Security
Security Overview
Last updated: August 30, 2026
Your data is yours, and here is how we keep it that way. Plainly, and without a badge we haven’t earned.
The short version
- Your data is encrypted in transit and at rest.
- Your data is isolated per account. Core tables enforce owner-only access at the database level. The only exception is what you deliberately share with collaborators.
- Your Google tokens never touch your browser. Third-party credentials are handled server-side only.
- We send the AI only what a feature needs, and the provider does not train on it.
- We are a private beta and not formally certified. We will tell you plainly as that changes.
Hosting and encryption
Theater runs on established cloud infrastructure. Your data is stored in a managed Supabase (PostgreSQL) database, and the application is hosted on Vercel, both in the United States. Data is encrypted in transit using TLS between your browser, our hosting, and our database, and at rest at the infrastructure-provider level (Supabase-managed Postgres). We do not run our own additional field-level encryption today.
Access controls and data isolation
- Owner-only by default. Your core data is protected by row-level security in the database, so one account cannot read another’s rows directly.
- Collaboration is the deliberate exception. When you invite a collaborator to a production, access is granted for that specific shared production and role, through controlled server-side endpoints that check your permissions before returning data. We are a small team in private beta and are still expanding automated tests around these boundaries.
- Third-party credentials stay server-side. Your Google authorization tokens are stored so that only our server can use them, and are never sent to your browser or to other users. Your own Theater login session is held in your browser as a standard scoped session token so the app can act on your behalf; it grants access only to your own account and ends when you sign out.
- Access to production systems is limited to the founder(s). We do not have a support team browsing your data.
The application layer
Three things worth naming, because they are the failures that actually hurt small products.
- Every AI endpoint requires a signed-in session. The functions that spend our model budget verify your account before they do anything. An anonymous request gets refused, so nobody can use our key as a free relay.
- Everything you or a collaborator types is escaped before it renders. Text is displayed as text, and links are limited to ordinary web addresses, so a note or a production name cannot carry code into anyone else’s browser.
- Usage is metered per account. We count each account’s monthly AI calls and tokens, which lets us stop runaway use before it becomes a bill, and lets you see your own usage in Backstage.
Theater also runs no analytics platform, no advertising network and no third-party tracking script. There is no tracking cookie to disclose because there is none to set.
Authentication
Sign-in is handled by Supabase Auth, with sessions tied to your account by scoped tokens. Multi-factor authentication is not offered yet; it is on our list as we move out of private beta.
The AI layer
Maistro is powered by Anthropic’s Claude API. Two security-relevant practices:
- Data minimization. We send the model only the fields a given feature needs at the moment it runs, not your whole account.
- No training on your data. Under Anthropic’s commercial API terms, your prompts are not used to train models, and Anthropic auto-deletes API inputs and outputs within a limited window (currently up to 30 days). That is Anthropic’s processing window, not our storage of your account, which is retained until you delete it. We are pursuing Zero Data Retention with Anthropic; it is not enabled today.
Backups and deletion
Our database provider performs automated backups of the underlying database. Backups exist so the service can be restored after a failure, and they age out on the provider’s rolling schedule, which is no longer than 30 days. Deleting your account removes your content from our active database. Copies may persist briefly in provider backups until they age out, and anything already sent to the Claude API ages out on Anthropic’s window described above.
Your controls
- Export or delete, yourself. Backstage holds both. Export writes every row we have for you into one file. Delete removes your productions, scenes, notes, contacts, messages, calendar blocks, writing samples, settings and the account itself, immediately and for good. Neither one waits on us.
- Disconnect Google Calendar at any time, which revokes our ongoing access.
- Sign out to end a session, and manage or remove collaborators on shared productions.
Subprocessors
We rely on a small set of vetted infrastructure providers: Supabase (database), Vercel (hosting), Anthropic (AI), Loops (email), and Google (calendar, only if you connect it). We do not sell or share your data, and see our Privacy Policy for the full commitment, including that any future successor is bound by the same terms.
If there is a breach
If we become aware of a security incident that affects your data, we will notify affected users without undue delay and describe what happened and what we are doing about it, as required by law.
Responsible disclosure
If you find a vulnerability, email hello@gettheater.app. We welcome good-faith reports.
Safe harbor: we will not pursue or support legal action against researchers who, in good faith, find and report vulnerabilities in line with this policy. Please give us a reasonable time to fix an issue before public disclosure, do not access or modify data that isn’t yours, use only your own test accounts, and do not degrade the service (no high-volume automated scanning, no social engineering). We will acknowledge your report as quickly as we can. We are a small team, so please allow a little patience.
Where we are right now. Theater is an early-stage product built by a small team, in private beta. We are not SOC 2 certified, and we won’t imply otherwise. Formal audits come with scale, and we would rather tell you exactly what we do today than wave a badge we haven’t earned. As we grow, we will invest in formal audits and update this page.
Learn more
See our Privacy Policy for what we collect and who we share it with, and our Terms of Use for the rules of the road.