Privacy Policy
Effective Date: September 7, 2026
Contents
- Who We Are
- What Data We Collect
- How We Use Your Data
- Cookies
- Google Analytics
- Third-Party Services
- Data Retention
- Your Rights
- Data Security
- Data Breach Notification
- BusWatch
- Children’s Privacy
- International Data Transfers
- Changes to This Policy
- Contact Us
- Changelog
1. Who We Are
These sites and services are provided by Attention Feed, Inc. Our sites and services include:
- attentionfeed.com — Our homepage and blog
- auth.attentionfeed.com — Our authentication service
- archivelivedead.attentionfeed.com — A service for finding and streaming Grateful Dead concerts from the Internet Archive
- peplist.attentionfeed.com — A podcast playlist creation and curation tool
- booklist.attentionfeed.com — A client-side tool to extract the books you’ve bought from your Amazon data export
- locations.attentionfeed.com — A client-side tool to map the countries you’ve visited from your Google Timeline export or CSV data
- BusWatch — A Wear OS app for London bus arrival times (covered by its own separate privacy policy)
This privacy policy covers all of these services except where noted. When we say “we,” “us,” or “our,” we mean AttentionFeed. When we say “you” or “your,” we mean you, the person using our services.
2. What Data We Collect
The data we collect depends on which service you use.
2.1 Data You Provide Directly
When you create an account (via auth.attentionfeed.com):
- Email address
- Username
- Display name
- Password (we store only a one-way hash — we never see or store your actual password)
When you log in to Archive Live Dead or PEPList, that service keeps its own copy of your username, display name, and email address so it can show your account and contact you.
When you use Archive Live Dead:
- Performance preferences (thumbs up, thumbs down, or mute on individual tracks)
- Song and year preferences
- Player settings you configure
When you use PEPList:
- Playlists you create (titles, descriptions, and the author name you choose to show publicly)
- Episodes you add to playlists
- Notes you write about episodes
- Your username, which appears in the public URL of every feed you create
When you use Booklist:
- Nothing beyond Google Analytics data (see Section 5), and only if you accept analytics cookies and standard page request handling. Booklist runs entirely in your browser. Your Amazon export data never leaves your device. Loading Booklist is done by sending a page request to our static site host (GitHub Pages) and Cloudflare for javascript libraries (see Section 6).
When you use Locations:
- Nothing beyond standard request handling. Locations runs entirely in your browser. Your Google Timeline or CSV data never leaves your device. Google Analytics runs on this page only if you accept analytics cookies (see Section 5). Loading Locations is done by sending page requests to our static site host (GitHub Pages) and jsDelivr for javascript libraries (see Section 6).
2.2 Data We Collect Automatically
When you create or use an account:
- Account creation, update and login timestamps
- Email verification status
When you use Archive Live Dead:
- Your playback position (saved so you can resume where you left off — this persists between sessions until your next listening session overwrites it)
- Your listening history (which concerts you listened to, how much you completed, whether you skipped)
- Session identifiers
- Your last login time
On sites that use Google Analytics (homepage, auth, Archive Live Dead, Booklist and Locations):
- See Section 5: Google Analytics for details.
On the services we host on Railway (auth, Archive Live Dead, PEPList):
- Your IP address is held in server memory for rate limiting and abuse prevention, and it appears in our application and access logs. Railway, our hosting provider, retains those logs for a limited period (see Section 7). These services also load a static shared stylesheet, scripts and fonts from GitHub Pages (see below).
On our static pages (homepage, Booklist, Locations):
- These pages are served by GitHub Pages, which keeps its own request logs — see Section 6 and Section 7. The services hosted on Railway (auth, Archive Live Dead, PEPList) are not served by GitHub Pages, but every service loads our shared stylesheet, scripts, and fonts from attentionfeed.com, which is served from there.
