Privacy Policy

Not yet in effect — this draft takes effect on the date counsel approves it.

Long Live has no accounts, no logins, no passwords, and no payments, and it never asks you for your name or email. Three features do send something: the feedback button sends what you type to our private issue tracker; the mood chat sends what you type to an AI service so it can read the feeling; and Clownbot sends your questions to an AI service to answer them, and — only once an identity system described below is switched on — remembers the conversation in our database for up to 180 days. Everything else on this page is detail.

Who we are

Long Live (https://www.longlivets.com) is an independent, unofficial fan project about Taylor Swift's career. It is operated by JW Labs LLC. It is not affiliated with, endorsed by, sponsored by, or connected to Taylor Swift, her management, her record labels, or her publishers.

Questions about this policy, or a request about your information, go to privacy@longlivets.com.

There are no accounts

You browse Long Live anonymously. There is no sign-up, no sign-in, no profile, no password, no payment, and no newsletter. We never ask for your name, email address, phone number, postal address, date of birth, photos, contacts, or precise location, and there is no way to give them to us through a form.

Because there is no account, there is also no account to delete. The only information we ever hold that could be traced back to you is whatever you choose to type into the feedback box, or — if its memory feature is switched on — into Clownbot. See below for both.

The feedback button

Every page carries a feedback button. If you open it and send a message, we receive what you typed plus a small amount of context describing where in the site you were when you sent it. Sending is entirely optional — the button does nothing until you press send.

What a feedback submission contains
WhatWhy
The message you typed (up to 5,000 characters)It is the feedback.
Where you were in the site: the era, view, and the ids of any open moment, song, guide, or threadSo a report about "this page" can be traced to an actual page.
The page address (URL) and page title at the moment you sent itSame reason — it is the most reliable pointer to what you were looking at.
Your browser window size and your browser's user-agent string (browser and operating system name and version)Layout and rendering bugs are usually specific to a browser or a screen size.
The date and time you sent itOrdering and triage.

A submission is filed as a ticket in our private source-code repository on GitHub. That repository is private: it is readable by the project's founders, by the automated agents that triage tickets, and by GitHub as the service provider. It is not published, and feedback is not displayed anywhere on this site.

Please do not type anything into the feedback box that you would not want kept — it is a free-text field, so it will faithfully record a name, an email address, or anything else you put in it. We do not ask you for any of that and we do not need it to act on a bug report.

Retention: a feedback ticket stays in that tracker indefinitely unless it is deleted. There is no automatic expiry today.

Your IP address is read when you send feedback, purely to enforce a short-term rate limit (a few submissions per minute) that keeps automated abuse off the endpoint. It is held in memory for about a minute, is not written into the ticket, and is not stored anywhere by us.

The mood chat

The mood feature recommends songs from how you say you are feeling. You can use it two ways: by tapping one of the preset mood chips, which sends no text at all, or by typing in your own words.

If you type your own words, that text is sent to our server and, from there, to Anthropic's Claude API, whose only job is to score the feeling on eight numeric mood axes. The AI model is never given our song catalogue and never chooses a song; the actual song matching is ordinary code running on our server against the numbers it returns.

We do not store what you type. Our server keeps a log line recording only the resulting numeric mood scores and which song slugs were returned — never your words. If the message trips our crisis check, the feature responds with support resources instead of songs, does not call the AI service, and logs nothing at all.

Anthropic processes the text as a service provider under its own commercial terms and privacy policy, which govern how long it retains an API request. As with feedback, your IP address is read only to rate-limit the endpoint and is not stored.

People sometimes describe genuinely painful things to a feature like this. That is exactly why we do not keep the text. Please still treat it as you would any message typed into a website: send it thoughtfully.

Clownbot

Clownbot is a chat assistant, separate from the mood chat above, that answers questions about the site's content. Every question you send it — plus the recent turns of that conversation, so it has context — is sent to our server and, from there, to Anthropic's Claude API to generate the answer. Your IP address is read only to enforce a short-term rate limit (at most 15 messages per minute) and is not stored.

