Troi
These policies are drafts pending legal review and may change before launch.

Troi Privacy Policy

Effective date: 2026-07-09 · Version: 1.0 · Last updated: 2026-07-09

DRAFT — pending attorney review. This is a usable draft implementing Kanah LLC's documented privacy decisions. It is not a substitute for licensed-counsel sign-off and should not be published as final until reviewed.


The short version (plain-language summary)

  • Who we are. Troi (Troi Studio and Troi Life) is operated by Kanah LLC, a Wyoming company. When you use Troi for your own account, we are the controller of your personal data.
  • What we collect. Your account details, the content you create, technical/device data, and — only in Troi Life and only if you turn it on — sensitive wellness data (health, journal/mood, cycle, voice, sensitive financial).
  • We ask before we collect sensitive data. Sensitive Life data is collected only with your explicit, per-category opt-in consent, and deleted immediately if you withdraw that consent.
  • We don't sell or share your personal data for advertising, and we use no third-party ad trackers. Analytics are first-party and minimal.
  • AI. By default you use your own AI-provider account and key ("bring your own key"), often running on your own Troi Runner — your provider's own settings govern. Any Troi-provided ("managed") AI uses a zero-retention, no-training tier. AI output can be wrong and is not professional advice.
  • Your rights. You can access, export, correct, and delete your data — self-service in the app or by emailing us. We respond within 30 days.
  • Adults only. Troi is for users 18 and over.
  • More detail on wellness data is in our separate Consumer Health Data Privacy Policy; cookies are covered in our Cookie Policy.

1. Who we are and how to reach us

Troi — comprising Troi Studio, Troi Life, and the optional Troi Runner desktop software — is operated by:

Kanah LLC 1603 Capitol Avenue, Suite 413A, #2280 Cheyenne, WY 82001, Laramie County, USA Email: info@kanah.app · Phone: +1 (424) 291-5470

In this policy, "we", "us", "our", and "Kanah" mean Kanah LLC. "Troi" or "the Service" means the Troi products above. "You" means the person using the Service.

Privacy questions and requests: info@kanah.app

2. Our role: controller and processor

  • When you use Troi for your own account (a Troi Life user, or the individual owner of a Troi Studio workspace), Kanah LLC is the data controller — we decide how and why your personal data is processed, and this policy governs.
  • When you invite a team into a Troi Studio workspace, the workspace owner directs what content is created and stored there. For that shared workspace content, Kanah LLC acts largely as a processor / service provider on the workspace's behalf, while remaining the controller for the underlying account and technical data we need to run the Service.
  • For personal data about other people that you enter into Troi (for example contacts, people, or emergency contacts), you are responsible for having a lawful basis to provide it; we process it on your behalf to deliver the feature you're using.

Troi is not a social platform: there is no public feed, no stranger-to-stranger sharing, and no user-to-user discovery. Collaboration happens only within a workspace you own or are invited to.

3. The personal data we process

We use the following canonical categories across all Troi documents:

  1. Account data — email, display name, country of residence, age confirmation (18+), and authentication tokens.
  2. User content — everything you create or store: in Studio, your projects, designs, code, chats, videos, and social posts; in Life, your entries across all topics (notes, tasks, journals, and so on).
  3. Special-category / sensitive data (Troi Life only) — health & wellness (workouts, sleep, nutrition, labs, conditions), mental-health/journal data (mood, reflections), reproductive/cycle data, and sensitive financial data. We process these only with your explicit, per-category opt-in consent. (If you choose to upload a "voice profile," we store that audio recording as your own content to use in features you enable — we do not create a biometric voiceprint of you or clone your voice.)
  4. Third-party personal data you enter — contacts, people, and emergency contacts you add.
  5. Connected-account data — data from third-party services you choose to connect (email, calendar, storage, social, payment, communications), used only to provide the connected feature.
  6. Payment datanot collected while the Service is free (as at launch). If and when paid plans are introduced, payments will be handled by Stripe (card details never touch Troi servers), and we would store only billing metadata (plan, status, country).
  7. Device / technical data — push tokens, IP address, device/browser information, and diagnostics/logs.

