Privacy policy
Updated October 1, 2026
Your records
Trove is developed by Sequoyah Geber. It is a personal budgeting and recordkeeping app. Your accounts, balances, transactions, bills, goals and imported investment records are stored on your device in an encrypted ledger. Trove does not operate a server that receives your financial records, sell your data, display advertisements, or include advertising or behavioral analytics SDKs.
Optional Apple services
Local budgeting does not require a Trove account. Sign in with Apple is optional; Trove stores an Apple user identifier in this device’s Keychain, without retaining your email, password or identity token. Optional sync sends encrypted ledger records and sync metadata to your private iCloud storage. Sync keys may be shared through your iCloud Keychain if you enable that option. Apple processes these services under its own privacy policy. Settings → Account and sync lets you pause or stop sync, sign out, and use Advanced → Remove the iCloud copy to delete Trove’s cloud vault. Signing out alone does not delete your records.
Financial connections and exchange rates
If you connect Wise or Interactive Brokers, Trove sends your provider credentials directly to that provider to read your balances, transactions or statement reports. Credentials stay in this device’s Keychain, or in memory if you choose not to save them, and are not shared through Trove’s ledger sync. Disconnect a provider in Settings to remove its saved connection credentials; previously imported records remain until you remove them. Trove cannot trade, transfer money, or open a financial account. For currency display, Trove requests public exchange rates from Coinbase with a currency code; financial records and balances are not included. Network providers receive normal connection information, including an IP address, and apply their own policies.
Receipts, files and on-device assistance
Trove reads only receipts, photos and files that you choose to scan or import. Receipt recognition and optional language-model assistance run on your device. Trove does not upload receipt images, import files or your questions to an AI provider. Original receipt images are not retained after the intake session; reviewed information you save becomes part of your ledger. Camera access is requested when you choose to scan. Device authentication is used only if you enable Lock Trove; Trove does not receive biometric templates.
Widgets, reminders and diagnostics
Widgets may read a small summary in Trove’s App Group on this device. Settings → Widgets controls sharing and whether amounts appear. Notifications are optional and can be disabled in Trove or system settings. Trove keeps a local activity log for troubleshooting. No diagnostic log is automatically sent to the developer. When you export records, a backup or a diagnostic log, you choose where to save or share it. Readable CSV exports are not encrypted. TestFlight may provide crash reports and feedback to Apple and the developer under Apple’s beta-testing terms.
Retention and removal
Records remain until you remove them or delete your local app data. Removed records may remain recoverable within Trove and its encrypted ledger, backups or other devices. To remove cloud data, use Account and sync → Advanced → Remove the iCloud copy before stopping sync. This keeps local ledgers on each device. Remove local app data and any backup or export files separately if you want to erase those copies too. On iPhone, deleting the app removes its local app container; offloading does not. Saved credentials and Apple authorization may remain in Keychain or Apple account settings; disconnect providers and sign out first, and revoke provider tokens at the provider when appropriate. The developer cannot access or erase your private iCloud vault or local records for you.
Demo and support
Explore a demo uses fictional records in memory. Its sample Wise and Interactive Brokers connections do not contact financial providers or require credentials. Leaving the demo restores your original ledger. For a beta issue, use Send Beta Feedback in TestFlight. The Trove support page has further contact and troubleshooting information. Include your app build and device version, and avoid sending financial records, API tokens, recovery keys or receipt images unless you deliberately choose to share them. Information you choose to send for support is used to respond and investigate your issue.
Changes
This policy describes the current Trove beta for iPhone and Mac. If its data handling changes, the policy and its update date will be revised. Review the privacy policies of Apple, Wise, Interactive Brokers and Coinbase when using their optional services.
Provider policies: Apple, Wise, Interactive Brokers, Coinbase.