Skip to content
LekhaPoth

119 chapters • 9 series

  • Home
  • Series
  • Tags
  • Search
  • My shelf

    You are not following any series yet.

See all series
Tags
সেডাকশন118 chaptersমিল্ফ114 chaptersক্রিমপাই103 chaptersকার্ভি94 chaptersহর্নি94 chaptersউপন্যাস90 chaptersচটি90 chaptersহার্ডকোর90 chaptersবড় ধোন70 chaptersম্যাচিওর68 chaptersবড় দুধ67 chaptersডগি44 chapters
See all tags
LekhaPoth
Sign in

© 2026 LekhaPoth. Operated by Sophiya Lena.

18+PrivacyTermsContact
Sign in
  1. Home
  2. Privacy Policy

Privacy Policy

Last updated: 10 September 2026

This policy describes how LekhaPoth (www.lekhapoth.com) handles information. The site is operated by Sophiya Lena. Contact: admin@lekhapoth.com.

LekhaPoth is an 18+ library of fictional Bangla choti, sex stories and erotic works. It is not directed at children.

1. Who this applies to

Anyone who visits the site, creates an account, uses a personal API key, saves a library locally, or uses character chat.

2. What we collect

Account (if you register): email address, password (stored as an argon2id hash, never in plaintext), optional display name and handle, email-verification and password-reset tokens (hashed), account status.

Session: httpOnly cookies (lp-access / lp-refresh, or __Host-* on HTTPS). Access tokens are short-lived JWTs. Refresh tokens are opaque and stored only as hashes, with rotation and reuse detection.

Reader library (signed-in): favourites, watch-later, reading history and progress, reactions (vote / rating), follows, personal collections and items you put in them.

Character chat (if enabled on your account): messages you send, assistant replies, and a short memory summary for that thread. These are private to you. They are not published chapters.

API keys: if you create a personal key (lpak_…), we store only a hash of the full token. The plaintext is shown once at creation.

Age gate: a cookie (lekha-poth:age-ok) recording that you attested you are 18 or older. The same flag may also sit in localStorage.

Locale and appearance: NEXT_LOCALE cookie; theme / typography preferences in localStorage.

Device-only (not sent until you import): anonymous library data in localStorage; up to five saved chapter bodies in IndexedDB for offline reading.

Security logs: we do not store raw IP addresses or user-agents. Rate-limiting and abuse controls use salted, truncated HMACs. The audit log records user ids, not emails.

Optional diagnostics: if error reporting (Sentry) is configured by the operator, crash reports may include URL, browser, and a stack trace — not your password or API key.

We do not collect payment cards (the site is free), government ID, or precise GPS.

3. Why we use it

  • To run the library, accounts, and (where offered) character chat.
  • To keep you signed in safely and to detect stolen refresh tokens.
  • To send transactional email (verify address, reset password, confirm deletion).
  • To enforce rate limits and stop abuse.
  • To honour your age attestation and locale.

4. Character chat and third-party models

If you use character chat, the configured OpenAI-compatible provider receives the staff personality prompt, retrieved public chapter text for that series, and your recent messages so it can reply in character.

We do not control that provider’s retention. Do not put real names, phone numbers, addresses, or anyone else’s personal data in chat. Roleplay is fictional. Chat does not change published chapters.

5. Who we share with

We do not sell personal data.

Processors that may see data needed to run the service: database and cache hosts, object storage (S3-compatible) for media and account exports, email delivery, the optional error reporter, search index, and the LLM endpoint if chat is enabled.

Staff can see what they need to operate the site (for example moderation of public collections). Personality prompts are staff-only. We do not treat your private chat as public content.

We may disclose information if required by applicable law or to protect someone from imminent harm.

6. Cookies

NameRoleTypical life
lp-access or __Host-lp-accessSigned-in accessMinutes (shorter than the token)
lp-refresh or __Host-lp-refreshSession refreshUntil logout / rotation
NEXT_LOCALELanguage1 year
lekha-poth:age-ok18+ attestation1 year

Session cookies are HttpOnly, SameSite=Lax, and Secure on HTTPS. We also use localStorage / IndexedDB as described above.

7. How long we keep it

Account data until you delete the account (or we close it for a Terms breach). Refresh tokens until they expire or are revoked. API-key hashes until you revoke them. Security HMACs only as long as the rate-limit window needs. After account deletion, authored public stories (if any) are anonymized (created_by cleared); the account row is tombstoned so the same email cannot silently reappear.

8. Your choices

  • Export: signed-in users can request an archive of their account data (POST /me/export). Download is a short-lived private link.
  • Delete: account deletion requires your password and a token emailed to the address on file. It is irreversible.
  • Correct: you can change display name and related profile fields in Account.
  • Email: change or confirm through the emailed flows. API keys require a verified email.
  • Age gate: leave the site if you do not accept; clearing the cookie will show the gate again.
  • Local data: you can clear site data in the browser.

A suspended account can still load the profile; writes are refused until staff lift the suspension. A deleted account cannot sign in.

9. Children

You must be 18 or older. We do not knowingly collect data from anyone under 18. If we learn an account belongs to a minor we will delete it. Report that to admin@lekhapoth.com.

10. International processing

Servers, storage, email, or the LLM vendor may be outside Bangladesh. If you use the site from Bangladesh, your data may be processed in those locations.

11. Security

Passwords use argon2id. Refresh tokens and API keys are stored hashed. Public pages do not embed your library. We still cannot promise that any internet service is unbreakable — use a unique password.

12. Changes

We may update this policy. The date at the top will change. Continued use after an update means you accept the new text. Material changes that affect how we use personal data will be reflected here before they apply.

13. Contact

Sophiya Lena — admin@lekhapoth.com