Privacy Policy
Version 2026-09-07 · applies from [PUBLICATION DATE]
Draft. This has not been through the legal review SPEC-08 §12.4 requires, and the values in [SQUARE BRACKETS] are decisions the operator has still to make. They are left visible on purpose: a blank would read as an answer.
What the operator still has to decide
Decisions the operator must make before publishing
Every placeholder in this document, in one list. Publishing with any of these still in brackets would be worse than not publishing at all.
| Placeholder | What it needs |
|---|---|
| [PRIVACY CONTACT EMAIL] | The address privacy requests go to. Can be the same inbox as copyright@thespiary.com, but say so. |
| [OPERATOR NAME / LOCATION] | Who runs Thespiary and in what country. This decides which data-protection law applies. |
| [PUBLICATION DATE] | The date this version goes live. |
| [EMAIL PROVIDER] | The configured EMAIL_PROVIDER. Console/SMTP/Resend/Postmark are all supported; name the real one and link its privacy page. |
| [OCR PROVIDER] | The configured OCR_PROVIDER. Naming this matters more than anything else on this list: uploaded playbill images are sent to it in full. |
| [HOSTING PROVIDER / REGION] | Where the server and its disks physically are. |
| [BACKUP RETENTION] | The real value of BACKUP_RETENTION_DAYS in production. The scripts default to 14 days. |
| [SERVER LOG RETENTION] | How long container logs are kept. Today they rotate by size, not age - 3 files of 10 MB per service - so the answer is "it depends on traffic" unless the operator changes it. |
| [MINIMUM AGE] | Default 13, per SPEC-08 section 11.4. Raise it to 16 if the operator's jurisdiction requires it. |
| [SUPERVISORY AUTHORITY] | The data-protection authority a user can complain to. Follows from [OPERATOR NAME / LOCATION]. SPEC-08 section 12.4 asks for this to be settled before launch. |
Two further decisions have no placeholder because they are questions, not blanks:
- Whether to publish at all yet. Several things this policy would ideally promise are not built. They are marked "not yet" below rather than promised. The operator should be comfortable publishing a policy that says "not yet" in those places.
- Whether a DPO is required, and which DPAs are in place with the email, OCR and hosting providers. SPEC-08 section 12.4 requires this assessment before public launch. It has not been done.
The short version
- Thespiary is a hobby project run by one person. It does not sell your data, show you ads, or track you across the web.
- Your attendance log, your ratings, your reviews and your notes are private by default. You choose, per entry, what becomes public.
- Facts you contribute to the shared archive - shows, productions, who performed in what - are public and stay public, without your name on them.
- Playbill scans you upload are yours alone. Nobody else on Thespiary can see them, and they are never published.
- We send your uploaded playbill images to an outside service to read the credits out of them. That is the one place your uploads leave our server.
- You can export everything we hold, and you can delete your account.
1. Who we are
Thespiary is operated by [OPERATOR NAME / LOCATION]. There is no company, no staff, and no third-party analytics. For anything in this policy, write to [PRIVACY CONTACT EMAIL].
2. What we collect, and why
We collect what a feature needs and nothing else. Where a field is optional, it is genuinely optional - leaving it blank does not break anything.
2.1 Your account
| What | Why | Required? |
|---|---|---|
| Your email address | To sign you in. There are no passwords, so the link we email you is the way in. | Yes |
| Display name | So other people can see who wrote a public review. | Yes |
| Bio, city, country | Shown on your profile; the city is used to suggest things near you. | No |
| Language and time zone | To show dates and times the way you would expect. | No |
| Preferred production types | To tune what Discover shows you. | No |
| Avatar image | Your profile picture. | No |
| Privacy defaults | The visibility settings applied to new log entries. | Set by you |
| Explicit-content opt-in, and the date you confirmed your age | To keep explicit material out of your view unless you ask for it. | No |
| Your role, and supporter status if you have it | To decide what you can do on the site. | Set by us |
| When you agreed to this policy, when you last used the site, and whether you have asked for an export or a deletion | To honour those requests, and to know whether you have seen the current policy. | Set by us |
Your email address is encrypted at rest. We store it as ciphertext, plus a one-way keyed hash used to find your account when you sign in. The hash cannot be turned back into your address.
