Last updated: 2026-08-06
Provoke (“we”, “our”, “the app”) is a theater cataloging and diary app. This policy explains what information we collect through the Provoke website and mobile app, why we collect it, and how it’s used.
Information we collect
When you create an account, we collect:
- Email address
- Username and display name
- Password credential, managed by Supabase Auth. Provoke does not store password hashes or plaintext passwords in its application database.
Optionally, you may add to your profile:
- A short bio
- A profile image you submit, along with the moderation status and metadata needed to review it
- Your city and country
As you use the app, we store the content you create:
- Reviews and ratings of productions, including diary entries (when you watched something) and whether you’ve marked a review as containing spoilers
- Watchlist entries (productions you want to see)
- Favorite productions you choose for your profile
- Lists you create and the productions you add to them
- Who you follow and who follows you
- Catalog requests, reports, and contact inquiries you submit, including the information you provide in them
- Account-security, moderation, and audit records needed to operate and protect the service
Reviews use public, followers-only, or private visibility. Retained Lists data uses public, unlisted, or private visibility, although the current website and mobile interfaces do not expose list management. Content is disclosed according to its applicable visibility setting.
What we don’t collect
Provoke does not use third-party analytics, advertising, or tracking SDKs. We don’t request access to your camera, location, or contacts. We don’t sell or share your personal data with third parties for marketing purposes. We use service providers only to operate the services described below.
How we use your information
- To authenticate you and keep your account secure
- To display eligible public activity and records to other users according to their visibility rules
- To operate core features such as your diary, feed, watchlist, favorites, and catalog discovery
- To review catalog requests, reports, and profile-image submissions, and to prevent abuse
Data storage and security
Provoke application data is stored in a Supabase-hosted PostgreSQL database. Supabase Auth manages account credentials and sessions. If you submit a custom profile image, it is sent to Cloudinary for storage and automated moderation using AWS Rekognition. We store the resulting image reference and moderation information needed to operate that feature. We never trust a client-supplied user id or role; every request is checked against your actual account on our server.
Your rights
You can edit or delete your reviews and manage watchlist and favorite entries from within the app. The current interfaces do not expose Lists management. You can permanently delete your account from Profile settings after confirming your current password; account deletion also removes owned list records through their database relationships. It removes your Provoke account, deletes the linked Supabase Auth account, and requests deletion of associated custom profile-image assets from Cloudinary. We may retain submitted contact inquiries and limited moderation or audit records when needed to resolve an inquiry, prevent abuse, or meet legal obligations; those records are no longer linked to an active account. To request an export of your data, exercise another applicable data right, or ask a privacy question, contact us at the email below.
Children’s privacy
Provoke is not directed at children under 13, and we do not knowingly collect data from them.
Changes to this policy
If this policy changes, we’ll update the date at the top of this page. Continued use of the app after a change means you accept the updated policy.
Contact
Questions about this policy or your data? Contact us at privacy@provoke.gr.