Trovary Privacy Policy — English
1. About Trovary
Trovary lets people save YouTube links in Collections, organize those links, and share a Collection through a capability link. Trovary does not download, host, or provide its own player for YouTube videos.
This policy explains the information handled by the Trovary Android and iOS apps, Trovary's shared Collection website, and the backend services used to provide them.
2. Information we process
Account and authentication information
Account-based Collection features require sign-in. Trovary supports Google sign-in and, on iOS, Sign in with Apple. Authentication is handled by Supabase Auth and the selected identity provider. Depending on what the provider makes available, Supabase Auth may process a provider account identifier, email address, and limited profile or authentication metadata. Apple sign-in requests the email scope and may provide a private relay email. Trovary does not receive a Google or Apple password.
After Supabase sign-in, the app sends the one-time Apple authorization code to an authenticated Trovary backend. The backend exchanges and validates it with Apple without retaining the code. It encrypts the returned refresh token and stores it server-side, linked to the account, only for Apple authorization validation and account-deletion revocation. The token and Apple server credentials are not stored in the app.
Supabase assigns an account identifier that links an account to its owned Collections. Authentication session information is kept on the device so a session can be restored.
Collection and sharing information
Trovary stores Collection titles, optional descriptions, timestamps, included YouTube videos, and item order. A cached video record can include the YouTube video ID, title, thumbnail URL, channel name, and metadata-fetch time.
Reports, moderation, and device-local blocks
An anonymous viewer may report an active shared Collection using a predefined reason. Trovary stores internal Collection, ShareLink, and owner references, the reason, report status, and review/action times. It does not ask for reporter identity, free text, a device or advertising ID, a persistent fingerprint, the full shared URL, or the raw ShareLink token. A device-local block list stores opaque Collection/creator keys, a minimal display label, and block time and is not synced to an account. Sharing users also store the accepted Terms version and acceptance time.
Collections are private by default. If an owner enables sharing, Trovary creates a random ShareLink token and stores its enabled state and timestamps. The token is a capability: anyone with an enabled link can view the Collection title, optional description, video metadata, and ordering without signing in. Trovary does not put the token in Firebase Analytics.
YouTube links and metadata
The app validates a supported YouTube URL and extracts its 11-character video ID. The authenticated metadata backend receives the video ID, not the complete URL, and uses the YouTube Data API to request title, thumbnail, and channel information. Trovary caches that metadata to avoid unnecessary repeat API calls. Trovary does not download or host videos and does not provide a separate player. Opening a video takes the user to YouTube.
Received Collections stored on the device
A shared Collection can be saved without signing in. Received Collections are stored only in the app's local Drift database and are not synchronized to a Trovary account. A local record can contain the ShareLink token, Collection title and optional description, video IDs and metadata, save/open/sync times, and availability state. The token is sent to the public shared service when the app refreshes the saved Collection. Removing it, clearing app data, or uninstalling the app can remove that local data. In-app account deletion also clears every Received Collection and account cache on that device after server deletion succeeds. An email request cannot remotely erase local-only records on another device.
Support requests
About & Support can open the user's mail composer with a draft to aros.care@gmail.com. The draft may include app version/build, Android or iOS, OS/version, and device model. The user can review, edit, or remove everything before sending. Trovary does not send support data in the background.
If sent, Trovary receives the sender address, message, user-added attachments, and diagnostics left in the draft. The draft does not automatically include a Trovary user ID, login email, ShareLink token, Collection content, YouTube URL or video ID, advertising identifier, or location.
3. Firebase Analytics
Firebase Analytics is enabled in release builds and disabled in debug builds. Trovary records these product events:
collection_createdvideo_addedcollection_share_startedshared_collection_viewed (with a video count)shared_collection_savedreceived_collection_viewedshare_link_enabledshare_link_disabledshare_link_regenerated
Trovary does not add a ShareLink token, complete URL, YouTube URL or video ID, Collection title, free-form input, email address, or Supabase user ID to these events, and does not set an Analytics user ID.
The SDK can separately collect standard app, device, installation, session, lifecycle, interaction, and general-location information derived from a masked IP address. It assigns an app-instance identifier. Trovary disables automatic screen reporting and, on Android, Analytics advertising-ID collection and default ad-personalization signals. The SDK can still process other app, device, installation, and network information.
4. Firebase Crashlytics
Crashlytics is enabled in release builds and disabled in debug builds. It may process crashes and uncaught exceptions, stack traces, relevant app state, version/build, device and OS details, session or diagnostic data, and Firebase/Crashlytics installation identifiers. Firebase may associate Analytics breadcrumbs with a crash report. Trovary does not set an explicit Crashlytics user ID or attach developer-defined custom keys or logs.
5. Google AdMob and privacy choices
Trovary includes Google Mobile Ads and UMP for banner advertising only. It has no interstitial, rewarded, app open, or native ads. Production ads are disabled unless a release build explicitly enables them with a valid banner unit.
