Privacy Policy
Effective date: March 21, 2026
Last updated: March 22, 2026
This Privacy Policy explains how Torve collects, uses, shares, stores, and protects personal data when you use the Torve website, mobile app, TV app, and related services.
1. Who is responsible for your data
The controller responsible for the processing of personal data described in this Privacy Policy is:
Torve Media
Email: privacy@torve.app
2. Scope
This Privacy Policy applies to:
- the Torve website, including torve.app and related pages,
- the Torve Android mobile app,
- the Torve Android TV app,
- customer support, account administration, and related communications, and
- any connected services that Torve operates or controls and that link to this Privacy Policy.
3. Personal data we collect
Depending on the features you use, we may collect the following categories of personal data.
Account and identity data
- email address
- username or display name
- account identifiers
- authentication status and verification state
Device and app data
- device type, model, operating system, language, region, and app version
- app instance identifiers or installation identifiers
- diagnostic information, crash logs, and performance events
- paired-device information needed for syncing, remote features, or account linking
Settings and preference data
- playback, UI, personalization, watchlist, and app configuration settings
- connected source configuration and related technical settings
- feature toggles and service preferences
- storage mode preferences for integrations (account-linked or device-only)
Integration and connected-service data
If you choose to configure optional integrations, addons, or connected services within Torve, we may collect and store:
- integration type and connection status
- non-secret configuration, such as quality preferences or feature settings
- a display identifier, such as a username or masked key, to help you identify your saved integration
- verification and connection timestamps
If you choose account-linked storage for an integration, credentials such as API keys, authentication tokens, or service login details may also be stored on Torve servers in encrypted form. If you choose device-only storage, those credentials remain on your device and are not stored on Torve servers.
Passwords, API keys, and similar secrets saved to your account are not shown back to you in full in normal app flows after saving.
Usage data
- feature usage events
- service interaction logs
- session and reliability information
- supporting data needed to maintain security, prevent abuse, and improve the service
Purchase and transaction data
- purchase status and store-provided transaction metadata
- store-provided purchase tokens or identifiers
We do not receive your full payment card number when purchases are processed by Google Play or another payment provider.
Support and communications data
- emails or messages you send to us
- support requests, bug reports, and legal/privacy requests
- attachments, screenshots, or logs you voluntarily provide
Website data
- basic server logs, such as IP address, user agent, request time, and referral data
4. How we collect personal data
- directly from you, for example when you create an account, sign in, contact support, or change settings,
- directly from you when you configure optional integrations, addons, or connected services, which may involve providing credentials such as API keys, tokens, usernames, or service login details,
- automatically from your device or app usage, for example diagnostics, app events, or security logs,
- from app stores or payment providers to confirm purchases and entitlements, and
- from service providers or third-party integrations that support our product, only where necessary for the feature you use.
5. Why we process personal data and the legal bases we rely on
To provide the service
We process personal data to create and manage accounts, authenticate users, sync settings and devices, enable supported app features, provide playback-related functionality, and deliver customer support. This includes associating user-selected integrations and settings with your account, authenticating optional connected services where the user has configured them, maintaining device-only versus account-linked storage preferences, and supporting restoration of account-linked integrations where available in the app version you are using.
Legal basis: performance of a contract, or steps taken at your request before entering a contract.
To secure the service and prevent misuse
We process data to detect abuse, investigate suspicious activity, protect accounts, maintain audit logs, and keep our services stable and secure.
Legal basis: legitimate interests, and where applicable compliance with legal obligations.
To improve reliability, performance, and product quality
We use diagnostic and usage information to troubleshoot crashes, improve stability, fix bugs, and understand how features perform.
Legal basis: legitimate interests, or consent where required by applicable law.
To verify purchases and maintain records
We process purchase and transaction metadata to verify entitlements, manage access, and maintain accounting or tax records.
Legal basis: performance of a contract and compliance with legal obligations.
To communicate with you
We may send service-related notices, security alerts, account messages, support responses, and legally required communications.
Legal basis: performance of a contract, legitimate interests, or compliance with legal obligations.
With your consent
Where we rely on consent, such as for optional marketing or certain optional analytics, you may withdraw your consent at any time.
Legal basis: consent.
6. When we share personal data
We do not sell personal data. We may share personal data only as described below.
- Infrastructure and hosting providers. We use hosting and server infrastructure providers to operate Torve, including Hetzner.
- Transactional communications providers. We use email delivery providers, including Resend, to send account verification, password reset, and other service-related emails.
- App marketplaces and payment processors. We use Google Play for app distribution and in-app purchases on Android and Android TV, and Paddle as merchant of record for purchases made on torve.app. Each handles billing, payment data, and platform compliance under their own privacy terms.
- User-configured connected services. If you choose to connect optional integrations or third-party services within Torve, the data needed to authenticate and operate those integrations may be sent to the relevant service. This only occurs when you actively configure and enable a connection. Torve does not share your data with third-party services you have not chosen to connect.
- Legal and regulatory recipients. We may disclose data where required by law, legal process, or to protect rights, safety, security, or the integrity of our services.
- Corporate transaction recipients. We may disclose data in connection with a merger, financing, acquisition, restructuring, or sale of assets, subject to appropriate safeguards.
