Privacy Policy
Effective August 5, 2026
This Privacy Policy explains what data Trovetto collects, how it's used, and the rights you have over your information. It applies to the Trovetto mobile app, web companion, and any related services that link to this notice.
What we collect
When you create an account, we store the identifiers you supply (email address, username/handle, password hash, optional display name and avatar) plus authentication metadata needed to keep you signed in securely — device identifiers, session tokens, and the IP addresses we observe each refresh.
Anything you voluntarily add to Trovetto is stored on your behalf: items in your Finds, photos you attach, receipts you scan, binder captures, decks, trip plans, consultations, Want Trove alerts, marketplace listings, messages tied to negotiations, and posts you publish. Notifications use device push tokens you grant.
How we use it
We operate the service — showing your library, syncing across devices, running AI features when you initiate them, notifying you per your settings, fulfilling subscriptions and marketplace transactions, diagnosing crashes, measuring product engagement, securing the service, complying with law, and communicating service updates where permitted.
AI processing of photos
Photos you submit to AI features (scan-to-identify, receipt OCR, image search, care guides, similar items, deck recommendations, insurance notes, trip budgets) are processed by Trovetto's backend and our model partners (currently Ximilar for visual similarity and Google Gemini for vision and text). Processing happens only when you trigger the feature; we do not silently send your photos to AI providers. Each AI call is logged for billing and abuse detection.
Third-party subprocessors
We rely on the following subprocessors, each bound by their own data-processing agreement:
- Cloudflare R2 — photo and document storage
- Cloudflare Images — image variant pipeline
- Ximilar — visual similarity + catalog identification
- Google Gemini — vision and text AI
- Stripe — payments, payouts, marketplace escrow
- RevenueCat — IAP subscription management
- Postmark — transactional email
- Customer.io — lifecycle email and marketing
- Sentry — error reporting
- PostHog — product analytics (opt-out available in Settings)
- Branch.io — deep-link attribution
Marketplace data
When you list or buy, we share the minimum necessary information with the counterparty (your seller/buyer pseudonym, shipping address at the time of label purchase, dispute evidence when raised). Stripe handles cardholder data directly — Trovetto never stores raw card numbers.
Your rights
You can request export of your data at any time from Settings → Privacy & Safety → Download my data. You can delete your account from Settings → Account → Delete account; we provide a 24-hour grace period during which you can cancel the deletion, then we delete all personally identifiable information within 30 days while retaining anonymized aggregates and records the law requires us to keep (e.g. tax invoices).
If you are in a jurisdiction with applicable privacy rights (GDPR, UK GDPR, CCPA, LGPD, PIPEDA, or analogous laws), you can also request access, correction, restriction, portability, or objection by writing to privacy@trovetto.app. We will respond within the statutory deadline that applies.
Children
Trovetto is not designed for users under 13. If you believe a child has created an account, contact privacy@trovetto.app and we will investigate and delete the account.
Cookies and analytics
The web companion uses essential cookies for session management. PostHog product analytics use a first-party identifier we can rotate. You can disable analytics from Settings → Privacy & Safety → Analytics opt-out at any time.
Contact
Privacy questions and rights requests — privacy@trovetto.app.
Trovetto, Inc. — Florida, United States. Governing law: State of Florida. Disputes are resolved through binding arbitration except where prohibited by applicable consumer protection law.