Theoatrix Toolkit ("the App") is operated by Theoatrix ("we", "us", "our"). This Privacy Policy explains what information we collect, how we use it, and your choices when you use the App.
You can change your privacy choices anytime in the App at Settings → Privacy. Toggles control whether we collect analytics + crash reports and whether we record session replays. We do not use these for personalized advertising.
Information We Collect
Account Information
If you choose to create an account, you can sign in using Google, Apple, or email and password. When you do, we receive information from your chosen sign-in provider to authenticate you and maintain your account. This may include:
- A unique user identifier
- Your name or display name (if provided by the provider)
- Your email address
We do not request or access your Google/Apple password.
Content You Provide in the App
The App may allow you to enter information for calculators or tools. This information is processed to provide the feature. We do not treat these entries as personal profile data.
App Usage Data (Analytics)
We use Firebase Analytics and PostHog to collect app usage data to improve performance, features, and stability. This includes which screens are used most, basic device and app version info, and session duration. Firebase Analytics may collect device identifiers and app interaction data automatically; PostHog identifies events using your Firebase user ID when you are signed in (otherwise an anonymous device identifier).
Analytics collection is gated by your consent. In the European Economic Area, the United Kingdom, and Switzerland, we do not collect analytics until you opt in via the consent prompt that appears the first time you open the App. Everywhere else, analytics is on by default with a clear notice; you can change this in Settings → Privacy at any time.
Session Recordings (Optional)
We may record session replays via PostHog to diagnose bugs and improve usability. A session recording is a sequence of screenshots of the App as you use it, with sensitive fields masked.
- Session recordings are off by default in every region, and require analytics consent to be on.
- The following are masked in recordings: email address fields, password fields, account re-authentication prompts, and the contact-form message body. If you spot a personal identifier we missed, please contact us and we will mask it.
- You can disable session recordings independently of analytics in Settings → Privacy.
Crash and Performance Data
We use Firebase Crashlytics and PostHog Error Tracking to collect crash logs, stack traces, and device state at the time of a crash. We use Firebase Performance Monitoring to collect performance traces and network request metrics. This data helps us identify and fix issues.
Crash collection is bundled under the analytics consent toggle — when you opt out of analytics, we stop collecting crash data as well.
Notifications
If you opt in via Settings, we use Firebase Cloud Messaging (FCM) to deliver push notifications to your device. On iOS, FCM hands off to Apple's Push Notification service (APNs). On Android, FCM is delivered through Google Play Services.
Notifications are organized into categories so you can choose which to receive. The Settings page in the App shows each available category with a description of what it sends; you can opt in or out of each independently.
Each notification contains:
- A short title and body describing what the notification is about
- A deep-link into the App to the relevant screen
Notifications do not contain your name, email, account identifier, or other personal identifiers.
We do not use notifications for advertising, marketing, or promotional offers.
You can turn any category on or off at any time in Settings → Notifications, or revoke notification permission entirely via your device's OS Settings. Once revoked, you will not receive further notifications from us until you re-grant permission.
Subscription Data
We use RevenueCat to manage subscriptions and in-app purchases. RevenueCat processes your purchase history, subscription status, and transaction identifiers to provide subscription functionality.
Advertising
Free-tier users may see advertisements within the App. Premium subscribers do not see advertisements. Ads are delivered through Playwire, which routes ad requests through a network of advertising and mediation partners. The partners that may bid on or deliver ads include:
- Playwire (mediation, yield management, consent management)
- AppLovin (MAX mediation, Ad Review creative quality monitoring)
- Google (Google Mobile Ads, AdMob, Google Ad Manager, User Messaging Platform)
- Meta Audience Network
- Unity Ads
- IronSource / LevelPlay
- Vungle (Liftoff)
- Chartboost
- InMobi
- Pangle (ByteDance)
- Moloco
- Smaato
- HyBid / BidMachine / Verve
- Ogury
- PubMatic (OpenWrap)
- Amazon Publisher Services
For the purpose of serving ads, these partners may receive:
- Your device advertising identifier (IDFA on iOS, AAID on Android). This is a device-level identifier, separate from your sign-in account, that you can reset or limit in your device's OS settings.
- A coarse, IP-derived approximate location (city-level), used for ad relevance and frequency capping. Precise GPS location is not requested or shared.
- Ad interaction events such as which ads were shown, clicked, or dismissed.
- Diagnostic and performance data about ad rendering (load time, fill rate, error reports). Some of this data may be associated with your advertising identifier.
Advertising partners are listed individually because Apple's App Store and Google Play require disclosure of every third-party SDK that may collect or share data. Each partner operates under its own privacy policy: Playwire (policy), AppLovin (policy), Google (policy), Meta (policy), Unity (policy), IronSource (policy), Vungle (policy), Chartboost (policy), InMobi (policy), Pangle (policy), Moloco (policy), Smaato (policy), BidMachine (policy), Ogury (policy), PubMatic (policy), Amazon Publisher Services (policy).
Your controls.
- iOS: When the App first requests it, you may decline tracking via Apple's App Tracking Transparency prompt. You can change this choice anytime in Settings → Privacy & Security → Tracking. You can also reset or limit the advertising identifier in Settings → Privacy & Security → Apple Advertising.
- Android: You can reset or delete the advertising identifier in Settings → Privacy → Ads. Deleting the identifier (Android 13+) prevents apps from receiving a stable identifier across sessions.