When ads are enabled, Google Mobile Ads may collect and share an IP address used for general location, app/ad interactions, diagnostics or performance information, advertising data, and device-, app-, or account-scoped identifiers for advertising, analytics, and fraud prevention. Ad serving can vary with region, privacy choices, Google settings, and Google's rules.
Android removes the AD_ID and AdServices Advertising ID, Attribution, and Topics permissions. iOS has no ATT prompt, tracking usage description, or explicit IDFA request. These settings limit certain identifiers but do not mean the SDK processes no identifiers or other data.
When required, UMP asks for privacy choices before ads initialize. If ads cannot be requested, Trovary does not initialize them. Where required, an in-app privacy options control lets users revisit their choices.
6. How we use information
- authenticate users and restore sessions
- create, organize, synchronize, and share Collections
- retrieve and cache YouTube metadata
- save and refresh Received Collections on a device
- protect public and authenticated endpoints from abuse
- understand feature use and improve reliability
- diagnose crashes and operational failures
- display banner ads when production advertising is enabled and permitted
- respond to support requests that a user chooses to send
Trovary does not use Collection titles, YouTube URLs/video IDs, ShareLink tokens, support content, login emails, or Supabase user IDs as custom Firebase Analytics event parameters.
7. Service providers and external services
- Supabase — authentication, PostgreSQL data, and Edge Functions
- Google — Google sign-in, Firebase Analytics, Crashlytics, AdMob, UMP, and the YouTube Data API
- Apple — Sign in with Apple on iOS
- YouTube — linked video service and metadata source
Providers may process information under their own terms, policies, retention settings, and legal obligations. Trovary does not add unrelated analytics or advertising vendors to shared Collection pages or this page.
8. Public links, network data, logs, and security
Anyone with an enabled ShareLink can open it without login. Treat a link as sensitive and disable or regenerate it if necessary. Hosting and service providers may process ordinary request metadata such as IP address, time, endpoint, status, and device/software information for delivery, reliability, and security.
Public and authenticated endpoint limits use per-instance salted hashes held in memory. They are not durable account logs, are discarded with the function instance, and inactive entries are pruned. Application error logs are designed not to contain raw tokens, authorization headers, emails, account IDs, YouTube API keys, or raw request bodies.
Trovary uses access controls, row-level security, authenticated endpoints, request validation, transport encryption, and rate limiting where appropriate. No technical measure guarantees absolute security.
9. Retention and deletion
- Account and owned Collections: kept while the account is active or as needed for the service. An authenticated user can choose Delete account in About & Support. The authenticated service deletes the current Auth user, and database relationships remove owned Collections, items, and ShareLinks. A user without app access can start a verified request at /delete-account, subject to legitimate legal/security retention.
- YouTube metadata cache: reusable records for public videos are not owned by or directly linked to one account and may remain after account or item deletion.
- Received Collections: remain only on the device until removed, app data is cleared, or the app is uninstalled. In-app deletion clears them on that device. An outside request cannot erase them remotely.
- Firebase and AdMob: Google controls SDK data retention under its policies and account settings.
- Apple authorization credential: the one-time code is not retained. The encrypted refresh token is kept only while needed for the Apple-linked account and is deleted with that account. In-app deletion revokes the Apple authorization before deleting the account.
- Support email: may be kept as reasonably needed to investigate, reply, maintain a support record, or meet legal obligations. A user may request deletion.
The public account deletion page explains both paths and starts an email request to aros.care@gmail.com. Trovary may ask for limited ownership verification. Do not send passwords, access/refresh tokens, ShareLinks, complete shared URLs, or YouTube URLs. A request email and minimal verification/completion record may be retained as reasonably needed for security, support, legal obligations, or documenting completion.
For an in-app Sign in with Apple deletion, Trovary first asks Apple to revoke the authorization and deletes the Auth user and related data only after Apple accepts the request. If the credential is missing or revocation is unavailable, the account and local data are not deleted, and the user can sign in with Apple again or retry. An outside request may require an additional verified Apple-authorization disconnection step.
10. User choices
Users choose whether to sign in, enable a ShareLink, save/remove a Received Collection, send support mail, permanently delete their Trovary account, and answer UMP choices where shown. Platform account, advertising, and privacy controls are also available. Disabling or regenerating a link cannot retract information someone already viewed or copied.
11. Children
Trovary is not designed or intentionally directed to children below the age at which they can independently consent to online data processing in their location. Trovary does not intentionally ask for a child's age. A parent or guardian may contact us if they believe a child provided account or support information.
12. International processing
Trovary and its providers may process information outside the user's country or region. Rules differ by location. Provider terms and safeguards apply; this policy does not promise that information remains in one country.
13. Changes to this policy
We may update this policy when features, providers, settings, or requirements change. We will update the date and publish the current version here. Material changes may also be communicated through the app or another appropriate method.
14. Contact
For privacy questions, support, or a deletion request, email aros.care@gmail.com.