Privacy Policy
This policy explains what Kitabghar collects, why, and what you can ask us to do about it. It covers both the people who run a library on Kitabghar and the students whose records they keep in it.
In effect from
1.Who is responsible for what
For your own account — your name, email, phone and sign-in activity — we decide how the data is used, and this policy describes it.
For the student records you enter, the library is in charge and we act on its instructions. If you are a student and want your record changed or removed, ask the library you are enrolled at; they can do it themselves in the product.
2.What we collect
Account details: name, email address, username, phone number, and a password stored only as an Argon2 hash that cannot be reversed.
Workspace content: branches, books and copies, students and their contact and guardian details, seats and allocations, loans, invoices, payments and fines — whatever you enter.
Technical records: sign-in attempts, session activity, IP address and browser string. We keep these to spot account takeovers and to lock an account after repeated failed sign-ins.
An audit log of significant actions — who changed a role, who waived a fine, who removed a member of staff — so a library can answer that question later.
3.Why we hold it
To provide the service you asked for: showing your catalogue, issuing books, allotting seats, raising invoices and producing reports.
To keep accounts secure, including rate limiting, account locking and the audit log.
To bill you for a paid plan, and to contact you about your account or a material change to the service.
We do not sell your data, and we do not use your workspace content for advertising or to train models.
4.Cookies
We set a session cookie when you sign in. It is HTTP-only, so page scripts cannot read it, and it holds a random token rather than anything about you.
We also remember small preferences — the branch you are looking at, your language, and whether the sidebar is open. There are no advertising or cross-site tracking cookies.
5.Who else sees it
Our hosting and database providers, who store the data on our behalf and are bound to keep it confidential.
Our payment processor, if you are on a paid plan. Card details go to them directly and never reach our servers.
Anyone you give access to inside your own workspace, limited to the branches and permissions you granted them.
Authorities, where the law requires it. We will tell you unless we are forbidden from doing so.
6.How long we keep it
Workspace content stays while the workspace is open. After it is closed we keep it for 30 days so it can be restored by mistake-recovery, then delete it.
Sign-in attempt records are kept for 90 days. Audit log entries are kept for as long as the workspace, because their purpose is to answer questions about the past.
We may keep invoices and payment records longer where tax law requires it.
7.Your rights
You can ask for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Most of it you can edit yourself from the profile screen.
You can withdraw consent for anything we do that relies on it, and you can complain to the relevant data protection authority if you think we have got it wrong.
Write to [email protected] and we will respond within 30 days.
8.Security
Passwords are hashed with Argon2id. Session tokens are random and stored only as a SHA-256 digest, so a copy of our database cannot be replayed as a login.
Every workspace's data is scoped by the organization on the session, and every branch by the access its staff were granted. No request can widen that scope by changing what it sends.
No system is perfectly secure. If a breach affects you, we will tell you and the relevant authority without undue delay.
9.Changes
If we change this policy in a way that matters, we will tell you in the product before it takes effect. The date at the top always shows the current version.