- European Union / EEA / UK: A consent prompt appears on first launch (delivered via Google's User Messaging Platform through Playwire's consent flow). You can withdraw or change consent later.
- Upgrade to remove ads: Subscribing to Premium removes all in-app advertisements while the subscription is active.
We do not target advertising to children. The App is not directed to users under 13 (or the equivalent age in your jurisdiction).
Locally Stored Data
The App stores user preferences (such as theme and accent color) and cached content locally on your device. This data is not transmitted to our servers.
How We Use Information
We use the information described above to:
- Authenticate you and provide login functionality
- Create and manage your account
- Maintain app security and prevent abuse
- Provide customer support (if you contact us)
- Improve the App through analytics and crash reporting
- Process subscriptions and manage entitlements
- Deliver notifications for categories you have opted in to
- Show advertisements to free-tier users via our advertising partners
What We Do Not Do
- We do not sell your personal information.
- We do not use your sign-in information (name, email, account identifier) for advertising profiling. Advertising partners receive your device-level advertising identifier (IDFA / AAID) which is separate from your account.
- We do not show advertisements to Premium subscribers.
- We do not target advertising to children.
- We do not access your contacts, photos, microphone, or precise location unless a feature clearly requires it and you grant permission.
Sharing of Information
We may share limited information only in these cases:
With Sign-In Providers
When you log in, the sign-in process is handled by Google or Apple. Their privacy practices are governed by their own policies.
With Service Providers
We use third-party services to operate the App. These providers may process limited data on our behalf under contractual obligations to protect it. Our service providers include:
- Google Firebase (authentication, analytics, crash reporting, performance monitoring, push notifications)
- PostHog (product analytics, error tracking, optional session recordings)
- Apple Push Notification service (APNs, used by Firebase to deliver iOS push notifications)
- Google Play Services (used by Firebase to deliver Android push notifications)
- RevenueCat (subscription management)
Each of these vendors processes data on our behalf under a data processing addendum — they may not use the data for their own purposes.
With Advertising Partners
Free-tier users may see ads delivered by Playwire and its mediation network. See the Advertising section above for the full list of partners and a description of what each receives. Premium subscribers do not see advertisements, and advertising partners receive no data tied to their session.
Legal Requirements
We may disclose information if required to comply with applicable laws, regulations, legal process, or enforceable governmental requests.
Data Retention
We retain account information only as long as needed to:
- Keep your account active, and
- Provide the App's functionality.
If you request deletion, we will take reasonable steps to delete or anonymize account information unless we are required to keep it for legal or security reasons. See Delete Your Account for the deletion paths.
Your Choices and Rights
Every user, regardless of region, can control:
- Analytics + crash reports. Toggle in Settings → Privacy. When off, no analytics events or crash logs are collected.
- Session recordings. Toggle in Settings → Privacy. Recordings require analytics to be on; disabling analytics also disables recordings.
- Personalized ads. In the European Economic Area, we present a Google User Messaging Platform consent prompt. You can change your choice anytime via the "Manage Ad Privacy" link in Settings → Account (free tier only). Premium subscribers see no ads at all.
- Push notifications. Per-category toggles in Settings → Notifications, and OS-level Notifications settings.
- Account information. Delete your account from the Account page in the App ("Delete Account" button), or follow the steps on the Delete Your Account page.
Depending on your location, you may additionally have rights to access, correct, or port the personal information we hold about you. Contact us using the "Contact Us" details below to exercise any of these.
California Residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act give you the following rights with respect to the personal information we collect about you:
- Right to know what personal information we collect, use, share, or sell. This Privacy Policy describes the categories of personal information we collect and the purposes for collection throughout the sections above.
- Right to delete personal information we hold about you. Use the "Delete Account" action on the Account page in the App.
- Right to correct inaccurate personal information. Contact us using the "Contact Us" details below.
-
Right to opt out of sale or sharing of personal
information. We do not sell your personal information. We do
"share" personal information for cross-context behavioral
advertising when you see ads in the free tier — advertising
partners may use information about your interactions to show you
relevant ads. To opt out of this sharing, either:
- Use Settings → Privacy in the App to disable analytics (which also stops the data flow that ad partners use for personalization), or
- Decline personalized ads in the consent prompt that appears the first time you open the App (delivered via Google's User Messaging Platform), or
- Subscribe to Premium — Premium subscribers see no ads and no data flows to advertising partners.
- Right to non-discrimination. We will not deny you the App, charge you a different price, or provide a different level of service because you exercised any of these rights.
Our analytics vendors (Firebase, PostHog, RevenueCat) act as service providers / processors under signed data processing addenda. They process the data only to provide their services to us — not for their own purposes — which is why first-party analytics is not a "sale" under CPRA.
We do not use IP-based geolocation to detect California users. California residents see the same Settings → Privacy controls as every other user; the rights above apply regardless of where the App detects you are.
Children's Privacy
The App is not designed to collect personal information from children. If you believe a child has provided personal information to us, please contact us and we will address it promptly.
Security
We take reasonable measures to protect account information from unauthorized access, alteration, or disclosure. No method of transmission or storage is 100% secure, but we work to protect your data using appropriate safeguards.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date and publish the updated policy at this URL.
Contact Us
Questions or requests regarding this Privacy Policy: