Privacy Policy
Posted: July 11, 2026 · Effective: July 18, 2026
Advance notice: This update takes effect July 18, 2026. It adds disclosures and controls for the optional Known Places feature.
This Privacy Policy explains how Trevio (“Trevio,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information when you use the Trevio mobile app, website, and related services (collectively, the “Service”). By creating an account or otherwise using the Service, you agree to this Policy. If you do not agree, do not use the Service.
1. Summary
- Trevio is a personal-memory recall tool. You save things you want to remember (photos, notes, voice clips, links, locations) and we surface them at relevant moments.
- We collect what you put into the Service plus what we need to make it work (account info, device info, basic usage). We do not sell your personal information.
- Known Places is optional. If you turn it on, Trevio can use precise location while the app is open, or in the background if you separately choose that access, to learn commercial places where you stay. We keep place aggregates and visit counts, not a route or movement trail.
- We share data only with the service providers we need (Clerk for login, Stripe for billing, Anthropic and Google AI for the AI features, and OpenAI or Deepgram to transcribe voice memos you record) and only as described below.
- You can delete your account, export your data, or contact us at any time using the contact information in Section 13.
2. What we collect
2.1 Information you give us
- Account. Email address, display name, profile photo, sign-in provider (Apple, Google, email/password), timezone, and locale. If you set a home location, the city/neighborhood you enter and (optionally) its coordinates.
- Memories. Anything you save: photos, voice recordings and their transcripts, notes, links, QR or barcode payloads, tags, and any metadata you attach (people, occasions, locations).
- People. Names, relationships, birthdays, hobbies, and (if you choose to import them) phone numbers, email addresses, and contact photos you select via the device contact picker.
- Clubs. The memberships, memories, comments, and invite links you create or accept inside a Club (e.g., a gift collaboration).
- Payment information. Subscription billing details are handled by Stripe (on the web) or by Apple or Google and RevenueCat (for purchases made inside the app); we receive a customer identifier, plan tier, renewal status, and billing emails. We never see or store full card numbers.
- Support. Anything you send us via email, in-app feedback, or other support channels.
2.2 Information collected automatically
- Device + diagnostics. Device model, operating system version, app version, language preference, IP address, and crash logs.
- Usage events. Pages viewed, features tapped, memories created/edited/deleted, push-notification deliveries, search queries, and similar interaction data.
- Capture metadata. EXIF data and location data attached to photos or memories you capture, when you grant the relevant permission.
- Optional Known Places observations. If you turn on Known Places, the app sends a quality-gated summary after it observes a stable stay: an averaged coordinate, horizontal accuracy, approximate start/end time, duration, sample count, and whether the observation was made while the app was open or in the background. We combine repeat visits into a place with a visit count and preference ranking. We do not upload or retain the individual location samples, route, speed, heading, or continuous movement history used to form that summary.
- Cookies and local storage (web only). Session cookies for sign-in, preference cookies for UI state, and our local cache of your latest queries. We do not use third-party advertising cookies.
2.3 Information from third parties
- Sign-in providers. When you sign in with Apple or Google, we receive your name, email, and a stable opaque identifier from that provider via Clerk.
- Link previews. When you save a link or scan a QR code, our server fetches the destination page's public metadata (Open Graph tags, favicon, and similar). For social-media or business URLs, we may also run a Google search (via SerpApi) to resolve the canonical business name, address, and coordinates so the memory shows a useful preview.
3. How we use information
- Provide, operate, and improve the Service.
- Generate AI summaries, gift suggestions, person profiles, and related recall features using your memories as context. These calls are routed to Google (Gemini) and/or Anthropic (Claude). When you record a voice memo, its audio may be sent to a speech-to-text provider — OpenAI (Whisper) or Deepgram, depending on configuration — to transcribe it into text. When transcription is handled entirely on your device, the audio is not uploaded. All are subject to those providers' data-handling terms referenced in Section 4.
- Send reminder notifications (push, email) tied to the people, dates, and occasions you save.
- Identify and rank places you repeatedly visit, when you opt in, so Trevio can remember preferences such as a grocery store or gas station and personalize private assistant answers and reminders.
- Process subscriptions, prevent fraud, and handle disputes.
- Communicate with you about the Service, security, and policy changes.
- Diagnose crashes and improve performance.
- Enforce our Terms of Use and comply with law.
We do not use your memories, contacts, or person profiles to train third-party models, and we do not sell your personal information to third parties.
4. Service providers we share data with
We share information only with the providers we need to deliver the Service, and only as needed for that specific function. The ones that touch user data today are:
- Clerk — authentication and session management.
- Stripe — subscription billing and payments (web only).
- RevenueCat — validating in-app purchases made through the App Store or Google Play and keeping your subscription status in sync. It receives your Trevio account identifier and the store's transaction details, never your card number.
- LiveKit — carrying the live audio of a club voice room while it is in session, and recording it when a member starts a recording everyone in the room can see.
- Fly.io — application hosting and the primary Postgres database (United States).
- Cloudflare R2 / AWS S3-compatible storage — encrypted photo and voice-clip storage.
- Google (Gemini API) — text and image analysis, OG-tag enrichment, and AI summaries.
- Anthropic (Claude API) — fallback AI summarization and web search.
