←Backtroth
Privacy Policy

Privacy Policy

Effective 2026-04-23 · Last updated 2026-04-23

Pending legal review — last updated 2026-04-23.

Troth is a spec-to-task tool made up of a CLI, a web app at troth.dev, and an MCP server at mcp.troth.dev. This Privacy Policy explains what we collect, how we use it, who we share it with, and the rights you have over your data.

The short version: we collect only what we need to run the Service, we don't train models on your content, and you can export or delete everything at any time.

On this page
  • What we collect
  • How we use it
  • Sub-processors
  • Sharing
  • Retention
  • Your rights
  • Security
  • Cookies
  • Children
  • International transfers
  • Changes
  • Contact

What We Collect

We collect the minimum data needed to run the Service.

  • Account information. Your name, email, avatar, and provider ID from the OAuth provider you sign in with (GitHub or Google). Supabase handles authentication on our behalf.
  • Project data. Specs, tasks, context bundles, decisions, learnings, and run logs you create in Troth. This is Your Content.
  • AI prompts and outputs. When you use AI decomposition or task-assistance features, the relevant spec, task, or bundle content is sent to Anthropic's Claude API and the response is returned to you and stored in your project. Narrative-generation features send the relevant content to Mistral.
  • Billing data. If you subscribe to a paid plan, Stripe processes and stores your payment details. We receive only non-sensitive billing metadata (plan, status, last four digits, invoice identifiers).
  • Technical logs. Standard server logs (IP, user agent, request path, timestamp) generated by our hosting providers (Vercel, Fly.io, Supabase) for security and reliability.
  • Error reports. When something goes wrong, diagnostic reports including stack traces and your user ID are sent to Sentry so we can diagnose and fix the problem.
  • Anonymized usage events. Aggregate events such as spec creation, task completion, and feature usage, used to understand how the product is used and where to improve it.

How We Use It

  • To run the Service: store Your Content, authenticate you, and deliver the features you use.
  • To process AI requests when you invoke AI features. If you configure your own Anthropic API key via ANTHROPIC_API_KEY, requests are sent from your key instead of ours.
  • To process payments for paid plans via Stripe.
  • To send transactional emails about your account (sign-in, billing receipts, deletion confirmations).
  • To monitor errors and diagnose failures via Sentry.
  • To analyze anonymized usage to improve reliability and design.
  • To detect abuse and to comply with law.

We do not use Your Content to train machine learning models. If that ever changes, it will be strict opt-in and announced in advance.

Sub-Processors

We rely on the following sub-processors to run the Service. Each one is bound by its own data processing terms.

ProviderPurposeLocation
SupabaseAuthentication (GitHub + Google OAuth), Postgres database for specs, tasks, and project data.United States
AnthropicAI decomposition and task assistance via the Claude API. Content you submit to AI features is sent to Anthropic.United States
MistralAI narrative generation. Project content you submit to narrative features is sent to Mistral.European Union (France)
StripeBilling and payment processing for paid plans.United States
SentryError monitoring. Error reports, including stack traces and user IDs, are sent to Sentry.United States
VercelHosting for the web application at troth.dev.Global edge network
Fly.ioHosting for the Troth MCP server at mcp.troth.dev.Global edge network

Sharing

We do not sell your personal information, and we do not share it with advertisers or data brokers.

We share data only with the sub-processors listed above (as needed to run the Service), with authorities when legally required, and with a successor entity in the unlikely event of a merger, acquisition, or asset sale — in which case we will notify you in advance.

Retention

We retain Your Content for as long as your account is active.

When you delete a project, its data is removed within 30 days. When you delete your account, deletion is subject to a 7-day grace period during which you can reverse the action; after the grace period elapses, your personal data and content are removed within 30 days, except where we must retain information for legal or accounting reasons (typically billing records, retained for the period required by applicable tax law).

Anonymized, aggregated usage statistics may be retained indefinitely because they cannot be used to identify you.

Your Rights

Depending on where you live, you may have some or all of the following rights:

  • Access. Ask for a copy of the personal data we hold about you.
  • Export. Download Your Content in YAML or JSON from the web app or CLI at any time.
  • Correction. Ask us to correct inaccurate data.
  • Deletion. Delete your account from within the Service, subject to the 7-day grace period above.
  • Objection and restriction. Object to, or ask us to restrict, certain processing (e.g. analytics).
  • Portability. Receive your data in a machine-readable format (YAML or JSON).
  • Complaint. Lodge a complaint with your local data protection authority.

To exercise any of these rights, email privacy@troth.dev. We will respond within 30 days.

Security

We use industry-standard safeguards: TLS in transit, row-level security in our Postgres database, short-lived OAuth sessions, and least-privilege access for operators. Passwords are handled by your OAuth provider; we never see or store them.

No system is perfectly secure. If you discover a vulnerability, please report it responsibly to privacy@troth.dev and give us reasonable time to fix it before public disclosure.

Cookies and Local Storage

The web app uses browser local storage to keep you signed in (via Supabase) and to remember preferences. We do not use third-party advertising or tracking cookies. Essential session data is cleared when you sign out.

Children

The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal data, contact privacy@troth.dev and we will delete it.

International Transfers

Troth is operated from the United States, and our sub-processors operate globally. By using the Service, you understand that your data may be transferred to and processed in countries with different data protection laws than your own. Where required, we rely on Standard Contractual Clauses or equivalent safeguards with our sub-processors.

Changes to This Policy

We may update this Policy from time to time. For material changes, we will update the effective date at the top of this page and notify you by email or through the Service before the change takes effect. Continued use of the Service after that date means you accept the revised Policy.

Contact

Questions about this Policy, your data, or a privacy request? Email privacy@troth.dev. For non-privacy legal matters, contact legal@troth.dev.

Troth Privacy Teamprivacy@troth.dev