Privacy policy
Effective July 3, 2026 · Trove is built and operated by Hollyburn Analytics.
The short version: we collect what's needed to run your account and your connection, we don't sell it, we don't run ads, and you can delete all of it.
What we collect
- Account information — your name and email, handled by our sign-in provider (Clerk).
- Your configuration — which toolkits you've enabled and any toolkits you've deployed.
- Your content — documents you save to your library, stored in your own isolated per-user store.
- Toolkit credentials — API keys you provide, sealed in an encrypted, write-only vault (see the security overview).
- Operational records — tool-call metadata (which tool ran, when, and whether it succeeded) used for reliability, debugging, and abuse prevention. Tool arguments and results are not stored; short-lived operational logs expire within seven days, and the code paths that handle tool calls and credentials write no payloads or secret values into them.
- Site analytics — this website sends first-party, cookieless event counts (e.g. "the copy button was clicked") with no user identifiers, no cookies, and no fingerprinting. A random token generated per page view (never stored in your browser) lets us count steps within a single visit.
What we don't do
We don't sell your data. We don't share it with advertisers. We don't use your content to train models. Your content is processed only to provide the service — for example, generating the search embeddings that make your library searchable.
Where your data lives
Trove runs on Cloudflare's developer platform; your data is stored in a dedicated per-user store and user-partitioned storage there. Authentication is provided by Clerk. These are our two subprocessors. When a toolkit calls an upstream source (arXiv, SEC EDGAR, FRED, …), your query goes to that source under its own terms — that's the point of the tool — and each toolkit's page says exactly which source it talks to.
Deletion
Deleting your account — from your account menu, or by emailing us — purges your per-user store, stored files, credentials, and connection state. You can also remove any individual credential or disable any toolkit at any time from your dashboard.
Changes & contact
If this policy changes materially, we'll note it here with a new effective date. Questions, or a deletion request we can help with? Email us — a human reads every message.