Privacy Policy for Trilly

Last Updated: August 15, 2026

This Privacy Policy explains how Trilly ("the App"), the website at trilly.app("the Site"), operated by Rodrigo Rosa("we", "us", or "our"), handle information when you use them. Together, the App and the Site are referred to as "the Service."

1. Data Controller

The data controller responsible for the processing of personal data under the General Data Protection Regulation (GDPR) is:

Rodrigo Rosa
Email: general@trilly.app

2. Scope of This Policy

This policy is split into two parts, because the App and the Site handle data differently:


Part A — The Trilly App

A.1 Information We Collect

Trilly is designed to operate locally on your device.

We do not collect, store, transmit, or process your expense, trip, or financial data on our servers through the App. The App does not require a user account and does not collect information such as:

The one exception is crash and error diagnostics, described in A.2 below.

A.2 Crash and Error Reports

The App uses Sentry, a crash-reporting service, to automatically detect and report crashes and unhandled errors. This helps us find and fix bugs. When a crash or error occurs, a report is sent to Sentry that may include:

We have configured Sentry with personal data collection disabled ("sendDefaultPii" off), so identifiers such as your name, email address, or IP address are not attached to crash reports by default. Crash reporting only runs in the published version of the App, not during development. If you choose to submit feedback through an in-app feedback tool, any information you voluntarily include (such as your email address or a description of the issue) will also be sent to Sentry.

A.3 Data Stored on Your Device

Any information you enter into the App (expenses, trips, categories, and related financial or travel data) is stored locally on your device using an on-device database and remains under your control. We do not have access to this information and cannot view, modify, export, or delete it on your behalf.

A.4 Legal Basis for Processing

A.5 Data Sharing

We do not sell, rent, share, disclose, or transfer your expense or trip data to third parties. No advertising or marketing services are integrated into the App. The only third party the App shares data with is Sentry, which processes crash and error diagnostics on our behalf as described in A.2.

A.6 Data Retention

Information created in the App remains stored locally on your device until you delete it, uninstall the App, or clear the App's local storage through your device settings. We do not retain copies of this data. Crash and error reports sent to Sentry are retained per Sentry's standard data retention policy, after which they are automatically deleted.


Part B — The trilly.app Website

B.1 Information We Collect

When you visit trilly.app, we collect:

We do not collect names, payment information, or any other personal data through the Site beyond what's described above.

B.2 How We Use This Information

B.3 Third-Party Service Providers (Subprocessors)

ProviderPurposeData Involved
SupabaseWaitlist storageEmail address
VercelHosting + analyticsAggregated, anonymized usage data

These providers process data on our behalf under their own privacy and security commitments and do not use your data for their own purposes.

B.4 Legal Basis for Processing

B.5 Data Retention

We retain your waitlist email until you ask us to delete it. Analytics data is retained by Vercel per its standard aggregation policies and is not tied to your identity.

B.6 Cookies

The Site does not use tracking or advertising cookies. Vercel Analytics operates without cookies.


3. International Data Transfers

Where data is processed by third-party providers (Supabase, Vercel, Sentry), it may be processed on servers outside your country of residence. Crash and error reports from the App are processed in Sentry's EU data region. These providers maintain appropriate safeguards (such as standard contractual clauses) for international transfers where required by GDPR.

4. Your GDPR Rights

Where GDPR applies, you have the right to:

To exercise any of these rights regarding your waitlist email, contact us at general@trilly.app. Because the App itself does not send us data, these rights do not apply to information stored only on your device — you control deletion of that data directly through the App or your device settings.

5. Data Security

We take reasonable measures to protect data using industry-standard practices, and rely on the security infrastructure of our service providers (Supabase, Vercel) for data collected via the Site. For data stored on your device, you are responsible for your device's security (passwords, screen locks, OS updates).

6. Children's Privacy

Trilly and trilly.app are not directed at children and are not intended for use by individuals below the age required under applicable law to provide valid consent for data processing. We do not knowingly collect personal information from children.

7. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Last Updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

8. Contact Information

If you have any questions about this Privacy Policy or privacy-related matters, please contact:

Rodrigo Rosa
Email: general@trilly.app