The short version. lastwake keeps your email address, a random nickname, and whatever you put on your own shelves. It shows no ads, sells nothing, and runs no analytics or tracking of any kind — not on the website, not in the apps. The only cookie is the one that keeps you signed in.
You can erase all of it yourself, in one step, from your account page. Deletion is immediate, not a request in a queue.
This Privacy Policy explains how XenVault Interactive (“we”, “us”, “our”) collects, uses and discloses information when you use the lastwake website at lastwake.com and the Lastwake applications for Android and iOS (together, the “Service”). We are the data controller for that information. We are based in Ukraine.
The website and the mobile apps share one account system and one database, so this policy covers both. Where a practice applies to only one of them, it says so.
Titles you add from the built-in search also carry a snapshot of public catalogue data from The Movie Database — title, original title, year, poster path and overview — copied at the moment you add the card. That is information about a film, not about you.
law_sid, containing a random token. It is HttpOnly, Secure and SameSite=Lax, and only a SHA-256 hash of the token is kept on our side, so a copy of our database does not hand anyone a working session./api/tmdb/search?q=…, the words you type into the search box appear in those logs for as long as Cloudflare keeps them. We do not store your searches anywhere else, and we do not build a search history against your account.That is the whole list. The mobile apps add nothing to it — no crash reporting, no diagnostics, no third-party SDK of any kind.
If you use the Service without an account, your Found and Watched stamps are stored in your browser’s local storage under the key lastwake-progress and are never sent to us. Once you sign in, they are mirrored to your account so they follow you between devices. Clearing your browser data removes the local copy; deleting your account removes the server copy.
| Purpose | Data used | Legal basis (UK/EU GDPR) |
|---|---|---|
| Create and run your account; store and sync your ledgers | Email, password hash, nickname, your content | Performance of a contract (Art. 6(1)(b)) |
| Verify your address and let you reset a password | Email, one-time token hashes | Performance of a contract; legitimate interests in account security |
| Keep you signed in | Session cookie and its hash | Strictly necessary for a service you asked for |
| Prevent abuse: bot signups, credential stuffing, scraping our upstream quota | Security counters, IP address, Turnstile result | Legitimate interests (Art. 6(1)(f)) in a working, un-abused service |
| Look up titles and posters you search for | The text you typed | Performance of a contract |
| Publish a shelf you chose to share | The shelf’s contents, minus notes | Your instruction, at the moment you press share |
| Comply with law; establish or defend legal claims | Whatever is strictly relevant | Legal obligation (Art. 6(1)(c)); legitimate interests |
We do not use your content to train machine-learning models, and we do not read your notes except where you ask us to investigate a problem with your own account.
We use a small number of service providers. They act on our instructions and may not use your data for their own purposes.
| Provider | What it does | What it receives |
|---|---|---|
| Cloudflare, Inc. (US) | Hosting, CDN, the application itself, and the D1 database where your account lives | Everything you send to the Service, plus request metadata |
| Cloudflare Turnstile | Bot check shown on the signup form only | Signals from your browser needed to tell a human from a script. Turnstile is designed not to profile users or track them across sites |
| Resend, Inc. (US) | Sends the verification and password-reset emails. Nothing else | Your email address and the contents of those two messages |
| The Movie Database (TMDB) (US) — attribution | Title, year, poster and overview lookups | The search text only. These calls are made by our server, so TMDB does not receive your IP address or any account identifier. Poster images are loaded by your device directly from TMDB’s image host, which does expose your IP address to it |
| Google Fonts and unpkg — website only | Serve the site’s typefaces and its JavaScript runtime | Your IP address and user agent, as with any file your browser fetches from another host |
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we have no advertising partners, affiliates or data brokers. We may disclose information if we are legally required to, to enforce our terms, or to protect the rights and safety of our users or the public. If the Service were ever transferred to another owner, your data would move with it and you would be told before this policy stopped applying.
You can publish a shelf as a read-only page at an unguessable link. While that link is live, anyone who has it can see the shelf’s name, its ledgers and its cards — including each card’s status and rating.
noindex, so search engines are asked not to list them. Anyone you give the link to can pass it on, and we cannot recall a copy someone has already made.Sign in, open your account page, and choose Delete my account. You will be asked for your password and to type the word DELETE. When you confirm, we immediately remove your user record, email address, password hash, nickname, every shelf, ledger and card with its notes and ratings, all curated-ledger stamps, every session, any pending email tokens, and the security counters tied to you. Any shared link you published stops working in the same moment.
The action is irreversible and there is no grace period — once it is done we hold nothing to restore. If you cannot reach your account, email xenvault.interactive@gmail.com from the address you signed up with and we will erase it within 30 days.
You have the right to access your data, to correct it, to erase it, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent where consent is the basis we rely on. Where we rely on legitimate interests, you may object and we will stop unless we have compelling grounds not to.
Most of these you can exercise yourself: your data is visible in the Service, your notes and ratings are editable, and deletion is one button. For a copy of your data in machine-readable form, or anything else, email us. We answer within one month. You may also complain to your local data protection authority — in Ukraine, the Ukrainian Parliament Commissioner for Human Rights.
In the past twelve months we have collected these categories of personal information: identifiers (email address, account number, nickname, IP address, session token), internet or network activity (request logs), and other information you provide (your ledgers, ratings and notes). Each is collected for the purposes in §2 and comes from you or is generated by your use of the Service.
We have not sold personal information and have not shared it for cross-context behavioural advertising in that period, and we do not do so now. We do not collect sensitive personal information, and we have no actual knowledge of selling or sharing the personal information of anyone under 16.
You have the right to know what we have collected, to delete it, to correct it, to opt out of sale or sharing (there is nothing to opt out of), and not to be discriminated against for exercising any of these — the Service is free and behaves identically either way. Exercise them through the account page or by email; an authorised agent may act for you with written proof.
Whatever jurisdiction you are in, the same account page and the same email address are available to you, and we apply the protections in this policy to all users rather than only to those a particular law covers.
Our providers are based in the United States and operate global infrastructure, so your information is processed outside your country and outside Ukraine. Where the GDPR requires it, transfers rely on the European Commission’s Standard Contractual Clauses in our agreements with those providers, together with the technical measures described here. Ask us and we will tell you which safeguard applies to which provider.
Traffic runs over HTTPS. Passwords are salted and hashed with PBKDF2. Session and email tokens exist on our side only as SHA-256 hashes. Every query is scoped to the signed-in account, and a record belonging to someone else answers as if it did not exist. Mutating requests are checked against the request origin, and the session cookie is SameSite=Lax. Our TMDB key stays on the server and is never sent to your device.
No system is perfectly secure and we cannot guarantee absolute safety. If a breach affects your personal data, we will notify you and the relevant authority as the law requires.
The Service is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us their information, write to us and we will remove it. Where consent is our legal basis and your country requires a parent to give it, we will ask for that first.
Some pages link out to third-party sites, and posters come from TMDB. We do not control those sites and are not responsible for their content or their privacy practices. Read their policies before giving them anything.
We may update this policy. The date at the top changes with it, and material changes will be announced in the Service — and, where the law requires, by email — before they take effect. Continuing to use the Service after that means you accept the revised policy.
Questions, requests, or a privacy complaint:
See also our Terms of Service.