Unlike the mood chat, Clownbot's server can remember a conversation across visits, using an anonymous identity system built on Supabase (the same third party named in the table below). That system requires a setting ("allow anonymous sign-ins") to be switched on in a dashboard outside this codebase, and as of this policy's effective date it has not been switched on — while it is off, nothing else in this section happens: no cookie is set, no message is stored, and Clownbot answers from the current conversation only. We are describing the capability here, as it is built into our code, rather than only its moment-to-moment on/off state, because that switch can be flipped without a new release of the site and we do not want this page to fall out of date the moment it is.

Once that identity system is switched on: sending Clownbot a message assigns your browser an anonymous id — no name, email, or other identifying detail, just a randomly generated identifier — held in a first-party cookie scoped to the chat feature, marked so it cannot be read by page scripts and only sent over HTTPS, and set to expire after 180 days. Every message you send and every reply Clownbot gives is then stored against that anonymous id in our Supabase database for up to 180 days since the conversation was last used. Once a stored conversation passes 20 messages, the oldest ones are folded into a short running summary (capped at a few thousand characters) and deleted individually; the summary and the most recent messages are what persists. There is also a limit of 200 messages per day per anonymous id, to control cost and abuse.

Because the identity behind a stored Clownbot conversation is anonymous, we generally have no way to match an email from you to a specific one, so we cannot offer the same manual delete-on-request process described for feedback below. A stored conversation is deleted automatically once it has gone unused for 180 days. Clearing your browser's cookies for this site starts you on a fresh anonymous identity going forward, but does not reach back and delete rows already stored under the old one — those still expire on their own schedule. If you have a concern about a specific conversation, write to us anyway; we will do what we can.

As with the mood chat, please treat Clownbot as you would any message typed into a website: it is processed by us and by Anthropic, and, once the memory system above is active, may be held for a period of time.

Analytics

We use Vercel Web Analytics to count visits and see which parts of the site people actually use. It runs on every page.

It does not set cookies, does not assign you a persistent identifier, and does not follow you to other websites. What it records is aggregate: page views, the referring site, the device type, the browser and operating system, and the country the request came from. We cannot use it to identify you, and we do not try to.

We run no advertising, no advertising or marketing pixels, no cross-site trackers, and no session-replay tools. We do not sell or share personal information, and we do not engage in targeted advertising or profiling.

What stays on your device

The site sets no cookies of its own, except the one described in the Clownbot section above, and only once that feature's memory system is switched on. It does keep two small entries in your browser's local storage, which never leave your device and are never sent to us or to anyone else:

  • A record of what you have explored — the moments you have opened, the Easter eggs you have read, the clue trails you have started, and anything you have favourited — so your progress and favourites are still there when you come back.
  • A flag remembering that you have already seen the timeline-scrubber hint, so it is not shown to you twice.

Clearing your browser's site data for this site erases both, which resets your progress and your favourites. Nothing else is affected, because we hold no copy.

Third parties involved in running the site

Loading a page or using a feature means your browser or our server talks to the following services. Each has its own privacy policy, which governs what it does with what it receives.

