Privacy Policy

A ledger is a private thing. This page says exactly what is written down, who else can read it, and how to burn it.

Last updated: 6 August 2026

The short version. lastwake keeps your email address, a random nickname, and whatever you put on your own shelves. It shows no ads, sells nothing, and runs no analytics or tracking of any kind — not on the website, not in the apps. The only cookie is the one that keeps you signed in.

You can erase all of it yourself, in one step, from your account page. Deletion is immediate, not a request in a queue.

This Privacy Policy explains how XenVault Interactive (“we”, “us”, “our”) collects, uses and discloses information when you use the lastwake website at lastwake.com and the Lastwake applications for Android and iOS (together, the “Service”). We are the data controller for that information. We are based in Ukraine.

The website and the mobile apps share one account system and one database, so this policy covers both. Where a practice applies to only one of them, it says so.

1. What we collect

Information you give us

Titles you add from the built-in search also carry a snapshot of public catalogue data from The Movie Database — title, original title, year, poster path and overview — copied at the moment you add the card. That is information about a film, not about you.

Information assigned to you

Information collected automatically

That is the whole list. The mobile apps add nothing to it — no crash reporting, no diagnostics, no third-party SDK of any kind.

What we deliberately do not collect

Data kept on your device instead of on our servers

If you use the Service without an account, your Found and Watched stamps are stored in your browser’s local storage under the key lastwake-progress and are never sent to us. Once you sign in, they are mirrored to your account so they follow you between devices. Clearing your browser data removes the local copy; deleting your account removes the server copy.

2. Why we use it, and on what legal basis

PurposeData usedLegal basis (UK/EU GDPR)
Create and run your account; store and sync your ledgersEmail, password hash, nickname, your contentPerformance of a contract (Art. 6(1)(b))
Verify your address and let you reset a passwordEmail, one-time token hashesPerformance of a contract; legitimate interests in account security
Keep you signed inSession cookie and its hashStrictly necessary for a service you asked for
Prevent abuse: bot signups, credential stuffing, scraping our upstream quotaSecurity counters, IP address, Turnstile resultLegitimate interests (Art. 6(1)(f)) in a working, un-abused service
Look up titles and posters you search forThe text you typedPerformance of a contract
Publish a shelf you chose to shareThe shelf’s contents, minus notesYour instruction, at the moment you press share
Comply with law; establish or defend legal claimsWhatever is strictly relevantLegal obligation (Art. 6(1)(c)); legitimate interests

We do not use your content to train machine-learning models, and we do not read your notes except where you ask us to investigate a problem with your own account.

3. Third parties who process data for us

We use a small number of service providers. They act on our instructions and may not use your data for their own purposes.

ProviderWhat it doesWhat it receives
Cloudflare, Inc. (US)Hosting, CDN, the application itself, and the D1 database where your account livesEverything you send to the Service, plus request metadata
Cloudflare TurnstileBot check shown on the signup form onlySignals from your browser needed to tell a human from a script. Turnstile is designed not to profile users or track them across sites
Resend, Inc. (US)Sends the verification and password-reset emails. Nothing elseYour email address and the contents of those two messages
The Movie Database (TMDB) (US) — attributionTitle, year, poster and overview lookupsThe search text only. These calls are made by our server, so TMDB does not receive your IP address or any account identifier. Poster images are loaded by your device directly from TMDB’s image host, which does expose your IP address to it
Google Fonts and unpkgwebsite onlyServe the site’s typefaces and its JavaScript runtimeYour IP address and user agent, as with any file your browser fetches from another host

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we have no advertising partners, affiliates or data brokers. We may disclose information if we are legally required to, to enforce our terms, or to protect the rights and safety of our users or the public. If the Service were ever transferred to another owner, your data would move with it and you would be told before this policy stopped applying.

4. Shared shelves

You can publish a shelf as a read-only page at an unguessable link. While that link is live, anyone who has it can see the shelf’s name, its ledgers and its cards — including each card’s status and rating.

5. How long we keep it

6. Deleting your account

Sign in, open your account page, and choose Delete my account. You will be asked for your password and to type the word DELETE. When you confirm, we immediately remove your user record, email address, password hash, nickname, every shelf, ledger and card with its notes and ratings, all curated-ledger stamps, every session, any pending email tokens, and the security counters tied to you. Any shared link you published stops working in the same moment.

The action is irreversible and there is no grace period — once it is done we hold nothing to restore. If you cannot reach your account, email xenvault.interactive@gmail.com from the address you signed up with and we will erase it within 30 days.

7. Your rights

If you are in the EU, the UK, or another GDPR-aligned jurisdiction

You have the right to access your data, to correct it, to erase it, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent where consent is the basis we rely on. Where we rely on legitimate interests, you may object and we will stop unless we have compelling grounds not to.

Most of these you can exercise yourself: your data is visible in the Service, your notes and ratings are editable, and deletion is one button. For a copy of your data in machine-readable form, or anything else, email us. We answer within one month. You may also complain to your local data protection authority — in Ukraine, the Ukrainian Parliament Commissioner for Human Rights.

If you are a California resident (CCPA/CPRA)

In the past twelve months we have collected these categories of personal information: identifiers (email address, account number, nickname, IP address, session token), internet or network activity (request logs), and other information you provide (your ledgers, ratings and notes). Each is collected for the purposes in §2 and comes from you or is generated by your use of the Service.

We have not sold personal information and have not shared it for cross-context behavioural advertising in that period, and we do not do so now. We do not collect sensitive personal information, and we have no actual knowledge of selling or sharing the personal information of anyone under 16.

You have the right to know what we have collected, to delete it, to correct it, to opt out of sale or sharing (there is nothing to opt out of), and not to be discriminated against for exercising any of these — the Service is free and behaves identically either way. Exercise them through the account page or by email; an authorised agent may act for you with written proof.

Everyone

Whatever jurisdiction you are in, the same account page and the same email address are available to you, and we apply the protections in this policy to all users rather than only to those a particular law covers.

8. International transfers

Our providers are based in the United States and operate global infrastructure, so your information is processed outside your country and outside Ukraine. Where the GDPR requires it, transfers rely on the European Commission’s Standard Contractual Clauses in our agreements with those providers, together with the technical measures described here. Ask us and we will tell you which safeguard applies to which provider.

9. Security

Traffic runs over HTTPS. Passwords are salted and hashed with PBKDF2. Session and email tokens exist on our side only as SHA-256 hashes. Every query is scoped to the signed-in account, and a record belonging to someone else answers as if it did not exist. Mutating requests are checked against the request origin, and the session cookie is SameSite=Lax. Our TMDB key stays on the server and is never sent to your device.

No system is perfectly secure and we cannot guarantee absolute safety. If a breach affects your personal data, we will notify you and the relevant authority as the law requires.

10. Children

The Service is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us their information, write to us and we will remove it. Where consent is our legal basis and your country requires a parent to give it, we will ask for that first.

11. Links to other sites

Some pages link out to third-party sites, and posters come from TMDB. We do not control those sites and are not responsible for their content or their privacy practices. Read their policies before giving them anything.

12. Changes to this policy

We may update this policy. The date at the top changes with it, and material changes will be announced in the Service — and, where the law requires, by email — before they take effect. Continuing to use the Service after that means you accept the revised policy.

13. Contact

Questions, requests, or a privacy complaint:

See also our Terms of Service.

lastwake.com privacytermsdata byTMDB 夜未央 · the night is not over