Trove

Privacy Policy

Last updated: October 2026

1. Data Controller

Trove (formerly CandleKeep) is operated by Sahar Carmel as a sole proprietorship based in Israel. For any privacy-related questions or requests, you can reach our data protection contact at [email protected].

As a small company, we do not have a designated Data Protection Officer. For all data protection inquiries, contact our data protection lead at [email protected].

2. What We Collect

We collect the following categories of personal data:

  • Account data — provided via our authentication provider (Clerk): name, email address, and profile image.
  • Uploaded documents — PDFs, EPUBs, and Markdown files you add to your library, along with associated metadata.
  • Usage data — page views, feature usage, and interaction events. Client-side analytics (PostHog) are collected only with your consent. Certain server-side events (e.g., onboarding steps, subscription changes, desktop downloads) are logged under our legitimate interest in operating and improving the service, regardless of cookie consent.
  • Coding agent — when you use the Trove CLI, we record the name of the coding agent it is running under (for example “Claude Code” or “Codex”) so we know which agents to support. This is the agent’s name only — never your prompts, files, or commands. You can turn this off at any time in Settings, or by setting TROVE_NO_CLIENT_TELEMETRY=1 (the older CK_NO_CLIENT_TELEMETRY=1 also works) in your environment.
  • Session recordings — only if you accept analytics cookies, PostHog records how you move through the web app (clicks, scrolling, page changes) so we can find bugs. Everything you type into form fields is masked, and recordings are deleted after 30 days.
  • Support requests — what you send us through the in-app feedback form, trove report, or email: your message, any attachments, and your email address.
  • Assistant connections — if you connect Trove to an AI assistant, we store the connection details described in Connecting Trove to AI Assistants.
  • Device & browser info — browser type, operating system, and screen resolution, collected only when client-side analytics consent is granted.
  • Technical identifiers — IP addresses and user agent strings may be collected for download tracking, abuse prevention, and analytics. IP addresses are not displayed in our admin interface and are used only for deduplication and security purposes.
  • Billing data — email address and subscription status, processed by our billing provider (Polar). We do not store payment card details directly; these are handled by Polar's payment processor.
  • Service usage logs — records of which library items you access, pages read, and API calls made. These are used to enforce usage limits, provide reading history, and improve the service.
  • Research topics supplied by your agent — when you use Trove through a coding agent or the Claude Cowork plugin, the agent writes three short pieces of text on your behalf:
    • A one-line topic for a research session — kept so we can group a run of reads together. Up to 500 characters. The topic is removed after 90 days; the record that a session happened stays.
    • The topic of a question your library could not answer — kept so we know which book to publish next, and can tell you when it exists. Up to 1,000 characters.
    • The reason a book was suggested to you — kept so we do not suggest the same book twice. Up to 1,000 characters.
    We do not store your conversation with the agent: no transcript, no prompt stream, no message history. Agents are instructed to write the subject matter rather than your question as you typed it, and our servers redact recognisable email addresses, API keys, access tokens and phone numbers from all three of the above before storing them.

3. Lawful Basis for Processing (GDPR Art. 6)

  • Contract performance — processing your account data and documents is necessary to provide the Trove service you signed up for.
  • Legitimate interest — security monitoring and service improvement, balanced against your privacy rights.
  • Consent — client-side analytics cookies and Google Analytics are only activated when you explicitly opt in via our consent banner.
  • Legitimate interest — server-side event logging (onboarding, subscriptions, downloads) is necessary for operating the service, enforcing usage limits, and preventing abuse.

4. How We Use Your Data

  • To provide and maintain the Trove service
  • To authenticate you and manage your account via Clerk
  • To process, store, and serve your uploaded documents
  • To monitor and protect the security of our infrastructure
  • To improve the product through analytics (client-side tracking requires your consent; server-side operational events are processed under legitimate interest)
  • To enforce usage limits and subscription tiers
  • To track downloads and prevent abuse
  • To answer support requests
  • To keep the AI assistants you connect working (see Connecting Trove to AI Assistants)
  • To find and fix bugs (session recordings, with your consent)

5. Connecting Trove to AI Assistants

You can connect Trove to AI assistants such as Claude and ChatGPT, or to any other app that supports MCP. You sign in to Trove and approve the connection (OAuth). After that, the assistant can read and add to your library for you.

What we receive and keep:

  • An access token and a refresh token. We store only a scrambled form (a one-way hash), never the token itself. An access token stops working after 1 hour. A refresh token stops working after 30 days unless the assistant uses it, and each use replaces it with a new one.
  • The name the assistant app gives itself when it registers (for example, “ChatGPT”). We use it to show which assistants are connected.
  • The requests the assistant makes for you: which tool it used, which books and pages it read, what it saved, and when it last used its access. These are the same usage and reading records we keep when you use the Trove CLI.
  • Any short research topic, missing-topic note or suggestion reason the assistant writes, as described in What We Collect.

