Terms of Service
Version 2026-09-07 · applies from [PUBLICATION DATE]
Draft. This has not been through the legal review SPEC-08 §12.4 requires, and the values in [SQUARE BRACKETS] are decisions the operator has still to make. They are left visible on purpose: a blank would read as an answer.
What the operator still has to decide
Decisions the operator must make before publishing
| Placeholder | What it needs |
|---|---|
| [OPERATOR NAME / LOCATION] | Who is offering these terms, and from where. |
| [PUBLICATION DATE] | The date this version goes live. |
| [SUPPORT CONTACT EMAIL] | Where account and moderation questions go. |
| [PRIVACY CONTACT EMAIL] | Same address as the privacy policy uses. |
| [COPYRIGHT CONTACT EMAIL] | Currently copyright@thespiary.com on the live copyright page - keep them the same. |
| [MINIMUM AGE] | 13 by default, per SPEC-08 section 11.4. Must match the privacy policy. |
| [GOVERNING LAW / VENUE] | Which country's law applies, and where disputes are heard. Follows from [OPERATOR NAME / LOCATION]. |
| [SITE URL] | The canonical public URL, used in the attribution string. https://thespiary.com is what the specs assume. |
Judgement calls for the operator, not blanks to fill:
- Whether to require a contributor licence grant explicitly at signup. Section 4 below states it in the terms. Consenting to the terms is the only place it is captured; there is no separate per-contribution licence checkbox. That is normal for a wiki-style archive, but it is the operator's call.
- Whether "one account" is a rule you want to enforce. The code enforces one account per email address, not one per person. Section 3 is written to match the code.
- The disclaimer strength in section 10. Written for a hobby project run by an individual. Some jurisdictions will not enforce parts of it against consumers; that is what the legal review is for.
For the open data licence notice below
| Placeholder | What it needs |
|---|---|
| [SITE URL] | The canonical public URL used in the attribution string. The specs assume https://thespiary.com. Whatever is chosen must then be used verbatim, forever - it is baked into every downstream attribution. |
| [DUMP URL] | Where the dump is fetched from. Today that is the API host plus /v1/open-data/dumps/latest.json. |
The short version
- You need to be at least [MINIMUM AGE] to use Thespiary.
- Your inbox is your key. Look after it.
- Facts you add to the shared archive become part of a public, openly licensed database. That is the whole point.
- Your attendance log and your reviews stay yours. They are never published in the data dumps.
- Upload only playbills you legitimately hold. Do not upload things you were told to take down.
- Be decent to people. Do not vandalise the archive.
- This is one person's hobby project. It comes with no warranty and could go away.
1. What Thespiary is
Thespiary is two things sharing a database:
- A public archive of live performances - which shows ran, where, when, and who was in them. It is built by its users and published openly.
- A private diary of what you personally attended, what you thought of it, and what you want to see next.
The line between the two matters, and it runs through everything below. The first is community property. The second is yours.
These terms are offered by [OPERATOR NAME / LOCATION]. By creating an account you agree to them and to the Privacy Policy.
2. Who may use it
You must be at least [MINIMUM AGE] years old.
We do not ask your age when you sign up, so this is a promise you make rather than a check we run. If we find out an account belongs to someone under that age, we close it and delete the data.
Separately, explicit-rated material is hidden unless you opt in and confirm you are old enough to see it. That opt-in is not the same thing as the minimum age above.
If a previous account of yours was banned, you may not open a new one.
3. Your account
There are no passwords. You sign in by asking for a link, which arrives in your email and works once, for 15 minutes.
That has a consequence worth stating plainly: anyone who can read your email can get into your Thespiary account. Securing your inbox is securing your account. We cannot add a second factor for you - two-factor sign-in and passkeys are described in SPEC-08 but are not built yet.
So:
- Do not forward or share a sign-in link. It is a key, not a notification.
- Sign out on shared devices. A session lasts up to 30 days on its own.
- If you think someone else has been in your account, tell us at [SUPPORT CONTACT EMAIL] and change the email address on the account.
One account per email address. Do not open extra accounts to get around a sanction, to vote for your own reviews, or to make a contribution look independently corroborated.
Changing your email requires confirming from the old address first. If you have lost access to the old inbox, that is a manual support conversation - there is deliberately no automatic way around it.
You are responsible for what happens under your account.
4. What you contribute, and the licence you give
4.1 Two kinds of thing
When you use Thespiary you produce two different kinds of content, and they are treated completely differently.
