Privacy Policy
1. Who the controller is
ivmar, Inc., a company incorporated in the State of Delaware, United States, is the controller of the personal data described here. ivmar, Inc. operates Trouvo and decides why and how that data is processed.
You can reach us about anything in this policy at support@ivmar.co.
This policy covers Trouvo. It does not cover the sites of the companies listed under "Who receives your data", each of which has its own policy.
2. What we collect
We collect only what the service needs to work, and two things beyond it, both resting on your consent rather than on using the product: if you accept analytics cookies, Amplitude records how the product is used, and if you join our waitlist we collect what running it requires. Analytics is the one with a switch: it is off until you turn it on, and the Cookie settings link turns it off again. The waitlist has no switch: joining is itself the consent, and leaving the list, described below, is how you withdraw it. There is no tracking pixel and no advertising network on Trouvo.
Account data. Your name, your email address, and (if you signed up with an email address and a password) that password, stored only as a salted hash that cannot be reversed into the password itself. Your account also has a field for an avatar URL, so we can show your picture; it holds a plain web address and is not tied to any particular source, and today the only thing that fills it in is Google, Apple or LinkedIn handing us one when you sign in with them. We also store whether your email address has been verified, the role your account has in the product, and whether it is suspended, together with the reason and the date the suspension ends.
Authentication data. For each sign-in provider you connect (Google, Apple or LinkedIn), we store what identifies your account with them and the credentials that keep you signed in through them, until you disconnect the provider or delete your account. A link sent to verify your email address or reset your password stops working once it expires.
Session data. While you are signed in, we keep a record of that session: when it started, when it is due to expire, and basic technical details (your IP address and browser) about the device and connection it started from.
Analytics events. Only if you accept analytics cookies. We record three things you do (creating an account, signing in, and creating an interview briefing): the first two with the method you used, and nothing else about what you were doing; the third with nothing at all beyond the fact that it happened. Amplitude receives them together with the identifier it keeps in your browser, your IP address, from which it derives an approximate location (country and city), the user-agent string your browser sends, which names your browser, its version and your operating system, and the language your browser is set to. It does not receive your name, your email address or anything you type into the product. The Cookie Policy sets all of this out in full.
Error monitoring. Sentry receives the error and its stack trace, the page or request it happened on, and breadcrumbs: a short trail of the requests, console messages, clicks and navigations that led up to it. It also receives performance traces sampled from roughly one in ten ordinary page loads, whether or not anything went wrong, and every event carries technical details of your browser, operating system and device, including your browser's user-agent string. It does not receive request bodies, cookies, credential headers or email addresses (those are removed before an event leaves), and no IP address is attached to what it receives. On the signed-in pages of Trouvo the account identifier we hold for you is attached as well, so that a fault can be counted by how many people it reached rather than only by how many times it happened. That identifier is the one on your account record and nothing beyond it: it means nothing outside our own database, and your name, your email address and your IP address do not travel with it. Signed out, nothing identifying you is attached at all.
Waitlist. If you join our waitlist, we store the email address you give us (lowercased), the page you signed up from, and your language preference, together with whether the signup is pending or confirmed, the time you joined, and, once you confirm, the time you did. We also store the confirmation token itself and the time it expires (seven days after you join), and it stays on the record after that rather than being deleted on its own; using it while it is valid is what proves the address is yours (double opt-in). We use all of this only to confirm your address and to contact you about early access (we do not add you to any other list), and you can leave at any time by writing to support@ivmar.co, after which we delete the record, token included.
What you write to us. When you email support@ivmar.co (with a question, or to exercise one of the rights in section 9), we have your message, the address you sent it from and anything you chose to put in it. That correspondence is not part of Trouvo: it sits in the mailbox that received it.
Documents and briefings. If you upload a resume, we store the file itself, its name and size, and whether we have finished reading it into your profile. If you add work experience, education, certifications or a saved interview story, we store what you typed. Each interview briefing you create stores the company, role and job description it is built from (or the job posting link, if that is how it started), plus what Trouvo generates for it using the AI providers described in section 6: research on the company and the people you will meet, likely and tricky questions tailored to the role, and the stories from your profile that best fit it. If you record how an interview actually went, we store the call notes or transcript you give us, together with what Trouvo draws from them: questions you were actually asked, the feedback you received, and patterns we carry forward into your next briefing, such as a habit worth fixing or a story that worked well. Deleting a briefing deletes everything generated for it; deleting your account deletes all of this along with it, as section 4 describes.
We do not ask for and do not want special categories of data: health, ethnic origin, political opinions, trade-union membership, sexual orientation and the rest. Please keep them out of anything you send us.
