Concepts
Security & privacy
What we encrypt, what we never store, and how to delete everything.
Encryption
- TLS 1.3 in transit.
- AES-256 at rest (Postgres + storage).
- Row-level security on every table.
- Service-role keys server-only, rotated quarterly.
What we never store
- Bank login credentials. Trove has no bank connection at all.
- Credit card numbers. There is no billing during the testing phase.
- Full payment account numbers. Only last-4 masks.
Deleting your data
/settings → Delete account. Within 30 days, all data, backups included, is purged. We email a confirmation.
Reporting a vulnerability
security@trove.cool. We respond within 24 hours and credit researchers publicly.