Privacy Policy
Last updated: 2026-07-21
This policy explains how the TheoWorks marketing website (theoworks.io), our live browser demo (try.theoworks.io), and our download service (get.theoworks.io) handle personal data. It is written to meet the transparency requirements of the EU/UK General Data Protection Regulation (GDPR). It covers these three sites. The TheoWorks software itself is git-native: when you self-host it, your documents, requirements and repository content stay on your own infrastructure and are never sent to us.
1. Who we are (data controller)
The data controller (Verantwortlicher) for this website and the limited personal data described below is Monaco Labs GmbH, which operates the TheoWorks site. Its full legal and postal details are set out in our Impressum. If you have any question about this policy or how your data is handled, contact us at support@theoworks.io or through the contact form on our home page.
2. What we collect and why
We keep data collection to the minimum needed to understand how the site is found and used:
- Your email address, when you sign in to download TheoWorks. Downloading the self-hosted version requires you to sign in, and depending on how you sign in we receive and keep your email address. This is the main personal data we hold, and it is described in full in “Signing in to download TheoWorks” below. The live demo asks for nothing — see “The live demo”.
- Advertising & measurement (Google Ads). We use Google Ads with the gtag.js tag (Google Ads ID
AW-18412377215) to measure page views and advertising conversions — for example, to see whether a visit came from one of our ads. This may set cookies and process online identifiers such as your IP address. None of this runs until you actively consent via the cookie banner (see “Consent” below). - Your consent choice. When you accept or decline on the cookie banner, we store your choice in your browser's local storage under the key
tw-consent-v1(valuegrantedordenied). This is stored on your device only — it is not sent to us — and it exists so we can honour your choice and not re-prompt you on every visit. - Information you send us. If you fill in the enterprise contact form or email us, we receive the details you provide (such as your name, work email, company and message) so we can reply. We use this only to respond to and follow up on your enquiry.
We do not sell personal data, and we do not use the data collected here to build advertising profiles beyond what Google Ads measurement requires.
Product analytics on the marketing site
On the marketing site (theoworks.io) we run product analytics via PostHog to understand whether the site and the demo work — for example, how many visitors reach the live demo. It is cookieless: it sets no cookies and uses no local or session storage and no cross-site or cross-session identifier. It is anonymous: there is no account, no email, and no personal data in the events. It captures page views and explicit interaction events only — autocapture and session recording are disabled, so we record no page contents, keystrokes, or replays.
Who processes it, and where. Analytics data is processed by PostHog as our processor under a data processing agreement (DPA), hosted in the EU (PostHog Cloud EU, Frankfurt). PostHog is named under “Third parties and international transfers” below.
Your IP address. As with any request over the internet, the request carries your IP address so the response can reach you, so it is transmitted to PostHog in the EU — but on our EU project it is discarded and not stored. We do not keep a log of it against these analytics events.
Legal basis. Our lawful basis is legitimate interest (GDPR Article 6(1)(f)) in understanding whether the site and demo work. Because this analytics stores nothing on your device, it is outside the Google Ads Consent Mode v2 cookie banner: that banner governs Google Ads measurement, which stays off until you accept it, whereas this cookieless analytics runs without it because it sets nothing on your device.
3. The live demo (try.theoworks.io)
We offer a free, zero-install live demo of TheoWorks at try.theoworks.io, where you can edit a sample project and run a real build.
The demo is zero-signup. There is no account, no sign-in and no email for the demo. We do not ask who you are, and we collect no personal data to let you in — you open the page and you are in the editor. (Downloading the software is different, and does require a sign-in — see the next section.)
- The demo sets no cookies and loads no third-party scripts. There is no advertising and no tracking on
try.theoworks.io. The cookie banner and the Google Ads measurement described below apply to the marketing site, not to the demo. - Your edits stay in your browser. The demo keeps your working copy in your browser's local storage, under
theoworks.trial.workingcopy.v1(andtheoworks.trial.welcome.dismissed.v1, which just remembers that you dismissed the welcome note). This is stored on your device only. “Reset demo”, or clearing this site's storage in your browser, removes it. - When you press Build, the text you have typed is sent to our build service. This is the one thing the demo sends us, and it is what makes the build a real one rather than a canned animation. Your edited copy of the sample project is sent to a build service running in the EU (Amazon Web Services, Frankfurt), which builds it in a temporary working directory, returns the result to your browser, and deletes that directory immediately afterwards. It is processed automatically. We do not keep a copy of it, and it is not reviewed, reused, or used to train anything. As with any request over the internet, the request carries your IP address so the response can reach you.
- What we log.We do not run access logging on the demo's build service, so we do not keep a log of your IP address. The service does record technical diagnostics — mainly, when a build fails, the error it failed with — so that we can find and fix the failure. Because a build error message can quote the line of text that caused it, a short fragment of what you typed can appear in that diagnostic record. These records are kept for 30 days and then deleted, and are used only to fix the demo. They are not linked to you, not used to identify you, and not used for marketing.
- Legal basis. Our legitimate interest (GDPR Article 6(1)(f)) in operating, securing and fixing the demo you have chosen to use.
- Your rights. Because the demo has no account, no email and no identifier for you, there is no demo record of you for us to look up, correct, export or delete. (If you have signed in to download TheoWorks, we do hold a record from that — see the next section and “Your rights” below.)
4. Signing in to download TheoWorks (get.theoworks.io)
To download the self-hosted version of TheoWorks, you need to sign in. This is the main place where we collect and keep your email address, and it is separate from the live demo, which asks for nothing.
How you can sign in. Two alternatives:
- With an email address and password. You create an account with us directly. We send a verification code to your email address to confirm it is yours.
- Continue with Google. You choose Google on the sign-in page and authenticate with Google directly; Google then confirms who you are and tells us your email address, which we use to sign you in. We never see your Google password, and we do not receive access to your Google account beyond your basic profile and email. Google is a US-based provider — see “Third parties and international transfers” below.
What we keep, and where. Signing in — whether with an email and password or with Google — creates or uses an account for you in our identity service (Amazon Cognito), hosted in the EU (Frankfurt). That account holds your email address and an internal account identifier. If you hold a paid licence, we also keep a record of that entitlement, linked to your account identifier.
Why we collect it, and what we use it for. We use your email address only to sign you in and authenticate your download — to confirm who you are so you can access the software, and, if you hold a paid licence, to check your entitlement. We do not use it for marketing of any kind. Our legal basis is Article 6(1)(b) of the GDPR — processing necessary to provide the download service you have asked for.
Retention. We keep your download account and email address for as long as the account is in use. If an account is inactive for 6 months, we permanently delete it and the email address it holds. You can also ask us to delete it sooner at any time (see “Your rights” below).
Your rights. Unlike the demo, this is a record of you, and all of the rights in “Your rights” below apply to it in full. You can ask us to access, correct, export or delete your account and your email address at any time by emailing support@theoworks.io.
Buying a plan: your purchase email
When you buy a TheoWorks plan, we send a one-time purchase email to the address you enter at checkout. It delivers your licensing information — what you need to activate and manage your licence — and confirms what you bought. This is a service message required to complete your purchase (GDPR Article 6(1)(b), performance of a contract).
It is not marketing. We do not add your checkout email to any marketing or product-update mailing list — the purchase email and any future product updates are two different relationships, and buying a plan does not opt you into the second. The email contains no card details; we never see or store your card information.
Payments and purchases
How payment is taken. When you buy a TheoWorks plan, your payment is handled by Stripe, our payment processor. You are taken to a Stripe-hosted checkout page to enter your payment details. Your card and payment-instrument details are entered on Stripe's own page and go directly to Stripe — they never pass through, and are never seen or stored by, TheoWorks or our servers. We do not run any card-entry code on our own site.
What Stripe receives. To take your payment, Stripe receives your name, the email address you enter at checkout, your billing address, and your payment-instrument details (for example, your card number). Stripe handles this as our payment processor under its own privacy policy — see Stripe's Privacy Policy. Where Stripe processes this data, and the safeguards that apply to any transfer of it outside the EU/UK, are set out under {{STRIPE_TRANSFER_BASIS}}.
What TheoWorks keeps. From a completed purchase we store only what we need to give you the plan you bought and to keep a lawful record of the sale: a customer identifier and a subscription identifier from Stripe, the plan (tier), the number of seats, and the billing period. We never receive or store your card number or any other payment-instrument data.
This is separate from marketing and from our download contacts. The email you enter at checkout is used to perform your purchase and to send your one-time purchase email (see “Buying a plan: your purchase email”). It is not added to any marketing, product-update, or download-lead list. The purchase relationship and any marketing contact are kept distinct.
Retention. We keep the purchase and sale records described above for {{PURCHASE_RETENTION}}, because tax and accounting law requires us to keep records of a sale for a set period. This is separate from your download account (see “Signing in to download TheoWorks”), which has its own retention.
Legal basis. We process your purchase data to perform your contract with you (GDPR Article 6(1)(b)); we keep the sale and invoicing records to meet our legal obligations (Article 6(1)(c)).
