Last updated: 25 August 2026
This policy explains what information howyou.lol (“the Site”) collects, why each item is collected, who processes it, how long it is kept, and how you can review or delete it. It covers the Site itself and the sign-in flow that uses your X (formerly Twitter) account.
Who operates the Site
howyou.lol is operated by an independent individual developer. It is not operated by or on behalf of an incorporated company, and there is no corporate group, parent, subsidiary, or affiliate involved.
The Site is operated by Rohit Kundliwal, resident in India. Written enquiries should be sent to the contact address below rather than by post.
All privacy questions and requests go to contact@longbook.app.
What the Site does
howyou.lol is a public wall of 100 squares. A founder signs in with X, records a laugh of up to five seconds or selects a synthesized laugh instead, optionally uploads an icon for their project, and supplies a project name and project URL. Visitors click a square, hear that founder’s laugh, and are taken to that founder’s project. A square is a public listing, and everything placed on a square is published to anyone who visits the Site.
Information collected
Information received from X when you sign in
Signing in with X releases the following to the Site, and only after you approve the request on X’s own authorization screen:
- Your X handle (username) — identifies your square and links it back to your X profile.
- Your X display name — shown with your square so visitors know whose laugh they are hearing.
- Your X avatar image URL — the address of your existing profile picture, displayed on your square. The image itself stays hosted by X; the Site stores only the URL.
You can withdraw the Site’s access to your X account at any time from the connected-apps settings in your X account. Doing so stops any further data being received from X; it does not by itself delete a square you have already published, which you can delete yourself or ask to have deleted.
Information you provide
- Project name — labels your square.
- Project URL — the destination a visitor is sent to when they click your square.
- Product icon (optional) — an image file you upload, displayed on your square.
- Laugh audio — either a recording of up to five seconds that you make in your browser, or a synthesized laugh you select from the options offered. If you record your own laugh, that recording is a recording of your voice and it is published publicly on the wall. If you would prefer not to publish a recording of your voice, choose a synthesized laugh instead; the Site works the same way either way.
- Chosen laugh type — a record of whether your square uses your own recording or which synthesized option you picked, so the correct audio plays.
Information generated by use of the Site
- A play counter for each square — a single number showing how many times that square’s laugh has been played. It is a total only. It is not linked to visitors, and no visitor identity, account, device profile, or history is recorded when a square is played.
Separately, the hosting and backend providers named below generate ordinary technical logs when a page or file is requested (for example IP address, timestamp, and request path). These logs exist for reliability, security, and abuse prevention, are retained by those providers under their own retention schedules, and are not used to build profiles of visitors, are not combined with square data, and are not shared with anyone.
Information read from your public X profile
The Site runs one server-side function that calls the X API to read the website field on your public X profile — the link X already displays publicly on your profile page. It is used to offer a suggested project URL so you do not have to type it, and the value is stored only if you keep it as your project URL.
That function reads nothing else. It does not read your posts, drafts, direct messages, followers or following lists, likes, bookmarks, lists, or any other part of your account, and it is not used to look up anyone other than the signed-in user.
Why each item is collected
- X handle, display name, avatar URL — to build and display your public square and attribute it to you.
- Project name and project URL — to label your square and to send visitors who click it to your project.
- Uploaded icon — to display your project’s image on your square, if you choose to upload one.
- Laugh audio and chosen laugh type — to play the correct sound when a visitor clicks your square. This is the core function of the Site.
- Play count — to show, publicly, how often a square has been played.
- Public X profile website field — to suggest a project URL during setup.
This information is processed on the basis of the consent you give when you approve the X sign-in and choose to publish a square. You can withdraw that consent at any time by deleting your square or by writing to contact@longbook.app.
Your email address is not collected
The Site does not receive, request, or store your email address. Sign-in with X is configured so that no email address is released to the Site at all, because the Site has no use for one: your square is identified by your X account, and there is no email to send you.
- There is no mailing list, no newsletter, no promotional email, no announcements, and no bulk email of any kind.
- Because no address is held, none can be sold, rented, traded, leaked, or shared.
- If you write to contact@longbook.app, that message and the address you send it from are used only to answer you, and are not added to any list.
