Trovary

Privacy Policy

Effective August 21, 2026 · Last updated August 24, 2026

This English version is canonical. The Korean translation below is provided for convenience.

Trovary Privacy Policy — English

1. About Trovary

Trovary lets people save YouTube links in Collections, organize those links, and share a Collection through a capability link. Trovary does not download, host, or provide its own player for YouTube videos.

This policy explains the information handled by the Trovary Android and iOS apps, Trovary's shared Collection website, and the backend services used to provide them.

2. Information we process

Account and authentication information

Account-based Collection features require sign-in. Trovary supports Google sign-in and, on iOS, Sign in with Apple. Authentication is handled by Supabase Auth and the selected identity provider. Depending on what the provider makes available, Supabase Auth may process a provider account identifier, email address, and limited profile or authentication metadata. Apple sign-in requests the email scope and may provide a private relay email. Trovary does not receive a Google or Apple password.

After Supabase sign-in, the app sends the one-time Apple authorization code to an authenticated Trovary backend. The backend exchanges and validates it with Apple without retaining the code. It encrypts the returned refresh token and stores it server-side, linked to the account, only for Apple authorization validation and account-deletion revocation. The token and Apple server credentials are not stored in the app.

Supabase assigns an account identifier that links an account to its owned Collections. Authentication session information is kept on the device so a session can be restored.

Collection and sharing information

Trovary stores Collection titles, optional descriptions, timestamps, included YouTube videos, and item order. A cached video record can include the YouTube video ID, title, thumbnail URL, channel name, and metadata-fetch time.

Reports, moderation, and device-local blocks

An anonymous viewer may report an active shared Collection using a predefined reason. Trovary stores internal Collection, ShareLink, and owner references, the reason, report status, and review/action times. It does not ask for reporter identity, free text, a device or advertising ID, a persistent fingerprint, the full shared URL, or the raw ShareLink token. A device-local block list stores opaque Collection/creator keys, a minimal display label, and block time and is not synced to an account. Sharing users also store the accepted Terms version and acceptance time.

Collections are private by default. If an owner enables sharing, Trovary creates a random ShareLink token and stores its enabled state and timestamps. The token is a capability: anyone with an enabled link can view the Collection title, optional description, video metadata, and ordering without signing in. Trovary does not put the token in Firebase Analytics.

YouTube links and metadata

The app validates a supported YouTube URL and extracts its 11-character video ID. The authenticated metadata backend receives the video ID, not the complete URL, and uses the YouTube Data API to request title, thumbnail, and channel information. Trovary caches that metadata to avoid unnecessary repeat API calls. Trovary does not download or host videos and does not provide a separate player. Opening a video takes the user to YouTube.

Received Collections stored on the device

A shared Collection can be saved without signing in. Received Collections are stored only in the app's local Drift database and are not synchronized to a Trovary account. A local record can contain the ShareLink token, Collection title and optional description, video IDs and metadata, save/open/sync times, and availability state. The token is sent to the public shared service when the app refreshes the saved Collection. Removing it, clearing app data, or uninstalling the app can remove that local data. In-app account deletion also clears every Received Collection and account cache on that device after server deletion succeeds. An email request cannot remotely erase local-only records on another device.

Support requests

About & Support can open the user's mail composer with a draft to aros.care@gmail.com. The draft may include app version/build, Android or iOS, OS/version, and device model. The user can review, edit, or remove everything before sending. Trovary does not send support data in the background.

If sent, Trovary receives the sender address, message, user-added attachments, and diagnostics left in the draft. The draft does not automatically include a Trovary user ID, login email, ShareLink token, Collection content, YouTube URL or video ID, advertising identifier, or location.

