Repository navigation
Data and Privacy
Granthalay's current reader has no backend and does not intentionally transmit imported books, metadata, or reading progress to a Granthalay service.
The version 4 EpubReaderDB IndexedDB database contains:
| Store | Contents |
|---|---|
books |
Title, cover, creation time, and reading-progress metadata |
bookContents |
Original EPUB bytes, keyed by the same UUID |
annotations |
Versioned bookmarks and text highlights, indexed by book UUID |
Local storage contains the theme, library view, and progress for the bundled sample book. Cache Storage contains application assets and successful GET responses handled by the service worker.
- Storage belongs to one browser profile and site origin.
- Clearing site data removes the library, progress, bookmarks, and highlights.
- Granthalay does not currently export, synchronize, or recover a library.
- Duplicate imports are allowed.
Annotation locations contain an EPUB chapter href and normalized progression. Highlights also store the selected quote and a small amount of surrounding text so they can be restored after ordinary repagination. This selected text is local reading activity and is never sent to diagnostics or a backend by default.
Deleting an imported book removes its metadata, original EPUB bytes, and annotations in one IndexedDB transaction, so all related deletions commit together or none does. The annotation format is versioned for future portable-data work, but export and synchronization are not implemented yet.
EPUB archives, markup, and styles are untrusted input. Granthalay filters markup with
sanitize-html and converts internal resources to browser object URLs. This reduces risk but is
not an antivirus guarantee. Report suspected sanitizer bypasses privately through the repository's
security policy.
Future email/password accounts and bookstore services remain optional for importing and reading personal EPUBs. Passwords must be hashed, sessions revocable, and reset links single-use and short-lived. Reading history remains local unless a user explicitly enables synchronization; payment details remain with the payment provider.
Pino logs use allow-listed fields and redact credentials, tokens, email addresses, book content, reading activity, and payment data. Sentry remains disabled unless explicitly configured. Before activation, deployments must scrub events, disable session replay, minimize sampling, and document consent and retention. EPUB files, chapter text, library metadata, request bodies, authorization headers, and log payloads must never be attached to Sentry events.
Granthalay Wiki · Canonical docs · Privacy · Terms · Report an issue
Granthalay
Engineering
Repository