5. Consent
We use Google Consent Mode v2. When the page loads, all Google consent signals — ad_storage, analytics_storage, ad_user_data and ad_personalization — default to denied. Nothing is read from or written to your device for advertising or analytics until you choose.
A cookie banner asks you to Accept or Decline. Declining is as easy as accepting, and if you do nothing, measurement stays off.
Withdrawing or changing your consent. Your choice is remembered by the tw-consent-v1value in your browser's local storage. You can withdraw or change it at any time by clearing that stored value (or clearing this site's cookies and site data in your browser settings) — the banner then reappears on your next visit so you can choose again. You can also block or delete cookies directly in your browser at any time. Withdrawing consent does not affect the lawfulness of processing that happened while consent was in place.
6. Cookies and similar storage
- Google Ads cookies. Set only after you accept, to measure ad performance and conversions and to reduce duplicate measurement. These are managed by Google.
- Consent-choice storage. The
tw-consent-v1entry in local storage records whether you accepted or declined. It is strictly functional (it makes your choice stick) and is stored on your device only. - The live demo.
try.theoworks.iosets no cookies. It stores your demo working copy in your browser's local storage (see “The live demo”); that stays on your device. - Sign-in cookies. When you sign in to download TheoWorks, we set a short-lived cookie during sign-in and a session cookie afterwards, so you stay signed in. These are strictly necessary for the sign-in to work, and they expire on their own.
7. Third parties and international transfers
When you consent, advertising and measurement data is processed by Google (Google Ads / gtag.js) as an independent processor and/or controller under its own terms. See Google's Privacy Policy for details of how Google handles this data.
Google is a US-based provider, so consented data may be transferred to and processed in the United States and other countries outside the EU/UK. Where that happens, transfers rely on appropriate safeguards — principally the European Commission's Standard Contractual Clauses (SCCs) together with Google's supplementary measures.
The live demo's build service runs on Amazon Web Services in the EU (Frankfurt) region, which acts as our processor. The text you submit for a build is processed there and is not transferred outside the EU.
Our sign-in and accounts are handled by Amazon Cognito (Amazon Web Services), acting as our processor, in the EU (Frankfurt). If you choose Continue with Google, you authenticate with Google directly under its privacy policy, and it tells us who you are; we never receive your Google password. See Google's Privacy Policy. Google is a US-based provider; we never see your Google password and do not receive access to your Google account beyond your basic profile and email.
Payments are handled by Stripe (Stripe Payments Europe / Stripe, Inc.), acting as our payment processor. When you buy a plan you enter your card details on Stripe's own hosted checkout page; we never receive or store them. See Stripe's Privacy Policy and “Payments and purchases” above.
8. Legal basis for processing
Our legal basis for advertising and measurement (Google Ads) is your consent (GDPR Article 6(1)(a)), which you give through the cookie banner and can withdraw at any time. Where you contact us, we process your details on the basis of our legitimate interest in responding to your enquiry (Article 6(1)(f)), or to take steps at your request prior to entering a contract (Article 6(1)(b)). The live demo collects no personal data to enter. Our basis for processing what you submit for a build, and the technical diagnostics that come out of it, is our legitimate interest (Article 6(1)(f)) in operating, securing and fixing the demo (see section 3).
9. Data retention
Google retains advertising and conversion measurement data according to its own retention policies; we do not hold a separate copy of it. Your consent-choice value stays in your browser's local storage until you clear it. Enquiry details you send us are kept only as long as needed to handle your request and any reasonable follow-up, after which they are deleted. The live demo keeps no record of you, so there is nothing to retain; your demo working copy stays in your browser until you reset the demo or clear the site's storage. The build service's technical diagnostics are kept for 30 days and then deleted (see section 3). Accounts created when you sign in to download TheoWorks are kept while in use and permanently deleted after 6 months of inactivity, or sooner on request (see section 4).
Purchase and sale records created when you buy a plan are kept for {{PURCHASE_RETENTION}} to meet tax and accounting obligations (see “Payments and purchases”).
10. Your rights
If you are in the EU/UK, you have the right to:
- Access the personal data we hold about you;
- Rectification of inaccurate or incomplete data;
- Erasure of your data (“right to be forgotten”);
- Restriction of processing;
- Objection to processing;
- Portability — to receive your data in a portable format;
- Withdraw consent at any time, without affecting processing already carried out (see “Consent” above).
To exercise any of these rights, email us at support@theoworks.io. You also have the right to lodge a complaint with your local data protection supervisory authority if you believe your data has been handled improperly.
11. Contact
Questions about this policy or your data? Email support@theoworks.io or use the contact form. This policy was last updated on 2026-07-21.