3. Firebase Analytics

Firebase Analytics is enabled in release builds and disabled in debug builds. Trovary records these product events:

  • collection_created
  • video_added
  • collection_share_started
  • shared_collection_viewed (with a video count)
  • shared_collection_saved
  • received_collection_viewed
  • share_link_enabled
  • share_link_disabled
  • share_link_regenerated

Trovary does not add a ShareLink token, complete URL, YouTube URL or video ID, Collection title, free-form input, email address, or Supabase user ID to these events, and does not set an Analytics user ID.

The SDK can separately collect standard app, device, installation, session, lifecycle, interaction, and general-location information derived from a masked IP address. It assigns an app-instance identifier. Trovary disables automatic screen reporting and, on Android, Analytics advertising-ID collection and default ad-personalization signals. The SDK can still process other app, device, installation, and network information.

4. Firebase Crashlytics

Crashlytics is enabled in release builds and disabled in debug builds. It may process crashes and uncaught exceptions, stack traces, relevant app state, version/build, device and OS details, session or diagnostic data, and Firebase/Crashlytics installation identifiers. Firebase may associate Analytics breadcrumbs with a crash report. Trovary does not set an explicit Crashlytics user ID or attach developer-defined custom keys or logs.

5. Google AdMob and privacy choices

Trovary includes Google Mobile Ads and UMP for banner advertising only. It has no interstitial, rewarded, app open, or native ads. Production ads are disabled unless a release build explicitly enables them with a valid banner unit.

When ads are enabled, Google Mobile Ads may collect and share an IP address used for general location, app/ad interactions, diagnostics or performance information, advertising data, and device-, app-, or account-scoped identifiers for advertising, analytics, and fraud prevention. Ad serving can vary with region, privacy choices, Google settings, and Google's rules.

Android removes the AD_ID and AdServices Advertising ID, Attribution, and Topics permissions. iOS has no ATT prompt, tracking usage description, or explicit IDFA request. These settings limit certain identifiers but do not mean the SDK processes no identifiers or other data.

When required, UMP asks for privacy choices before ads initialize. If ads cannot be requested, Trovary does not initialize them. Where required, an in-app privacy options control lets users revisit their choices.

6. How we use information

  • authenticate users and restore sessions
  • create, organize, synchronize, and share Collections
  • retrieve and cache YouTube metadata
  • save and refresh Received Collections on a device
  • protect public and authenticated endpoints from abuse
  • understand feature use and improve reliability
  • diagnose crashes and operational failures
  • display banner ads when production advertising is enabled and permitted
  • respond to support requests that a user chooses to send

Trovary does not use Collection titles, YouTube URLs/video IDs, ShareLink tokens, support content, login emails, or Supabase user IDs as custom Firebase Analytics event parameters.

7. Service providers and external services

  • Supabase — authentication, PostgreSQL data, and Edge Functions
  • Google — Google sign-in, Firebase Analytics, Crashlytics, AdMob, UMP, and the YouTube Data API
  • Apple — Sign in with Apple on iOS
  • YouTube — linked video service and metadata source

Providers may process information under their own terms, policies, retention settings, and legal obligations. Trovary does not add unrelated analytics or advertising vendors to shared Collection pages or this page.

8. Public links, network data, logs, and security

Anyone with an enabled ShareLink can open it without login. Treat a link as sensitive and disable or regenerate it if necessary. Hosting and service providers may process ordinary request metadata such as IP address, time, endpoint, status, and device/software information for delivery, reliability, and security.

Public and authenticated endpoint limits use per-instance salted hashes held in memory. They are not durable account logs, are discarded with the function instance, and inactive entries are pruned. Application error logs are designed not to contain raw tokens, authorization headers, emails, account IDs, YouTube API keys, or raw request bodies.

Trovary uses access controls, row-level security, authenticated endpoints, request validation, transport encryption, and rate limiting where appropriate. No technical measure guarantees absolute security.

