Privacy Policy

Effective Date: September 7, 2026


Contents

  1. Who We Are
  2. What Data We Collect
  3. How We Use Your Data
  4. Cookies
  5. Google Analytics
  6. Third-Party Services
  7. Data Retention
  8. Your Rights
  9. Data Security
  10. Data Breach Notification
  11. BusWatch
  12. Children’s Privacy
  13. International Data Transfers
  14. Changes to This Policy
  15. Contact Us
  16. Changelog

1. Who We Are

These sites and services are provided by Attention Feed, Inc. Our sites and services include:

  • attentionfeed.com — Our homepage and blog
  • auth.attentionfeed.com — Our authentication service
  • archivelivedead.attentionfeed.com — A service for finding and streaming Grateful Dead concerts from the Internet Archive
  • peplist.attentionfeed.com — A podcast playlist creation and curation tool
  • booklist.attentionfeed.com — A client-side tool to extract the books you’ve bought from your Amazon data export
  • locations.attentionfeed.com — A client-side tool to map the countries you’ve visited from your Google Timeline export or CSV data
  • BusWatch — A Wear OS app for London bus arrival times (covered by its own separate privacy policy)

This privacy policy covers all of these services except where noted. When we say “we,” “us,” or “our,” we mean AttentionFeed. When we say “you” or “your,” we mean you, the person using our services.


2. What Data We Collect

The data we collect depends on which service you use.

2.1 Data You Provide Directly

When you create an account (via auth.attentionfeed.com):

  • Email address
  • Username
  • Display name
  • Password (we store only a one-way hash — we never see or store your actual password)

When you log in to Archive Live Dead or PEPList, that service keeps its own copy of your username, display name, and email address so it can show your account and contact you.

When you use Archive Live Dead:

  • Performance preferences (thumbs up, thumbs down, or mute on individual tracks)
  • Song and year preferences
  • Player settings you configure

When you use PEPList:

  • Playlists you create (titles, descriptions, and the author name you choose to show publicly)
  • Episodes you add to playlists
  • Notes you write about episodes
  • Your username, which appears in the public URL of every feed you create

When you use Booklist:

  • Nothing beyond Google Analytics data (see Section 5), and only if you accept analytics cookies and standard page request handling. Booklist runs entirely in your browser. Your Amazon export data never leaves your device. Loading Booklist is done by sending a page request to our static site host (GitHub Pages) and Cloudflare for javascript libraries (see Section 6).

When you use Locations:

  • Nothing beyond standard request handling. Locations runs entirely in your browser. Your Google Timeline or CSV data never leaves your device. Google Analytics runs on this page only if you accept analytics cookies (see Section 5). Loading Locations is done by sending page requests to our static site host (GitHub Pages) and jsDelivr for javascript libraries (see Section 6).

2.2 Data We Collect Automatically

When you create or use an account:

  • Account creation, update and login timestamps
  • Email verification status

When you use Archive Live Dead:

  • Your playback position (saved so you can resume where you left off — this persists between sessions until your next listening session overwrites it)
  • Your listening history (which concerts you listened to, how much you completed, whether you skipped)
  • Session identifiers
  • Your last login time

On sites that use Google Analytics (homepage, auth, Archive Live Dead, Booklist and Locations):

On the services we host on Railway (auth, Archive Live Dead, PEPList):

  • Your IP address is held in server memory for rate limiting and abuse prevention, and it appears in our application and access logs. Railway, our hosting provider, retains those logs for a limited period (see Section 7). These services also load a static shared stylesheet, scripts and fonts from GitHub Pages (see below).

On our static pages (homepage, Booklist, Locations):

  • These pages are served by GitHub Pages, which keeps its own request logs — see Section 6 and Section 7. The services hosted on Railway (auth, Archive Live Dead, PEPList) are not served by GitHub Pages, but every service loads our shared stylesheet, scripts, and fonts from attentionfeed.com, which is served from there.