What is public and what is not
Public — visible to anyone who visits howyou.lol, with no sign-in required:
- Your X handle
- Your X display name
- Your X avatar image
- Your project name and project URL
- Your uploaded product icon, if you uploaded one
- Your laugh audio, whether recorded or synthesized
- The play count for your square
Not public:
- Your X authentication tokens and session data
Because a square is public, anything on it can be seen, heard, linked to, copied, quoted, or archived by third parties, including search engines and archiving services, while it is published. Deleting your square removes it from the Site but cannot remove copies already made by others.
Service providers
The Site relies on three providers, each acting as a processor of data on the operator’s behalf:
- Supabase — authentication, database, and file storage (Supabase project reference kutuxisaugjefagdvfac). Supabase holds the account record, the square’s database row, and the stored laugh audio and uploaded icon files.
- Netlify — hosting and delivery of the Site and of the single server-side function described above.
- X — the sign-in provider, and the source of the public profile website lookup. Your use of X and the information X holds about you are governed by X’s own privacy policy and terms.
No other third party receives your information. Information may also be disclosed if required by valid legal process, or where necessary to investigate abuse of the Site or to protect the rights or safety of users; if that happens, no more is disclosed than is required.
Cookies and local storage
When you sign in, an authentication session is stored in your browser by Supabase so that you stay signed in and can edit your own square. That is the only purpose for which browser storage is used.
The Site sets no advertising cookies, no analytics cookies, and no cross-site or third-party tracking cookies. Visitors who do not sign in are not given a persistent identifier.
No analytics, advertising, or sale of data
The Site uses no analytics platform, no tracking pixels, no fingerprinting, no session recording, no advertising, and no advertising networks. No information collected by the Site is sold, rented, or otherwise made available to data brokers, marketers, or any other third party, and none of it is used to train or fine-tune machine learning models.
Data retention
Your square and the information that makes it up are kept for as long as your square is published. They are deleted when you delete your square, or when you ask for deletion at contact@longbook.app.
After deletion, residual copies may persist for a limited period in the routine backups taken by Supabase and Netlify before those backups expire and are overwritten on those providers’ ordinary schedules. Backups are not used to restore deleted squares. Technical server logs are retained by those providers under their own retention periods.
Deleting your square
You can delete your square yourself from the Site while signed in. Deleting a square:
- deletes the database row holding your X handle, display name, avatar URL, project name, project URL, chosen laugh type, and play count;
- deletes the stored laugh audio file; and
- deletes the uploaded icon image file.
To also delete the underlying account record held by the authentication system, email contact@longbook.app from the X account in question, or send the request from the X account itself, and ask for account deletion. You may additionally revoke the Site’s access from the connected-apps settings in your X account.
Your rights
Whatever your location, you may:
- ask what information about you is held, and receive a copy of it;
- correct anything inaccurate;
- delete your square, and request deletion of your account record;
- withdraw the consent on which this processing rests, by deleting your square and revoking the Site’s access in your X settings.
To exercise any of these, email contact@longbook.app. Requests are normally answered within 30 days. Because no email address is held for your account, a request is verified either by an action taken while signed in to the account, or by a direct message from the X account that owns the square; requests that cannot be matched to an account may be declined. There is no charge for making a request, and making one has no effect on your square.
Security
The Site is served over HTTPS, and account data and stored files are held in Supabase under access controls that restrict each signed-in user to their own record. Administrative access is limited to the operator. No method of transmission over the internet or of electronic storage is completely secure, and no absolute guarantee of security can be given.
Children
The Site is not directed to children. You must be at least 13 years old to use it, consistent with the minimum age required to hold an X account, and older if the law where you live sets a higher minimum for consenting to this kind of service. Information is not knowingly collected from anyone under 13. If it comes to the operator’s attention that a square belongs to someone under 13, the square and the associated account record will be deleted. Anyone who believes a child has published a square should write to contact@longbook.app.
International transfers
The providers named above operate infrastructure in a number of countries, and your information may be stored or processed in a country other than the one you live in, including the United States. Where that happens, the information continues to be handled as described in this policy.
Changes to this policy
This policy may be updated if the Site changes. The revised version is posted on this page with a new “Last updated” date. If a change materially affects how existing information is used, notice will be given on the Site before the change takes effect.
Contact
For any question about this policy, for a copy of your information, or to request deletion, email contact@longbook.app.