Privacy Policy
Last updated August 20, 2026
The short version
Tricollo is built so that we can't read the contents of your vault. Files are encrypted on your device before they're uploaded, and the key that would decrypt them is never stored anywhere as a single, complete piece, not even on our servers. We collect the minimum account and operational data needed to run the service. We do not show ads or use advertising trackers, this website uses a cookieless analytics tool that can't identify you individually, we do not collect your precise location, and we never sell or share your personal information.
1. Scope and who we are
This policy explains how Tricollo ("Tricollo," "we," "us") collects, uses, and protects information in connection with the Tricollo iOS app and this website. It applies to anyone who uses the app, visits this site, or is invited as a trusted contact. Some sections below apply specifically to Users in the European Union (under the GDPR) or in the United States (under state privacy laws); where they diverge from the general text, the specific section governs for that User.
Owner and data controller: Tricollo. Contact: support@tricollo.com.
2. Data we collect
Account information. When you create an account, our authentication provider (Clerk) processes your email address and manages sign-in. We store your Clerk user ID and the email address associated with your account.
Vault contents. Files you add to a vault are encrypted on your device before upload. We store only the resulting ciphertext. We do not have the ability to decrypt or view your files, photos, or documents.
Trusted contact information. When you invite a trusted contact, we store their email address and, once they accept, a public key they generate themselves. Their recovery phrase and private key are generated and used entirely in their own browser and are never sent to us.
Check-in and usage data. We record when you check in, your check-in schedule, and basic app usage needed to operate reminders and the handoff process, for example notification delivery status and device tokens for push notifications.
Subscription and payment data. Purchases are handled by Apple through the App Store. We (via RevenueCat) receive confirmation of your subscription status and entitlements, but never your card details, which stay with Apple.
What we don't collect. The Tricollo app does not use advertising SDKs or ad identifiers, does not use behavioral analytics or tracking pixels, does not request your device's location, and does not build an advertising profile of you. There is nothing in the app to opt out of on this front, because it isn't there in the first place. (This website, separately, uses cookieless aggregate analytics; see Section 13.)
3. Device permissions
Depending on how you use Tricollo, the app may ask for the following device permissions. Each is optional in the sense that iOS lets you deny or later revoke it in Settings, though doing so may limit the related feature.
- Photo Library / Camera: to let you choose or capture a photo or document to add to a vault. Access happens only when you actively pick a file; Tricollo doesn't scan your library in the background.
- Face ID / Touch ID: to lock your vault behind your device's biometrics. This check happens entirely on your device via Apple's system frameworks; your biometric data itself never reaches Tricollo or our servers.
- Notifications: to send you check-in reminders. You choose whether to enable this during onboarding and can change it any time in Settings.
4. Service providers we use
- Clerk: authentication and account management.
- RevenueCat: subscription and entitlement management for App Store purchases.
- OneSignal: delivering push notifications, transactional email, and (on Pro plans) SMS reminders.
- Neon (Postgres): encrypted database hosting for account and vault metadata.
- Apple: processes payment for subscriptions purchased through the App Store; we never see your payment card details.
- Umami: cookieless aggregate analytics for this website only (not the app); see Section 13.
Each of these providers processes only what's necessary to perform their function for us and is contractually restricted from using your data for their own purposes. We do not sell personal information to anyone, and we do not share it with data brokers or advertisers.
5. Why we process your data
We use the data above to:
- provide the core service: creating vaults, storing encrypted files, and running check-ins;
- operate the trusted-contact handoff feature you configure;
- send the reminders and transactional messages you've enabled;
- process subscription purchases and manage entitlements;
- maintain the security and integrity of the service, including detecting abuse; and
- comply with our legal obligations and respond to lawful requests.
6. How long we keep it
We keep account and vault metadata for as long as your account is active. Encrypted vault contents are deleted when you delete a vault or your account. Some records, for example billing history, may be retained longer where we're legally required to. Once the purpose for keeping a given piece of data has passed and no legal obligation requires otherwise, we delete it.
