Skip to content

TROVY / Legal

Privacy
policy

This privacy policy describes how Trovy collects, uses, retains and protects your personal data. It applies to all Trovy services, including the web app, SDK, CLI, MCP server and associated websites. We are committed to handling your data transparently, in compliance with the General Data Protection Regulation (GDPR) and applicable Ivorian law.

Last updated : July 15, 2026[email protected]Côte d’Ivoire
Table of contents1. Data controller2. Data we collect3. Purposes and legal bases4. Artificial intelligence5. Data retention6. Sharing with third parties7. International transfers8. Security9. Cookies and trackers10. Your rights11. Minors12. Changes to this policy13. Contact

1. Data controller

The data controller for personal data collected through Trovy is Trovy, located in Abidjan, Côte d’Ivoire. For any question regarding the protection of your data, you can write to us at [email protected].

2. Data we collect

We only collect the data necessary to operate the service and improve your experience:

  • Account data: name, email address, hashed password, optional profile picture.
  • Payment data: processed directly by our providers (Stripe, Paystack, CinetPay, etc.); Trovy does not store your card numbers.
  • Usage data: features used, frequency of use, device type, browser, IP address, device identifiers.
  • User content: tasks, projects, comments, attachments and any other content you create or import into the service.
  • Integration data: OAuth credentials and access tokens for third-party services (e.g. GitHub) you choose to connect.
  • Cookies and trackers: see the dedicated section below.

3. Purposes and legal bases

Your data is processed for the following purposes:

  • Operating the service: performance of the contract you accepted by creating an account.
  • Product improvement, audience measurement and security: Trovy’s legitimate interest in providing a reliable and performant service.
  • Support and communication: performance of the contract and, where applicable, your consent for optional marketing communications.
  • Billing and accounting: applicable legal obligations.
  • Fraud prevention and legal compliance: legal obligations and legitimate interest.

4. Artificial intelligence

Trovy offers generative AI features (summaries, suggestions, task generation). Content you submit to these features is transmitted to our technical sub-processors (OpenAI, Anthropic, Google, etc.) through secure APIs.

These sub-processors process your content only to execute the request you initiated. Trovy does not enable model training on your data. Requests are retained for the time required to provide the response and to manage abuse, then deleted.

You can disable AI from your workspace settings. No critical feature depends on AI: you stay in control of your content.

5. Data retention

We retain your data while your account is active. Upon termination, your data is deleted within 30 days, unless legal obligations require otherwise (e.g. accounting retention of invoices).

Security and audit logs may be retained for up to 12 months for service security needs.

6. Sharing with third parties

Trovy does not sell or rent your personal data. We only share the data strictly necessary with:

  • Our technical sub-processors (hosting, database, email, payment, AI) governed by GDPR-compliant contractual agreements.
  • Competent authorities, upon legal request or to protect our rights and the safety of our users.
  • Third-party services you choose to connect (e.g. GitHub), only with your explicit consent.

7. International transfers

Your data may be hosted or processed outside your country of residence, including in the European Union and in the United States. Where required, we frame these transfers with the mechanisms provided by GDPR (standard contractual clauses, adequacy decisions).

8. Security

We implement appropriate technical and organizational measures to protect your data: encryption in transit (HTTPS) and at rest, password hashing, strict access control, access logging, encrypted backups and regular security testing.

Despite these measures, no system is entirely infallible. In the event of a data breach likely to affect your rights, we will inform you as soon as possible, in accordance with applicable law.

9. Cookies and trackers

Trovy uses cookies and similar trackers for:

  • Essential service operation (session, security) — always active.
  • Preferences (language, theme) — always active.
  • Anonymized audience measurement and product improvement — only enabled with your consent via the cookie banner.
  • Marketing — not used by Trovy at this time.

10. Your rights

You have at any time the right to access, rectify, erase, port, restrict and object to the processing of your data, as well as the right to define directives regarding the fate of your data after your death.

To exercise these rights, write to us at [email protected] with proof of identity. We respond within one month. If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the Côte d’Ivoire data protection authority (ARTCI) or with the supervisory authority of your country of residence.

11. Minors

Trovy is not intended for persons under 16 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us with data, contact us so we can delete it.

12. Changes to this policy

We may modify this policy to reflect legal or operational changes. Any material change will be communicated by email and via an in-app notification at least 30 days before it takes effect.

13. Contact

For any question about this policy or to exercise your rights, write to us at [email protected]. For any other request, [email protected].

Any question?

Our team is available for any clarification. Requests are handled quickly.

Contact support