Privacy
Effective date: [[ SET LEGAL_EFFECTIVE_DATE ]]
This page describes what ActorBuddy actually collects. Where a common practice does not apply to us, we say so rather than leaving it vague.
This page is not finished.
The following values are unset and appear as placeholders below: LEGAL_ENTITY_NAME, LEGAL_JURISDICTION, LEGAL_EFFECTIVE_DATE. Set them as environment variables (see docs/SETUP-CHECKLIST.md) and have a lawyer review this text before relying on it.
Analytics
No third-party analytics provider is currently installed.The application contains an internal analytics interface that records five product events β a workshop card scrolled into view, a click on a provider's outbound link, a workshop saved, a filter applied, and a listing report submitted.
In the current configuration these events are written to the browser's developer console in development and discarded in production. They are not transmitted to any server, ours or anyone else's. No event payload contains your name, email, IP address, or any free text you typed.
We do not send your browsing activity to workshop providers. A provider learns about you only when you click through to their own website, at which point their own analytics apply.
[[ REVIEW: if you connect a real analytics provider, name it here, say what it collects and where it stores data, and add any required consent banner. ]]
Saved workshops
Saving a workshop with the β control stores that workshop's identifier in your own browser's localStorage. It is never transmitted to us, we have no account system for it, and we cannot see what you have saved.
Clearing your browser's site data removes your saved list permanently β we hold no copy to restore from. Saved workshops are also not synced between your devices.
Casting director alerts
The casting directors you add to your alert list are stored in your own browser's localStorage, exactly like saved workshops. The names are never transmitted to us, and we cannot see who you are watching.
Email and text alerts are not switched on yet. When they are, they will need an account and a contact address, and this page will be updated in the same change β at that point the list would necessarily leave your browser.
Listing reports
The in-page report form has been removed. If a report was submitted while it existed, we stored:
- the workshop identifier, the provider, and the listing URL you reported
- the reason you selected from the dropdown
- your comments, if you wrote any (optional)
- your email address, if you provided one (optional)
- the date and time of the report
- a truncated, salted hash of your IP address β used to count repeat submissions and block spam. It is not reversible into an IP address and is not used to identify you.
Your email is used only to follow up about that specific report. We do not add it to a mailing list, sell it, or share it with the workshop provider. Reports are stored on our own infrastructure.
Cookies
We use no advertising, tracking, or analytics cookies.
The site sets cookies in exactly one situation:
- Sign-in cookies. Logging in sets an HttpOnly session cookie so the gated tools stay unlocked in your browser. It holds no personal data beyond the fact that a valid login occurred, and expires after 30 days.
Separately, your light/dark theme preference and your saved workshops are kept in localStorage, not in cookies, and are never sent to the server.
Server logs
Our application logs are structured and deliberately thin: they record event names, provider identifiers, and error reasons. Passwords, tokens, cookies, email addresses, and report comments are redacted before a log line is written.
IP addresses are held transiently in memory for rate limiting and are discarded when the rate-limit window expires. Note that your hosting provider or CDN may keep its own access logs under its own policy, which we do not control.
Retention
- Listing reports: retained while we investigate and for a reasonable period afterwards; the store keeps at most the 5,000 most recent reports, and older ones are dropped automatically.
- Rate-limit records: minutes to one hour, in memory only.
- Saved workshops and theme preference: kept in your browser until you clear site data.
- Workshop listings: replaced on each refresh; expired events are deleted.
You can ask us to delete a report you submitted β email hello@actorbuddy.com.
[[ REVIEW: set a concrete retention period for reports, and confirm what rights (access, deletion, portability) apply to your users under your jurisdiction. ]]
Third-party links
Every workshop links out to the provider's own website. Once you follow that link you are on their site, under their privacy policy and their cookies. Your browser will normally tell them you arrived from us via the referrer header. We do not pass them any other information about you.
Children
The Service is intended for adults working in the entertainment industry and is not directed at children.
Contact
Privacy questions: hello@actorbuddy.com β or use the contact page. Postal: [[ SET LEGAL_MAILING_ADDRESS ]].