What we do not receive: your conversation with the assistant. We never get your chat history, your prompts, or the assistant’s answers. We only see the requests it sends to Trove.

The assistant’s own privacy policy (for example, OpenAI’s for ChatGPT, or Anthropic’s for Claude) covers your conversation and anything the assistant does with what it reads from Trove. These companies are not our processors: you choose to connect them, and they act under their own terms.

To disconnect: remove or disconnect Trove in the assistant’s own settings. Settings in Trove shows which assistants are connected. The access token we issued expires within 1 hour. To end a connection right away on our side, email [email protected] and we will revoke it as soon as we can. Deleting your Trove account removes all connections.

6. No Model Training

We don't train models on your content and we don't use it to train anyone else's. The documents you upload, the books you write, and the text your agent reads from your library are never used to train or fine-tune any model — ours or a third party's. Apart from content you choose to publish to the Marketplace (see our Terms of Service), your content is processed only to operate the service for you.

7. Cookies & Analytics

Essential cookies — authentication session cookies are always active as they are required for the service to function. These cannot be disabled.

Analytics cookies (client-side) — we use PostHog for product analytics. Until you make a choice, PostHog counts your visit without cookies or browser storage; analytics cookies are only set if you explicitly accept them via our consent banner. Withdrawing consent is as simple as changing your cookie preferences — no account changes required. If you reject non-essential cookies, or your browser sends a Global Privacy Control signal, no client-side analytics data is collected. Google Analytics is loaded only after you accept.

Remembering how you found us — when you arrive, we keep a short note of how you got here: campaign tags in the link (such as utm_source), the referring site, and advertising click identifiers. It is stored in a first-party cookie called ck-utm (30 days, not readable by scripts) and in a per-tab session value that disappears when the tab closes. We keep it before you make any cookie choice so your first visit is not lost if you accept later. It stays on our own domain and is never sent to third parties before you consent. When you create an account, we store this source on your account so we can see which channels bring people to Trove. This is a first-party record on your account. If you rejected analytics, or your browser sends a Global Privacy Control signal, we do not send product analytics about the source of your account to PostHog.

Server-side event logging — certain events are logged server-side regardless of cookie consent, under our legitimate interest in operating the service. These include: subscription changes, onboarding steps, desktop app downloads, CLI token generation, and try-flow funnel events. These events are tied to your user ID (when authenticated) or IP address (for anonymous downloads) and are sent to PostHog for analysis.

You can change your cookie preferences at any time using the cookie preferences link in the site footer.

8. Automated Decision-Making

Trove does not use automated decision-making or profiling that produces legal effects or similarly significant effects on you. Document processing (e.g., PDF text extraction) is purely mechanical and does not involve profiling or algorithmic decision-making about individuals.

9. Your Rights (GDPR)

If you are located in the European Economic Area (EEA) or a jurisdiction that grants equivalent rights, you have the following rights under the General Data Protection Regulation:

  • Access (Art. 15) — request a copy of the personal data we hold about you.
  • Rectification (Art. 16) — request correction of inaccurate or incomplete data.
  • Erasure (Art. 17) — request deletion of your personal data ("right to be forgotten").
  • Restriction (Art. 18) — request that we limit the processing of your data.
  • Portability (Art. 20) — receive your data in a structured, machine-readable format.
  • Objection (Art. 21) — object to processing based on legitimate interests.
  • Withdraw consent (Art. 7(3)) — withdraw consent for analytics at any time via the cookie preferences link in the footer.
  • Lodge a complaint — you have the right to lodge a complaint with your local supervisory authority. For users in Israel, this is the Privacy Protection Authority (PPA). For EU residents, you may contact your national data protection authority.

We will respond to all data subject requests within one calendar month. In complex cases, this may be extended by up to two additional months, in which case we will inform you of the extension and the reasons for the delay.

To exercise any of these rights, contact us at [email protected].

10. Your Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act grants you the following rights:

  • Right to know — request details about the categories and specific pieces of personal data we have collected.
  • Right to delete — request deletion of personal data we have collected from you.
  • Right to opt-out of sale — we do not sell your personal data to third parties.
  • Non-discrimination — we will not discriminate against you for exercising your CCPA rights.
  • Right to correct — request correction of inaccurate personal information we hold about you.

11. Data Retention

We keep each kind of data only as long as below. Where there is no fixed period, we say what decides it.

