Privacy
What Trovva keeps, and where it goes
Trovva has no account and no server. There is nothing to sign in to, nothing to sign out of, and nothing of ours in the middle.
Until you share a household, Trovva itself makes no network requests. A copy of your records leaves the phone only when you send one somewhere, or when your phone’s own backup to Apple includes it. Both are described below. This page is about the iPhone and iPad app.
What “household” means
A household in Trovva is a way of organising — a label on your own records — and, if you choose, the boundary of what you share. It is still not an account: there is nothing to join and no credential, and a forwarded link grants nobody anything. Somebody you have not added has an entirely separate set of records, and neither of you can see the other’s.
What Trovva stores on the phone
| What | Where |
|---|---|
| Entries, fields, tags, collections, lists, history and reminders | A database in Trovva's private storage on the phone |
| Photos and files you add | Copied into the same private storage. A photo picked with Add photo is normally saved again, made smaller if it is large; a file, or anything sent with another app's Share button, is kept as it arrived |
| Something you sent to Trovva with another app's Share button, before you review it | A folder only Trovva can read. It stays there until you save it as an entry or discard it, and Erase all data removes it |
| A backup or handover you made, after the share sheet closes | Trovva's temporary storage, until iOS clears it or you erase all data. It is not sent anywhere from there |
| Theme, language, whether reminders are on, and which alerts are queued | The same database |
Trovva does not analyse photos or read the details stored inside them. A picture can still carry details its camera wrote into it, such as where it was taken, and those may travel with the picture wherever you send it.
When a copy leaves your phone
Household sharing, if you choose it. It is off until you turn it on, and you can turn it off again. Your records, photos and files go to a private area of your own iCloud, stored by Apple, and reach the people you add by Apple ID and nobody else. Their phones fetch changes when they open Trovva, not in the background. Turning sharing off stops further changes; it does not take back what the others already have, which stays with them as a household of their own. Sharing is not a backup: lose every phone and what was never exported is gone.
A backup you export. Settings → Backup writes a file and hands it to the share sheet, and where it goes is your choice. Your records are inside as readable JSON. Photos and files are beside them in an ordinary zip, as long as they are on this phone: one that is missing is not invented, and Trovva tells you how many it could not find.
A handover. Settings → Household handover writes one readable file of the records you tick, with their photographs inside it, for a new tenant or a house sitter. Nothing is selected until you select it. The file fetches nothing from the internet when it is opened, but it is not encrypted, and it is not a backup: it is part of a household on one day.
Opening a file you attached. A PDF or a document opens in Quick Look, inside Trovva. Nothing is copied to show it, and Trovva marks its own copy read-only so nothing writes back into it. Quick Look has its own Share button; if you use it to send the file to another app, what that app does with it is up to that app.
Opening a saved link hands it to your browser, which then loads the page. Inviting someone to a household sends the invitation link the way you choose.
Your phone’s own backup. Trovva’s storage is included in iCloud Backup and in backups to a computer, if you use them. Those are Apple’s, governed by your phone’s settings; Trovva cannot see them or switch them off.
Deleting, and what it reaches
Delete hides an entry from every screen but keeps it in Settings → Data, so you can change your mind. Permanently delete there removes it from this phone, with its photos and files. That cannot be undone, and no backup is taken first.
Removing a photo or file from an entry deletes it from this phone straight away. Removing a history note clears its words from the entry.
Erase all data, in Settings, removes from this phone every entry, list, photo, file, reminder, collection, tag and history record, anything waiting to be reviewed from the Share button, the backups and handovers left in temporary storage, the examples if you added them, and your household name. Your theme, colours, language and whether reminders are on are kept, because they describe this phone rather than your household. The erase screen offers to export a backup first.
Adding a photo or file, or choosing a backup to restore, makes a temporary copy in Trovva’s storage while Trovva reads it. Trovva deletes that copy once the photo or file is saved or the restore ends, however it ends, and finishes the job the next time it opens if it was interrupted. The file you chose stays where it was.
Every one of these acts on this phone, and means Trovva no longer keeps or shows what was removed. Like most apps, it does not overwrite the storage that held it. None of them reaches:
- a backup or handover you have already exported, wherever you put it;
- your phone’s backup to iCloud or a computer;
- in a shared household, everything the others already have. Deletions and removed notes are passed on to their phones when they next open Trovva. But a removed photo or file, or a permanently deleted entry, can remain in the household’s iCloud storage, and Erase all data removes nothing from iCloud or from anyone else’s phone.
Permissions the app asks for
| Permission | When | Why |
|---|---|---|
| Notifications | When you choose to allow them, on the Reminders tab or in Settings → Notifications | To schedule alerts on the phone itself |
| Photo library | When you tap Add photo | To copy the photo you pick into the entry |
Both are optional, and refusing either leaves the rest of the app working. Due dates still show inside the app without notification permission. Adding a file uses the system’s own file picker, which hands Trovva only the file you choose. Trovva does not ask to use the camera.
What Trovva collects
Nothing. The app contains no analytics, no crash reporting, no advertising and no usage measurement of its own, and it never asks for a push notification token. Trovva does not know how many entries you have, and there is nowhere for it to say.
Reminders are scheduled on the phone itself, which is why they keep working with no signal.
Buying Trovva
Trovva is bought from the App Store, so the purchase is a transaction with Apple: Apple takes the payment and handles refunds. Apple gives us sales figures by country, not who bought the app. If you have chosen, in your phone’s settings, to share analytics with app developers, Apple may also give us usage and crash information about the app. That is Apple’s reporting, under Apple’s privacy terms, and paying for the app does not change what the app itself collects.
This site
The page you are reading is static files, served by Vercel, a hosting company. Like any web host, Vercel receives the requests your browser makes in order to answer them. The site sets no cookies, loads nothing from anywhere else, and has no analytics of any kind — which is why there is no consent banner: there is nothing to consent to.
It runs one small script, and only one. It remembers which of the two colour schemes you picked on the homepage, in this browser, on this device. Nothing about that is sent anywhere, and it is not a cookie: it is a single stored value that never leaves the machine you are reading on. Clearing your browser’s site data forgets it.
Questions about this page can go to the address on the support page.
Trovva