9. Retention and deletion

  • Account and owned Collections: kept while the account is active or as needed for the service. An authenticated user can choose Delete account in About & Support. The authenticated service deletes the current Auth user, and database relationships remove owned Collections, items, and ShareLinks. A user without app access can start a verified request at /delete-account, subject to legitimate legal/security retention.
  • YouTube metadata cache: reusable records for public videos are not owned by or directly linked to one account and may remain after account or item deletion.
  • Received Collections: remain only on the device until removed, app data is cleared, or the app is uninstalled. In-app deletion clears them on that device. An outside request cannot erase them remotely.
  • Firebase and AdMob: Google controls SDK data retention under its policies and account settings.
  • Apple authorization credential: the one-time code is not retained. The encrypted refresh token is kept only while needed for the Apple-linked account and is deleted with that account. In-app deletion revokes the Apple authorization before deleting the account.
  • Support email: may be kept as reasonably needed to investigate, reply, maintain a support record, or meet legal obligations. A user may request deletion.

The public account deletion page explains both paths and starts an email request to aros.care@gmail.com. Trovary may ask for limited ownership verification. Do not send passwords, access/refresh tokens, ShareLinks, complete shared URLs, or YouTube URLs. A request email and minimal verification/completion record may be retained as reasonably needed for security, support, legal obligations, or documenting completion.

For an in-app Sign in with Apple deletion, Trovary first asks Apple to revoke the authorization and deletes the Auth user and related data only after Apple accepts the request. If the credential is missing or revocation is unavailable, the account and local data are not deleted, and the user can sign in with Apple again or retry. An outside request may require an additional verified Apple-authorization disconnection step.

10. User choices

Users choose whether to sign in, enable a ShareLink, save/remove a Received Collection, send support mail, permanently delete their Trovary account, and answer UMP choices where shown. Platform account, advertising, and privacy controls are also available. Disabling or regenerating a link cannot retract information someone already viewed or copied.

11. Children

Trovary is not designed or intentionally directed to children below the age at which they can independently consent to online data processing in their location. Trovary does not intentionally ask for a child's age. A parent or guardian may contact us if they believe a child provided account or support information.

12. International processing

Trovary and its providers may process information outside the user's country or region. Rules differ by location. Provider terms and safeguards apply; this policy does not promise that information remains in one country.

13. Changes to this policy

We may update this policy when features, providers, settings, or requirements change. We will update the date and publish the current version here. Material changes may also be communicated through the app or another appropriate method.

14. Contact

For privacy questions, support, or a deletion request, email aros.care@gmail.com.

Trovary 개인정보처리방침 — 한국어

이 문서는 영어 정본의 한국어 번역입니다. 해석상 차이가 있으면 영어 정본이 우선합니다.

1. Trovary 소개

Trovary는 YouTube 링크를 Collection에 저장·정리하고 capability 링크로 공유할 수 있게 하는 서비스입니다. Trovary는 YouTube 동영상을 다운로드하거나 자체 호스팅하지 않으며 자체 player를 제공하지 않습니다.

이 방침은 Trovary Android/iOS 앱, shared Collection 웹사이트 및 이를 제공하는 backend service에서 처리하는 정보를 설명합니다.

2. 처리하는 정보

계정 및 인증 정보

계정 기반 Collection 기능에는 로그인이 필요합니다. Trovary는 Google 로그인과 iOS Apple 로그인을 지원합니다. Supabase Auth와 선택한 인증 제공자는 제공자 계정 식별자, 이메일 주소, 제한된 profile/authentication metadata를 처리할 수 있습니다. Apple 로그인은 email scope를 요청하며 비공개 relay email을 제공할 수 있습니다. Trovary는 Google/Apple password를 받지 않습니다. Supabase account identifier는 owned Collection과 연결되고 session 정보는 복구를 위해 기기에 보관됩니다.