2.2 What you log
When you record a performance you attended, we store what you tell us: which performance, and optionally your seat, what you paid, private notes, a star rating, a review, tags, a spoiler flag, and who you went with.
Companions can be tagged as other Thespiary users, or just typed in as a name - in which case that name is personal data about someone who is not our user, so please be considerate about what you type.
We also keep previous versions of your reviews, so that a review edited after someone complained about it can still be looked at by a moderator.
Your wishlist - what you want to see, its priority, notes, an optional reminder date - is stored the same way, and is private.
2.3 Playbills you upload
We store the image files, their size and dimensions, and the raw text the extraction step produced from them.
We strip metadata from every image on upload. Photos often carry the GPS coordinates and camera details of where they were taken. We re-encode the image without any of it before storing it, so that data never reaches our disk or the extraction service.
2.4 Notifications
We keep the notifications we have sent you, whether you have read them, and your per-event preferences for in-app and email delivery.
2.5 Signing in
- Sessions. When you sign in we store a one-way hash of your session token - never the token itself - with the times it was created, last used, and expires.
- Sign-in links. A hash of the link token, which email it was for, and when it expires or was used.
- Email changes. The new address (encrypted) and the hashes of the confirmation tokens, until the change completes or lapses.
- External sign-in, if you are a moderator or admin who signs in through an identity provider: which provider, your subject identifier there, and when you last used it.
The database has columns for a hashed IP address and browser fingerprint on each session. They are never filled in. No code writes them.
2.6 API keys
If you register for an API key we store a one-way hash of your email address - not the address itself - a hash of the key, its first few characters, and the description of what you plan to use it for.
A practical consequence: we cannot email you. We do not hold your address in a form we can read. Watch the changelog rather than your inbox.
2.7 Technical data
- Your IP address is used to count requests. Sign-in requests and API-key registrations are throttled per IP per hour. The counter lives in a cache with a short expiry and is not written to the database.
- The web server writes an access log line per request containing the IP it saw, the method, the path and the status. Application logs deliberately do not include raw paths, request bodies, or headers.
These logs rotate by size, not by age: [SERVER LOG RETENTION].
2.8 What we do not collect
No advertising identifiers. No third-party analytics. No tracking pixels in our emails. No cross-site tracking. No behavioural profiling. No location beyond the city you type in yourself.
Your city is used for discovery and nothing else. It is not returned by the public API and does not appear in data dumps.
3. Who can see it
3.1 Your log is private by default
Every visibility setting on a new entry starts at private.
You can set your attendance, your rating and your review each to one of three levels: private, friends, or public.
- Private - only you.
- Friends - you and people you are mutually connected to.
- Public - anyone on the internet, signed in or not.
3.2 What "public" actually exposes
If you mark a review public, it appears on that production's page to anyone, with your display name, the venue, and the date and time of the performance you attended. Your star rating appears alongside it only if you also marked the rating public.
Be aware of what that implies: a public review tells people you were in a particular building on a particular evening.
Public star ratings are also counted into a production's average score, which is only shown once at least five people have rated it.
3.3 What is never shown to anyone else
Your seat, what you paid, your private notes, your companions and your wishlist are not served to any other user by any part of the site today. They appear only in your own view and in your data export.
Your playbill scans are served only to you, by an endpoint that checks you own the file before it hands it over.
3.4 Moderators and the operator
Moderators can see content that has been reported, and previous versions of a review that was edited. The operator, as the person who runs the server, can technically reach anything in the database - that is inherent in self-hosting, and we would rather say so than imply otherwise.
Moderation records identify you by a stable pseudonym rather than your user ID, so that when your account is deleted the record can survive without pointing at you.
3.5 The public API and open data
Anyone can register a free API key and read the shared archive. There is also a public data dump that needs no key at all.
Neither contains any of your personal data. The dump is built from seven tables: shows, productions, venues, performances, persons, cast credits and crew credits.
- Your attendance and your reviews are never in a dump, at any visibility setting, and are not reachable through the public API.
- Credits you contribute are - that is the point of the archive - but without your name. Contributor attribution is stored internally and is not published.
- Playbill images, the raw extraction output, and storage keys are never in a dump.
- A performer whose profile is hidden is excluded from dumps and from the API entirely, as though they did not exist.
