Back to home

Privacy Policy

Last updated: 2026-07-18

This Privacy Policy explains how Theta ("we", "us", "our") collects, uses, and protects your personal data when you use our mobile application and our website at thetatheater.com.

1. Data We Collect

We collect the following data when you use Theta:

  • Account data: Email address, display name, profile photo (optional)
  • Location data: Your approximate location to show nearby theaters and performances (only when you grant permission)
  • Usage data: Shows you view, reviews you write, theaters you save, interactions with other users
  • Device data: Device type, operating system, app version
  • 2. How We Use Your Data

    We use your data to:

  • Provide and improve the Theta app experience
  • Show you relevant shows and theaters near you
  • Enable social features (follows, messaging, activity feeds)
  • Send you notifications about shows you're interested in
  • Ensure the security and integrity of our platform
  • 3. Legal Basis for Processing

    Under the GDPR, we only process your personal data when we have a lawful basis to do so:

  • Performance of a contract: To create and operate your account and provide the core features you sign up for, such as your profile, reviews, messages, and saved shows.
  • Consent: For optional features such as push notifications and, where applicable, location-based suggestions. You can withdraw your consent at any time in the app or your device settings.
  • Legitimate interests: To keep the platform secure, prevent fraud and abuse, diagnose technical problems, and improve our service, balanced against your rights and freedoms.
  • Legal obligation: To retain certain information where the law requires it, or to respond to lawful requests from public authorities.
  • 4. Third-Party Services

    We share personal data with trusted service providers who process it on our behalf, only as needed to run Theta:

  • Google and Apple — secure sign-in (authentication) when you choose social login.
  • Brevo — sending transactional emails, such as confirmation and password-reset messages.
  • Expo — delivering push notifications to your device.
  • Cloudflare R2 — cloud storage of uploaded images and encrypted database backups.
  • Sentry — error and crash reporting to diagnose technical problems (configured not to attach identifying data such as your email address).
  • Mistral AI — generating event descriptions and genres from public event information; it does not process your account data.

  • We do not sell your personal data.

    5. International Data Transfers

    Some of our service providers are located outside the European Economic Area (EEA), including in the United States (for example, Sentry, Cloudflare, Google, and Apple). Whenever we transfer your personal data outside the EEA, we rely on appropriate safeguards recognized under the GDPR — such as the European Commission's Standard Contractual Clauses (SCCs) or the EU–U.S. Data Privacy Framework — so that your data continues to receive an equivalent level of protection.

    6. Data Retention

    We retain your personal data for as long as your account is active. When you delete your account, we delete your personal data from our active systems within 30 days, except where we are required by law to retain it. Residual copies may remain in our routine encrypted, access-controlled backups for a limited period (up to 90 days) until those backups are rotated and overwritten, after which they are permanently erased.

    7. Your Rights (GDPR)

    Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Port your data to another service
  • Object to processing of your data
  • Restrict processing of your data

  • To exercise any of these rights, contact us at the email below.


    You also have the right to lodge a complaint with a data protection supervisory authority. In Greece, this is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), www.dpa.gr.

    8. Data Security

    We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

    9. Children's Privacy

    Theta is intended for users aged 16 and over. When you create an account, you confirm that you are at least 16 years old. We do not knowingly collect personal data from anyone under 16. If we learn that we have collected personal data from a child under 16 without appropriate consent, we will delete that data as soon as possible. If you believe a minor has provided us with personal data, please contact us at the email below.

    10. Contact

    For any privacy-related questions or requests, contact us at: