Legal

Privacy Policy

Last updated: September 1, 2026

This Privacy Policy explains how Council Fire (“Trovance,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information in connection with the Trovance application available at app.trovance.ai and related services (the “Service”). It applies to visitors of our sites, people who create an account, members of a workspace, and end users who interact with the Service.

Trovance is “the growth engine for the agentic web.” The Service monitors how AI answer engines (such as ChatGPT, Perplexity, Google AI Overviews, Gemini, and Claude) respond to buyer questions about your brand; runs a first-party, cookieless analytics pixel you can install on your own website to measure human and AI-assistant traffic; connects — with your permission — to your Google Analytics and Google Search Console accounts to show your reporting alongside AI-visibility data and to generate content recommendations; and drafts marketing content for your brand.

1. Who we are

The data controller responsible for your information is Council Fire. You can reach us at zachc@councilfire.org with any privacy question, or to exercise the rights described below.

2. Data we collect

Account and profile data

  • Email address. Used to authenticate you, to name your workspace (from the email’s local part), and to identify you to fellow workspace members.

  • Password. Set at sign-up and hashed and held by our authentication provider (Supabase Auth). Trovance never sees or stores your plaintext password.

  • Anonymous / URL-only sign-up sessions. You can start onboarding with only your website URL. We create an anonymous session on a placeholder account that becomes a permanent account when you claim it; unclaimed sessions are kept until you claim them or ask us to delete them.

  • Member profile. Optional display name, job title, avatar photo, and an author “voice” text sample used to match content to your writing style.

  • Team invitations. Email addresses, roles, and invite tokens for teammates you invite to a workspace.

  • Collaboration data. Comment bodies, @-mention identities, quoted selections, and decision/publish attribution.

Usage and analytics data

  • Product analytics (Mixpanel) — on by default. When you use the app while signed in, we send behavioral analytics to Mixpanel to understand activation, funnels, retention, and feature usage. This includes your account identifier (used as a distinct id), registered properties (brand id, plan, role, plan status), and events such as page views (URLs with path), onboarding steps, card actions, and publishing, plus server-side events for subscription and engine-cycle outcomes. This analytics is enabled by default and does not honor the browser “Do Not Track” signal. You can turn it off at any time using the in-app opt-out in Settings, which stops tracking and deletes your Mixpanel identity. See Cookies & tracking.

  • Cookieless traffic pixel. If you install the Trovance Pixel on your website, we collect website-visitor telemetry to measure human pageviews and AI-assistant referrals: pathname, full URL, document referrer, and UTM parameters, plus a random per-event id and (via an optional server middleware snippet) the names of AI crawlers that fetch your pages. The pixel is cookieless — it sets no cookie. A visitor’s IP address and user-agent are used only transiently to compute a daily-rotating, salted SHA-256 visitor hash and are never stored in raw form. Because the salt rotates daily, visitors can be counted within a day but not tracked across days.

  • IP address (transient). Because all traffic passes through our hosting provider, we briefly process client IP addresses to build the cookieless visitor hash and a rate-limiting hash for our public onboarding “door,” and to send to our bot-protection provider for verification. We do not store raw IP addresses.

  • Standard logs. Our hosting and infrastructure providers generate access logs (URLs, user agents, timestamps) as part of serving requests.

Connected-service data

  • Google Analytics 4 & Google Search Console. If you connect them, we access your Google reporting and search-performance data on a read-only basis. This is described in full in the dedicated Google user data section below.

  • Bing Webmaster Tools. We read Bing/Copilot search-performance metrics for the connected site to display in your dashboard and to generate recommendations. This currently uses a Trovance-owned platform key, not a per-user Microsoft sign-in.

  • Stripe (billing). When you subscribe, we store Stripe object identifiers (customer id, subscription id, price/plan, status) and the brand id linking checkout to your brand. Card and payment details are entered on Stripe-hosted checkout and are held by Stripe — the Service never receives or stores your card data.

  • Stored third-party credentials. To publish and integrate on your behalf, we store credentials you provide or authorize: Google OAuth refresh tokens (for Analytics and Search Console), WordPress usernames and application passwords, webhook signing secrets, and other connector access/refresh tokens. These are locked to an internal worker role and are never readable by the browser. API keys for our MCP/agent server are stored as hashes (digests) only.

Content you create

  • Brand details (name, website domain, settings, pixel id), your Brand Core, ICP personas, taxonomy, notes, and sources.

  • Drafts and other brand-authored and AI-generated content you create in the editor, including images you select from the stock-image search.

  • Crawled content from your own website and from competitor websites (public pages, extracted entities, crawl runs) used to build your brand model and recommendations.

3. Google user data (Google Analytics & Search Console)

This section describes exactly what Google data Trovance accesses, how we use it, where we store it, how long we keep it, and how you can revoke access. Connecting Google is entirely optional and initiated by you.

Trovance requests two Google OAuth scopes, both read-only:

A brand owner or editor connects each service through Google’s standard offline OAuth flow. At the callback we exchange the authorization code for an offline refresh token and store only that token, per brand. We only read your Google data — we never create, modify, or delete anything in your Google Analytics or Search Console accounts.

What we access

  • Google Analytics 4 (Data API + Admin API): aggregate, non-personal traffic metrics — active users, new users, sessions, user engagement duration, and screen/page views by date — plus breakdowns by session source, default channel group, and page path, and the list of your GA4 properties (account summaries) so you can choose which property to display.

  • Google Search Console (Search Analytics API): totals (clicks, impressions, CTR, average position) and breakdowns by date, by search query (the actual search-term strings), and by page URL, plus per-page query drill-downs and the list of your verified sites.

How we use it

All Google data is used solely to (a) display your own analytics and search-performance data inside your Trovance dashboards, and (b) generate content recommendations for your own brand. We do not sell it, share it onward with any third party, use it for advertising, or use it to develop, improve, or train any generalized or non-personalized AI/ML models. Our AI probe engines receive brand- and ICP-derived questions, never your Google data.

How we store and retain it

  • Refresh token. Stored per brand in our database (Supabase Postgres), in a column granted only to an internal worker role and never selectable by the browser, and scoped by row-level security to members of the owning brand. It is stored as reversible text at rest because it must be usable to call Google’s APIs; it is not additionally encrypted at the application layer. Short-lived access tokens are minted on demand from the refresh token and are never persisted.

  • Analytics & Search Console dashboard reads. Fetched live from Google each time a dashboard renders and are not written to our database.

  • Recommendations (Search Console). Our recommendations “organic loop” reads your top Search Console query rows and persists derived recommendation cards whose stored title, angle, and evidence embed the actual search-query strings and their clicks, impressions, and position into our database. This is the one place where Google-derived data is stored beyond the refresh token.

  • Retention & deletion. The refresh token and any Search-Console-derived recommendation cards persist until you disconnect the integration or the brand is deleted, at which point they are removed (row deletions cascade on brand deletion). You can disconnect at any time in the app, or email us at zachc@councilfire.org to request deletion. You may also revoke Trovance’s access directly from your Google Account’s third-party access settings.

Limited Use

Limited Use Disclosure. Trovance’s use and transfer of information received from Google APIs — including data obtained through the Google Analytics Data API (https://www.googleapis.com/auth/analytics.readonly) and the Google Search Console API (https://www.googleapis.com/auth/webmasters.readonly) scopes — will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Specifically: (1) we only access your Google Analytics and Google Search Console data to provide and improve user-facing features that are prominent in Trovance’s interface (your reporting, traffic, and search-performance dashboards and analyses); (2) we do not transfer or sell this data to third parties such as advertising platforms, data brokers, or information resellers; (3) we do not use this data for serving advertisements, including personalized, retargeted, or interest-based advertising; (4) we do not allow humans to read this data unless we first obtain your explicit consent to view specific data, it is necessary for security purposes (such as investigating abuse) or to comply with applicable law, or the data is aggregated and anonymized and used for internal operations; and (5) we do not use this data to develop, improve, or train generalized or non-personalized AI and/or ML models. We access your Google data on a read-only basis and do not modify or delete it.

4. How we use information

  • Provide, operate, secure, and maintain the Service and your account.

  • Authenticate you and manage workspaces, teams, roles, and invitations.

  • Monitor AI answer engines and search engines for your brand and display AI-visibility, traffic, and search-performance results.

  • Generate drafts, brand models, recommendations, and other content for your brand.

  • Process subscriptions, billing, and plan management through Stripe.

  • Send transactional and lifecycle email (digests, alerts, sign-off requests, notifications).

  • Understand product usage and improve the Service (product analytics), subject to your opt-out.

  • Detect, prevent, and investigate abuse, fraud, and security incidents.

  • Comply with legal obligations and enforce our terms.

5. Legal bases for processing (GDPR)

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract — to create your account, provide the Service, run monitoring and content generation, and process billing.

  • Consent — to connect your Google Analytics and Search Console accounts, and where consent is otherwise required. You may withdraw consent at any time (e.g. by disconnecting an integration or opting out of analytics).

  • Legitimate interests — to secure the Service, prevent abuse, measure and improve our product, and operate our cookieless traffic analytics, balanced against your rights.

  • Legal obligation — to meet accounting, tax, and other legal requirements.

6. Sharing and subprocessors

We do not sell your personal information. We share data only with the service providers (subprocessors) below, who process it on our behalf to run the Service, and only as needed for the purposes described. We may also disclose information to comply with law, enforce our terms, or protect rights and safety, and in connection with a merger, acquisition, or asset sale.

Subprocessor

Purpose

Data involved

Supabase

Authentication, primary application database, and object storage

Account, profile, workspace, brand, content, collaboration, billing linkage, traffic telemetry, and stored connector credentials

Vercel

Application hosting and edge/serverless functions

Request/access logs; transient client IP addresses (not stored raw)

Mixpanel

Product/behavioral analytics (default-on; opt-out in Settings)

Account id, plan/role/brand properties, in-app events, server revenue/engine events

Stripe

Payments, subscriptions, and billing

Stripe customer/subscription ids, plan and status; card data held by Stripe, not by us

Resend

Transactional and lifecycle email delivery

Recipient email address, subject, and message body

Google (Analytics & Search Console)

User-authorized read access to your reporting and search-performance data

OAuth refresh token; GA4 and Search Console metrics/dimensions (see Section 3)

Microsoft / Bing (Webmaster Tools)

Read Bing/Copilot search-performance data

Search queries, clicks, impressions, position for the connected site

Anthropic (Claude)

Generative engine for drafts, brand model, and analysis; grounded AI-visibility probe

Brand/ICP/voice context, crawled site content, probe questions (returned output stored by us)

OpenAI

AI-visibility probe engine

Buyer-style probe prompt (answer + cited sources stored by us)

Perplexity

AI-visibility probe engine

Buyer-style probe prompt (answer + sources stored by us)

Google (Gemini API)

AI-visibility probe engine (platform key; not access to your Google account)

Buyer-style probe prompt (answer + grounding sources stored by us)

DataForSEO

Google AI Overviews probe (SERP data)

Probe keyword/question (overview text + reference URLs stored by us)

Cloudflare (Turnstile)

Bot/abuse protection on the public onboarding flow

Challenge token and visitor IP (for verification; not stored by us)

Firecrawl

Rendered-crawl fallback for protected sites (currently disabled in production)

Target public URL and returned HTML (when enabled)

Pexels

Stock-image search in the content editor

Image search query typed by you

Inngest

Background job orchestration (analysis cycles, crawls, emails, voice learning)

Event metadata carrying identifiers (brand id, run id, user id)

Fathom Analytics

Cookieless site analytics on our marketing site, trovance.ai (not the application)

Page URL, referrer, UTM parameters, browser and device type; no cookies, and no personal identifiers retained by us

Your WordPress site (outbound)

Publishing approved drafts to your own site

WordPress URL, username, application password, and the published content

Your webhook endpoint (outbound)

Signed event notifications to an endpoint you configure

Event type, brand id, timestamp, event data, and an HMAC signature

Workspace member email addresses are visible only to fellow members of the same workspace. Content you publish (e.g. to your WordPress site) and webhook payloads are sent only to the destinations you configure.

7. Data retention

We retain personal information for as long as your account, workspace, or brand is active and as needed to provide the Service. When a brand or workspace is deleted, associated rows are deleted and cascade accordingly. Google refresh tokens and Search-Console-derived recommendation cards are retained until you disconnect the integration or the brand is deleted (see Section 3). Cookieless traffic events contain only a daily-rotating hashed visitor identifier and derived pageview metadata; raw IP addresses and user-agents are never stored. We may retain limited records longer where required for legal, tax, security, or dispute-resolution purposes.

8. Security

We take reasonable technical and organizational measures to protect your information. Access to the database is governed by row-level security scoped to workspace and brand membership. Sensitive credential columns — including Google and connector refresh tokens and webhook secrets — are granted only to an internal worker role and are never readable by the browser. MCP/agent API keys are stored as hashed digests. Passwords are hashed by our authentication provider and never seen by the app. Card data is handled entirely by Stripe. Outbound network calls are centrally allowlisted per vendor and protected against server-side request forgery. Note that, because they must be usable to call the respective third-party APIs, Google refresh tokens and connector secrets are stored as reversible text at rest (locked to the worker role) rather than one-way hashed. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your rights and choices

GDPR (EEA, UK, and Switzerland)

If the GDPR or UK GDPR applies to you, you have the right to:

  • Access the personal data we hold about you and obtain a copy.

  • Rectify inaccurate or incomplete data.

  • Erase your data (“right to be forgotten”), subject to legal exceptions.

  • Restrict or object to certain processing, including processing based on legitimate interests.

  • Data portability — receive your data in a structured, machine-readable format.

  • Withdraw consent at any time, without affecting prior processing.

  • Lodge a complaint with your local supervisory authority (Data Protection Authority).

To exercise these rights, email zachc@councilfire.org. We will respond within the timeframes required by applicable law.

CCPA/CPRA (California)

If you are a California resident, you have the right to:

  • Know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of parties with whom we share it.

  • Delete personal information we collected from you, subject to legal exceptions.

  • Correct inaccurate personal information.

  • Opt out of the “sale” or “sharing” of personal information. Trovance does not sell your personal information and does not share it for cross-context behavioral advertising.

  • Non-discrimination — we will not discriminate against you for exercising your rights.

You may exercise these rights, including through an authorized agent, by emailing zachc@councilfire.org. We will verify your request as required by law.

10. Cookies & tracking

  • The Trovance traffic Pixel is cookieless. It sets no cookies and stores no raw IP addresses or user-agents; it identifies visitors only through a daily-rotating, salted, non-reversible hash, so visitors can be counted within a day but not tracked across days or across sites.

  • Product analytics is on by default. Our in-app product analytics (Mixpanel) is enabled by default and intentionally does not honor the browser “Do Not Track” signal. You can turn it off at any time using the opt-out switch in Settings; doing so stops tracking and deletes your analytics identity. Your choice is remembered on your device and, for signed-in accounts, on our servers.

  • We and our authentication provider use strictly necessary cookies/local storage to keep you signed in and to remember your analytics and theme preferences.

  • Our marketing site uses Fathom Analytics. trovance.ai runs Fathom, a cookieless analytics service that counts pageviews without cookies or cross-site tracking. It is not used inside the application.

11. International data transfers

Trovance is operated from the United States, and our subprocessors may process data in the United States and other countries. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism. Contact us for more information about the safeguards we use.

12. Children

The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us at zachc@councilfire.org and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.

14. Governing law

This Privacy Policy is governed by the laws of the State of Maryland, USA, without regard to its conflict-of-laws rules, except where mandatory local data-protection law provides you additional rights.

15. Contact us

Questions, requests, or complaints about this policy or your data? Contact Council Fire at zachc@councilfire.org.