  • Account data (name, email, profile image) — until you delete your account. When you delete it, we delete your account record and everything linked to it at once.
  • Sign-in data (Clerk) — until you delete your account. You delete your account from the Account tab in Settings, which removes your Clerk user (our sign-in provider) and erases your data with us. Clerk keeps sign-in data under its own privacy policy and sets no fixed period of its own.
  • Books and documents — until you delete them or your account. When you delete your account, we delete your files from storage and your library from our database.
  • Reading and usage records (API usage, research sessions, reads) — until you delete your account. Research topics are removed after 90 days. Reads of books owned by other people (for example, marketplace books) are kept as anonymous counts after you delete your account, with your identity removed.
  • Missing-topic reports — kept so we can plan new books. After you delete your account, they are no longer linked to an account. Book-suggestion reasons are deleted with your account.
  • Analytics (PostHog) — session recordings are deleted after 30 days. Analytics events are kept for up to 7 years, the limit of our PostHog plan, so we can compare how Trove is used over time. PostHog stores IP addresses in anonymised form. Before you answer the cookie banner, visitors are counted without cookies; session recordings and cookie-based analytics start only after you accept. You can stop analytics at any time with the cookie preferences link in the footer.
  • Google Analytics — kept for 14 months, then deleted by Google, and only collected if you accept analytics cookies.
  • Server logs (Railway) — deleted automatically by our hosting provider within 30 days.
  • Billing records (Polar) — Polar is the seller of record for Trove subscriptions. Polar keeps billing records under its own privacy policy and for as long as tax and accounting law requires. We delete our copy of your subscription when you delete your account.
  • Assistant connections and API keys — tokens and keys are stored only in hashed form. Access tokens stop working after 1 hour; refresh tokens after 30 days without use; API keys when you revoke them. The hashed records are deleted with your account.
  • Support messages — requests you send in Trove are deleted with your account. Copies in our support tools (Linear, and our internal team alerts) and emails sent to [email protected] are kept so we can follow up on your request, and deleted within 30 days of you asking us to delete them.
  • Email records — we keep a record that an email was sent and whether it was delivered. When you delete your account, your address and the email's content are removed from these records; only the delivery status stays. Our email provider (Resend) keeps its own delivery logs under its own terms.
  • Install and download records — new records are stored with an anonymised IP address; some older download records may hold the full address, and we delete them if you ask. Your account link is removed when you delete your account.
  • DMCA records — records of copyright takedown notices and counter-notices are retained for a minimum of 3 years to support repeat infringer tracking and legal compliance.

12. Your Choices

  • Analytics and session recordings — change them with the cookie preferences link in the footer. We honour Global Privacy Control.
  • Coding agent name — turn it off with the Privacy toggle in Settings, or set TROVE_NO_CLIENT_TELEMETRY=1.
  • Product emails — manage them in the Email tab in Settings.
  • Connected assistants — disconnect in the assistant, or email [email protected] and we will end the connection on our side.
  • Books — delete any book from your library.
  • Account — delete it from the Account tab in Settings. If you cannot find the control, email [email protected].
  • Access, export or correction — email [email protected]. We answer within one month.

13. International Data Transfers

Your data may be processed outside your country of residence. We ensure appropriate safeguards are in place for all international transfers:

  • PostHog — EU (Frankfurt). Data stays within the EEA.
  • Clerk — US. Transfers are subject to Clerk's data processing terms and transfer mechanisms.
  • Railway — US. Transfers are subject to Railway's data processing terms and transfer mechanisms.
  • Polar — EU (Sweden). Subscription billing.
  • Cloudflare — Global. DNS and email routing.
  • Resend — US. Transactional email delivery.
  • Google Analytics — US. Website analytics, only with your consent.
  • Linear — US. Support request tracking.
  • Discord and Slack — US. Internal team alerts.

International transfers are governed by each provider's standard transfer mechanisms, including the EU-US Data Privacy Framework where applicable. Transfers are subject to each provider's data processing terms. For details, contact [email protected].

14. Data Storage & Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption in transit — all data is transmitted over TLS 1.2 or higher.
  • Encryption at rest — uploaded documents are encrypted using AES-256 via SSE-S3. Database encryption is managed by our hosting provider (Railway).

For more details on our security practices, see our Security page.

15. Who Receives Your Data

  • Service providers (processors) — we share data with a limited number of third-party service providers who process data on our behalf. Each is subject to their standard data processing terms. For the full list, including purposes and locations, see our Sub-processors page. We do not send your documents to any AI model provider. Text extraction runs on our own servers.
  • People you share with — members of a team you share books with can see those books. If your assistant reports that a marketplace book is missing a topic, that book's author sees the topic (not who you are).
  • AI assistants you connect — these are not our processors. You choose to connect them (see Connecting Trove to AI Assistants).
  • Legal requests — when the law requires it.

16. Children's Privacy

Trove is not directed at children under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that data promptly.

17. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice via email before the changes take effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.

18. Data Provision Requirements

Providing your name and email address is a contractual requirement necessary to create and maintain your Trove account. Without this data, we cannot provide the service. Document uploads are entirely voluntary. Analytics data collection requires your explicit consent and is never required to use the service.

19. Contact

For any privacy-related questions, data requests, or concerns, contact us at [email protected].

For help with your account, email [email protected].