trovePrivacy

Updated June 27, 2026

Your money's privacy,
clearly shown.

trove is a personal finance app. Your salary, your spending, your accounts — that's sensitive ground. This page explains exactly what we collect, what we do with it, and what we will never do. Plain language, no jargon, finish it in five minutes.

Our short version

  • We don't sell your data. Ever.
  • We don't read your transactions to target ads.
  • We don't train AI models on your personal financial data.
  • You can export everything and delete your account at any time.

01

What we collect

When you create a trove account and use the app, we collect three buckets of information:

Account information

Your name, email address, and a profile photo if you sign in with Google or Apple. We use this to identify your account across devices.

Financial information you enter

Transactions, balances, wallets, budgets, categories, and notes — the financial picture you build inside trove. This stays inside your account. We don't connect to your bank automatically; everything that ends up here, you put there.

Technical and usage information

Device model, OS version, app version, language, and crash logs. We use this to fix bugs and decide which platforms to support next.

We also collect anonymized in-app usage events through Google Firebase Analytics — which screens and features you open, and how the trove Pro upgrade flow performs (for example, when an upgrade prompt is shown, tapped, or dismissed). These events describe how the app is used, never the contents of your finances: no transaction amounts, balances, notes, or budgets are ever sent to analytics.

02

How we use it

We use your data to:

  • Sync your finances across the devices you sign in with.
  • Generate the charts, summaries, and budgets you see in the app.
  • Send transactional emails (receipts, password resets, security alerts).
  • Investigate bug reports you send us.
  • Improve the product based on aggregate, anonymized usage signals.

We do not use your data for advertising. We do not sell, rent, or lease it to third parties. We do not train AI models on the contents of your transactions, notes, or budgets.

03

Where it lives

Your data is stored on managed cloud infrastructure in Southeast Asia (primary region: Singapore). It's encrypted at rest with AES-256 and in transit with TLS 1.3. Daily backups are encrypted with separate keys and retained for 30 days.

A copy of your most recent data is also cached on your device so the app works offline. When you delete the app, that cache goes with it.

04

Who else sees it

We share data only with the service providers we need to run trove, and only the minimum amount required:

  • Cloud hosting — for storing and serving your data.
  • Authentication — Google Sign-In and Apple Sign-In verify your identity. They receive your sign-in request, not your financial data.
  • Payments — Apple App Store and Google Play handle subscriptions. We never see your card number.
  • Transactional email — for receipts and security alerts.
  • Crash reporting — only crash stack traces and device model. No transactions, no notes, no balances.
  • Analytics — Google Firebase Analytics receives anonymized usage and interaction events plus standard device information, so we can understand how features are used and improve them. It never receives the contents of your finances. See Firebase's privacy and security practices.

We may also disclose data if required by a valid legal order. If that ever happens and we're permitted to tell you, we will.

05

Your rights

You can, at any time:

  • Export everything you've entered as a CSV or JSON file.
  • Edit or delete individual transactions, wallets, or budgets.
  • Delete your account entirely from Settings → Account → Delete account. We remove your data from live systems within 7 days and from backups within 30 days.
  • Revoke Google or Apple sign-in access from your provider's account settings.
  • Email us to request a copy of all data we hold about you, or to ask us to correct anything that's wrong.

06

How we protect it

Production systems require multi-factor authentication and use short-lived access credentials. Database access is audit-logged. Sensitive fields use field-level encryption on top of disk encryption. We run dependency scans and a third-party security review at least once a year.

No system is unbreakable, and we won't pretend otherwise. If a breach ever affects your account, we'll notify you within 72 hours of confirming it, in line with applicable data-protection law.

07

Children

trove is not designed for, or directed at, anyone under 13. We don't knowingly collect data from children. If you believe a child has created an account, email us and we'll remove it.

08

Changes

We may update this policy as the product evolves. The current version always lives at this URL with the date you see at the top. For material changes, we'll notify you in the app and by email at least 14 days before they take effect.

09

Contact

Privacy questions, data requests, or anything that feels off — we want to hear about it.

Email[email protected]
ResponseWithin 5 business days

trove · A clearer view of your money.

© 2026 trove. All rights reserved.