Privacy
Last updated 19 August 2026.
SceneWeave publishes community event calendars. This page explains what it collects, why, how long it keeps it, and — because several of them are unusual — the things it deliberately does not collect.
Reading needs no account. Public calendars, unlisted events opened by their link, and private calendars opened by a shared link can all be read without signing in. SceneWeave does not ask who you are in order to let you read, and keeps no profile of visitors who do not sign in.
What SceneWeave does not collect
Each of these is worth stating plainly, because the absence is unusual.
- No third-party analytics, tag manager, or advertising pixel. There is no tracking script on any page.
- No external fonts or content-delivery networks. Every asset is served by SceneWeave itself, so loading a page does not tell another company you visited.
- Nothing is sold, and nothing is shared for advertising. SceneWeave runs no advertising and has no advertising relationships.
- Anonymous plans never leave your device. If you use the festival planning view without signing in, your selections are stored only in your own browser, as a list of event identifiers, and are never uploaded. SceneWeave has no server-side record of what a signed-out visitor is interested in.
Signing in with Google
Signing in is optional and is only needed to administer a calendar or to save things to an account. SceneWeave uses Google Sign-In and requests only the standard sign-in scopes — your basic profile and your email address. It requests no access to Gmail, Google Calendar, Contacts, Drive, or any other Google service.
What is stored as a result:
- an account record, held by SceneWeave’s authentication service, containing your email address and the fact that you signed in with Google;
- a profile row identified by that account. SceneWeave does not copy your Google display name or your profile picture into it — the field is left empty, and people you work with on a calendar see your account identifier rather than a name imported from Google.
Your email address is used to identify your account and to reach you about it. It is not published on any calendar page, and it is not used for marketing.
What you create
If you administer a calendar, what you enter — calendar names and descriptions, events, dates and times, venue names and addresses, and the roles you grant other people — is stored so it can be published as you direct.
Public means public. A calendar or event you publish publicly is readable by anyone, including search engines where you allow indexing. Non-public material is shown according to the disclosure settings on the calendar: unlisted events are reachable only by their link, and private calendars only through a link you share. Anyone who holds such a link holds that access until it is revoked.
Street addresses are treated more carefully than the rest. A venue street address is subject to its own visibility setting, and it never appears in any machine-readable output — subscription feeds and the publisher API omit it unconditionally, even for someone entitled to see it on the web page.
Presenters you publish
If you credit an instructor, speaker or performer on an event, you create a presenter profile: a name, and optionally pronouns, an affiliation, a short biography and a website. It is public information that you publish about someone else, and it is deliberately not an account — creating one signs nobody in, grants nobody access, and does not mean the person named holds a SceneWeave account. SceneWeave never connects a presenter to an account, and never infers that two people are the same because their names match.
A presenter profile holds no email address, no telephone number and no postal address, because there are no such fields to fill in. Their public page lists only publicly visible sessions: an event that is private, unlisted or invitation-only never appears there, for anybody, including you.
If you are named as a presenter and want that changed or removed, ask the organisation that published the profile — they can edit or archive it. Because a presenter is not an account, deleting a SceneWeave account does not remove presenter profiles, which is why that request goes to the organisation rather than to us.
Things you save
When you are signed in, what you save to your library is stored as identifiers only — a pointer to the event or calendar, not a copy of it. That is a privacy choice as much as a technical one: a copy would survive the cancellation or withdrawal of the thing it copied.
Cookies and local storage
SceneWeave sets first-party cookies only, and none of them is for advertising or tracking:
- a sign-in session cookie, if you sign in;
- sw_done — a one-shot confirmation that a change was saved, lasting sixty seconds;
- sw_capability_session and sw_invitation — short-lived cookies that hold a shared link’s credential after you choose to open it, so it does not have to stay in the address bar.
Your browser’s local storage is used for the anonymous festival plan described above, and for nothing else.
Who processes data on SceneWeave’s behalf
- Supabase — hosts the database and the authentication service. Your account record and everything described above is stored there.
- Google Cloud, including Firebase App Hosting — serves the website and keeps ordinary infrastructure request logs (such as IP address, time, and the URL requested), as any web server does.
- Google — provides the sign-in itself, when you choose to use it.
There are no other processors, and no data is transferred to anyone for their own purposes.
One disclosure worth making plainly. A private subscription feed address has to carry its credential in the web address itself, because calendar applications cannot supply one any other way. That means the address appears in infrastructure request logs. The credential is deliberately weak in what it opens — one read-only document, revocable at any time — and SceneWeave’s own application logs never record it.
How long things are kept
- Calendars and events — until the people who administer them delete them.
- Expired shared-link sessions — swept automatically every hour.
- Rate-limit counters — deleted after 90 days.
- Change records — SceneWeave keeps a record of administrative changes (what was changed, when) so that the people responsible for a calendar can see its history. These are kept without a time limit and are not deleted, because a history that can be thinned is not a history. When an account is deleted, the record of the change remains but is no longer linked to the person — see below.
Deleting your account
During this early pilot, deletion is handled by a person rather than by a button. Email cyriac.apps@gmail.com from the address you signed in with, and ask for your account to be deleted.
What is deleted:
- your account record, including your email address, and your sign-in identities;
- your profile;
- everything you saved to your library, and any personal subscription feed;
- your roles on other people’s calendars.
What happens to the rest:
- Calendars and events stay. Material published on a shared calendar does not disappear because a contributor closes their account — other people rely on it, and in many cases other people wrote parts of it.
- Change records stay, but stop naming you. Your identifier is removed from them; the record that a change happened remains.
- If you own a calendar, we will ask you to hand it over first. Deleting the last owner of a live calendar would leave a published page nobody can manage, so we ask you to transfer ownership — or tell us to retire the calendar — before the account is deleted.
Backups taken before a deletion may still contain the data until they are rotated out.
Your rights
What legal rights you have over your personal data depends on where you live, and SceneWeave does not attempt to state them for you here. Whatever your jurisdiction, you can ask what SceneWeave holds about you, ask for it to be corrected, or ask for it to be deleted, using the contact address below.
Security
SceneWeave is built with access controls enforced in the database rather than only in the application, so that a mistake in one layer does not by itself expose another person’s material. Links that grant access are bearer credentials: anyone holding one has the access it carries, which is why they can be revoked and why they should be shared deliberately.
No service can promise it will never be breached, and this page does not make that promise.
Children
SceneWeave is not directed at children and accounts are not intended for them. Event listings may of course describe events that families attend.
Who operates SceneWeave, and how to get in touch
SceneWeave is operated by its owner and is a small, free service in an early pilot. For any question about privacy, for a deletion request, or to report a problem with content on a calendar, email cyriac.apps@gmail.com.
Changes to this policy
This page is kept in the same version control as the software, so every change to it is a dated, reviewable change. If it changes in a way that materially affects people with accounts, the date above changes and material changes will be described here.