← Stagedoord

Privacy and support

Stagedoord is a logbook for performances you have seen. This page says exactly what it keeps, what it never keeps, and how to take it back.

Last updated: 28 August 2026

Signed out, nothing leaves your device

The logbook works without an account. Entries are stored in your browser's local storage on that device only. Nothing is sent anywhere, and we cannot see it. Clearing your browser's data for this site deletes it, and there is no copy.

Signed in

Signing in uses your Google account. We receive a user ID, your email address and your display name from Google. We never see your password.

Your logbook is then stored in Google Cloud Firestore under that user ID. For each performance that is: the date and whether it was a matinee or evening, the show and production, the venue, your seat, your ratings, your notes and tags, and the cast changes you recorded. If you scanned a slip, the text the reader produced is stored with the entry so you can check it against what was saved.

Photographs of cast-change slips are never uploaded

Scanning is done entirely on your device, by a text reader that runs in your browser. The photograph is read and discarded. It is not sent to us, and it is not sent to anyone else.

This is not a promise about how we behave. There is no file storage attached to this project at all, so there is nowhere for a photograph to go.

Sharing is off unless you turn it on

Every entry is private by default. Marking one as shared publishes a projection of it — the show, the date, the venue, the cast, your rating and tags — so other people who were at that performance can compare cast lists.

A shared report never carries your seat number, your notes, your rating of the seat, or the raw text from a scan. That is enforced by the database rules rather than by the app: those fields have no place in a shared report to be written into. A seat number plus a date plus a name is a record of where somebody sat, and it has no business being public because they shared a cast list.

A public profile page works the same way. It exists only if you create one, and turning it off deletes it rather than hiding it behind a setting.

Analytics only if you agree

We ask once, before loading anything. If you decline, no analytics code is loaded at all — not loaded and disabled, not loaded. If you accept, Google Analytics records anonymous usage so we can see which parts of the app get used. Declining is a single tap and the button is not hidden.

Getting your data back

Two downloads, both from the app, both immediate and neither requiring you to ask us:

Deleting everything

The same screen has Delete my account. It removes every performance you logged, your profile, your public profile if you made one, and your sign-in account. It is not a flag or a queue; the records are deleted. Once it finishes there is nothing of yours left on our servers.

Who else can see it

Google, as the operator of the servers this runs on — Firebase Hosting, Firebase Authentication and Cloud Firestore — and Google Analytics if you agreed to it. Nobody else. We do not sell data, and there are no advertising or tracking services in this app.

Children

Stagedoord is not directed at children under 13 and we do not knowingly collect their information.

Changes

If this policy changes materially we will update the date at the top. The history of this page is public in the project's source repository, so what changed and when is checkable rather than asserted.

Support

Questions, a bug, a show or venue we have wrong, or anything about your data: CONTACT@EXAMPLE.COM.

If you think a cast list is wrong, say which performance and what it should be — cast records are built from public sources and they do get things wrong.