Third-party services and what reaches them
ServiceRoleWhat reaches it
VercelHosting and analyticsEvery request to the site, including your IP address, in ordinary server logs; plus the anonymous analytics events described above.
SupabaseContent database; Clownbot anonymous identity and conversation storageMost site content is baked in when the site is built, not fetched while you browse — one illustrative image, and a pair of machine-readable content endpoints the site itself does not call, are the only content paths that reach it. Separately, and only once the anonymous-identity system described in the Clownbot section is switched on, your Clownbot messages, replies, and anonymous id are stored here for up to 180 days.
GitHubWhere feedback tickets are storedOnly what a feedback submission contains, and only if you send one.
Anthropic (Claude API)Reads the feeling in mood-chat text; answers Clownbot questionsThe text you type into the mood chat, only if you type instead of tapping a preset chip; and every message (plus recent conversation turns) you send to Clownbot.
YouTube (via the privacy-enhanced youtube-nocookie.com domain)Music-video playbackA thumbnail image while you browse. The player itself only loads when you press play — and on YouTube's privacy-enhanced domain, which does not set tracking cookies before playback.
SpotifyAlbum playbackOn most pages, nothing until you press play. On the "Taylor's Version" comparison, two Spotify players load with the page. Once a player loads, Spotify sees your IP address and may set its own cookies.
Instagram (Meta)Embedded postsWhere a moment quotes an Instagram post, the post is embedded and loads with the page rather than on a click. That means Meta sees your IP address, your browser, and the page you were on, and may set its own cookies, without you doing anything.
Image hosts — around a hundred of them (Wikimedia, news publishers, photo agencies, their CDNs)Photographs illustrating the contentMost photographs load directly from the site that published them rather than being copied to our servers. Loading one tells that host your IP address, your browser, and that you were on a Long Live page.

Fonts are served from our own domain — they are bundled into the site when it is built, so no request goes to a font provider while you browse. Links out to news articles and sources are ordinary links; following one takes you to a site with its own policy.

We set one first-party cookie of our own — the anonymous Clownbot session id described in the Clownbot section above — and only once that feature's memory system is switched on; while it is off, we set none. Spotify, YouTube and Instagram may set their own cookies once one of their embeds loads, and we have no control over those — your browser settings do. Blocking third-party cookies, or using a content blocker, does not stop you reading the site.

The mobile app

This policy describes the Long Live website. A companion mobile app exists in development but has not been released in any app store. If and when it is, its data handling will be described here — or in its own policy — before it ships, and its store data-safety disclosures will be made to match.

Before this app is submitted to either app store, its data-safety disclosures will be re-verified against the website's current data handling described above and updated to match.

Server logs

Like any website, the infrastructure serving Long Live keeps short-lived operational logs — IP address, time, request path, user agent — for security, abuse prevention, and reliability. These are our hosting provider's standard logs, kept under its retention policy. We do not use them to build a profile of you and we do not combine them with anything else.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or restrict the use of personal information about you, to object to processing, to receive a copy in a portable form, and to complain to your data-protection regulator. Californian residents additionally have rights of access, deletion, correction, and to opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of.

In practice we hold almost nothing that could be tied to you. The realistic case is a feedback ticket you sent. Write to privacy@longlivets.com — quote roughly when you sent it and what it was about — and we will find it and delete it. A Clownbot conversation, once its memory system is switched on, works differently: see the Clownbot section above for why we generally cannot match a request to a specific one, and how it expires on its own instead. We will not retaliate against you for exercising any of these rights.

To erase what is stored on your device, clear this site's data in your browser.

Children

Long Live is a general-audience site and is not directed to children under 13. We do not knowingly collect personal information from children under 13, we have no accounts, and we ask for no personal details anywhere on the site.

If you believe a child has sent us personal information through the feedback box, write to privacy@longlivets.com and we will delete it.

We have determined, with counsel, that Long Live is not "directed to children" under COPPA.

Where your information goes

Our hosting, our issue tracker, our content and Clownbot database, and the AI service used by the mood chat and Clownbot are all operated by companies based in the United States, and information sent to them may be processed there and in other countries. Each provides its own safeguards for international transfers under its terms.

Security

The site is served over HTTPS. Feedback tickets sit in a private repository behind the founders' accounts. The honest framing is that our best protection is holding almost nothing: there is no account database, no password store, and no payment data to lose.

Changes to this policy

If a feature ever starts collecting something new, we update this page in the same change that ships the feature — that rule is written into the source file this page is generated from, so it is a build-time habit rather than a good intention. The effective date at the top of the page tells you when the current version took effect.