Privacy Policy
Last updated 30 July 2026
This policy explains what Swiftieverse collects, why, who it reaches, and how long it is kept. It is written to describe what the software actually does.
1. What we collect
Account: your email address, a salted hash of your password (never the password itself), your role, and whether your email is verified.
Profile: your handle, display name, bio, any links you add, and your avatar image if you upload one. All of this is public.
Activity: your song rankings and scores, lists, posts, comments, likes, follows, invite links you create, and who joined through them. Published rankings, lists, posts, and comments are public.
Spotify, only if you connect it: your Spotify user id, OAuth tokens encrypted at rest, and any playlists you choose to showcase. If you additionally opt into play tracking, we store per-track play counts for Taylor Swift catalogue songs — how many times, total listening time, and when you last played each one. Listening to anything outside that catalogue is read and discarded, never stored.
Spotify data exports, only if you upload one: the file is stored temporarily so it can be processed, then deleted once counting finishes. We keep the filename, the number of entries it contained, and the resulting catalogue play counts.
2. IP addresses and analytics
We do not retain your IP address or user agent in any durable record. Both are used transiently: they are combined into a keyed hash for rate limiting, and your IP is sent to Cloudflare Turnstile so it can tell humans from bots. Neither value is written to our database in raw form.
Visit counting is first-party. Anonymous visitors are represented by a hash that includes a per-day salt, so it cannot be reversed to an IP or user agent and cannot be linked across days. Signed-in visits are recorded against your account. Analytics records are deleted after 90 days.
Our hosting provider, Cloudflare, keeps its own operational logs of requests as part of running the service. Those are outside our control and subject to Cloudflare's retention.
3. Cookies
A session cookie keeps you signed in. It is HttpOnly, restricted to this site, and holds only an opaque identifier.
If you arrive through someone's invite link, a short-lived cookie remembers who invited you until you finish signing up.
We do not use advertising or cross-site tracking cookies.
4. Third parties your browser contacts
Cloudflare hosts the site, provides the Turnstile anti-bot widget on the signup, login, and password-reset pages, and delivers our transactional email. Turnstile receives your IP address and performs browser checks to distinguish humans from automated traffic.
Cloudflare also measures page performance — load times and similar readings from your browser's own timing API — so we can monitor site health. That script sets no cookies, reads no browser storage, builds no profile of you, and reports back to this domain rather than to a third party.
Typefaces are served from this site rather than from Google Fonts, so loading a page does not send your IP address to Google.
Spotify embeds appear on public profiles, song pages, and list pages. Loading one sends your IP address to Spotify, and if you are signed in to Spotify in the same browser it may recognise you.
YouTube embeds may appear in the community feed on official news posts. We use YouTube's no-cookie player, but your IP address still reaches Google when one loads.
We do not sell your personal data, and we do not share it with advertisers.
5. How long we keep things
Analytics records: 90 days.
Email verification and password reset tokens: they expire within 24 hours and 1 hour respectively, and are removed shortly after.
Uploaded Spotify export files: deleted as soon as they have been processed.
Everything else — your account, profile, rankings, lists, posts, and comments — is kept until you ask us to delete it.
6. Your choices and rights
You can edit your profile, delete your own posts, comments, and lists, disconnect Spotify at any time (which deletes your stored tokens, showcased playlists, and play counts), and clear your play counts separately without disconnecting.
You can ask us for a copy of your data, ask us to correct it, or ask us to delete your account and associated data. Email privacy@taylorswiftsongranking.com from the address on the account and we will act on it within 30 days. Self-service deletion is not built yet — until it is, this is the route.
Depending on where you live you may have additional rights, including under the UK and EU GDPR or the CCPA. We will honour those requests through the same contact address.
7. Security
Passwords are hashed with PBKDF2-HMAC-SHA256 and a per-account salt. Spotify tokens are encrypted at rest. Email verification and password reset tokens are stored only as hashes. Traffic is served over HTTPS.
No service can promise perfect security. If we become aware of a breach affecting your data, we will notify you and any regulator as required by law.
8. Children
Swiftieverse is not intended for children under 13, or under the higher minimum age that applies where you live. We do not knowingly collect data from them, and we will delete such an account if we learn of it.
9. Changes
If this policy changes materially we will update the date at the top and make reasonable efforts to tell you.
10. Contact
Privacy questions and data requests: privacy@taylorswiftsongranking.com.