7. Third-party services and processors
We use selected third-party service providers and infrastructure partners to operate, secure, and improve Torve. These providers process personal data only as needed to provide their services to us and subject to appropriate contractual, technical, and organizational safeguards where required by law.
Hosting and infrastructure
- Hetzner, for virtual server infrastructure and hosting. This may involve server-side processing and storage of account data, device data, settings, tokens, logs, and related service data on infrastructure we control.
- PostgreSQL, self-hosted by Torve on Hetzner infrastructure, for core application database storage. This may include account, device, settings, token, and related service data.
- Let's Encrypt, for TLS certificate issuance and renewal. This generally involves domain and certificate-related technical data.
Communications
- Resend, for transactional email delivery such as email verification, password reset, account notices, and similar service communications. This may involve email addresses, message metadata, and email content required to deliver those communications.
App marketplaces and payment processors
- Google Play, for Android and Android TV app distribution, updates, in-app purchase verification, billing, and related platform operations. This may involve purchase tokens, transaction metadata, app install and update data, and other platform-provided transaction information.
- Paddle.com Market Ltd, as merchant of record for purchases made through torve.app. Paddle processes the transaction, collects and remits any applicable taxes, and issues the customer-facing invoice. This may involve your email, billing name and address, payment-instrument metadata (never the full card number — that stays with Paddle), transaction ID, and refund history.
Other SDKs and integrations
Torve may also include third-party libraries or SDKs in its Android mobile or TV apps. Where those SDKs collect, transmit, or otherwise process personal data, we will update this Privacy Policy and our app store disclosures accordingly.
8. Data retention
We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the service, maintain security, comply with legal obligations, resolve disputes, and enforce our agreements.
- Account data: retained while your account is active and for a limited period afterward where needed for security, fraud prevention, backup cycles, dispute handling, or legal compliance.
- Account-linked integration data: integration metadata and encrypted credentials stored under your account are retained while your account is active and until you remove the integration or delete your account. Encrypted credentials are deleted along with the account-linked integration record.
- Device-only integration credentials: credentials stored in device-only mode are held only on your device. They are cleared when you sign out and are not retained by Torve servers.
- Transactional email records: retained for as long as needed to deliver, verify, and document account-related communications and to investigate misuse or delivery issues.
- Operational logs and diagnostics: retained for a limited period appropriate to troubleshooting, security monitoring, and service integrity.
- Billing and tax records: retained for the period required by applicable law and platform obligations.
- Support communications: retained for as long as needed to resolve the request, maintain support history, and satisfy legal obligations.
When retention is no longer necessary, we delete, anonymize, or securely isolate the data unless continued storage is legally required.
9. International data transfers
Your personal data may be processed in countries other than the country in which you live. Where required by law, we use appropriate safeguards for international transfers, such as adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms.
10. Your privacy rights
Depending on your location and applicable law, you may have the right to:
- request access to your personal data,
- request correction of inaccurate or incomplete data,
- request deletion of your personal data,
- request restriction of processing,
- object to certain processing,
- request data portability,
- withdraw consent where processing is based on consent, and
- lodge a complaint with a supervisory authority.
To exercise your rights, contact privacy@torve.app. We may need to verify your identity before completing your request.
If you are in the EEA, UK, or another jurisdiction with similar rights, you may also complain to the relevant data protection authority in your country.
11. Account deletion and data deletion
If you create a Torve account, you can request deletion of your account and associated personal data:
- in the app, through Settings > Account > Delete Account, and
- through our web deletion page at torve.app/account-deletion.
When you request account deletion, we will delete or anonymize your personal data, including account-linked integration records and any encrypted credentials stored under your account, unless we must retain certain information for legal, security, fraud prevention, financial reporting, or other lawful reasons.
If some data cannot be deleted immediately, for example because it remains in secure backups for a limited period, we will isolate it and delete it according to our retention and backup schedules.
12. Security
We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. These measures may include encryption in transit, access controls, logging, least-privilege practices, and secure development and operational procedures.
Account-linked integration credentials are encrypted at rest before storage. Passwords, API keys, and similar secrets are not displayed back to you in full in normal user-facing flows after saving.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Children
Torve is not directed to children under 13, or the minimum age required by applicable local law. We do not knowingly collect personal data from children in violation of applicable law. If you believe a child has provided personal data to us, contact us at privacy@torve.app so we can investigate and take appropriate action.
14. Integration storage choices
When you configure optional integrations, addons, or connected services within Torve, you may choose how your credentials are stored:
- Account-linked storage. Credentials are encrypted and stored on Torve servers under your account. Account-linked storage may allow your integrations to be restored when you sign in again, where supported by the app version you are using. You can remove a saved integration at any time.
- Device-only storage. Credentials are stored locally on your device only. They are not saved to Torve servers, are not synced to other devices, and are cleared when you sign out. Only non-secret metadata such as the integration type and configuration preferences may be recorded under your account.
In both modes, passwords, API keys, and similar secrets are not displayed back in full after saving.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data practices. When we make material changes, we will update the effective date above and provide additional notice where required by law.
16. Contact us
For privacy questions, rights requests, or complaints, contact:
privacy@torve.app