7. Where your data is processed
Our service providers host infrastructure in the United States and the European Union. If you're located outside those regions, using Tricollo necessarily involves transferring your account metadata (never your unencrypted vault contents, which we can't read regardless of location) to those countries. Our providers maintain appropriate safeguards, such as standard contractual clauses, for these transfers.
8. Security
Every file is encrypted on your device before it's uploaded; our servers only ever store ciphertext. The key that would decrypt your vault is not stored anywhere as one complete piece; it's split across your device, our servers, and your trusted contact, so no single piece and no single party can open it alone. We use industry standard safeguards (encryption in transit and at rest, access controls, and least-privilege practices) to protect the data we do hold. No system is completely immune to compromise, and we can't guarantee absolute security, but our architecture is deliberately built so that a breach of our servers alone cannot expose your files.
9. The trusted-contact handoff
Tricollo's core feature is letting you decide who can reach specific files if you ever stop checking in. We only begin that handoff after multiple missed check-ins in a row, following the schedule and reminder channels you configured. Your trusted contact's recovery phrase and private key are generated and used entirely in their own browser and are never transmitted to or stored by us. You can change your trusted contact or check-in schedule, or delete your vault entirely, at any time.
10. Your rights if you're in the European Economic Area or UK (GDPR)
If GDPR applies to you, our legal basis for processing your data is one or more of: your consent, the necessity of processing to perform our contract with you (providing the app), a legal obligation we're subject to, or our legitimate interest in operating and securing the service, balanced against your rights.
You have the right to, free of charge:
- access the personal data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data erased ("right to be forgotten");
- restrict or object to certain processing, including for direct marketing;
- receive your data in a portable format and have it transferred to another provider where technically feasible; and
- withdraw consent at any time, where processing is based on consent.
To exercise any of these, email support@tricollo.com. We'll respond within one month. You also have the right to lodge a complaint with your local data protection authority at any time.
11. Your rights if you're a US resident
Depending on your state, laws like the California Consumer Privacy Act (as amended by the CPRA), and similar laws in states including Virginia, Colorado, Connecticut, Utah, Texas, and others, give you rights over your personal information. To the extent these apply to you, you have the right to:
- know what personal information we've collected about you and why;
- access a copy of that information;
- correct inaccurate information;
- delete your personal information;
- receive your data in a portable format; and
- not be discriminated against for exercising any of these rights.
Tricollo does not sell personal information and does not share it for cross-context behavioral advertising, so there is nothing to opt out of on that front. In the past 12 months, the categories of personal information we've collected fall under identifiers (like your email address and device tokens) and commercial information (like subscription status); we have not collected sensitive personal information beyond what's described in this policy, and any biometric check for unlocking your vault happens entirely on your device.
To exercise these rights, email support@tricollo.com. We may need to verify your identity before completing certain requests, and you can designate an authorized agent to submit a request on your behalf.
12. Children
Tricollo is not directed at children under 16, and we don't knowingly collect data from them. If you believe a child has provided us with personal information, contact us and we'll delete it.
13. Cookies and analytics on this website
This marketing website (not the app) uses Umami, a privacy-focused analytics service, to understand aggregate traffic like page views, referring sites, general (country-level) location, and device or browser type. Umami is cookieless: it doesn't set tracking cookies, doesn't collect personally identifiable information, doesn't build a profile of you, and can't follow you across other websites. This data isn't linked to your Tricollo account and is used only to understand how visitors find and use this site.
Beyond that, any cookies strictly necessary for the site to function (for example, remembering your color scheme preference) are not used to identify or track you.
14. Changes to this policy
If we make material changes, we'll notify you in the app or by email before they take effect. We'll also update the date at the top of this page.
15. Contact us
Questions about this policy or your data? Email support@tricollo.com.