3. Why we process it, and on what legal basis
If you are in the European Economic Area, the United Kingdom or Switzerland, each purpose has a legal basis under the GDPR (or, for the UK, the UK GDPR):
| Why | What it uses | Legal basis |
|---|---|---|
| Creating your account and letting you sign in | Account data, authentication data | Performance of a contract (Article 6(1)(b)) |
| Keeping you signed in and ending the session when it expires | Session data | Performance of a contract (Article 6(1)(b)) |
| Generating your interview briefing: company and interviewer research, questions, and the debrief | Documents and briefings data | Performance of a contract (Article 6(1)(b)) |
| Answering you when you write to us | Account data, what you write to us | Performance of a contract (Article 6(1)(b)), or our legitimate interest in replying (Article 6(1)(f)) |
| Keeping accounts secure, investigating abuse and enforcing the Terms of Service | Session data, account data | Our legitimate interest in a secure service (Article 6(1)(f)) |
| Finding and fixing errors in the product | The error monitoring data described in section 2 | Our legitimate interest in a working, debuggable product (Article 6(1)(f)) |
| Understanding how the product is used | Analytics events, the Amplitude identifier in your browser, your IP address, your user-agent string and your browser language | Your consent (Article 6(1)(a)) |
| Contacting you about early access (waitlist) | Waitlist data | Your consent (Article 6(1)(a)) |
We do not sell personal data, and we do not use it to build advertising profiles. We do not make decisions about you by automated means that produce legal effects for you or similarly significantly affect you.
4. How long we keep it
- Account data: for as long as the account exists. When the account is deleted we delete it, and your sessions and your connected sign-in providers are removed together with it. Section 10 says how to ask us to do that.
- Session data: until the session expires or you sign out. A session lasts seven days from the moment you sign in, and using Trouvo does not push that out: the sign-in cookie your browser holds is issued to expire seven days later whatever you do in between, so after seven days you sign in again and that creates a new session.
- Documents and briefings: for as long as the account exists, or until you delete the specific briefing, story or document yourself. Deleting the account deletes all of it, as section 10 describes.
- What you write to us: for as long as we keep the correspondence. Section 10 says how to ask us to delete it.
- Email verification and password reset tokens: until they expire, and no longer.
- Waitlist data: for as long as the record exists, confirmed or not. Nothing deletes it on its own: the confirmation token described in section 2 stays with the record after it expires rather than being removed, and the record itself is removed only when you ask us to, as section 10 describes.
- Backups: copies of the database are kept in backups and roll off on their own schedule, so deleted data may persist in a backup for a short period after it is gone from the live service.
5. Who receives your data
We share personal data only with the companies Trouvo needs in order to run, and only what each of them needs: the ones that host and store it for us, the AI providers that generate your interview briefing (section 6 says more about them), the analytics service that receives usage events if you accept analytics cookies, the error monitoring service that receives what section 2 describes, the email provider that handles sending email on our behalf, and the sign-in providers that send us a profile when you choose to sign in with them. The tables on this page name every company that handles your data inside Trouvo, what it does for us, where it is, and where to read its own privacy policy.
Service providers
| Company | Purpose | Country | Privacy policy |
|---|---|---|---|
| DigitalOcean, LLC | Application hosting and the managed PostgreSQL database | United States | Read policy |
| Amplitude, Inc. | Product analytics, loaded only after you accept analytics cookies | United States | Read policy |
| Functional Software, Inc. | Error monitoring: finding and fixing application errors. Runs on our legitimate interest, not your consent. | United States | Read policy |
| Resend, Inc. | Sending account email: password reset links and address confirmations. Part of providing your account, so it does not wait on consent. | United States | Read policy |
| Anthropic PBC | Generating your interview briefing: company research, interviewer research, likely questions, and reading back call transcripts. Does not use what you send it to train its models. | United States | Read policy |
| Hangzhou DeepSeek Artificial Intelligence Co., Ltd. | Generating parts of your interview briefing. May use what you send it to train its own models; see the AI processing section above. | China | Read policy |
| Moonshot AI Pte. Ltd. | Generating parts of your interview briefing, including company research that needs a live web search. May use what you send it to train its own models; see the AI processing section above. | Singapore | Read policy |
Sign-in providers
| Company | Purpose | Country | Privacy policy |
|---|---|---|---|
| Google LLC | Signing in with a Google account | United States | Read policy |
| Apple Inc. | Signing in with an Apple account | United States | Read policy |
| LinkedIn Corporation | Signing in with a LinkedIn account | United States | Read policy |
6. AI processing
Trouvo's interview briefings are generated with the help of AI language models, not written by hand. We currently route that work across three providers, by task: Anthropic (Claude), DeepSeek and Moonshot AI (Kimi). What each of them receives is limited to what the task needs, drawn from what section 2 describes under "Documents and briefings": company and role details, job descriptions, interviewer names, and, for the debrief, the call notes or transcript you provide. We do not send your resume file itself, your account credentials, or any payment details to any of them.
