Privacy
Privacy Policy
Last updated: July 24, 2026
LitLab is a reading platform. We make money from subscriptions — never from your data. We do not sell or rent personal information, we do not run advertising, and we do not embed third-party tracking pixels. This page explains, in plain language, exactly what we store and why.
Who is responsible
LitLab operates litlab.app and is the controller of the personal data described here. For any privacy question or request, write to [email protected].
What we collect
- Account data. Your name, e-mail address and — if you sign up with a password — a cryptographic hash of that password. We never store the password itself.
- Google sign-in (optional). If you choose to sign in with Google, we receive your name, e-mail address and profile picture from Google. Nothing else.
- Reading activity. Which books you open, the chapter you stopped at, your progress percentage and the books you save. This exists so you can pick up where you left off across devices.
- Purchases. Your subscription status, purchase records and invoices. Payment itself is handled by Stripe — see below.
- Approximate location of visits. To see where our readers are in the world, we store the country, region, city and approximate coordinates that Cloudflare derives from the connection — never the IP address itself. This is not linked to your account.
What we deliberately do not collect
- Your IP address is not stored. It is used in transit to protect the site from abuse, then discarded — it is never written to our database.
- Card numbers never reach us.Payment details are entered directly on Stripe's hosted checkout. We only receive the outcome (paid, active, cancelled).
- No advertising or analytics trackers. No Google Analytics, no Meta pixel, no cross-site cookies, no data brokers.
Why we are allowed to use it
- To provide the service (performance of a contract): your account, your reading progress, your access to purchased or subscribed content.
- Legitimate interest: keeping the platform secure (limiting brute-force sign-in attempts) and understanding, at an aggregate level, where our readers are.
- Legal obligation: keeping the billing records that tax and accounting rules require.
- Consent: where required, for example when you choose to sign in with Google. You may withdraw it at any time by deleting your account.
Cookies and local storage
We only use what the site needs to work. There are no advertising cookies.
- Session cookie (essential). Keeps you signed in. Without it, you would have to log in on every page.
- Your browser's local storage. Reading preferences (font size, light or dark mode) and — for visitors who are not signed in — reading progress. This stays on your device; we cannot read it from our servers.
Who processes data on our behalf
We rely on a small number of established providers. They act on our instructions and only for the purposes below.
- Railway — application hosting and database (United States).
- Cloudflare — domain, network protection and file storage for book content and artwork.
- Stripe — payment processing and invoices.
- Resend — transactional e-mail (confirmation and password reset).
- Google — only if you choose to sign in with a Google account.
International transfers
LitLab is available worldwide and our infrastructure is located primarily in the United States. When your data is transferred out of your country, we rely on the safeguards offered by these providers, including standard contractual clauses where applicable.
How long we keep it
- Account and reading data: for as long as your account exists. Delete the account and it goes with it.
- Billing records: retained for the period required by tax law, even after the account is closed.
- Sign-in and confirmation links: password reset links expire in 1 hour, confirmation links in 7 days. Both are single-use and stored only as a hash.
- Visit records: kept in aggregate, with no link to your identity.
Your rights
Wherever you live — and specifically under Brazil's LGPD and the European GDPR — you may ask us to:
- confirm whether we hold data about you, and get a copy of it;
- correct anything that is wrong or incomplete;
- delete your account and the personal data tied to it;
- receive your data in a portable, machine-readable format;
- object to or restrict a particular use;
- withdraw consent where the processing was based on it.
Write to [email protected] and we will respond within the legal deadline. You also have the right to complain to your data protection authority — the ANPD in Brazil, or your local supervisory authority in the European Union.
How we protect your data
- Passwords are stored using bcrypt — they cannot be read back.
- The whole site runs over HTTPS, with strict transport security.
- Book files and artwork live in private storage, delivered only through short-lived signed links.
- Sign-in attempts are rate-limited to frustrate brute-force attacks.
- Access to production data is restricted to the people who operate the service.
No system is perfectly secure, but if a breach ever affects your personal data, we will notify you and the competent authority as the law requires.
Children
LitLab is not directed at children under 13. We do not knowingly collect their data. If you believe a child has created an account, write to us and we will remove it.
Changes to this policy
If we make a material change, we will update the date at the top of this page and, where the change is significant, tell you by e-mail.
Contact
Privacy questions, requests or complaints: [email protected].