Supabase 로그인 후 앱은 일회용 Apple authorization code를 authenticated Trovary backend로 보냅니다. Backend는 code를 Apple과 교환·검증한 뒤 보관하지 않습니다. 반환된 refresh token은 암호화하여 account와 연결한 server-side 저장소에 보관하고 Apple 승인 확인과 계정 삭제 시 revoke에만 사용합니다. Token과 Apple server credential은 앱에 저장하지 않습니다.

Collection 및 공유 정보

Trovary는 Collection 제목, 선택적 설명, timestamp, 포함된 YouTube 영상과 item 순서를 저장합니다. Cached video record에는 YouTube video ID, 제목, thumbnail URL, channel name, metadata 조회 시각이 포함될 수 있습니다.

Collection은 기본 비공개입니다. 소유자가 공유를 활성화하면 무작위 ShareLink token, 활성 상태와 timestamp를 저장합니다. 활성 link를 가진 사람은 로그인 없이 Collection 제목, 선택적 설명, video metadata와 순서를 볼 수 있습니다. Token은 Firebase Analytics에 보내지 않습니다.

신고, moderation 및 기기 내 차단

익명 열람자는 활성 공유 컬렉션을 미리 정한 이유로 신고할 수 있습니다. Trovary는 내부 Collection·ShareLink·소유자 참조, 신고 이유, 처리 상태 및 검토·조치 시각을 저장합니다. 신고자 신원, 자유 입력, 기기·광고 ID, 장기 fingerprint, 전체 공유 URL 또는 원본 ShareLink token은 수집하지 않습니다. 기기 내 차단 목록은 불투명한 Collection/작성자 key, 최소 표시명과 차단 시각을 저장하며 계정과 동기화되지 않습니다. 공유 사용자의 동의한 약관 버전과 동의 시각도 서버에 저장됩니다.

YouTube 링크 및 metadata

앱은 지원되는 YouTube URL을 검증하고 11자 video ID를 추출합니다. Authenticated metadata backend는 전체 URL이 아니라 video ID를 받아 YouTube Data API에서 제목, thumbnail, channel 정보를 요청하고 불필요한 반복 호출을 막기 위해 cache합니다. Trovary는 영상을 다운로드·호스팅하지 않고 별도 player를 제공하지 않습니다. 영상을 열면 YouTube로 이동합니다.

기기에 저장되는 Received Collections

Shared Collection은 로그인 없이 저장할 수 있습니다. Received Collections는 local Drift database에만 저장되며 Trovary 계정과 동기화되지 않습니다. ShareLink token, 제목/설명, video ID/metadata, 저장·열람·동기화 시각과 접근 상태를 포함할 수 있습니다. 새로고침할 때 token을 public shared service로 보냅니다. 사용자가 제거하거나 app data를 지우거나 uninstall하면 local data가 삭제될 수 있습니다. 앱 내 계정 삭제는 server 삭제 성공 후 해당 기기의 Received Collection과 계정 cache를 지웁니다. 이메일 요청은 다른 기기의 local-only data를 원격 삭제할 수 없습니다.

문의 메일

About & Support는 사용자의 mail composer에서 aros.care@gmail.com 앞으로 보내는 초안을 열 수 있습니다. App version/build, Android/iOS, OS/version, device model이 포함될 수 있으며 사용자는 전송 전에 모두 확인·수정·삭제할 수 있습니다. Background 전송은 없습니다.

실제 전송 시 발신 주소, message, 사용자가 추가한 attachment 및 남겨 둔 diagnostics를 받습니다. Trovary user ID, login email, ShareLink token, Collection 내용, YouTube URL/video ID, advertising identifier, location은 자동으로 포함하지 않습니다.

3. Firebase Analytics

Release build에서 활성화되고 debug build에서 비활성화됩니다. 위 영어 section에 나열한 9개 product event를 기록하며, custom event에는 token, 전체 URL, YouTube URL/video ID, Collection 제목, 자유 입력, email, Supabase user ID를 넣지 않고 Analytics user ID도 설정하지 않습니다.