3. How We Use Your Data
We use your data for these purposes:
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Create and manage your account | Email, username, display name, password hash | Contractual necessity |
| Verify your email address | Email address, verification tokens | Contractual necessity |
| Reset your password | Email address, reset tokens | Contractual necessity |
| Send you transactional emails | Email address | Contractual necessity |
| Let you resume playback | Playback position, session ID | Legitimate interest |
| Recommend concerts you haven’t heard | Listening history, preferences | Legitimate interest |
| Generate your podcast RSS feeds | Playlist and episode data | Contractual necessity |
| Prevent abuse and enforce rate limits | IP address (in memory and in server logs) | Legitimate interest |
| Remember your analytics choice | Consent cookie (see Section 4) | Legitimate interest |
| Understand how our services are used | Google Analytics data | Consent (where required) / Legitimate interest |
| Load web fonts and shared page assets | IP address, page URL (sent to GitHub Pages, which hosts attentionfeed.com) | Legitimate interest |
| Load JavaScript libraries | IP address, page URL (sent to Cloudflare CDN for Booklist, jsDelivr CDN for Locations) | Legitimate interest |
| Load map data | IP address, page URL (sent to jsDelivr CDN for Locations) | Legitimate interest |
| Stream audio content | IP address, request headers (sent to archive.org by your browser) | Contractual necessity |
| Look up book metadata | Book titles, ISBNs (sent to Open Library by your browser) | Legitimate interest |
| Search for podcasts | Search queries (sent to Podcast Index) | Contractual necessity |
| Play podcast episodes | IP address, request headers (sent to the podcast’s hosting provider by your browser) | Contractual necessity |
| Serve static pages | IP address, request headers (sent to GitHub Pages for the homepage, Booklist, and Locations) | Legitimate interest |
What do these legal bases mean? “Contractual necessity” means we need the data to deliver the service you signed up for. “Legitimate interest” means we have a reasonable business reason to process the data, balanced against your privacy — for example, preventing abuse or loading fonts that make the site readable. “Consent” means we ask your permission first.
We use your data to provide, understand the use of and improve the services.
4. Cookies
We use cookies to keep you logged in, to protect your account, and understand your use of the services. Here is what we set:
Essential Cookies (Required for Services to Work)
| Cookie | Service | Purpose | Lifespan |
|---|---|---|---|
auth_session | Auth service | Keeps you logged in | 24 hours |
oauth_params | Auth service | Temporary OAuth flow data | 10 minutes |
access_token | Archive Live Dead | Your login session | 30 days |
refresh_token | Archive Live Dead | Refreshes your session | 30 days |
id_token | Archive Live Dead | Identifies your account | 30 days |
peplist_session | PEPList | Your login session | 24 hours |
peplist_refresh | PEPList | Refreshes your session | 30 days |
__Host-peplist_csrf | PEPList | Prevents cross-site attacks | 30 days |
| CSRF token | Archive Live Dead | Prevents cross-site attacks | Session |
| OAuth state/nonce | All authenticated services | Secures the login flow | 10 minutes |
af_consent | All sites | Remembers whether you accepted analytics cookies; shared across attentionfeed.com subdomains | 1 year |
Google Analytics Cookies
Google Analytics sets its own cookies (such as _ga and _gid) on sites where we
enable it. These cookies can last up to 2 years. See Section 5
for details and opt-out options.
5. Google Analytics
We use Google Analytics on these services to understand general usage patterns — which pages people visit and how they find our site.
Google Analytics collects:
- Pages you visit and time spent on each
- Your browser type and screen size
- Your approximate location (Google derives this from your IP address)
- How you reached the site (search engine, direct link, etc.)
- A pseudonymous cookie identifier to distinguish returning visitors
We never combine this data with personally identifying information, and we do not use Google’s advertising or remarketing features.
Google processes this data under its own privacy policy. For details on how Google handles data from sites that use its services, visit: How Google uses information from sites or apps that use our services
Cookie Consent for Analytics
We do not load Google Analytics until you accept analytics cookies in the banner
shown when you first visit one of our sites. Your choice is stored in the
af_consent cookie, which is shared across all attentionfeed.com subdomains, so you
only need to choose once. You can change your choice at any time using the “Cookies”
link in the footer of any of our sites. If you decline, we set no analytics
cookies and Google receives nothing from your visit.
Opting Out of Google Analytics
You can block Google Analytics by:
- Installing the Google Analytics Opt-out Browser Add-on
- Using a browser extension that blocks tracking scripts (such as uBlock Origin)
6. Third-Party Services
Your use of our services entails the use of some third party services and they also receive data when you use the services.