Archive data - shows, productions, venues, performances, people, and cast and crew credits. These are shared facts about the world. Once accepted they belong to the archive, not to you, and other people's records depend on them.
Your own material - your attendance log, ratings, reviews, tags, private notes, wishlist, seat and ticket details, and the playbill scans you upload.
4.2 The licence you grant on archive data
Thespiary publishes its archive under Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0).
So when you contribute archive data, you licence it to us and to everyone else under CC BY-SA 4.0, and you confirm you are able to do that - that you are supplying facts you have compiled yourself or read off a source, not copying someone else's copyrighted description.
You keep whatever rights you had. This is a licence, not a transfer. But it is irrevocable in the practical sense: once a contribution is in a published data dump we cannot recall the copies people have downloaded.
Your name is not attached. Contributions are attributed to "the Thespiary community" collectively. We record internally who added what, for moderation purposes, but no display name is ever published through the API or in a dump.
If you delete your account, your contributions stay in the archive and the internal link back to you is erased.
4.3 Your own material stays yours
You keep every right you have in your reviews, notes and log. We do not licence them to anyone. We ask only for the permission we need to run the site: to store your material and show it to exactly the people your visibility settings say it should go to.
Your log and reviews are never included in the open data dumps, at any visibility setting, and are not available through the public API.
Everything starts private. Making something public is a choice you make per entry.
Note what a public review reveals: your display name, the venue, and the exact date and time of the performance.
4.4 Contributions are reviewed
New archive data may sit in a moderation queue before it goes live, and there is a cap on how many submissions you can have pending at once.
Credits extracted automatically from a playbill are marked as unreviewed, and are kept out of the public API and the data dumps until a human has checked them.
5. Playbill uploads
You may upload playbills, programmes, cast-change slips and similar production material. You do not have to have attended the performance yourself.
Only upload material you hold lawfully. Do not upload:
- material you obtained unlawfully;
- material a rights holder or a court has told you not to share;
- material that has already been removed from Thespiary after a takedown request.
A playbill is somebody else's copyrighted work. Uploading it transfers nothing to us and grants you nothing you did not already have. What we take from it is the facts printed in it - who performed, in what, where, when - and those facts, not the scan, are what goes into the public archive.
Your scan stays private to your account and is never published. The full details are in the copyright and takedown policy and the upload notice.
If you hold rights in something on Thespiary, email [COPYRIGHT CONTACT EMAIL]. We remove or disable access to the material while we look at it, rather than after, and we tell the uploader what went and why.
Accounts that repeatedly upload infringing material may be restricted or closed.
6. Acceptable use
Thespiary is a small community around a shared archive. The rules follow from that.
Do not harass anyone. No abuse, threats, slurs, sexual harassment, or sustained unwanted attention toward another user or a performer. A review of a performance is fair game; an attack on a person is not.
Do not vandalise the archive. Do not enter data you know to be false, delete or corrupt correct records, invent credits, or claim a performer profile that is not yours. The archive's value is that people can trust it.
Do not spam. No promotional content dressed as a review, no bulk automated submissions, no manipulation of ratings through extra accounts or coordinated voting.
Do not impersonate. Do not use a display name designed to pass you off as someone else, and do not claim a performer's profile unless you are that performer or represent them.
Do not attack the service. No scraping around the rate limits, no probing for vulnerabilities without asking first, no attempts to reach other users' private data. If you find a security problem, tell us at [SUPPORT CONTACT EMAIL] before you tell anyone else.
Do not post other people's private information. This includes tagging a companion with details they would not want visible.
Explicit material stays behind the opt-in. Do not route around it or mis-rate content to escape it.
7. Moderation
7.1 What can happen to content
A moderator can approve or reject a pending contribution, remove content that is already live, restore something removed in error, rule on a disputed credit, or lock a discussion thread. Removal is soft: content comes out of public view but is retained for a period so it can be restored or reviewed.
Where content is rejected or removed, you are told why. A reason is required for a rejection.
7.2 What can happen to your account
Three sanctions exist:
- Warning - a formal note on your account. Three within 180 days flags you for a moderator to consider escalating.
- Suspension - a temporary restriction with a set duration. You cannot sign in, and existing sessions end. It lifts automatically when it expires, and a moderator can lift it early.
- Ban - indefinite, and admin-only. You cannot sign in, and you may not create a new account on the same email address.
You are notified of a sanction, with the reason and, for a suspension, the duration.
In serious cases - typically a pattern of malicious edits - a moderator can remove a batch of your contributions in one action. That action is logged in full.
