TroveStep
TroveStep
Pricing

Privacy and cookies

How TroveStep handles account information, research access, integrations and website usage, including your data rights and privacy requests.

Effective and last updated: 2026-09-08

Who is responsible

Olena Holub, operating TroveStep from Ireland, is the data controller for the personal data processed to run this service. The TroveStep team handles requests on her behalf; authorised technical staff carry out the necessary account and data operations.

For privacy requests, contact trovestep@gmail.com, +353 873584555, or 177 The Waterside, Block B/C, Charlotte Quay, Dublin 4, D04P300, Ireland. You do not need to find or contact an individual developer.

Research access and connected clients

Pro provides research data access, daily insight details, and MCP and plugin access. It does not include model inference, generation or usage credits.

MCP access returns research data to the client you connect. A connected client is a separate service you choose, and what it does with the research it retrieves is governed by that client's own arrangements.

MCP access and TroveStep plugin integrations are Pro features, delivered as access linked to your TroveStep account. Supported plugin integrations are confirmed as each one is released.

Information we process

Account and session information: Clerk handles sign-in identifiers, email addresses and other profile information you provide through sign-in, together with authentication and session data. Our application uses your sign-in state and user identifier to control account access.

Website and security information: requests expose technical information such as an IP address, requested URL, browser details and errors to the infrastructure serving them. We use Cloudflare Web Analytics for aggregate page usage and performance measurements, not advertising profiles.

Support information: if you email us, we receive your email address, message and any information you choose to include. Share only what is needed for the request. We do not currently collect card details or operate checkout.

Public research data: our product corpus contains publicly available information about products, websites, markets and their growth evidence. It is separate from user account data. Public material may sometimes identify an individual operating a product; those individuals can also contact us about their personal data.

Why we use it

We process account information and the inputs you submit to provide the software service you request and manage your account. The legal basis is performance of that service agreement, or steps you ask us to take before entering it.

We rely on legitimate interests to protect the service from abuse, diagnose faults, understand aggregate performance and maintain useful public product research, while considering the rights and reasonable expectations of affected people. You may object to processing based on legitimate interests.

We process support requests to respond to you and manage the service, and process rights requests and legally required records to comply with legal obligations. If optional processing requires consent, it must be explained and consent obtained before it starts; consent can be withdrawn.

We do not currently connect to users' Google Search Console or Google Analytics accounts. The project's own search-performance reporting is not a user-authorised integration. Your account data is not added to the public product corpus.

Service providers and recipients

Clerk provides identity and session services. Render hosts the web service and PostgreSQL database in Frankfurt.

Cloudflare supplies DNS and Web Analytics. Google Fonts serves the interface font, so your browser contacts Google to request the font resources. Google also handles support correspondence sent to our Gmail address. Necessary technical request information is processed when using these services.

Authorised people supporting TroveStep may access information needed to respond to a request or maintain the service. Information may also be disclosed where required by law or necessary to establish, exercise or defend legal claims.

A compatible MCP client is a separate service you choose. Its handling of the research it retrieves is governed by that client's arrangements. Our MCP endpoint exposes research data, not your TroveStep account data.

Cookies and browser storage

Clerk uses authentication and session storage when sign-in is activated. These mechanisms are needed to keep an account signed in and protect access. The Clerk interface is loaded for signed-in users or when you explicitly open sign-in or sign-up. Authentication infrastructure may also set security cookies when its resources are requested, before you sign in.

Cloudflare describes Web Analytics as cookie-free and says it does not use browser storage or fingerprinting to identify visitors. We have not added advertising trackers or an optional marketing-cookie system. A cookie-free analytics service does not mean all infrastructure requests are free of technical information.

You can manage cookies through your browser, although blocking necessary authentication storage can prevent sign-in from working. If we introduce non-essential tracking requiring consent, it must remain off until consent is given and offer refusal and withdrawal.

Retention and international processing

Account information is used while your account remains active and is reviewed for deletion when you close it or exercise your rights. Support correspondence is kept only as needed to resolve the request and meet any applicable legal obligations or claims. Retention depends on the type of record, its purpose and the obligations that apply.

Infrastructure logs, provider records and backup copies have separate retention arrangements and may not disappear when a page session ends.

Although our application database is hosted in Frankfurt, providers and authorised support may process information in other countries, including outside the EEA. Such transfers are subject to applicable GDPR requirements. The applicable mechanism depends on the recipient and destination, such as an adequacy decision or appropriate safeguards including standard contractual clauses.

You may request the relevant recipient, destination, retention information and applicable transfer safeguards through trovestep@gmail.com. We will explain the arrangements relevant to your data. A Frankfurt database does not mean all processing stays in the EEA.

Your rights and our response times

Subject to the GDPR conditions that apply, you may request access, correction, erasure, restriction and portability of your personal data, object to processing based on legitimate interests, and withdraw consent where processing relies on it. Erasure is not an unconditional right to remove every record, for example where retention is legally required or needed for legal claims.

Send your request to trovestep@gmail.com. We will reply within 3 working days and delete personal data eligible for erasure within 7 working days of receiving your request. Working days are Monday to Friday, excluding Irish public holidays. These are our service commitments, not a statement of the GDPR's standard response period.

We may need proportionate information to confirm your identity before releasing or deleting account data. We will ask promptly, explain what is needed and keep you informed. If a record must be retained, or provider or backup handling affects completion, we will explain the reason, scope and next steps rather than claim deletion is complete.

Under the GDPR, requests must be handled without undue delay and normally within one month. Where the law permits an extension for complexity or the number of requests, we must explain it within the first month; the extension can be up to two further months. These statutory rules are not a routine replacement for our faster service commitments.

Privacy requests are handled by people, not an automated deletion portal. We do not normally charge for a rights request. If we cannot act on a request, we will explain why and your complaint and judicial remedy options.

You can complain to the Irish Data Protection Commission or another competent supervisory authority. Visit dataprotection.ie for the Irish authority's current contact and complaint information.

Changes to this notice

We will update this notice when the service or its data processing changes and show the revision date. Material changes will be communicated as required.

Contact the TroveStep team

trovestep@gmail.com+353 873584555

177 The Waterside, Block B/C, Charlotte Quay, Dublin 4, D04P300, Ireland

Supervisory authority: Irish Data Protection Commission.