We do not knowingly collect data from anyone under 18 (see Section 12).

4. Why we process your data, and our legal bases (GDPR Art 6 and Art 9)

What we doData usedLegal basis (GDPR)
Provide the Service — accounts, workspaces, storing and syncing your content, running Troi Runner jobsAccount, user content, connected-account, devicePerformance of a contract (Art 6(1)(b))
Collect and process sensitive Life data (health, journal/mood, cycle, sensitive financial)Special-category / sensitive dataYour explicit consent (Art 6(1)(a) + Art 9(2)(a)), per category
Keep the Service secure; prevent fraud and abuse; operate and improve the productAccount, user content (non-special-category), device/technicalLegitimate interests (Art 6(1)(f))
Functional preference cookies (theme, language)DeviceYour consent (Art 6(1)(a)), given when you choose the preference
Meet legal duties — tax, sanctions screening, mandatory reportingAccount, billing, countryLegal obligation (Art 6(1)(c))

Where we rely on legitimate interests, you can object at any time (Section 9). Where we rely on consent, you can withdraw it at any time without affecting processing already carried out.

5. How long we keep your data (retention schedule)

We keep personal data only as long as we need it for the purposes above, then delete or de-identify it on this schedule:

DataRetention
Account & profileLife of the account, then a 30-day grace window after a deletion request, then hard delete
User contentLife of the account (you can delete it anytime)
Agent chat message bodies12 months from your last interaction (plus your "clear history" action)
Special-category Life dataDeleted on account deletion, and immediately when you revoke consent for that category
Identity documents (SSN / passport / policy numbers)Deleted on account deletion; encrypted at rest (AES-256-GCM) while stored
Uploaded voice-profile audio (your own recording; not a biometric voiceprint)Kept as your content; deleted on account deletion or when you delete it
Chat attachments / application logs7 days
BackupsPurged on rotation, maximum 35 days

Because backups rotate, data you delete may persist in encrypted backups for up to 35 days before it is purged.

6. Who we share data with (recipients and sub-processors)

We share personal data only with the service providers ("sub-processors") we need to run Troi, and only for the purposes above. We publish and maintain our current list on our Sub-Processor List page (/legal/subprocessors) and commit to 30 days' advance notice before adding a new Troi-operated sub-processor. Our sub-processors fall into three groups:

  • Troi-operated (infrastructure): Microsoft Azure (hosting, storage, and Azure Communication Services email), Stripe (payments, only once paid plans launch), and the AI/media providers below. (Troi sends no SMS for its own service; Twilio is used only if you connect your own Twilio account — see user-initiated connections.)
  • AI / media providers: in bring-your-own-key mode these are your providers (accessed with your key, under your account) — not Troi sub-processors; for any Troi-provided managed AI they are Troi sub-processors on a zero-retention/no-training tier. See Section 11 and the Sub-processor List.
  • User-initiated connections (only if you connect them): Google, Microsoft, Apple, Slack, Meta/Instagram, TikTok, X, LinkedIn, YouTube, and other services you link. These act on your instruction to provide the connected feature or to publish content you choose to publish.

We may also disclose data when legally required (for example a valid court order), to enforce our terms, or to protect rights and safety — and as part of a merger, acquisition, or sale, in which case we'll notify you and this policy will continue to protect your data. We do not sell or share your personal data for advertising (see Section 11).

7. International data transfers

Troi is hosted in the United States at launch. When we transfer personal data from the EU, UK, or Switzerland to the US or to a sub-processor, we rely on:

  • Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum);
  • the EU-US Data Privacy Framework (DPF), where the recipient participates; and
  • a Transfer Impact Assessment (TIA) evaluating the protections in the destination country.

EU-region hosting is a planned option and is not yet available. You can request a copy of the relevant transfer safeguards from info@kanah.app.