7.3 Appeals
You can appeal a warning, a suspension or a ban. Two limits, both enforced by the software rather than by goodwill:
- You have 30 days from when the sanction was issued.
- A decision made by an admin cannot be appealed inside Thespiary. In practice the operator is the admin, so an admin decision is final here.
Send a written statement explaining why you think the decision was wrong. A moderator who did not make the original decision, or an admin, reviews it and either upholds, reduces, or overturns it. If it is overturned, content removed because of it can be restored. You are told the outcome either way, and every outcome is recorded.
Every moderation action is written to an append-only audit log, including actions by the operator.
8. The public API and the open data
Anyone can register for a free API key. Doing so means agreeing to this section.
8.1 What you give us to register
An email address and a short description of what you intend to build. The description helps us spot abusive registrations.
We store only a one-way hash of your address, so we cannot contact you. If a breaking change is coming, watch the changelog - not your inbox. SPEC-07 sections 3.1 and 7.1 describe email deprecation notices and a developer mailing list; neither exists, and with the address stored as a hash neither can, without a change to how registration works.
8.2 Rules for using the API
- Read-only. There is no write access through the API, by design. All contributions go through the application so they pass validation and moderation.
- Keep your key secret. It is shown once, at creation, and we store only a hash of it. Lose it and you rotate it; there is no recovery.
- Stay inside your rate limit. Standard keys get 1,000 requests an hour. Higher tiers exist in the design; the tooling to grant them is not built yet, so in practice everyone is on standard today.
- Over the limit you get an HTTP 429 with a
Retry-Afterheader. Respect it. - Do not route around the limits with multiple keys or multiple addresses. If you need more, ask. If you need bulk data, take a dump - that is what it is for and it costs you nothing and us less.
- Attribute the data. See 8.4.
- Do not try to get at user data. The public API exposes none, and attempting to extract it is a breach of these terms as well as a bug worth reporting.
- Respect hidden performers. A person who has hidden their profile is absent from the API and the dumps entirely. Do not reconstruct them from older dumps and re-publish them.
We can revoke a key at any time for breach of these rules. You can revoke or rotate your own at any time.
8.3 What the data contains
Shows, productions, venues, performances, people, and cast and crew credits - active, human-reviewed records only.
It never contains user accounts, attendance, reviews, ratings, playbill images, raw extraction output, or storage keys.
8.4 The licence, and the attribution you must give
The data is licensed CC BY-SA 4.0. You may use it for anything, including commercially. You must credit it, and you must release anything you build from it under the same licence.
The required attribution:
Data sourced from Thespiary ([SITE URL]),
licensed under CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/).
Data contributors: the Thespiary community.
The ShareAlike condition is deliberate. It stops a well-funded actor from taking a community-built database, enriching it, and closing it off.
The licence covers the data. It does not cover the Thespiary source code, which has its own licence, and it does not cover playbill scans or the artwork and text printed in them - which are not ours to licence and are never published anyway.
9. Ending things
You can leave whenever you like. Ask for deletion from your account settings. Your account is hidden immediately and erased permanently after 30 days, during which you can change your mind. Your archive contributions stay, without your name on them. The details are in the Privacy Policy.
We can suspend or close your account for a serious or repeated breach of these terms, following section 7. Where we can tell you first, we will.
Thespiary itself might end. It is one person's project. If it is going to shut down, we will give as much notice as we can and make sure you have a way to export your data first. The archive is openly licensed and dumps are public precisely so that it can outlive the site.
10. What we do and do not promise
Thespiary is provided as is, with no warranty of any kind, express or implied.
Concretely:
- The archive is crowd-sourced, and some of it is machine-read. It will contain errors. Do not rely on it for anything that matters - a legal claim, a contract, a broadcast, a CV - without checking a primary source.
- There is no uptime guarantee. No SLA, no support commitment, no promised response time. One person maintains this in their spare time.
- Data can be lost. We take backups and test them, but this is a hobby deployment, not a bank. Export anything you would be upset to lose.
- Features described in the specifications may not exist. The public specifications are a design, not an inventory. Where the two differ, what the running software actually does is what you get.
- We are not liable for indirect, incidental or consequential loss arising from your use of Thespiary, to the extent the law allows. Nothing here excludes liability that cannot lawfully be excluded, including for death or personal injury caused by negligence, or for fraud.
- Other users' content is theirs. A review expresses its author's opinion, not ours. Reports go to [SUPPORT CONTACT EMAIL].