SDK는 별도로 표준 app/device/installation/session/lifecycle/interaction 정보와 masked IP에서 파생된 일반적 위치, app-instance identifier를 처리할 수 있습니다. Automatic screen reporting을 끄고 Android Analytics AD_ID 수집 및 기본 ad personalization signal을 비활성화했지만, 다른 SDK 정보까지 전혀 처리하지 않는다는 의미는 아닙니다.

4. Firebase Crashlytics

Release build에서 활성화되고 debug build에서 비활성화됩니다. Crash, uncaught exception, stack trace, 관련 app state, version/build, device/OS, session/diagnostic data, installation identifier 및 Analytics breadcrumb를 처리할 수 있습니다. Trovary는 명시적 Crashlytics user ID와 개발자 정의 custom key/log를 설정하지 않습니다.

5. Google AdMob 및 개인정보 선택

Trovary에는 banner 광고용 Google Mobile Ads/UMP만 포함되며 Interstitial, Rewarded, App Open, Native 광고는 없습니다. Release build에서 production 광고와 유효한 banner unit을 명시하지 않으면 production 광고는 꺼져 있습니다.

광고가 활성화되면 SDK는 일반적 위치 추정용 IP address, app/ad interaction, diagnostic/performance, advertising data, device/app/account 범위 identifier를 광고, analytics, fraud prevention을 위해 수집·공유할 수 있습니다.

Android는 AD_ID와 AdServices Advertising ID/Attribution/Topics permission을 제거합니다. iOS는 ATT prompt, tracking usage description, explicit IDFA request가 없습니다. 이는 특정 identifier를 제한하지만 SDK가 모든 identifier/data를 전혀 처리하지 않는다는 뜻은 아닙니다. 필요한 경우 UMP가 광고 initialize 전에 choice를 받고, 광고 요청 불가 상태이면 initialize하지 않으며 privacy options를 다시 열 수 있게 합니다.

6. 정보 이용 목적

  • 사용자 인증 및 session 복구
  • Collection 생성·정리·동기화·공유
  • YouTube metadata 조회 및 cache
  • 기기에서 Received Collection 저장 및 새로고침
  • public/authenticated endpoint의 abuse 방지
  • 기능 이용 현황 파악 및 안정성 개선
  • crash와 운영 장애 진단
  • production 광고가 활성화되고 허용된 경우 banner 광고 표시
  • 사용자가 보내기로 선택한 문의에 답변

Collection 제목, YouTube URL/video ID, ShareLink token, support 내용, login email 또는 Supabase user ID는 custom Analytics parameter로 쓰지 않습니다.

7. 외부 서비스 및 처리 제공자

  • Supabase — authentication, PostgreSQL data, Edge Function
  • Google — Google login, Firebase Analytics/Crashlytics, AdMob, UMP, YouTube Data API
  • Apple — iOS Apple login
  • YouTube — linked video service 및 metadata source

각 provider는 자체 약관, policy, 보관 설정과 법적 의무에 따라 처리할 수 있습니다. Shared page와 이 page에는 무관한 tracking/ads를 추가하지 않습니다.

8. Public link, network data, log 및 보안

활성 ShareLink를 가진 누구나 로그인 없이 열 수 있으므로 민감하게 관리하고 필요하면 비활성화 또는 재생성해야 합니다. Hosting/provider는 전송, 신뢰성, 보안을 위해 IP, 시각, endpoint, status, device/software 같은 일반 request metadata를 처리할 수 있습니다.

Endpoint rate limit은 instance마다 salted in-memory hash를 사용합니다. 영구 account log가 아니며 instance와 함께 폐기되고 비활성 entry는 prune됩니다. Application error log는 raw token, auth header, email, account ID, YouTube API key, raw body를 기록하지 않도록 설계했습니다. Access control, RLS, authentication, validation, transport encryption, rate limit을 사용하지만 절대적인 보안을 보장할 수는 없습니다.

