Security

Security Overview

Last updated: August 30, 2026

Your data is yours, and here is how we keep it that way. Plainly, and without a badge we haven’t earned.

The short version

Hosting and encryption

Theater runs on established cloud infrastructure. Your data is stored in a managed Supabase (PostgreSQL) database, and the application is hosted on Vercel, both in the United States. Data is encrypted in transit using TLS between your browser, our hosting, and our database, and at rest at the infrastructure-provider level (Supabase-managed Postgres). We do not run our own additional field-level encryption today.

Access controls and data isolation

The application layer

Three things worth naming, because they are the failures that actually hurt small products.

Theater also runs no analytics platform, no advertising network and no third-party tracking script. There is no tracking cookie to disclose because there is none to set.

Authentication

Sign-in is handled by Supabase Auth, with sessions tied to your account by scoped tokens. Multi-factor authentication is not offered yet; it is on our list as we move out of private beta.

The AI layer

Maistro is powered by Anthropic’s Claude API. Two security-relevant practices:

Backups and deletion

Our database provider performs automated backups of the underlying database. Backups exist so the service can be restored after a failure, and they age out on the provider’s rolling schedule, which is no longer than 30 days. Deleting your account removes your content from our active database. Copies may persist briefly in provider backups until they age out, and anything already sent to the Claude API ages out on Anthropic’s window described above.

Your controls

Subprocessors

We rely on a small set of vetted infrastructure providers: Supabase (database), Vercel (hosting), Anthropic (AI), Loops (email), and Google (calendar, only if you connect it). We do not sell or share your data, and see our Privacy Policy for the full commitment, including that any future successor is bound by the same terms.

If there is a breach

If we become aware of a security incident that affects your data, we will notify affected users without undue delay and describe what happened and what we are doing about it, as required by law.

Responsible disclosure

If you find a vulnerability, email hello@gettheater.app. We welcome good-faith reports.

Safe harbor: we will not pursue or support legal action against researchers who, in good faith, find and report vulnerabilities in line with this policy. Please give us a reasonable time to fix an issue before public disclosure, do not access or modify data that isn’t yours, use only your own test accounts, and do not degrade the service (no high-volume automated scanning, no social engineering). We will acknowledge your report as quickly as we can. We are a small team, so please allow a little patience.

Where we are right now. Theater is an early-stage product built by a small team, in private beta. We are not SOC 2 certified, and we won’t imply otherwise. Formal audits come with scale, and we would rather tell you exactly what we do today than wave a badge we haven’t earned. As we grow, we will invest in formal audits and update this page.

Learn more

See our Privacy Policy for what we collect and who we share it with, and our Terms of Use for the rules of the road.