Privacy Policy
ShowFlow does not track you, and never sells or shares your personal data. Everything below describes what is actually built and running today.
Last updated 9 September 2026
Who we are
ShowFlow is operated by Curtain Call Worldwide LLC, a New Jersey limited liability company, in the USA. What the product actually does is described in the Terms of Service. For anything on this page, including a request about your own data, write to privacy@showflow.io.
What we collect
Only what the product needs to work. Your email address, which is used to sign you in and to recover your account. Your username and display name. Your bio and profile photo, if you add them. Your profile visibility setting. Then what you do in the app: the shows you log and when you logged them, who you follow and who follows you, the likes and comments you leave, the accounts you block, the badges you earn, the share cards you save, and any abuse reports you file. That is the whole list.
We never see your password
Sign-in is handled by AWS Cognito, which holds your credential. ShowFlow never stores a password and never receives one; how that is enforced is described in ShowFlow Security Information. If you sign in with Google or with Apple, you authenticate with them directly in a browser window this app cannot see inside, and we receive only your email address and name. If you use Apple’s Hide My Email, we receive the relay address and treat it as your email, which is the whole point of the feature.
What we deliberately do not collect
No location or GPS. No contacts. No advertising identifiers. No device fingerprinting. No behavioural analytics: there is no log of what you tap or look at, and the one table that used to record anything like it was removed on purpose. No third party analytics, advertising or data-broker code runs anywhere in ShowFlow. This is a design decision, not a setting, so there is nothing here for you to turn off.
How we use it
To operate the service, and nothing else. Your data is never sold, rented, or handed to anyone for their own purposes. We do not profile you, we do not build an advertising audience, and we do not share your information between products.
Requesting an artist is not tracked to you
When you ask us to add an artist we do not have yet, we store the artist name and a count of how many times it has been asked for. We do not store who asked, or when any individual did. It is a wish-list of what to add next, not a record of your activity. You have to be signed in only so we can rate limit it, and your identity is used for that and then discarded.
How long we keep it
Until you delete it. We do not expire your account for inactivity, and we do not quietly archive your history. Operational logs, which record that a request happened rather than what you did in the app, are kept for 30 days and then deleted.
Your rights, and where to exercise them
You can see and change your profile in Settings. You can export everything you have created as a JSON file from Settings in the ShowFlow iOS app, and it is generated for you rather than sent anywhere. The web app has no export button yet: write to us and we will send you the same file. You can delete your account from Settings. Deleting is real deletion: your email, username, display name, bio and photo are overwritten immediately, your show history is removed, and your follows end in both directions. Comments you left on other people’s posts stay, shown as [deleted], so other people’s conversations do not develop holes. Signing up again with the same email gives you a new, empty account rather than the old one back. If you would rather ask us to do any of this, write to privacy@showflow.io.
Children
The age requirement for an account is set in the Terms of Service. We do not knowingly collect anything from children under 13, and if you believe a child under 13 has an account, write to us and we will remove it.
Governing law
The law governing ShowFlow, this policy included, is stated once in the Terms of Service.
Changes to this policy
If this policy changes in a way that affects what we collect or what we do with it, we will update the date at the top of this page and, for a material change, tell you in the app. The date is the honest signal: if it has not moved, nothing here has.
Who we share information with
ShowFlow shares information only with the service providers it relies on to operate.
- Amazon Web Services. Nearly everything runs here. Cognito holds your email and the verifier derived from your password, and sends account confirmation and password reset emails. A database holds everything else: your shows, follows, comments and likes. Object storage holds your avatar and any cards you save. Short-lived rate limit counters are keyed to your account.
- Vercel. Hosts and serves the website. Vercel sees the ordinary things a web host sees, including your IP address and which pages you requested.
- Google and Apple. Only if you choose to sign in with them. They tell us your email address and name. We do not send them anything about what you do in ShowFlow.
- Deezer. Artist photos load straight from Deezer’s image CDN rather than being copied onto our own servers, so your browser requests them directly and Deezer sees your IP address when it does. No account information is sent.
That is the whole list. ShowFlow also builds its concert catalogue from the sources named in the Terms of Service. Those run on our own servers and only ever ask about artists and venues. Nothing about you is sent to them.
For how your account is protected, see ShowFlow Security Information. For the rules of using ShowFlow, see the Terms of Service.
