Privacy Policy for Trilly
Last Updated: August 15, 2026
This Privacy Policy explains how Trilly ("the App"), the website at trilly.app("the Site"), operated by Rodrigo Rosa("we", "us", or "our"), handle information when you use them. Together, the App and the Site are referred to as "the Service."
1. Data Controller
The data controller responsible for the processing of personal data under the General Data Protection Regulation (GDPR) is:
Rodrigo Rosa
Email: general@trilly.app
2. Scope of This Policy
This policy is split into two parts, because the App and the Site handle data differently:
- Part A — The Trilly App: the expenses, trips, and other data you enter stays on your device. The App does automatically send us crash and error diagnostic reports to help us fix bugs.
- Part B — The trilly.app Website: collects a limited amount of data (your email, if you join the waitlist) and uses privacy-oriented analytics.
Part A — The Trilly App
A.1 Information We Collect
Trilly is designed to operate locally on your device.
We do not collect, store, transmit, or process your expense, trip, or financial data on our servers through the App. The App does not require a user account and does not collect information such as:
- Name
- Email address
- Phone number
- Postal address
- Payment information
- Location data
- Usage analytics
- Advertising identifiers
The one exception is crash and error diagnostics, described in A.2 below.
A.2 Crash and Error Reports
The App uses Sentry, a crash-reporting service, to automatically detect and report crashes and unhandled errors. This helps us find and fix bugs. When a crash or error occurs, a report is sent to Sentry that may include:
- Device model and operating system version
- App version
- Error messages and stack traces describing what the App was doing when it crashed
- A randomly generated, anonymous identifier used to group related reports
We have configured Sentry with personal data collection disabled ("sendDefaultPii" off), so identifiers such as your name, email address, or IP address are not attached to crash reports by default. Crash reporting only runs in the published version of the App, not during development. If you choose to submit feedback through an in-app feedback tool, any information you voluntarily include (such as your email address or a description of the issue) will also be sent to Sentry.
A.3 Data Stored on Your Device
Any information you enter into the App (expenses, trips, categories, and related financial or travel data) is stored locally on your device using an on-device database and remains under your control. We do not have access to this information and cannot view, modify, export, or delete it on your behalf.
A.4 Legal Basis for Processing
- Your expense and trip data: under Article 6(1)(b) GDPR, any processing that occurs within the App is necessary for the functionality you requested. Since this data remains exclusively on your device and is not transmitted to us, we do not process it as a remote service provider.
- Crash and error diagnostics: under Article 6(1)(f) GDPR (legitimate interest), we rely on crash reports to identify, diagnose, and fix defects in the App.
A.5 Data Sharing
We do not sell, rent, share, disclose, or transfer your expense or trip data to third parties. No advertising or marketing services are integrated into the App. The only third party the App shares data with is Sentry, which processes crash and error diagnostics on our behalf as described in A.2.
A.6 Data Retention
Information created in the App remains stored locally on your device until you delete it, uninstall the App, or clear the App's local storage through your device settings. We do not retain copies of this data. Crash and error reports sent to Sentry are retained per Sentry's standard data retention policy, after which they are automatically deleted.
Part B — The trilly.app Website
B.1 Information We Collect
When you visit trilly.app, we collect:
- Waitlist email address: if you voluntarily submit your email to join the launch waitlist, we store it in our database (hosted by Supabase) so we can notify you about Trilly's availability.
- Aggregated usage analytics: we use Vercel Analytics to understand how visitors use the Site (e.g., page views, referrers, general device/browser type, approximate country derived from IP address). This is cookieless, does not build individual visitor profiles, and does not identify you personally.
We do not collect names, payment information, or any other personal data through the Site beyond what's described above.
B.2 How We Use This Information
- Your waitlist email is used solely to contact you about Trilly's launch and related updates. We do not use it for unrelated marketing and will not sell or rent it.
- Analytics data is used in aggregate to improve the Site's performance and content.
B.3 Third-Party Service Providers (Subprocessors)
| Provider | Purpose | Data Involved |
|---|---|---|
| Supabase | Waitlist storage | Email address |
| Vercel | Hosting + analytics | Aggregated, anonymized usage data |
These providers process data on our behalf under their own privacy and security commitments and do not use your data for their own purposes.
B.4 Legal Basis for Processing
- Waitlist email: Article 6(1)(a) GDPR (consent)— you provide your email voluntarily and can withdraw consent at any time.
- Analytics: Article 6(1)(f) GDPR (legitimate interest)— understanding and improving the Site, using data that is aggregated and not used to identify you.
B.5 Data Retention
We retain your waitlist email until you ask us to delete it. Analytics data is retained by Vercel per its standard aggregation policies and is not tied to your identity.
B.6 Cookies
The Site does not use tracking or advertising cookies. Vercel Analytics operates without cookies.
3. International Data Transfers
Where data is processed by third-party providers (Supabase, Vercel, Sentry), it may be processed on servers outside your country of residence. Crash and error reports from the App are processed in Sentry's EU data region. These providers maintain appropriate safeguards (such as standard contractual clauses) for international transfers where required by GDPR.
4. Your GDPR Rights
Where GDPR applies, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request erasure ("right to be forgotten")
- Restrict or object to processing
- Request data portability
- Lodge a complaint with a supervisory authority
To exercise any of these rights regarding your waitlist email, contact us at general@trilly.app. Because the App itself does not send us data, these rights do not apply to information stored only on your device — you control deletion of that data directly through the App or your device settings.
5. Data Security
We take reasonable measures to protect data using industry-standard practices, and rely on the security infrastructure of our service providers (Supabase, Vercel) for data collected via the Site. For data stored on your device, you are responsible for your device's security (passwords, screen locks, OS updates).
6. Children's Privacy
Trilly and trilly.app are not directed at children and are not intended for use by individuals below the age required under applicable law to provide valid consent for data processing. We do not knowingly collect personal information from children.
7. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Last Updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
8. Contact Information
If you have any questions about this Privacy Policy or privacy-related matters, please contact:
Rodrigo Rosa
Email: general@trilly.app