DOORS
PrivacyTerms

Doors

Privacy Policy

Effective 6 August 2026. We’ll post the new date here whenever this changes, and tell you in the app if the change is significant.

The short version.Doors stores the concerts you log, who you follow, and roughly where you live so we can show you nearby shows. We don’t sell your data, we don’t run ads, we don’t track you across other websites, and there are no third-party analytics or advertising trackers in this app. You can delete your account and everything in it from Settings, yourself, at any time.

Privacy nutrition label

A plain summary of every category of data Doors handles. The detail follows underneath.

Categories of personal data collected by Doors
DataWhat exactlyWhy we have itIdentityWho else sees it
AccountEmail address, password (stored only as a hash we cannot reverse)To sign you in and to send account emailLinked to youSupabase (auth provider). Never shown to other users.
ProfileUsername, display name, bio, profile photoSo people can find and recognise youLinked to youAny signed-in user. This is your public face on Doors.
LocationHome city, region and country. Coordinates, if you tap “use my location”.To sort shows and people by distance from youLinked to youNobody. Your city may appear on your profile; your coordinates are never shown to another user or sent to your browser.
Concert activityShows you log, ratings, private notes, photos, who you went with, RSVPsIt is the product — your concert historyLinked to youDepends on the entry. See “Who can see what”.
Social graphWho you follow, who follows you, blocks, likesTo build your feed and enforce blockingLinked to youFollower and following lists are visible. Blocks are private — the person you blocked is not told.
SpotifyYour Spotify display name, top artists, and access tokens — only if you connect itTo suggest artists you might want to see liveLinked to youNobody. Tokens are readable only by our server, never by any user including you.
SupportFeedback messages, and reports you fileTo fix things and to act on abuseLinked to youDoors administrators only.
TechnicalServer logs, and a hashed IP address when you sign in or request an emailSecurity — to stop password guessing and mail floodingNot linkedNobody. IP addresses are hashed before storage; we cannot read them back.

Not collected, at all: advertising identifiers, browsing history on other sites, contacts, microphone or camera access (photos are chosen by you from your device), payment details (Doors is free and has no payment processing), and precise background location.

Who can see what

Doors is a social product, so some of what you enter is meant to be seen. Here is exactly where the lines are.

  • Anyone signed in to Doors can see your profile, the shows you have logged and rated, your follower and following lists, and photos you attach to a show unless the entry is marked private.
  • Only you can see your private notes on a show, your home coordinates, your email address, entries you marked private, and the list of people you have blocked.
  • Nobody who is not signed in can see any of it. Doors requires an account to view anything; there are no public profile pages indexed by search engines.
  • Someone you block cannot see your activity, follow you, like your entries, tag you, or reach your notifications.

Automated systems and AI

We think you should be able to tell the difference between “a computer sorted this list” and “a model wrote this”, so here it is precisely.

  • Recommendations are algorithmic, not AI. The shows and people Doors suggests are produced by ordinary code: genre overlap with artists you have logged, distance from your home city, and how many people you follow are going. There is no machine-learning model and no large language model involved in ranking anything you see.
  • Parts of this software were written with AI assistance. That is a fact about how the code was authored, not about your data: no user content was involved.
  • We do not send your content to any AI provider,and we do not use it to train models — not ours, not anyone else’s. Your logs, notes, photos and messages are not training data.
  • No automated decisions with legal or significant effects are made about you. Moderation decisions — removing content, suspending an account — are made by a person.
  • If we ever add a feature that sends your content to an AI system, we will say so here before it launches, and where consent is required we will ask for it rather than assume it.

Who we share data with

We do not sell personal data, and we do not share it for advertising. We use a small number of service providers who process data on our instructions:

  • Supabase — database, authentication and file storage. Everything you enter is stored here.
  • Vercel — application hosting. Handles requests and keeps short-lived server logs.
  • Ticketmaster and Setlist.fm — we read concert, artist and venue data from them. We send them search terms and artist identifiers; we do not send them anything about you.
  • Spotify — only if you connect your account, and only then to read your top artists.
  • Resend— delivers the notification email we send to ourselves when you submit feedback, so it doesn’t sit unread. It carries your message and your username; it does not carry your email address.

We may also disclose data where the law genuinely requires it, or to protect someone’s safety. If we are ever compelled to hand over your data, we will tell you unless we are legally prohibited from doing so.

How long we keep things

  • Your account and content — until you delete them.
  • Deleted account — removed from the live database immediately, including your uploaded photos. Encrypted backups may retain a copy for up to 30 days before they roll off.
  • Security counters (the hashed sign-in throttle) — cleared within a day.
  • Reports and moderation records — kept after the reported content is gone, because a record of what was actioned is the only way to handle repeat behaviour.

Your choices and rights

Wherever you live, you can do all of the following, and most of them without asking us:

  • See and change your data — Settings holds your profile, location and privacy options.
  • Delete your account— Settings → Delete account. It removes your profile, logs, ratings, notes, photos and social graph. It is immediate and cannot be undone.
  • Get a copy of your data — email us and we will send you an export.
  • Disconnect Spotify — Settings. This deletes the stored tokens.
  • Object or complain — email us. If you are in the UK or EU you may also complain to your data protection authority; in Canada, to the Office of the Privacy Commissioner.

If you are in the EU or UK: our lawful bases are performance of a contract (running the account you asked for), legitimate interests (keeping the service secure and working), and consent (Spotify, and precise location — both of which you can withdraw at any time).

Security

Access to your data is enforced in the database itself rather than only in the app, so a bug in one page cannot expose another user’s records. Passwords are hashed by our authentication provider and are never visible to us. Photos live in a private bucket and are served through short-lived signed links. Sign-in attempts and account emails are rate limited, and IP addresses used for that are hashed before they are stored.

No system is perfect. If you find a security problem, please tell us at the address below before disclosing it publicly — we would much rather hear from you than read about it.

Children

Doors is not intended for people under 13, and we do not knowingly collect their data. If you believe a child has an account, contact us and we will remove it.

International transfers

Our providers may process data in countries other than yours, including the United States. Where required, transfers rely on Standard Contractual Clauses or an equivalent safeguard.

Contact

Questions, requests, or a data export: hunnisettcarter@gmail.com. We answer within 30 days, usually much sooner.

© 2026 DoorsPrivacy PolicyTerms of ServiceBack to Doors