3. How We Use Your Data

We use your data for these purposes:

PurposeData UsedLegal Basis (GDPR)
Create and manage your accountEmail, username, display name, password hashContractual necessity
Verify your email addressEmail address, verification tokensContractual necessity
Reset your passwordEmail address, reset tokensContractual necessity
Send you transactional emailsEmail addressContractual necessity
Let you resume playbackPlayback position, session IDLegitimate interest
Recommend concerts you haven’t heardListening history, preferencesLegitimate interest
Generate your podcast RSS feedsPlaylist and episode dataContractual necessity
Prevent abuse and enforce rate limitsIP address (in memory and in server logs)Legitimate interest
Remember your analytics choiceConsent cookie (see Section 4)Legitimate interest
Understand how our services are usedGoogle Analytics dataConsent (where required) / Legitimate interest
Load web fonts and shared page assetsIP address, page URL (sent to GitHub Pages, which hosts attentionfeed.com)Legitimate interest
Load JavaScript librariesIP address, page URL (sent to Cloudflare CDN for Booklist, jsDelivr CDN for Locations)Legitimate interest
Load map dataIP address, page URL (sent to jsDelivr CDN for Locations)Legitimate interest
Stream audio contentIP address, request headers (sent to archive.org by your browser)Contractual necessity
Look up book metadataBook titles, ISBNs (sent to Open Library by your browser)Legitimate interest
Search for podcastsSearch queries (sent to Podcast Index)Contractual necessity
Play podcast episodesIP address, request headers (sent to the podcast’s hosting provider by your browser)Contractual necessity
Serve static pagesIP address, request headers (sent to GitHub Pages for the homepage, Booklist, and Locations)Legitimate interest

What do these legal bases mean? “Contractual necessity” means we need the data to deliver the service you signed up for. “Legitimate interest” means we have a reasonable business reason to process the data, balanced against your privacy — for example, preventing abuse or loading fonts that make the site readable. “Consent” means we ask your permission first.

We use your data to provide, understand the use of and improve the services.


4. Cookies

We use cookies to keep you logged in, to protect your account, and understand your use of the services. Here is what we set:

Essential Cookies (Required for Services to Work)

CookieServicePurposeLifespan
auth_sessionAuth serviceKeeps you logged in24 hours
oauth_paramsAuth serviceTemporary OAuth flow data10 minutes
access_tokenArchive Live DeadYour login session30 days
refresh_tokenArchive Live DeadRefreshes your session30 days
id_tokenArchive Live DeadIdentifies your account30 days
peplist_sessionPEPListYour login session24 hours
peplist_refreshPEPListRefreshes your session30 days
__Host-peplist_csrfPEPListPrevents cross-site attacks30 days
CSRF tokenArchive Live DeadPrevents cross-site attacksSession
OAuth state/nonceAll authenticated servicesSecures the login flow10 minutes
af_consentAll sitesRemembers whether you accepted analytics cookies; shared across attentionfeed.com subdomains1 year

Google Analytics Cookies

Google Analytics sets its own cookies (such as _ga and _gid) on sites where we enable it. These cookies can last up to 2 years. See Section 5 for details and opt-out options.


5. Google Analytics

We use Google Analytics on these services to understand general usage patterns — which pages people visit and how they find our site.

Google Analytics collects:

  • Pages you visit and time spent on each
  • Your browser type and screen size
  • Your approximate location (Google derives this from your IP address)
  • How you reached the site (search engine, direct link, etc.)
  • A pseudonymous cookie identifier to distinguish returning visitors

We never combine this data with personally identifying information, and we do not use Google’s advertising or remarketing features.

Google processes this data under its own privacy policy. For details on how Google handles data from sites that use its services, visit: How Google uses information from sites or apps that use our services

We do not load Google Analytics until you accept analytics cookies in the banner shown when you first visit one of our sites. Your choice is stored in the af_consent cookie, which is shared across all attentionfeed.com subdomains, so you only need to choose once. You can change your choice at any time using the “Cookies” link in the footer of any of our sites. If you decline, we set no analytics cookies and Google receives nothing from your visit.

Opting Out of Google Analytics

You can block Google Analytics by:


6. Third-Party Services

Your use of our services entails the use of some third party services and they also receive data when you use the services.

ServiceWhat We ShareWhyTheir Privacy Policy
Google AnalyticsUsage data via cookies and scripts (includes IP addresses and cookie identifiers)Understand site usageGoogle Privacy
RailwayEverything we store for auth, Archive Live Dead, and PEPList (they run on Railway’s servers and databases), plus application logs that include IP addresses. You are accessing us through Railway so they also see IP address and other standard request information.Host our services and databasesRailway Privacy
ResendRecipient email address, email contentSend verification and password reset emailsResend Privacy
Archive.orgStream URL, IP address and other standard request information (from your browser connecting directly)Stream concert recordingsArchive.org Terms
Open LibraryBook titles, ISBNs, IP address and other standard request information (from your browser connecting directly)Look up author names (Booklist only)Open Library Privacy
Podcast IndexPodcast search queriesDiscover podcasts (PEPList only)Podcast Index
Podcast hosting providersWhen playing podcast episodes in the browser, the browser sends your IP address and other standard request informationStream podcast audio (PEPList only)Varies by publisher
Cloudflare CDNYour IP address and other standard request informationLoad JavaScript libraries (Booklist only)Cloudflare Privacy
jsDelivr CDNYour IP address and other standard request informationLoad JavaScript libraries and map data (Locations only)jsDelivr Privacy
GitHub PagesYour IP address and other standard request informationHost our static pages (homepage, Booklist, and Locations) and the shared stylesheet, scripts, and fonts used by all our servicesGitHub Privacy

