Privacy
It stays on the device unless you share it
Trovva has no account and no server. There is nothing to sign in to, nothing to sign out of, and nothing of ours in the middle.
Sharing a household is the one thing that sends anything anywhere. It is off until you turn it on, it reaches only the people you add by Apple ID, and it goes through the iCloud account already on your phone rather than through us. Until you share one, the app makes no network requests at all.
What “household” means
A household in Trovva is a way of organising — a label on your own records — and, if you choose, the boundary of what you share. It is still not an account: there is nothing to join and no credential, and a forwarded link grants nobody anything. Somebody you have not added has an entirely separate set of records, and neither of you can see the other’s.
The word is easy to misread, so the app states the limit wherever it appears: during setup, in Settings, and on the About screen.
What is stored, and where
| What | Where |
|---|---|
| Entries, fields, tags, collections, checklist items, history, reminder rules | A SQLite database in the app's private storage |
| Photos and files you attach | Copied into the app's private storage, alongside the database |
| Theme, language, whether reminders are on, and whether you have finished setup | The same database |
| Which alerts are currently queued with the operating system | The same database — device-local, and rebuilt whenever it needs to be |
| A shared household's records and photographs, if you turn sharing on | A private zone in your own iCloud, readable by the people you added and nobody else. Nothing of ours is in the middle, and with sharing off this row does not apply |
The app’s private storage is exactly that: a place only Trovva can read, on your phone, removed with the app if you delete it.
What is not collected
No analytics. No crash reporting. No telemetry, advertising identifiers, or usage measurement. No third-party code that could collect any of those. Trovva does not know how many entries you have, and there is nowhere for it to say.
Reminders
Alerts are scheduled on the device itself. No push token is ever requested and no remote notification service is involved, which is why reminders keep working with no signal.
Your copy is yours
Settings → Backup writes an ordinary zip and hands it to the system share sheet. Trovva never sends it anywhere; where it goes is entirely your choice, and the records inside are plain, readable JSON you can open in a text editor.
Your photographs and files are in that file too, beside the records, so a backup is the whole of what you have saved rather than the half of it that is text.
Deleting really deletes
Ordinary deletion has two stages on purpose. Delete hides an entry from every screen but keeps it in Settings → Data, so you can change your mind. Permanently delete there removes it for real and unlinks the files attached to it. That cannot be undone, no backup is taken first, and the confirmation says both of those things.
There is one further path, kept deliberately separate: Erase all data removes everything — every entry, list, photo, file, reminder, collection, tag and history record, the examples if you added them, and your household name. Your theme, your language and whether reminders are switched on are what survive, because they describe this installation rather than your household.
Those are the only two destructive paths in Trovva. Both are reached only from Settings, both name what will happen before they do it, and neither takes a backup on your behalf — the erase screen offers to export one first, and says plainly that a backup carries your records as readable JSON, with your photos and files alongside them in an ordinary zip.
Permissions the app asks for
| Permission | When | Why |
|---|---|---|
| Notifications | When you first switch reminders on, or from Settings | To schedule alerts on the device itself |
| Photo library | When you tap Add photo | To copy the photo you pick into the entry |
Both are optional, and refusing either leaves the rest of the app working. Due dates still show inside the app without notification permission, and entries work perfectly well without photographs.
This site
The page you are reading is static files. It sets no cookies, loads nothing from anywhere else, runs no JavaScript, and has no analytics of any kind — which is why there is no consent banner: there is nothing to consent to.