These three providers do not all treat that data the same way. Anthropic's commercial terms, which govern our use of Claude, say plainly that it does not use what we send it to train its own models. DeepSeek's and Moonshot AI's policies say the opposite: content submitted through their services may be used to train and improve their models, and neither guarantees an opt-out we can rely on for every request. We use DeepSeek and Moonshot AI today because they cost meaningfully less than Anthropic. ivmar, Inc. is not venture-funded, and keeping the product affordable to run is part of why we use them; once the product has revenue behind it, we intend to move this processing to Anthropic only. Until then, this is where things stand, stated plainly rather than left for you to find out later. Section 9 describes your right to restrict or object to how we process your data, and section 10 says how to reach us about it.
7. International transfers
Trouvo is hosted in the United States: the application and the managed PostgreSQL database run in DigitalOcean's nyc3 region in New York, and the images published with our articles are stored in DigitalOcean Spaces. If you accept analytics cookies, the analytics events described in section 2 go to Amplitude, Inc., which is in the United States as well. The error monitoring data described in section 2 goes to Functional Software, Inc. (Sentry), also in the United States. Of the AI providers described in section 6, Anthropic is in the United States and Moonshot AI is in Singapore; DeepSeek is in China. If you use Trouvo from the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred to, and processed in, whichever of these countries the purpose it serves requires.
We are stating plainly, rather than implying arrangements that are not yet in place, that two things remain open: ivmar, Inc. has not yet appointed a representative in the European Union under Article 27 GDPR (until it does, write to support@ivmar.co: that address reaches the people who can answer), and the safeguard for the transfers above (standard contractual clauses, or reliance on a provider's certification under the EU–US Data Privacy Framework where one applies) is being put in place and is not yet concluded for all of them. This section will be updated, with a new effective date, when each is done.
8. US state privacy rights
If the CCPA/CPRA (California's privacy law) applies to us, and you are a California resident, you have the right to:
- know what personal information we have collected about you, and why;
- delete personal information we hold about you, subject to certain exceptions;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information. We do not sell or share personal information as the CCPA/CPRA defines those terms, so there is nothing to opt out of;
- limit the use of sensitive personal information. We do not collect sensitive personal information, so there is nothing to limit;
- not be discriminated against for exercising any of these rights.
We are not certain the CCPA/CPRA's thresholds apply to ivmar, Inc. today. We list these rights regardless: section 10 explains how to exercise them, through the same process this policy already offers under the GDPR.
9. Your rights
If the GDPR applies to you, you have the right to:
- know what we hold about you and get a copy of it (Article 15);
- correct anything inaccurate or incomplete (Article 16);
- delete your data (Article 17);
- restrict how we process it while a question about it is open (Article 18);
- take it with you in a machine-readable format, or have it sent to another provider (Article 20);
- object to processing we base on a legitimate interest (Article 21);
- complain to the data protection authority of the country where you live, work, or where you believe the problem occurred (Article 77).
Where processing rests on your consent, you may withdraw it at any time; that does not affect what was lawful before you withdrew it.
10. How to exercise them
Some of this you can now do yourself, in the product:
- Correct or update your data. Account Settings lets you change your name, email, password and picture. Personal Profile lets you edit or remove your work experience, education, certifications and interview stories.
- Get a copy of your data. Account Settings → Data and privacy has an Export data button.
- Delete your account. The same page has a Delete account button: it asks you to confirm, sends a link to your email, and nothing is deleted until you open that link. Deleting the account deletes the account data described in section 4, and everything described under "Documents and briefings" in section 2, along with it.
- Withdraw analytics consent. The Cookie settings link at the bottom of any public page brings back the card you were shown on your first visit; declining there stops the sending and deletes the Amplitude cookie from your browser on the spot, without writing to us.
Your resume file is not yet something you can replace yourself once uploaded. For that, for restricting or objecting to processing, or for anything else this list does not cover, write to support@ivmar.co. The rights in sections 8 and 9 apply in full whichever path you use.
We answer within one month, as Article 12(3) requires, and tell you if we need longer because the request is complex. We may ask you to confirm your identity (from the address the account uses) so that we do not hand your data to someone else.
11. Children
Trouvo is not for children. It is intended for people aged 18 and over, and we do not knowingly collect data from anyone younger. If you believe a child has given us personal data, write to support@ivmar.co and we will delete it.
12. Changes
We may update this policy as the product and the law change. The current version is always at this address, with the date it took effect at the top. Where a change materially affects your rights, we will tell you by email or in the product before it takes effect.
13. Contact
Questions, requests and complaints about this policy go to support@ivmar.co.
ivmar, Inc.