Privacy Policy
Last updated: July 23, 2026 · Document version 2026-07-23
1. Who we are and our role
Troviii is operated by Femtechnology, Inc. For our own member and product operations we act as controller. When an organization supplies participant, subscriber, CRM or partner data for us to process only on its instructions, that organization is controller and we act as processor under the applicable Data Processing Addendum. Final postal, privacy and representative details are listed in section 14 once confirmed.
2. Categories we collect or derive
- Identity, contact, account, authentication, device, session and delivery information.
- Content you submit or authorize: notes, messages, worlds, manuscripts, URLs, images, audio, voice, transcripts, files and contributions.
- Imported source, catalogue, schedule, subscriber and public-web information, together with source and rights evidence.
- Activity and context: saves, scans, deliberate choices, attendance, routes, room presence, invitations and interactions.
- Inferences you ask the product to create: taste, recommendations, relationships, current intent, needs, offers and possible opportunities.
- Commerce and evidence: purchases, bookings, checkout references, commissions, payouts, attribution and partner-reported outcomes.
- Optional location only where a collection surface explains it and you choose to provide it. Wellness experiences record non-clinical rituals, products, stories and participation—not health records or health-risk profiles.
3. Sources
We receive information from you; people and organizations you authorize; product interactions; authentication, payment and delivery providers; partner read-backs; and sources you deliberately import or ask us to resolve. We do not treat an imported source as owned or licensed merely because it is publicly reachable.
4. Purposes and legal bases
We use information to provide and secure accounts; host sources, worlds and artifacts; carry your chosen encounters into a passport; deliver recommendations and permissioned introductions; operate events and partner experiences; process commerce and credit; deliver opted-in communications; prevent abuse; and comply with law. Depending on the purpose and jurisdiction, our basis is contract, legal obligation, legitimate interests that do not override your rights, or consent. Optional analytics, marketing, cross-app identity, people discovery, matching and precise location are separate choices.
5. AI and profiling
AI may interpret or generate content, recommendations and possible connections. User text is sent as untrusted data rather than system instruction; paid calls are metered and access-controlled. AI can be wrong. We do not use solely automated decisions to determine legal rights, employment, credit, medical treatment or similarly significant outcomes. Troviii does not create clinical or health-risk profiles.
6. Sharing and processors
We disclose only what is needed to configured infrastructure, authentication, database, storage, AI, payment, email/push, communications, maps, ingestion and support providers; to a creator, host, merchant or partner when you direct or permit the interaction; and where law or safety requires. A production subprocessor schedule must identify only providers actually enabled, their purposes, locations and transfer mechanisms. Partners receive permissioned operational or aggregate readings—not private individual taste profiles.
7. Cross-border transfers
Where data leaves the EEA, UK or Switzerland, we use an applicable adequacy decision, contractual safeguards such as Standard Contractual Clauses, or another lawful mechanism, with supplementary measures where required. The final DPA and subprocessor schedule will state the applicable mechanism by vendor.
8. Retention
Account and creative data generally follow the account or user-directed world lifecycle. Current intent, presence and delivery data expire sooner. Financial, settlement, fraud, security, rights and legal-compliance evidence may be retained as legally required. Our subject-store registry currently classifies each actor-bearing Supabase store as delete, legally retain, or manual remove-versus-anonymize review; new stores default to review rather than silently escaping the rights process.
9. Your rights and choices
Depending on where you live, you may request access, portability, correction, deletion, restriction or objection; withdraw consent; appeal certain decisions; and complain to a regulator. Authenticated export and erasure cover registered Firebase stores and the live schema-generated registry of actor-bearing Supabase stores. Newly discovered stores default to manual review rather than being silently omitted or automatically destroyed. Shared/public authorship requires a remove-versus-anonymize decision; legally retained records are identified in the response. Versioned consent and rights-request evidence is recorded server-side.
10. California
See our California Notice at Collection. Statutory applicability and whether any affiliate, analytics or partner flow constitutes a California sale or sharing are still being assessed; we do not rely on an unqualified “never sell or share” statement until that mapping is complete.
11. Wellness and consumer health
See the Consumer Health Data Boundary. Troviii and Vivere do not intentionally collect diagnoses, medication lists, reproductive-health histories, clinical records or health-risk profiles. Wellness means non-clinical rituals, products, cultural stories and participation. Do not submit urgent or clinical health information.
12. Security, cookies and children
We use encryption in transit, server-side authorization, row-level database security, scoped secrets, rate and spend controls, evidence logs and least-privilege access. No system is perfectly secure. Essential storage operates the service; optional analytics requires a choice and can be withdrawn. General accounts are for people aged 16 or older. An adult may create a private artifact about or for a minor only through a specifically guardian-gated experience; that does not create an account for the minor and the artifact cannot become public without guardian consent.
13. Intellectual property and complaints
Our Copyright & IP Policy provides an operational notice, counter-notice, evidence and repeat-infringer workflow. Rights assertions are source-specific and remain unknown until evidence is supplied.
14. Contact and changes
Privacy requests: pending confirmation. Legal notices: pending confirmation. Operator: Femtechnology, Inc., registered address pending confirmation. EU representative: appointment analysis pending. UK representative: appointment analysis pending. Swiss representative: appointment analysis pending. DPO: appointment analysis pending. Material changes require a new version and, where necessary, renewed acceptance.