Legal / Privacy

Privacy Policy

Last updated: June 18, 2026

This Privacy Policy explains how Trouve, Inc. ("Trouve," "we," "us," or "our") collects, uses, shares, and protects information when you use our website, applications, and services (the "Services"). Trouve provides AI agents that operate enterprise software, such as NetSuite, SAP, Salesforce, and HubSpot, on behalf of our business customers.

1. Scope and roles

Trouve serves business customers. It is important to understand the two roles we play:

  • Processor (on behalf of our customers). When Trouve accesses, reads, or modifies data inside your connected systems (e.g., a sales order in NetSuite, a record in Salesforce, a message in Slack) to carry out a task you ask it to perform, we act as a processor (or "service provider"). Our customer is the controller of that data and decides what we do with it. Our handling of that data is governed by the agreement (including any Data Processing Addendum) between Trouve and the customer, which controls if it conflicts with this Policy. When we process protected health information (PHI) for a HIPAA covered entity or business associate under an executed Business Associate Agreement (BAA), we act as a business associate or subcontractor business associate, as applicable.
  • Controller. For information we collect to run our own business, such as your account details, billing, how you use the Services, and our website, we act as a controller, and this Policy governs that processing.

If you are an employee, customer, or contact of a Trouve customer and have questions about data processed through the Services, please contact that organization first; they control how their instance of Trouve is used.

2. Information we collect

Account and contact information. Name, work email, employer, role, and credentials you create when you sign up.

Connection and authorization data. To operate an application on your behalf, Trouve uses one of two methods:

  • Authorization tokens you grant. OAuth tokens, API keys, or similar credentials for NetSuite, SAP, Salesforce, HubSpot, and MCP-connected tools such as Email, Slack, Notion, and Linear. Where you choose to save these so Trouve can act on your behalf, they are stored encrypted and used only to perform the tasks you direct.
  • Credentials entered in our cloud browsers. When you sign in to an application through a sign-in form inside one of our cloud browsers, those credentials are never stored and never keylogged. They are passed directly to the target application to establish your session and are not retained by Trouve.

Task and instruction data. The prompts, instructions, files, and documents you provide so Trouve can complete a task (for example, a sales order you ask it to enter).

Customer Data. Data Trouve reads from or writes to your connected systems while completing a task. This may include business records and, depending on your systems, personal data about your employees, customers, or contacts. In a specifically approved HIPAA-supported deployment, it may include PHI. Trouve accesses only what is needed to perform the requested task.

Execution logs and audit records. Trouve logs the actions its agents take, what was read, created, edited, and when, to provide the audit trail and reviewability that the Services are built around.

Usage and device data. Log data, IP address, browser/device type, pages viewed, feature usage, and similar diagnostic information.

Cookies and similar technologies. Used to keep you signed in, remember preferences, secure the Services, and understand usage. See Section 11.

3. How we use information

We use information to:

  • Provide, operate, and maintain the Services, including running agents that complete the tasks you request;
  • Authenticate to and operate your connected applications on your instruction;
  • Generate audit logs and let you review and trace every action;
  • Secure the Services, detect and prevent fraud or abuse, and troubleshoot;
  • Provide support and communicate with you about your account and service updates;
  • Bill and manage payments;
  • Improve and develop features, measure performance, and analyze usage (in aggregated or de-identified form where practical);
  • Comply with legal obligations and enforce our agreements.

4. AI and automated processing

Trouve's Services rely on AI models, including third-party large language model providers, to plan and carry out tasks.

  • Authorized AI subprocessors may receive the limited Customer Data needed to perform a task, subject to contractual restrictions and the applicable customer agreement. We do not use Customer Data to train our own general-purpose or foundation models, and we do not permit it to train models that serve other customers, except where you have explicitly instructed or permitted us to do so in writing.
  • We may use aggregated or de-identified information that does not identify you or any individual to evaluate, debug, and improve the Services.
  • Trouve performs actions automatically based on your instructions. You remain responsible for reviewing outputs; the audit log is provided so you can do so.

If you require specific AI data-handling terms (e.g., zero-retention processing with model providers), contact us; these are typically addressed in the customer agreement.

Where the GDPR or UK GDPR applies and we act as a controller, we process personal data on these bases: performance of a contract (to provide the Services), legitimate interests (to secure, improve, and operate the Services and our business), consent (where required, e.g., certain cookies or marketing), and legal obligation. Where we act as a processor, our customer determines the legal basis.

