Theatre Register

Privacy

You can read every page of this catalogue without telling us anything. No account, no consent box, no tracker. Below is the small amount that happens anyway, and what changes if you decide to join in.

Version 2026-08-16.1 — describes the site as of August 16, 2026.

Not written by a lawyer

Researched carefully and with sources, but written by someone not qualified to give legal advice, and not yet checked by a solicitor. What it says about the software was checked against the code line by line. What it says about the law may be imperfect.

The short version

Who runs this

One person, in the United States, as a personal project rather than a company. No team, no investors, no parent organisation. When this page says "we", it means that person and whoever they have asked for help.

Two things follow from that. Write to us and a human answers, rather than a ticketing system. But the formal apparatus a large organisation has — a data protection officer, a designated representative in Europe — does not exist here.

Reading the catalogue

Signed out, nothing happens at all

No cookie is set and no account database is even opened. The site checks whether you have a session cookie, finds that you do not, and gets on with drawing the page. A test fails if that ever stops being true.

What we count

We keep a record of which pages get served, so we can tell which parts of the catalogue people actually reach. For each page view we store:

We do not store your address. It is used for a fraction of a second, to build a short code that groups today's page views into visits. Then it is thrown away. It is never written to a database and never leaves the server.

The secret behind that code is replaced every night and the old one destroyed. Tomorrow the same reader gets a different code. Yesterday's cannot be worked out again by anyone — not by us, not by somebody holding a copy of the file.

The cost is real. We cannot tell you how many different people read the site last month, because we have made that impossible to know. Knowing that 40 people read a page today is useful. Knowing which of them also read it in March would cost a permanent identifier, and it is not worth that.

Searches

We record what was searched for, with nothing attached saying who searched.

Searches that find nothing are the most useful thing here. Somebody came looking for a show and we did not have it. That tells us exactly what is missing.

It is a catalogue search box, so please do not type anything private into it.

The small script that runs in your browser

It measures two things the server cannot see: how long a page stayed visible, and when you click a link that leaves the site.

For a link out it records which site you went to, not the full address, and which page you left from. It sets no cookie, stores nothing on your device, and uses no identifier. Turn JavaScript off and everything else works the same.

How to ask not to be counted

If your browser sends Do Not Track or Global Privacy Control, we do not count you. Not anonymised further — not recorded at all. Most of the web ignores those signals. Here they do what they say.

How long we keep it

Individual page records last 90 days. Before they go, they are added up into per-day, per-page totals. So we keep the shape of a year without keeping a year's worth of individual reads.

The server's own log

We keep no request log of our own. The company that runs the site keeps one, as any host does, and it records the addresses requests arrive from. We do not add to it, copy it, or read it.

We can see one hour of those logs. That is the limit on our plan, and after it they are gone from our view. What our host keeps beyond that, and for how long, is theirs to say rather than ours.

What we do not do

No advertising network. No social media pixels. No fingerprinting, no session recording, no heatmaps. No analytics company, and nobody paid to measure you. We never send an address to a lookup service to find out who your employer is, which is common and mostly invisible.

Nothing on a page comes from anyone else

Every part of every page — the words, the pictures, the typefaces, the small amount of code — is served by us. Reading this site sends nothing to any other company, and no other company learns you were here.

That includes the fonts. Most sites load them from Adobe or Google, which hands over the address of every reader on every page. This one uses the fonts already on your computer.

Pictures

Cover art and photographs come from our own storage. They are not pulled from a label, a shop or an archive as you look at them. So looking at a record sleeve here does not tell a shop you were looking at it.

Links to other sites

Part of this catalogue's job is telling you where to hear something, so pages link out to shops, libraries, streaming services and archives. Following one takes you into somebody else's privacy policy. We send nothing about you along with the link.

If you make an account

Accounts are optional and always will be. The whole catalogue is readable without one.

Signing in

You sign in through Google or Apple rather than choosing a password here, so we never see, store or handle a password. That is the single best thing a small site can do for your security. It does mean Google or Apple learns you signed in here, the same way they do for every other site you use them for.

