project run as a hobbyist community service. For this hosted instance, the controller is the operator of lelibrary.uk. Contact: GitHub issues or r/LeLibrary.
To provide the service you signed up for: running your library, storing your preferences and serving your streams (performance of a contract). To protect the service from abuse: short-lived IP rate limiting (legitimate interests). Optional connections such as watchlists and platform pushes happen only with your consent, which you withdraw by disconnecting them or deleting your account.
Some providers listed above (GitHub, Google, TMDB and others) process data outside the UK/EU. Using those features necessarily involves those transfers under each provider's own safeguards.
This policy covers the hosted service at lelibrary.uk. If you self-host LeLibrary, all data stays on hardware you control and this policy doesn't apply; you become the data controller instead.
If this policy changes materially, the updated date above will change and notable differences will be summarised on the home page or release notes. Continued use after changes means you accept the updated version.