11. Changes to these terms
These terms are versioned; the current version is at the top.
For a material change - anything affecting your rights, the licence you grant, or what we may do with your material - we ask you to agree again before you carry on. The next time you use the site after the new version goes live, a short screen appears with links to the current terms and privacy policy and a box to tick; accepting returns you to what you were doing.
Until you accept, ordinary use pauses; your account settings, data export and account deletion keep working, so declining never locks you out of leaving.
Two parts of SPEC-08 section 12.2 are not built, and we say so rather than promise them: we do not send an email or in-app notice when the version changes, and there is no 30-day deactivation for an account that has not re-agreed.
Clarifications and typo fixes are not material and will not interrupt you.
Continuing to use Thespiary after a change means you accept it. If you do not, delete your account - and take your export first.
12. Law, and getting in touch
These terms are governed by [GOVERNING LAW / VENUE]. Nothing in them removes consumer rights you have that cannot be waived.
- Accounts, moderation, appeals, bugs: [SUPPORT CONTACT EMAIL]
- Privacy, exports, deletion: [PRIVACY CONTACT EMAIL]
- Copyright and takedown: [COPYRIGHT CONTACT EMAIL]
Thespiary is run by an individual. A postal address is available on request where one is genuinely needed.
Open data: licence and contents
The notice that travels with every published data dump.
The licence
Thespiary's archive data is published under Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0). https://creativecommons.org/licenses/by-sa/4.0/
You may:
- use the data for any purpose, including commercially;
- copy, redistribute, remix and build on it.
You must:
- attribute Thespiary, using the string below;
- share alike - licence any derived database or dataset under CC BY-SA 4.0 as well;
- not add restrictions that stop anyone else doing the same.
The ShareAlike condition is deliberate. It means a well-funded actor cannot take a community-built database, enrich it, and close it off.
The attribution to use
Data sourced from Thespiary ([SITE URL]),
licensed under CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/).
Data contributors: the Thespiary community.
Individual contributors are not named, and there is no per-record attribution to give. The community is credited collectively, by design.
What the licence covers
The data. Not the Thespiary source code, which carries its own separate licence.
And not playbill scans or the artwork, photographs and text printed in them. Those belong to their publishers. They are never in a dump, and we do not purport to licence anyone else's work.
What is in a dump
Seven collections of shared archive records:
| Collection | What it is |
|---|---|
shows | The work itself - a play, a musical, an opera, a tour |
productions | A particular staging of a show |
venues | Where performances happen |
performances | An individual dated performance |
persons | Performers and creatives |
cast_credits / crew_credits | Who did what, in which production |
Only records that are active and human-reviewed are included. Credits that were read automatically off a playbill and never checked by a person are excluded, and so are pending, rejected, merged and deleted records.
Explicit-rated shows are included, unlike the default API behaviour. Every show record carries a content_rating field so you can filter them yourself.
What is never in a dump
No user data. None. Specifically:
- No attendance records. Who saw what, and when, is never published - at any visibility setting, including "public".
- No reviews, ratings, tags or private notes. A review a user chose to show on a production page is visible on that page; it is not in the dump and is not in the API.
- No user accounts, display names, email addresses, locations or social connections.
- No contributor attribution. Credits are in the dump; who added them is not.
- No playbill scans, no raw extraction output, no media storage keys, and no signed URLs.
Performers who have hidden their profile are absent entirely - from the person records and from every credit that would have referenced them. This cannot be overridden by any parameter, key tier, or authentication level. If you are building on this data, please do not reconstruct hidden people from older dumps and republish them.
Two limits worth knowing
Dumps we have already published cannot be recalled. If someone deletes their account, or a performer hides their profile, they disappear from every future dump immediately - but a dated dump already downloaded is out of our hands. We ask consumers of this data to honour later removals rather than treat an old dump as permanent licence.
The archive is crowd-sourced and partly machine-read. Credits extracted from a playbill are reviewed by a human before they reach a dump, but review is not proof. Expect errors, and check a primary source before relying on any record for something that matters.
Getting the data
Fetch it from [DUMP URL]. No API key is needed, and there is no charge.
If you need the whole dataset, take the dump rather than paging the API. It is one request instead of thousands, it is what the dump is for, and it costs us far less to serve.
Currently the dump is served as a single JSON document built on request. The nightly tarball with CSV files, checksums and CDN mirrors described in SPEC-07 section 6.1 is not built yet, so there are no dated archive URLs to link to either.