| Service | What We Share | Why | Their Privacy Policy |
|---|---|---|---|
| Google Analytics | Usage data via cookies and scripts (includes IP addresses and cookie identifiers) | Understand site usage | Google Privacy |
| Railway | Everything we store for auth, Archive Live Dead, and PEPList (they run on Railway’s servers and databases), plus application logs that include IP addresses. You are accessing us through Railway so they also see IP address and other standard request information. | Host our services and databases | Railway Privacy |
| Resend | Recipient email address, email content | Send verification and password reset emails | Resend Privacy |
| Archive.org | Stream URL, IP address and other standard request information (from your browser connecting directly) | Stream concert recordings | Archive.org Terms |
| Open Library | Book titles, ISBNs, IP address and other standard request information (from your browser connecting directly) | Look up author names (Booklist only) | Open Library Privacy |
| Podcast Index | Podcast search queries | Discover podcasts (PEPList only) | Podcast Index |
| Podcast hosting providers | When playing podcast episodes in the browser, the browser sends your IP address and other standard request information | Stream podcast audio (PEPList only) | Varies by publisher |
| Cloudflare CDN | Your IP address and other standard request information | Load JavaScript libraries (Booklist only) | Cloudflare Privacy |
| jsDelivr CDN | Your IP address and other standard request information | Load JavaScript libraries and map data (Locations only) | jsDelivr Privacy |
| GitHub Pages | Your IP address and other standard request information | Host our static pages (homepage, Booklist, and Locations) and the shared stylesheet, scripts, and fonts used by all our services | GitHub Privacy |
7. Data Retention
We keep your data only as long as necessary:
| Data | How Long We Keep It |
|---|---|
| Your account (email, username, display name, password hash) | Until you ask us to delete it |
| Refresh tokens | 30 days, or until you log out |
| Playback position (Archive Live Dead) | Persists between sessions so you can resume; overwritten by your next listening session; deleted with your account |
| Listening history (Archive Live Dead) | Until you clear it yourself or request account deletion |
| Preferences (Archive Live Dead) | Until you remove them or request account deletion |
| Playlists and episodes (PEPList) | Until you delete them or request account deletion |
| Google Analytics data | Per Google’s retention settings |
| IP addresses | In memory for rate limiting until the service restarts; in application logs for as long as Railway keeps them under its log retention policy |
| Your analytics cookie choice | 1 year, or until you change it |
| GitHub Pages request logs (homepage, Booklist, and Locations) | Per GitHub’s retention policy |
8. Your Rights
You have the following rights over your personal data:
- Access: You can ask us what data we hold about you.
- Correction: You can ask us to fix inaccurate data.
- Deletion: You can delete your data yourself. Log in at auth.attentionfeed.com/account to delete your data from any individual service, or to delete your whole account including your login. PEPList also offers deletion on its data export page. You can also ask us by email.
- Data Portability: You can request a copy of your data in a standard format. PEPList offers built-in data export (JSON or XML). For Archive Live Dead and your auth account, we handle data export manually upon request.
- Withdrawal of Consent: Where we rely on your consent (such as for analytics), you can withdraw it at any time — for example, by opting out of Google Analytics.
- Objection: You can object to processing based on legitimate interest.
To exercise any of these rights that you cannot handle yourself, email us at attnfeed@gmail.com. We will respond within 30 days and may ask you to verify your identity first.
Depending on where you live, you may also have the right to lodge a complaint with your local data protection authority.
9. Data Security
We take numerous steps to attempt to ensure your data security however, no site or service is perfectly secure and AttentionFeed was almost entirely coded by AI agents which make errors. So, please do not give us information that would be damaging to you if public. If you discover a vulnerability, please report it privately to attnfeed@gmail.com.
10. Data Breach Notification
If we discover a security breach that affects your personal data and we have your email address, we will:
- Notify affected users without undue delay, and where feasible within 72 hours of discovering the breach
- Describe the breach and the data affected
- Explain what steps we are taking in response
- Notify relevant supervisory authorities where required by law
We will send breach notifications to the email address associated with your account.
11. BusWatch
The BusWatch Wear OS app has its own privacy policy, tailored to the app’s data practices and Google Play Store requirements. You can find it within the app and on the Play Store listing.
12. Children’s Privacy
Our services are not directed at children under 13. We do not knowingly collect personal data from children under 13.
Users must be at least 13 years old to create an account, and we ask you to confirm this when you register. In jurisdictions where the minimum age for data processing consent is higher (such as 16 in some EU member states), users must meet that minimum age.
13. International Data Transfers
Our services and databases run on Railway’s servers and our static pages and other information are served by GitHub Pages, each from servers around the world. If you access our services from outside the United States, your data will be transferred to and processed there.
14. Changes to This Policy
We may update this privacy policy from time to time. When we make changes:
- We will update the effective date at the top of this page.
- For significant changes to how we handle your data, we will notify you at least 30 days before they take effect — by posting a notice on our homepage or emailing the address on your account.
- Where we rely on consent as a legal basis and new processing activities require consent, we will obtain your consent before beginning those activities.
- Continued use of our services after a change takes effect means you accept the update. If you disagree, please stop using the services and request deletion of your account.
All previous versions of this policy are available in the Changelog.
15. Contact Us
For questions about this policy, to exercise your data rights, or to report a security concern, reach us at:
Email: attnfeed@gmail.com
We aim to respond to all inquiries within 30 days.
16. Changelog
| Date | Summary of Changes |
|---|---|
| September 7, 2026 | Initial version |