See the open data licence notice on the terms page.
4. Who else handles your data
We use as few outside services as we can. Each one gets only what it needs.
| Who | What they get | Why |
|---|---|---|
| Email delivery - currently [EMAIL PROVIDER] | Your email address and the text of the message. | To deliver sign-in links, security notices, and the notifications you asked for. |
| Text extraction - currently [OCR PROVIDER] | The full playbill images you upload, with metadata already stripped. | To read the cast and crew list out of them. |
| Hosting - [HOSTING PROVIDER / REGION] | Everything, as the machine the database and files sit on. | To run the site. |
On the extraction step, specifically: your images are sent to that provider over the network. If the operator has configured a local model, they never leave the machine - but you should assume they do unless the table above names a local one.
We do not sell, rent, or share your personal data with anyone else. The only other circumstance in which we would hand it over is a legal obligation we cannot refuse.
5. How long we keep it
| Data | Kept for |
|---|---|
| Your account and everything in it | As long as your account exists |
| Sign-in links | 15 minutes, and they die the moment they are used |
| Email-change confirmations | 24 hours |
| A session, if you stop using it | 14 days idle, and 30 days maximum however active you are. Moderators: 3 and 7 days. Admins: 12 and 24 hours. |
| A data-export download link | 7 days, single use |
| A deleted account | 30 days, then permanently erased |
| Backups | [BACKUP RETENTION] - see section 9 |
| Previous versions of your reviews | See below |
| Notifications | See below |
Two honest caveats. Both concern retention limits that were designed but are not yet enforced by any scheduled job. We would rather tell you than let you assume.
- Previous versions of your reviews are marked for clearing one year after they are written, but no job currently does the clearing. In practice they last until your account is deleted, at which point they go with it.
- Notifications are likewise designed to be archived after 90 days and deleted after a year, and that job does not exist yet either. They last until your account is deleted.
Everything in both categories is destroyed by account deletion, which does work.
6. Your rights
6.1 Get a copy of everything
Ask for an export from your account settings. We build a ZIP with an HTML file you can open in a browser and a JSON file for machines, then email you a download link. The link works once and expires after 7 days.
The export contains your account details (including your email address in readable form), your full attendance history with notes and companions, your wishlist, who you follow, everything you have contributed to the archive, your notifications and preferences, and a log of your sessions and linked sign-in providers.
It does not contain other people's data, or the moderation records held about you. Those are internal records.
6.2 Delete your account
Ask from your account settings. Immediately: your profile and content are hidden and you cannot use the site. After 30 days, everything is erased for good. Within those 30 days you can sign in - but only onto a screen that lets you cancel the deletion and nothing else.
When the 30 days are up we hard-delete your account, your entire log, your reviews and their history, your wishlist, your follows and blocks, your notifications, your playbills, and the image files themselves off the disk.
Two things survive, by design:
- Facts you contributed to the archive - the shows, productions, venues, people and credits - stay, because other people's records depend on them. Your name is removed from them: the "contributed by" link is set to nothing.
- Discussion posts stay in place so threads still make sense, but the text is replaced with "[Deleted]" and the author with nobody.
Moderation records about you are kept, under the pseudonym described in 3.4, with your identity and any state snapshots stripped out.
Not yet built: there is no button for immediate deletion that skips the 30-day wait. SPEC-08 section 9.2 says one should exist. If you need it, write to [PRIVACY CONTACT EMAIL] and the operator will do it by hand.
You can also delete a single playbill without closing your account, from "My uploads" on the upload page. The scan and the text extracted from it are removed for good. Credits you already submitted from it stay in the shared archive, for the reason given above, with the link back to the scan cleared.
6.3 Correct something that is wrong
You can change your email address yourself, and it is deliberately awkward: we confirm with your old address first, and only then send a link to the new one. Both addresses are told when it completes.
Your display name, bio and city are yours to change whenever you like, from the Profile section of your account settings. Nothing is reviewed and nothing waits: the change is live as soon as you save it.
Your country is the one profile field with no screen behind it. Write to [PRIVACY CONTACT EMAIL] and the operator will set or clear it for you.
If you think a moderation decision about you is wrong, appeal it - see the terms.