From Google we ask for your email address and basic profile. From Apple, your name and email. What we keep is your display name, your email address, and the permanent identifier your provider uses for you. We do not store your profile picture, and we never receive your password.

If you use Apple's Hide My Email, we get the relay address and never learn your real one. We note that it is a relay, so we know not to treat it as a lasting way to reach you. It works fine.

What else is on your account

A role: ordinary, trusted, or administrator. It sets what you are allowed to do, not what we know about you.

Optionally, a contact address you type in yourself, kept separate from the one your sign-in provider gave us. It is for reaching you about your contributions and nothing else, and we never use it to match you to another account. We cannot check that it works, because nothing on this site sends email yet. Your account page says so, rather than showing an "unverified" badge that will never clear.

Staying signed in

The session cookie holds one random string. No name, no email, nothing anybody could read.

The record it points to sits on our server. Even that keeps only a one-way fingerprint of the cookie, not the cookie itself. So a stolen copy of the database cannot be used to sign in as you.

Signing out deletes that record. It really does end the session, rather than only forgetting it on this device.

Lists

Lists you make are private unless you change that. You can make one unlisted, so anyone with the link can see it, or fully public. Nothing is shared until you choose to share it.

Downloading your data, and deleting it

Both are buttons on your account page. Neither needs you to email anybody.

The download is one file holding everything we have about you:

The page lists what is in it, so you can check rather than take our word for it.

One thing is left out on purpose. Sessions are listed by when they started and when they expire, without the secret that makes each one work. Those are keys to your account, and a downloaded file gets emailed around and left in folders. Telling you three sessions are open is information about you. Handing over the keys would be a risk to you.

Deleting your account really deletes it. The row goes and everything attached to it goes too. Not deactivated, not flagged, not kept for 90 days in case you change your mind.

Backups are the exception. Our database provider takes them, as any provider does. A deleted row can survive in one of those for a while after it has gone from the live database. We cannot reach into a backup to remove a single row.

We do not yet know how long that window is. When we do, this page will say.

What deleting does not reach

Two things stay behind.

What you contributed stays in the catalogue. Corrections and additions are part of the record and other people's work builds on top of them. What goes is the personal part — your account, your email, your sign-in. What stays is the contribution itself, credited to the name you used, or to "a contributor" if you would rather. Just ask, and we do both at once.

The newsletter is a separate list. On purpose: it is keyed to an email address and knows nothing about accounts, so you can subscribe without one. That also means closing your account does not unsubscribe you.

So the closing screen says so, and puts the newsletter switch right there. You can turn it off in the same visit. The unsubscribe link in any issue works too.

Contributions

Correct a catalogue number or add a recording, and that change is public. It is credited to the name you contribute under, and it is part of the permanent record. This catalogue shows its working, so the history of who changed what has to stay readable.

It goes public straight away, before anyone reviews it. The record of changes lists everything as it arrives rather than once it is approved, so anybody can watch the queue rather than only us. Worth knowing before you type: there is no window where a contribution sits privately waiting for a decision.

So choose the name you use with that in mind. A username is fine. Plenty of the best contributors to catalogues like this one have never used their real name, and nothing here asks you to.

Your name stays on your work. We will never quietly take your credit off it, and if you want it removed, ask and we will. The contributions themselves stay, because other people's corrections build on top of them. The full terms are on the contributor licence page, worth reading before your first edit.

The newsletter

Optional, separate from having an account, and never automatic. Signing up for one does not sign you up for the other.

Subscribing takes two steps on purpose. You give us an address, we send one email asking you to confirm, and nothing else is sent until you click it. That stops somebody else signing your address up. We keep the address, when you asked, when you confirmed, and which page the form was on.

Every issue has an unsubscribe link that works in one click, and keeps working if you click it twice.

Unsubscribing does not delete the row. We keep it and mark it unsubscribed. That is what stops the address being added back by a later import, and what shows you agreed and then changed your mind.

If you would rather be forgotten than remembered as having left, there is a button for it. It is on the page you land on after unsubscribing, and it deletes the address outright.

Worth knowing what that costs. Once the row is gone, nothing remembers this address ever said no, so a future import could add it back. Your choice either way.