- OpenAI — speech-to-text transcription of voice memos you record (Whisper / gpt-4o-transcribe), when configured. When configured, your recording is sent to OpenAI to transcribe it and refine your device's draft.
- Deepgram — speech-to-text transcription of voice memos and of the sermons or club sessions you record, and text-to-speech for the spoken daily brief. Audio is sent only when you record a voice memo (and only when it is not transcribed on-device), start a sermon or club recording, or request a spoken brief.
- Google Places and SerpApi — public place-search results used to enrich saved links and, when Known Places is enabled, identify the business at an averaged settled-place coordinate. The coordinate sent for this lookup is not accompanied by your name, email, memories, or route.
- Expo — over-the-air JavaScript updates and push-notification delivery.
- Mapbox — map images and, when you've set a home location, estimating the likely route from your home to a place you saved. This sends the relevant coordinates to Mapbox to compute the map/route; it is an estimate, not location tracking.
Each provider is contractually limited to processing data for the purpose we engage them for. We do not authorize any of them to use your data for their own marketing.
5. Sharing with other users
- A memory you save is visible only to you unless you place it inside a Club and invite someone to that Club.
- Information inside a Club is visible to every member of that Club and may persist after you leave it.
- When you accept an invite link, the inviter sees that you joined; we do not show the inviter any of your other memories.
6. Permissions on your device
Trevio asks for the following device permissions and uses them only as described:
- Camera — to capture photos and scan QR / barcode codes you choose to save.
- Photo library — to add photos you select to a memory. We never browse your library in the background.
- Microphone & speech recognition — to record and transcribe voice memos that you initiate.
- Location (while using the app) — to attach a place to a memory, estimate an arrival or departure, and, only when you enable Known Places, observe stable stays that can become learned places.
- Location (background / “Always”) — optional and separate from While Using access. If you enable the background Known Places mode, the operating system can wake Trevio for low-frequency location updates when the app is not open. Trevio reduces those updates to completed stay summaries and does not store a route. Force-quitting the app may pause this until you reopen it, depending on your device.
- Contacts — only the single contact you pick via the system picker when adding a friend. We never read your contact list in the background.
- Notifications — to deliver the reminders you set.
You can revoke any of these from your device's Settings app at any time; some Service features will stop working without the permission they depend on.
7. International transfers
Trevio is operated from the United States. If you use the Service from outside the United States, you understand that we will process your information in the United States and other jurisdictions where our service providers operate. Where required by law (including the EU/EEA, UK, and Switzerland), transfers rely on the European Commission's Standard Contractual Clauses, the UK's International Data Transfer Addendum, or a recognized adequacy decision.
8. Data retention
- We retain your account and memories for as long as your account is active.
- When you delete a memory, it moves to Trash for 7 days before being permanently removed.
- Learned places remain until you remove them or delete all learned places. A removed place remains recoverable in Known Places Trash during a 7-day recovery period, then is permanently removed during the next cleanup pass. Turning learning off stops new observations but does not itself erase places already learned. Public business-resolution cache entries are not tied to your account and may remain for their normal cache period.
- When you delete your account, account access is disabled immediately, identifying profile fields are scrubbed, and shared Arrival access is revoked. Remaining account content stays in a 30-day deletion window and is then scheduled for permanent deletion from the application database.
- We retain billing records and security logs for the periods required by applicable law (typically 7 years for financial records).
9. Security
We use industry-standard technical and organizational measures including TLS in transit, encryption at rest for stored media, access controls, audit logs, and isolated environments. No system is perfectly secure; you use the Service at your own risk and are responsible for keeping your sign-in credentials safe. If we discover a breach affecting your information, we will notify you as required by applicable law.
10. Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your account and personal information.
- Receive a portable copy of your information.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
- Choose Known Places Off, While Using, or background access; remove an individual learned place; or delete all learned-place aggregates from the Known Places screen.
- For residents of California (CCPA/CPRA): the right to opt out of sale or sharing of personal information. Trevio does not sell or share personal information as those terms are defined.
- For residents of the EU/EEA/UK (GDPR/UK-GDPR): the rights listed in Articles 15–22 and the right to complain to your local supervisory authority.
You can exercise the deletion right at any time from Settings → Delete account. For all other requests, contact us at the address in Section 13. We will respond within the time required by applicable law (generally 30–45 days).
11. Children
The Service is not intended for and may not be used by children under 13 (or under 16 in the EU/EEA where required by local law). We do not knowingly collect personal information from children under those ages. If you believe a child has provided us with personal information, contact us and we will delete it.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be highlighted in the Service or via email at least 7 days before they take effect. Your continued use of the Service after the effective date constitutes acceptance.
13. Text messaging (SMS/MMS)
If you add and confirm your mobile number in the app, Trevio may send you text messages (SMS/MMS) — a one-time welcome, confirmations when you text a link to save it, and replies to your requests such as HELP. This is a transactional, account-related program; we do not send marketing texts.
We do not share your mobile phone number or SMS opt-in data with third parties or affiliates for their own marketing or promotional purposes. Mobile information collected for text messaging is used only to operate this messaging program and is shared only with the messaging providers that deliver the texts on our behalf (for example, Twilio).
Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP to any Trevio text, and reply HELP for help. Carriers are not liable for delayed or undelivered messages.
14. Contact
Questions, requests, or complaints about this Policy or your information: privacy@trevio.app.
For our companion document, see the Terms of Use.