triva
PrivacyTerms
Legal

Privacy Policy

This policy explains how Troiva handles your data across all of our apps and websites. Plain language first, legal second.

Last updated: August 13, 2026

Troiva (“Troiva”, “we”, “us”, or “our”) designs and runs a family of consumer apps, including Serena, Aloft, 2nd Menu, and others we release over time. This single policy covers all of them, along with this website. Where a particular app does something different, its App Store listing and its in-app settings spell out the specifics.

The short version

  • We collect as little as we can to run the app and improve it.
  • In our health and wellness apps, your sensitive entries are designed to stay on your device. We cannot read them.
  • We never sell your personal data, and we don’t run third-party ad networks inside our apps.
  • You can access, export, and delete your data, and you can turn off ad tracking when your device asks.

What stays on your device

Several of our apps are built to keep your most personal information local to your phone. Depending on the app, this can include the doses, weights, symptoms, and schedules you log, the sessions you listen to, and the preferences you set.

Your own cloud backup. On iOS, some apps can keep a backup in your personal iCloud account so you can restore it on a new phone. That backup lives under your Apple ID and never touches our infrastructure.

Health integrations. If you connect Apple Health or Health Connect, the app reads and writes only the entries you allow, within the health store on your device. That data is not sent to us.

What we collect

Account data. Most of our apps work without an account. If you create one, we store your email address, or the identifier Apple or Google provides when you use their sign-in.

Profile and setup answers. A small set of onboarding answers, such as goals, reminder preferences, and similar choices, so the app can personalise itself and restore your setup on a new device.

Purchase data. Your subscription status and plan, so the app knows what you have access to. Payments are processed by Apple or Google. We never see your card number.

Technical data. Device type, operating system, app version, and crash reports. The minimum needed to keep the app working.

Usage analytics. Which screens and features are used, so we know what to improve. In our health apps, analytics events are built to exclude your sensitive values, such as dose amounts, weights, and symptoms.

Advertising attribution. If you allow tracking when your device asks, we use standard measurement tools to learn which ad or channel brought you to the app. If you decline, we do not.

Camera and photos. Some apps let you scan or upload an image, such as a menu, to provide a feature. Where an app processes an image, it is used to deliver that feature and is not kept beyond what is needed to return your result, unless the app clearly states otherwise.

Approximate location. A few apps use coarse location, with your permission, to power features such as finding places near you. We do not track your precise location in the background.

Content you give to AI features. When you use a feature powered by AI, the text or image you submit is sent to an AI provider to generate your response. See AI features below.

What we do not do

We do not sell your personal data. We do not run third-party advertising networks inside our apps, and we do not embed SDKs whose purpose is to profile you across other companies’ apps. We do not collect your contacts, and we do not read the sensitive entries that stay on your device.

How we use your information

  • Provide the app and its features, and keep your account working.
  • Restore your setup and purchases on a new device.
  • Send reminders and notifications you asked for. In our apps these are usually scheduled locally on your phone.
  • Fix crashes and improve the features people actually use.
  • Understand, in aggregate, which marketing works.
  • Protect against fraud, abuse, and security threats, and meet legal obligations.

AI features

Some apps include features powered by artificial intelligence. When you use one, the content you submit is sent to a trusted AI provider (for example, Google) to generate a response. We do not permit these providers to use your content to train their general models, and we do not attach your sensitive on-device health entries to these requests. AI output can be wrong or incomplete, so please use judgment and, for health matters, talk to a professional.

Who we share information with

We share data only with the service providers we need to run the service, each bound by contract to use it only for that purpose:

  • Google Firebase, for sign-in, our database, analytics, and crash reporting.
  • RevenueCat, for subscription management.
  • Apple and Google, for app distribution and billing.
  • Singular, for privacy-conscious marketing measurement and attribution.
  • AI providers (such as Google), to power AI features you choose to use.

We may also disclose information if required by law, or to protect the rights, safety, and property of our users, the public, or Troiva. If we are ever part of a merger or acquisition, we will require the successor to honour this policy.

Advertising and measurement

On iOS, we ask for permission before any tracking through Apple’s App Tracking Transparency prompt. Where measurement happens, it relies on privacy-preserving frameworks such as Apple’s SKAdNetwork and AdServices, and aggregated results may be shared with the ad platforms we advertise on, such as Meta. You can decline tracking, and you can change your choice at any time in your device settings.

Your choices and rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict some processing. Our apps are built to make this easy:

  • Access and export. Many apps let you export your data from within the app.
  • Deletion. You can delete your account and associated server data from within the app, or by writing to us. We honour deletion requests within thirty days, and usually much sooner.
  • Tracking. You control ad tracking through your device settings.

If you are in the EEA or UK, our lawful bases include performing our contract with you, your consent, and our legitimate interests in running and improving the service. If you are in California, we do not sell or share your personal information as those terms are defined under the CCPA. To exercise any right, write to privacy@troiva.com.

Data retention

We keep account data for as long as your account is active. When you delete your account, we remove personal data within thirty days, apart from anything we are required to keep for legal or accounting reasons. Aggregated, non-identifying data may be kept longer to improve the service.

International data transfers

We and our providers may process data in countries other than your own, including the United States and the European Union. Where required, we rely on appropriate safeguards, such as standard contractual clauses, to protect your data when it moves across borders.

Children

Our apps are made for adults and are not directed to children. Some apps, including our health apps, require you to be at least 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, write to us and we will remove it.

Changes to this policy

We may update this policy from time to time. When we make a material change, we will note it here and, where appropriate, in the app before it takes effect. The date at the top shows the latest revision.

Contact

Questions about your privacy? Write to privacy@troiva.com, or reach us at hello@troiva.com.

This policy covers the whole Troiva family of apps. Individual apps may provide additional, app-specific privacy details in their App Store listing and in-app settings. Where an app-specific notice conflicts with this policy, the app-specific notice governs for that app.

triva
HomePrivacyTermshello@troiva.com
© 2026 Troiva