6. How we share information

We do not sell Customer Data, rent it, disclose it for cross-context behavioral advertising, or permit it to train models that serve other customers. We disclose information only as described below and subject to the applicable customer agreement:

  • Connected applications. We exchange Customer Data with the applications you direct Trouve to operate in order to complete your tasks.
  • Service providers and subprocessors. Trusted vendors help provide cloud hosting, AI inference, payment processing, support, security, and monitoring. They may process only the information needed to provide their contracted services and are bound by data-protection obligations. A current subprocessor list is available on request.
  • Within your organization. Authorized users in your account may see tasks, logs, and outputs.
  • Legal and safety. We may disclose information where required by law or valid legal process, or where reasonably necessary to protect the rights, safety, and security of Trouve, our customers, or the public. Where legally permitted, we will notify the affected customer and disclose only what is required.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy and to the confidentiality commitments above for Customer Data.

We do not permit service providers or subprocessors to use Customer Data for their own advertising or unrelated commercial purposes.

7. Data retention

We retain information for as long as needed to provide the Services and for legitimate business or legal purposes. Account and connection data are kept while your account is active. Audit and execution logs are retained for the period defined in your agreement or as needed for security and compliance. When data is no longer needed, we delete or de-identify it. Customers can request deletion of their data as described in their agreement; some information may be retained where law requires.

8. Data security

We use technical and organizational measures designed to protect information, including encryption of saved authorization tokens and data in transit and at rest, access controls and least-privilege principles, network and application security, logging and monitoring, and regular review of our practices. Credentials you type into our cloud browsers are never stored or keylogged; they are passed straight to the target application to establish your session. No method of transmission or storage is completely secure, but we work to protect your information and to notify affected parties of incidents as required by law.

HIPAA-supported deployments

Do not submit PHI to Trouve unless you and Trouve have executed a BAA and Trouve has confirmed in writing that the relevant application, workflow, infrastructure, model providers, and support processes are approved for a HIPAA-supported deployment.

For a designated HIPAA-supported deployment, Trouve operates under policies, procedures, safeguards, and contractual restrictions designed to support applicable business-associate obligations. This includes using PHI only as permitted by the BAA and law; applying reasonable and appropriate administrative, physical, and technical safeguards to protect electronic PHI; limiting access according to role and minimum-necessary principles; maintaining audit controls and incident procedures; and requiring any subprocessor that handles PHI to accept appropriate restrictions and safeguards.

HIPAA compliance is a shared, fact-specific responsibility. Customers remain responsible for determining whether their use of the Services complies with HIPAA, configuring access appropriately, limiting the PHI submitted, training their workforce, and fulfilling their own obligations as a covered entity or business associate. For more information, see the HHS Security Rule overview and HHS guidance on Business Associate Agreements.

9. International data transfers

Trouve may process and store information in countries other than where you are located, including the United States. Where required, we use appropriate safeguards for cross-border transfers, such as the European Commission's Standard Contractual Clauses and the UK Addendum. Contact us for more detail or a copy of the relevant safeguards.

10. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, port, or restrict your personal information, to object to certain processing, and to withdraw consent. Residents of California and certain other U.S. states may have rights to know, delete, correct, and opt out of "sale" or "sharing" of personal information and certain profiling. Trouve does not sell or share personal information for cross-context behavioral advertising. You also will not be discriminated against for exercising these rights.

To exercise rights, email shafin@trouve.ai. If your data is processed by Trouve on behalf of a customer (as a processor), we will refer your request to that customer and assist them in responding. We may need to verify your identity before acting.

EEA/UK residents may also lodge a complaint with their local data protection authority.

11. Cookies and tracking

We use strictly necessary cookies to operate and secure the Services, and optional analytics/preference cookies to understand and improve usage. You can manage cookies through your browser settings and, where offered, our cookie controls. Blocking some cookies may affect functionality.

12. Data from connected third-party services

When you connect a third-party service, your use of that service remains subject to its own terms and privacy policy. Trouve is not responsible for the privacy practices of third-party applications you choose to connect. Review their policies and grant only the access you intend.

13. Children's privacy

The Services are intended for business use and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

14. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice as appropriate. Your continued use of the Services after changes take effect means you accept the updated Policy.

15. Contact us