9. 보관 및 삭제

  • 계정 및 owned Collection: 계정이 활성 상태이거나 서비스에 필요한 동안 보관합니다. 로그인한 사용자는 앱 정보 및 지원에서 계정 삭제를 선택할 수 있습니다. Authenticated service가 현재 Auth user를 삭제하면 owned Collection/item/ShareLink가 relation에 따라 삭제됩니다. 앱에 접근할 수 없으면 /delete-account에서 확인 절차가 있는 요청을 시작할 수 있으며 정당한 법률/보안 보관은 예외입니다.
  • YouTube metadata cache: public video의 공용 재사용 record로서 한 계정에 직접 연결되지 않으며 account/item 삭제 뒤에도 남을 수 있습니다.
  • Received Collections: 제거, app data 삭제 또는 uninstall 때까지 기기에 남습니다. 앱 내 삭제는 해당 기기에서 이를 지우며, 외부 요청은 다른 기기에서 원격 삭제할 수 없습니다.
  • Firebase/AdMob: Google policy와 account 설정에 따라 보관됩니다.
  • Apple 승인 credential: 일회용 code는 보관하지 않습니다. 암호화한 refresh token은 Apple-linked account에 필요한 동안만 보관하고 account와 함께 삭제합니다. 앱 내 삭제는 account 삭제 전에 Apple 승인을 해제합니다.
  • Support mail: 조사, 답변, record 또는 법적 의무에 필요한 기간 보관할 수 있고 사용자가 삭제를 요청할 수 있습니다.

Public 계정 삭제 page는 두 경로를 설명하고 aros.care@gmail.com으로 보내는 요청을 시작합니다. 최소한의 계정 소유 확인을 요청할 수 있습니다. 비밀번호, access/refresh token, ShareLink, 전체 공유 URL 또는 YouTube URL을 보내면 안 됩니다. 요청 email과 최소 확인/완료 기록은 보안, 지원, 법적 의무 또는 완료 증명에 합리적으로 필요한 동안 보관될 수 있습니다.

앱에서 Apple 로그인 계정을 삭제하면 먼저 Apple에 승인 해제를 요청하고, Apple이 요청을 수락한 뒤에만 Auth user와 관련 data를 삭제합니다. Credential이 없거나 revoke를 처리할 수 없으면 account와 local data를 삭제하지 않으며 Apple로 다시 로그인하거나 재시도할 수 있습니다. 앱 밖의 요청은 추가로 검증된 Apple 승인 연결 해제 절차가 필요할 수 있습니다.

10. 사용자 선택

로그인, ShareLink 활성화, Received Collection 저장/제거, support mail 전송, Trovary 계정 영구 삭제, 표시되는 UMP choice를 사용자가 선택합니다. Platform의 account/ad/privacy control도 사용할 수 있습니다. Link 비활성화/재생성은 이미 열람·복사된 정보까지 회수하지는 못합니다.

11. 아동

Trovary는 거주 지역에서 online data 처리에 독립적으로 동의할 수 있는 연령보다 어린 아동을 위해 설계되거나 의도적으로 제공되지 않습니다. 아동의 나이를 의도적으로 묻지 않습니다. 보호자는 아동이 account/support 정보를 제공했다고 생각하면 연락할 수 있습니다.

12. 국제 처리

Trovary와 provider는 사용자 국가 밖에서 정보를 처리할 수 있으며 규칙은 지역마다 다를 수 있습니다. Provider 약관과 보호조치가 적용되며 정보가 한 국가에만 머문다고 보장하지 않습니다.

13. 방침 변경

기능, provider, 설정 또는 요구가 바뀌면 날짜를 갱신하고 최신 방침을 이 page에 게시합니다. 중요한 변경은 앱 또는 적절한 다른 방법으로 알릴 수 있습니다.

14. 문의

개인정보, support 또는 deletion request는 aros.care@gmail.com으로 보내 주세요.