7. Data Retention

We keep your data only as long as necessary:

DataHow Long We Keep It
Your account (email, username, display name, password hash)Until you ask us to delete it
Refresh tokens30 days, or until you log out
Playback position (Archive Live Dead)Persists between sessions so you can resume; overwritten by your next listening session; deleted with your account
Listening history (Archive Live Dead)Until you clear it yourself or request account deletion
Preferences (Archive Live Dead)Until you remove them or request account deletion
Playlists and episodes (PEPList)Until you delete them or request account deletion
Google Analytics dataPer Google’s retention settings
IP addressesIn memory for rate limiting until the service restarts; in application logs for as long as Railway keeps them under its log retention policy
Your analytics cookie choice1 year, or until you change it
GitHub Pages request logs (homepage, Booklist, and Locations)Per GitHub’s retention policy

8. Your Rights

You have the following rights over your personal data:

  • Access: You can ask us what data we hold about you.
  • Correction: You can ask us to fix inaccurate data.
  • Deletion: You can delete your data yourself. Log in at auth.attentionfeed.com/account to delete your data from any individual service, or to delete your whole account including your login. PEPList also offers deletion on its data export page. You can also ask us by email.
  • Data Portability: You can request a copy of your data in a standard format. PEPList offers built-in data export (JSON or XML). For Archive Live Dead and your auth account, we handle data export manually upon request.
  • Withdrawal of Consent: Where we rely on your consent (such as for analytics), you can withdraw it at any time — for example, by opting out of Google Analytics.
  • Objection: You can object to processing based on legitimate interest.

To exercise any of these rights that you cannot handle yourself, email us at attnfeed@gmail.com. We will respond within 30 days and may ask you to verify your identity first.

Depending on where you live, you may also have the right to lodge a complaint with your local data protection authority.


9. Data Security

We take numerous steps to attempt to ensure your data security however, no site or service is perfectly secure and AttentionFeed was almost entirely coded by AI agents which make errors. So, please do not give us information that would be damaging to you if public. If you discover a vulnerability, please report it privately to attnfeed@gmail.com.


10. Data Breach Notification

If we discover a security breach that affects your personal data and we have your email address, we will:

  • Notify affected users without undue delay, and where feasible within 72 hours of discovering the breach
  • Describe the breach and the data affected
  • Explain what steps we are taking in response
  • Notify relevant supervisory authorities where required by law

We will send breach notifications to the email address associated with your account.


11. BusWatch

The BusWatch Wear OS app has its own privacy policy, tailored to the app’s data practices and Google Play Store requirements. You can find it within the app and on the Play Store listing.


12. Children’s Privacy

Our services are not directed at children under 13. We do not knowingly collect personal data from children under 13.

Users must be at least 13 years old to create an account, and we ask you to confirm this when you register. In jurisdictions where the minimum age for data processing consent is higher (such as 16 in some EU member states), users must meet that minimum age.


13. International Data Transfers

Our services and databases run on Railway’s servers and our static pages and other information are served by GitHub Pages, each from servers around the world. If you access our services from outside the United States, your data will be transferred to and processed there.


14. Changes to This Policy

We may update this privacy policy from time to time. When we make changes:

  • We will update the effective date at the top of this page.
  • For significant changes to how we handle your data, we will notify you at least 30 days before they take effect — by posting a notice on our homepage or emailing the address on your account.
  • Where we rely on consent as a legal basis and new processing activities require consent, we will obtain your consent before beginning those activities.
  • Continued use of our services after a change takes effect means you accept the update. If you disagree, please stop using the services and request deletion of your account.

All previous versions of this policy are available in the Changelog.


15. Contact Us

For questions about this policy, to exercise your data rights, or to report a security concern, reach us at:

Email: attnfeed@gmail.com

We aim to respond to all inquiries within 30 days.


16. Changelog

DateSummary of Changes
September 7, 2026Initial version