6.4 Ask us to pause, or object
You can ask us to stop processing your data while a dispute is being worked out, and you can object to us keeping moderation records about you on legitimate-interest grounds. Both are handled by hand, by the operator, at [PRIVACY CONTACT EMAIL]. There is no automated flow, and given the size of this project there is not likely to be one.
6.5 Complain
If you are unhappy with how we have handled your data you can complain to [SUPERVISORY AUTHORITY]. You do not have to raise it with us first, though we would rather you did.
7. Cookies
We use three cookies and they are all strictly necessary:
- your session, so you stay signed in;
- a CSRF token, so a malicious site cannot act as you;
- during an external sign-in, a short-lived cookie holding the state of that sign-in.
There are no advertising cookies, no analytics cookies, and no third-party scripts. That is why you are not being asked to click a cookie banner: there is nothing optional to consent to.
If that ever changes, we will ask before setting anything non-essential.
8. Children
Thespiary is not for people under [MINIMUM AGE]. We do not knowingly collect their data. There is no age gate at signup - the terms simply say so - and if we find out an account belongs to someone under that age, we delete it and purge the data the same way as any other deletion.
9. Backups can hold data we have erased
Backups exist so that a disk failure does not destroy the archive. They are snapshots of the database and the uploaded files at a point in time, and a snapshot taken before you deleted your account still has your data in it.
We do not reach into old backups to remove one person's records - doing so reliably is not realistic, and a partly-rewritten backup is not a backup. Your data therefore persists in them until they age out: [BACKUP RETENTION].
If we ever have to restore from a backup, we replay the record of completed erasures over the restored database before it is allowed to serve anyone. A deletion you asked for does not come back to life because of a restore.
10. Published data dumps cannot be recalled
Once a dated data dump is downloaded by someone, it exists on their computer and we have no way to change it.
- Deleting your account removes your contributions' attribution from all future dumps.
- A performer who hides their profile disappears from all future dumps immediately.
- Dumps we published in the past stay as they were published, wherever copies of them have gone.
Since dumps never contain attendance, reviews, or the names of contributors, what is at stake here is the archive's factual records - not your personal log. We disclose it anyway, because it is a genuine limit on erasure.
11. How we protect it
- HTTPS everywhere, with HSTS.
- No passwords exist to be stolen, from us or from you.
- Your email address is encrypted in the database; session, sign-in and download tokens are stored only as one-way hashes; API keys the same.
- Sessions expire on their own, and can be revoked instantly.
- A strict Content-Security-Policy that permits no inline or third-party scripts.
- Uploaded images are re-encoded before storage, which strips metadata and defuses malformed files.
- The application runs against the database with reduced privileges; it cannot alter the moderation audit log.
No system is perfectly secure, and this one is maintained by one person in their spare time. We are telling you what we do, not promising it is enough.
12. If something goes wrong
If we discover a breach affecting personal data we will tell affected users within 72 hours of finding out, by email and in-app notification. We will say what happened, what data was involved, what we are doing, and what you should do. We will notify [SUPERVISORY AUTHORITY] where the law requires it, and disclose publicly if a lot of people are affected.
13. Changes to this policy
This policy is versioned. The current version is at the top of this page.
If we change something material - how your data is used, who it is shared with, or how long it is kept - we will ask you to agree again before you carry on using Thespiary. The first thing the site does after the new version goes live is put a short screen in front of you, with links to the current policy and terms and a box to tick. Accepting takes you straight back to what you were doing.
Until you accept, ordinary use of the site pauses - but your account does not. Your account settings, an email change, a data export and account deletion all keep working, so you are never trapped by a policy you have not agreed to.
Two things SPEC-08 section 12.2 asks for that are not built. We would rather tell you than let you assume. There is no email or in-app notice when the version changes - the screen is the whole of the notice you get. And there is no 30-day window after which an account that has not re-agreed is deactivated; an account that never accepts simply stays in that state, usable for the account tasks above and nothing else.
Fixing a typo or making a sentence clearer is not material and will not interrupt you.
14. Contact
Privacy questions, export or deletion requests, corrections, objections: [PRIVACY CONTACT EMAIL]
Copyright and takedown requests go to a different address - see the copyright and takedown policy.
Thespiary is run by an individual. A postal address is available on request where one is genuinely needed.