We do not track whether you opened an email or which links you clicked, and there are no tracking pixels in it.

Who else handles your data

Running a website means using other companies' computers. These are the ones in the path between you and this site:

WhoWhat forWhat they see
Vercel Runs the site, in Virginia, USA. Every request, including your IP address.
Cloudflare Stores and delivers every image. Your IP address when an image loads.
Supabase Holds the database, in northern California, USA. Accounts, contributions and the newsletter list. Nothing on its own. We ask it to store our data and hand it back, and nothing else.
Google, Apple Signing in, if you choose to. That you signed in here, and when. Only if you use them.

That is the whole list. No analytics company, no error-tracking service, no marketing platform. The counting is our own code writing to our own database. None of them is paid to build a picture of you. None of them gets anything from us beyond what is needed to draw the page.

We do not sell personal information. Not in the everyday sense, and not in the wider sense some privacy laws use, where certain kinds of sharing count as a sale.

Our database is shared with another project of the same owner's, kept in a separate section of it.

Where in the world your data goes

The site runs in the United States. The web server is in Virginia and the database is in northern California. If you are reading from Europe or the UK, your request crosses the Atlantic.

That transfer is covered by the EU–US Data Privacy Framework and the UK extension to it. Both were valid as of the date at the top of this page.

The framework is currently under appeal at the EU's highest court. That changes nothing about your reading today.

How long we keep things

WhatHow long
Individual page-view records90 days, then rolled into per-day totals.
Per-day, per-page totalsKept. They identify nobody.
Search queries90 days, except queries that found nothing, which are kept as a record of what the catalogue is missing.
Request logsKept by our host, not by us. We can see one hour of them.
Contributions and the record of changesPermanently.
Your accountUntil you delete it, then gone.
Expired sessionsDeleted once they lapse.
Newsletter subscriptionUntil you unsubscribe; the unsubscribe record itself is kept.

Your rights over your data

In the UK or the European Economic Area, the law gives you a set of rights. They are worth knowing even here, where we hold almost nothing. You can ask us to:

You can also complain to your national data protection authority if we handle it badly. In the UK that is the Information Commissioner's Office.

In California you have similar rights: to know, delete, correct, and opt out of any sale or sharing. This site is far too small for California's privacy law to apply, so we are not claiming to be covered by it. The rights cost nothing to honour, so we honour them anyway. There is no sale or sharing to opt out of.

How to use them

With an account, downloading and deleting are buttons on your account page. Those are faster than we are.

For anything else, email and ask. We aim to answer within a month, which is what the law allows, and it is usually much sooner.

Some things we cannot do.

We cannot find you in the counting data. There is no lasting identifier in it, so an access request there cannot be answered. Trying would mean collecting more about you rather than less.

The server's request log holds nothing about you at all. Contributions stay, as above, though your name can come off them.

One more, about the oldest records. Moderation decisions are tied to the account that made them, so removing a moderator's name is exact. But rows written before that link existed carry only a name, and names are not unique. We leave those alone rather than guess and risk anonymising somebody who happened to pick the same one. In practice they are housekeeping entries from before the site opened.

Children

This site is not aimed at children, and nothing on it is designed to appeal to them more than to anyone else. Accounts and contributions are for people aged 13 and over. If you are a parent and think we hold something about your child, email us and it will be removed.

European law lets each country set its own age here, anywhere from 13 to 16, and countries chose differently. Ireland and Spain picked 13, France and Germany 16. We use 13 everywhere.

Keeping it safe

Connections are encrypted. We store no passwords, because signing in goes through Google or Apple. Session records hold a one-way fingerprint rather than anything reusable. Account data sits in its own database, separate from the catalogue.

We will not claim a personal project has the security of a bank. If something goes wrong in a way that affects you, we will tell you, and tell the regulator, in the time the law allows.

When this page changes

Whenever the software does. This page describes the site as it actually is, so it changes in the same week as the thing it describes. Not once a year out of habit. The date at the top is when it was last true. If something changes that really affects you, we will say so on the site rather than editing quietly.

Getting in touch

Email johnhowrey@gmail.com with anything on this page. A question, a request about your own data, or a correction to something here that is wrong.