/privacy
Privacy Policy
Last updated: July 18, 2026
This policy explains what data Better Trove Tools collects, why, and what we do with it. The short version: we collect only the minimum needed to run the Services - no ads, no third-party trackers, and we never sell your data.
1. Who we are
Better Trove Tools ("we", "us") is a free, open-source community project for the game Trove, made up of the desktop app, the web app, this website, and the Kiwi API (together, the "Services"). This policy covers personal data handled by those Services. See also our Terms of Service.
Better Trove Tools is run by an individual, Aallyn Reed, who is the data controller responsible for the personal data described here. For any privacy question or request, you can reach the controller by email at support@aallyn.net.
2. Information we collect
Account information
The website dashboard signs in with Discord only. When you do, we store a basic identifier from Discord - your user id and username - to create your account. We do not request or store your email address at sign-in. You may optionally add an email in your dashboard to receive notifications (such as a giveaway win or an action on your content); we store that address only for that purpose, and you can remove it at any time. If you use the Discord Bot section of the Dashboard, we fetch your list of Discord servers live from Discord at that moment to show which ones you can configure - we don't store that list.
The separate developer portal (for the Kiwi API) uses an email address and password instead. If you create a developer-portal account, we store that email address, and - if you choose to link GitHub - a basic GitHub identifier.
API & usage data
When you use the Kiwi API or the developer portal, we store the API tokens you create and log request metadata - the endpoint called, a timestamp, the response status, and your IP address - to operate rate limits, keep the service secure, and prevent abuse.
Giveaway data
If you enter a giveaway, we record your entry against your account. If you win, your prize code always appears on your dashboard; if you've added an optional notification email, we email it to you as well.
Technical data
We generate standard server and security logs - including IP address and browser/user-agent - when you use the website or API.
Public game data
Leaderboards, market prices, rotations, and updates shown in the Services come from the game's own public services. This is game data, not personal information about you.
3. How we use your information
- to provide and operate the Services;
- to authenticate you and keep your account secure;
- to enforce rate limits and prevent abuse;
- to run giveaways and deliver prizes;
- to send essential transactional emails (for example, email verification and password resets);
- to diagnose problems and improve reliability.
Legal bases
If you are in the EU/EEA or the UK, we rely on the following legal bases under the GDPR:
- Performance of a contract - to provide your account, the Services and API access under our Terms, and to send essential developer-portal emails (verification, password resets).
- Our legitimate interests - to keep the Services secure, enforce rate limits, prevent abuse, and keep things running reliably.
- Your consent - for the optional notification email you choose to add, and for signing in with Discord or GitHub. You can withdraw consent at any time (remove the email, or delete your account).
- Legal obligation - where we must keep or disclose something to comply with the law.
4. What we don't do
We don't sell, rent, or trade your personal data. We don't show ads or embed third-party advertising or tracking. The apps ship with no telemetry. We don't use your data to build advertising profiles.
5. Cookies & local storage
The website sets no cookies of its own. To keep you signed in we store session and refresh tokens in your browser's local storage (not cookies), and we use local storage for preferences like theme and language. We don't use advertising or cross-site tracking cookies or storage. The one exception is the developer portal's bot-protection widget, which may set a strictly-necessary cookie during sign-in to tell humans from bots.
6. Third parties we rely on
To run the Services we use a small number of providers, each processing data only as needed to perform its function:
- Cloudflare - CDN, security, and edge in front of our domains;
- a bot-protection provider (Cloudflare Turnstile or hCaptcha) - on developer-portal sign-in/sign-up forms only, to tell humans from bots;
- Discord and GitHub - only if you choose to sign in with them;
- hosting infrastructure we operate.
Donation links (PayPal, Ko-fi, Buy Me a Coffee) are operated by those companies under their own policies; we don't receive your payment details.
Where your data is processed
Our hosting and email are self-operated. Some of the providers above may process data outside your country - in particular Cloudflare, and (only if you use them) Discord and GitHub, may process data in the United States. Where a transfer takes personal data outside the EU/EEA, it relies on an appropriate safeguard, such as the EU Standard Contractual Clauses or an adequacy decision.
7. Data retention
We keep account data for as long as your account exists. When you delete your account, we delete or anonymize the associated personal data, except where we must retain something for legal or security reasons.
Other data is kept only for a limited time:
- login sessions are removed automatically when they expire;
- API usage logs are kept about 30 days;
- website page-view analytics - which hold no identifying data, only a one-way hash that rotates daily - are kept about 90 days;
- records of emails we've sent are kept about 30 days;
- giveaway records are kept as needed to run and audit the giveaway.
8. Your rights
From your dashboard you can view and update your details, export a copy of your data, and delete your account (which removes or anonymizes your associated personal data). Developer-portal (API) accounts have the same export and delete options in the portal.
Depending on where you live, you may have additional rights over your personal data - such as access, correction, deletion, portability, restriction, and objection. To exercise any of these, contact us using the details below; we don't charge for this and will respond within the time the law allows.
If you are in the EU/EEA or the UK, you also have the right to lodge a complaint with your local data-protection supervisory authority. We'd appreciate the chance to address your concern first, but that right is always yours.
9. Security
We take reasonable measures to protect your data, including encryption in transit, hashed credentials, scoped API tokens, and access controls. No method of transmission or storage is perfectly secure, so we can't guarantee absolute security.
10. Children
The Services aren't directed at children under 16 - or the lower minimum digital-consent age set by your country's law, and never below 13 - and we don't knowingly collect their personal data. If you believe a child has provided us data, contact us and we'll remove it.
11. Changes to this policy
We may update this policy as the Services evolve. Material changes will be reflected by the "Last updated" date above.
12. Contact
Questions or privacy requests? Email us at support@aallyn.net, reach us on Discord, or use our Support page. This address is also our point of contact for data-protection matters.