Privacy policy

Last updated 6 October 2026

This policy explains what Trove does with personal information when you use the iOS and Mac apps, and when you visit this website. Trove is published by The React Native Rewind.

The short version

You give us an account, the circles you join, and the tasks and files you add. People in a circle can see that circle’s tasks. They cannot see your other circles, and they do not get your list. We do not sell personal information, and the apps do not show ads.

Information you give us

  • Account details: your name, email address, and a password.
  • Profile details: a display name and, if you add one, a profile photo.
  • Circle and task content: circle names, membership and roles, task titles, notes, status, priority, due dates, labels, and who a task is assigned to.
  • Files you choose to attach to a task, including photos and videos.
  • Invite details: if you invite someone, the email address you enter, the circle, and the role you offer. Invites expire.

Passwords are stored by our authentication provider in a form that cannot be read back. We cannot see your password.

Information from your device

  • Photos and videos, only when you choose one to attach to a task or to use as a profile photo. The file is stored so it can be shown with that task or profile.
  • Speech, only when you choose to dictate a task. Recognition runs on your device through the operating system. We store the text you keep in the task. We do not receive a recording of your voice.

The apps ask for the photo library, microphone, or speech recognition only for those actions. You can say no. The rest of Trove still works.

How we use it

We use this information to:

  • create and secure your account
  • show each circle its tasks
  • build your list from the tasks assigned to you across your circles
  • deliver invites and show files you attach
  • let an assistant you connect act on the circles you can already see
  • reply when you contact support, and delete data when you ask us to

Who can see a circle

Membership is the boundary. You can see a circle’s tasks only if you are a member of that circle. That rule is enforced in the database, not only on the screen. Your list is yours: other people get their own list of what is assigned to them. A circle with no other members stays visible only to you until you invite someone.

Who we share it with

We share a circle’s tasks with the other members of that circle, because that is the point of a shared circle. We do not sell personal information, and we do not share it with advertisers.

Account data, task data, and files you upload are stored with Supabase, which provides our database, authentication, and file storage. Supabase acts as a service provider for us. Those services may process data outside the United Kingdom.

How long we keep it

We keep account and task data for as long as the account exists, and we keep a task for as long as it remains in a circle. Invite records expire. Delete your account in the app under Account, then Delete account. That removes your profile, your personal circle, and your sign-in. Circles you own are handed to another member when one exists, and deleted when you are the only member. You can also email us if you cannot open the app. We delete the account and the personal data we hold for it, except where we must keep something to meet a legal duty.

Tasks and files you added to a shared circle may still be needed by the other members. Tell us if you want those removed as well, and we will remove what we can without wiping that circle’s tasks for everyone else.

Your choices and rights

You can:

  • decline photo, microphone, and speech-recognition access
  • edit your name and profile photo in the app
  • sign out, and revoke a connected assistant or a personal token
  • delete your account in the app under Account, then Delete account
  • email support@thereactnativerewind.com to access, correct, or export your personal information, to be removed from a circle, or to delete the account if you cannot open the app

If you are in the United Kingdom or the European Economic Area, you can also complain to your data protection authority. In the UK, that is the Information Commissioner’s Office.

Children

Trove is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child under 13 has given us information, email support@thereactnativerewind.com and we will delete it.

AI assistants and connected apps

You can connect an AI assistant in two ways.

A personal access token (trove_…) is created in the app under Account, then Connect an AI assistant. We store only a hash of the token. Anyone with the token can do what you can do in Trove until you revoke it there.

OAuth lets an assistant such as Claude, ChatGPT, Cursor, or another client sign in as you. You approve it on the web app at /oauth/consent. That screen shows the assistant’s name and the identity scopes it asked for (openid, email, and profile). Approving it lets that assistant read and change the circles and tasks you can already see. It cannot see a circle you have not joined. The same membership checks still apply. Inviting someone from an assistant sends that person an email.

Connected apps are listed under Account → Connected apps, on the Connect an AI assistant screen. Revoking one signs that assistant out. Revoking a personal token does the same for that token. How to connect is on the assistant docs.

This website

This marketing site is static. It does not use an account, analytics, or advertising cookies. Our host, Vercel, may keep ordinary connection logs, such as an IP address and the page requested, to operate and protect the site.

Changes

If this policy changes, the date at the top of the page changes with it. The current version is always on this page.

Contact

Privacy questions and requests go to support@thereactnativerewind.com, or through the support page.