Skip to content

Data and Privacy

SamsterZero edited this page Sep 3, 2026 · 5 revisions

Data and Privacy

Granthalay's current reader has no backend and does not intentionally transmit imported books, metadata, or reading progress to a Granthalay service.

Browser storage

The version 4 EpubReaderDB IndexedDB database contains:

Store Contents
books Title, cover, creation time, and reading-progress metadata
bookContents Original EPUB bytes, keyed by the same UUID
annotations Versioned bookmarks and text highlights, indexed by book UUID

Local storage contains the theme, library view, and progress for the bundled sample book. Cache Storage contains application assets and successful GET responses handled by the service worker.

Important limitations

  • Storage belongs to one browser profile and site origin.
  • Clearing site data removes the library, progress, bookmarks, and highlights.
  • Granthalay does not currently export, synchronize, or recover a library.
  • Duplicate imports are allowed.

Annotation locations contain an EPUB chapter href and normalized progression. Highlights also store the selected quote and a small amount of surrounding text so they can be restored after ordinary repagination. This selected text is local reading activity and is never sent to diagnostics or a backend by default.

Deleting an imported book removes its metadata, original EPUB bytes, and annotations in one IndexedDB transaction, so all related deletions commit together or none does. The annotation format is versioned for future portable-data work, but export and synchronization are not implemented yet.

Untrusted publications

EPUB archives, markup, and styles are untrusted input. Granthalay filters markup with sanitize-html and converts internal resources to browser object URLs. This reduces risk but is not an antivirus guarantee. Report suspected sanitizer bypasses privately through the repository's security policy.

Future email/password accounts and bookstore services remain optional for importing and reading personal EPUBs. Passwords must be hashed, sessions revocable, and reset links single-use and short-lived. Reading history remains local unless a user explicitly enables synchronization; payment details remain with the payment provider.

Diagnostics

Pino logs use allow-listed fields and redact credentials, tokens, email addresses, book content, reading activity, and payment data. Sentry remains disabled unless explicitly configured. Before activation, deployments must scrub events, disable session replay, minimize sampling, and document consent and retention. EPUB files, chapter text, library metadata, request bodies, authorization headers, and log payloads must never be attached to Sentry events.

Clone this wiki locally