What Backstage is
Backstage is a private booking-intelligence tool for freelance photo and video professionals. It monitors event listings, scores them for coverage opportunity, and helps draft outreach to event organizers. Access is by invitation only.
Backstage is operated by Invision Designs. References to “we,” “us,” or “the operator” in this policy mean Invision Designs.
What data we collect
- Account info — your name and email address, provided by Google (or Microsoft) when you sign in via OAuth. We never see your password.
- Profile — the professional details you enter (specialties, rates, bio, social links). Stored so the AI can score listings and draft outreach in your voice.
- Activity — notes, status changes, outreach drafts, emails sent, and post-show ratings you create inside the app. Tied to your account only.
- OAuth tokens — a refresh token issued by Google (or Microsoft) that lets the app send email on your behalf. Stored encrypted (AES-256-GCM); decrypted only at send time.
- Session cookie — a signed, HTTP-only cookie that keeps you signed in for up to 30 days. No tracking pixels or cross-site identifiers.
How we use it
- To operate the app — scoring listings, drafting outreach, sending email, and building your reputation history.
- Your profile and ratings feed the AI scoring prompts. That context stays private to your account; other users' data never enters your prompts, and yours never enters theirs.
- We do not sell, share, or use your data for advertising of any kind.
Who can see your data
- You — your notes, drafts, ratings, and outreach history are visible only to you on the board.
- The admin — has database access for maintenance and can see account records, but does not routinely review personal notes or outreach content.
- Anthropic — outreach drafts and scoring requests are processed by Claude (Anthropic's AI). Anthropic's privacy policy governs that processing. We do not send your name or email to the AI.
- Supabase — our database host. Data is stored in encrypted-at-rest Postgres. Supabase's privacy policy applies.
Email sending
When you send outreach, Backstage uses the Gmail (or Outlook) API to send the message as you, from your own account. The email travels through Google's or Microsoft's servers — Backstage does not operate a mail server. A copy of every send attempt (recipient, subject, body, outcome) is logged for your own audit trail and is visible in the message history on each listing.
Google API Services User Data — Limited Use
Backstage's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We request the
gmail.sendscope only to send outreach emails you have composed and reviewed in Backstage. - We do not read, store, or index your Gmail inbox, drafts, or other messages — the
gmail.sendscope is send-only and provides no read access. - We do not transfer your Google user data to any third party except as needed to send the email (i.e., to Google's own SMTP servers), or as required by law.
- We do not use your Google user data to serve advertisements or for any advertising purpose.
- We do not allow humans (including the operator) to read your Google user data, except: with your explicit consent; for security investigations (e.g., suspected abuse); to comply with applicable law; or when the data has been aggregated and anonymized for internal operations.
The same commitments apply, in equivalent form, to data received from Microsoft Graph (Outlook send) under Microsoft's developer terms.
Your privacy rights
Depending on where you live, you may have rights over your personal data under laws such as the EU/UK General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA/CPRA), including:
- The right to access the personal data we hold about you.
- The right to correct inaccurate data (most fields are user-editable on the Profile page).
- The right to delete your account and associated personal data (see “Data retention and deletion” below).
- The right to port your data to another service.
- The right to object to or restrict certain processing.
- The right to withdraw consent for any optional processing at any time (e.g., by disconnecting an OAuth provider on the Profile page).
Lawful basis (GDPR). We process your data on the basis of (a) your consent when you grant OAuth scopes for Gmail or Microsoft Graph, (b) legitimate interest in operating the product (e.g., logging your outreach for your own audit trail, scoring listings using your profile), and (c) contract performance when you use the service.
California (CCPA/CPRA). Backstage does not sell or share personal information as those terms are defined under the CCPA/CPRA. We do not use your data for cross-context behavioral advertising. California residents may exercise the access, deletion, and correction rights described above.
International transfers. Backstage is operated from the United States. Our sub-processors (Supabase, Anthropic, Google, Microsoft, Railway) may process data in the United States or other countries. Where applicable, transfers from the EU/UK rely on Standard Contractual Clauses or equivalent safeguards offered by those sub-processors.
To exercise any of these rights, contact the admin (see “Contact” below). We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
Data retention and deletion
Your data is retained as long as your account is active. To request deletion, contact the admin and we will respond within 30 days.
When your account is deleted, the following data is removed:
- Your user record (name, email, profile, OAuth refresh tokens, avatar, settings).
- Your per-listing state (notes, status, drafts, scores, snoozes, contact details).
- Your outreach history (every send attempt logged on your behalf, including recipient addresses and message bodies).
- Your ratings (any post-show feedback you submitted).
The following data is retained because it is not personal to you:
- Scraped event listings — these are derived from publicly available sources and are shared across all users of the app.
- Listings you created and made public (manual entries where you chose “Public”) — these become shared content. Private manual entries are deleted with your account.
You can also disconnect a single OAuth provider (Google or Microsoft) at any time from your Profile page without deleting your account — that removes the refresh token for that provider only.
Security
OAuth refresh tokens are encrypted at rest using AES-256-GCM with a per-user binding. The app is served over HTTPS. Session cookies are signed, HTTP-only, and marked Secure in production.
Contact
Questions or deletion requests — reach the admin through the app or at the email address you were invited with.