8. How we protect your data (security)

We use technical and organizational measures appropriate to the sensitivity of the data, including encryption in transit and at rest, access controls, and default-deny access controls that stop AI agents from reading your most sensitive tables unless you explicitly opt in per category. Identity numbers (SSN, passport, and insurance policy numbers) are encrypted at rest with AES-256-GCM. No system is perfectly secure, but we work to protect your data and to notify you and regulators of a breach where the law requires.

9. Your privacy rights

Depending on where you live, you have some or all of these rights:

Under the GDPR / UK GDPR (Arts 15–22):

  • Access — get a copy of your data (Art 15).
  • Rectification — correct inaccurate data (Art 16).
  • Erasure — delete your data ("right to be forgotten") (Art 17).
  • Restriction — limit how we use your data (Art 18).
  • Portability — receive your data in a machine-readable format (Art 20).
  • Objection — object to processing based on legitimate interests (Art 21).
  • No solely-automated decisions with legal or similarly significant effect (Art 22) — see Section 13.
  • Withdraw consent at any time, and lodge a complaint with your supervisory authority.

Under California law (CCPA / CPRA): the right to know, delete, and correct your personal information; the right to opt out of "sale" or "sharing" (not applicable — we don't sell or share); and the right to limit the use of sensitive personal information. See Section 11.

Under the Washington My Health My Data Act (MHMDA) and similar Nevada and Connecticut laws: the right to access and delete your consumer health data, to withdraw consent, and to have your data not sold or shared without a separate authorization. These are covered in detail in our separate Consumer Health Data Privacy Policy.

How to exercise your rights. The fastest way is self-service in the app: Settings → your data to export, and Settings → Delete account to delete. You can also email info@kanah.app. We will respond within 30 days (extendable where the law allows for complex requests, with notice to you). We will not discriminate against you for exercising your rights. You may use an authorized agent where the law permits.

10. Account deletion and data export

  • Deletion. You can delete your account in the app (Settings → Delete account) and at a public web page reachable without logging in at /legal/delete-account. Deletion runs a server-side purge across your account, content, connected data, and stored files. A 30-day grace window lets you recover from an accidental or hostile deletion before the purge becomes irreversible; during the grace window your account is disabled, not yet purged. Deleted data may remain in encrypted backups for up to 35 days (Section 5).
  • Export. You can request a data export in the app and receive your records in machine-readable JSON (plus CSV for tabular Life data) via a time-limited download link.

11. AI processing

Some Troi features use artificial intelligence to help you draft, summarize, generate, or transform content.

  • You usually use your own AI account ("bring your own key"). By default, you configure an AI provider (such as Anthropic or OpenAI) and supply your own API key; your prompts are sent to your own account with that provider — often executed on your own Troi Runner — under your agreement with that provider. In that mode, that provider's retention and training settings, which you control, govern — Troi is a conduit and does not set them. Choose a no-training/zero-retention setting in your provider account if that matters to you.
  • Temporary launch gateway. [[FOUNDER: remove once the launch gateway is disabled — active < 1 week after launch]] For a brief period after launch, we may offer a free AI gateway (funded by our Microsoft Azure resources, routing to the OpenAI/Azure OpenAI API) so you can try AI without your own key. Requests are handled on a no-training basis and pass through Microsoft/Azure (already a sub-processor). This gateway is switched off shortly after launch, after which AI is bring-your-own-key only.
  • AI can be inaccurate. AI output may be wrong, incomplete, or misleading. It is informational assistance, not professional advice — not medical, mental-health, financial, tax, legal, or other professional advice. You are responsible for reviewing AI output before relying on it.
  • Transparency. We label AI-generated content where required and apply provenance information to AI-generated media.

12. Voice data

Troi's voice features are text-to-speech using preset library voices — we do not clone your voice or create a biometric "voiceprint" of you. If you upload a "voice profile," we store that audio as your own content to use in features you enable; we don't turn it into a biometric identifier, sell it, or use it to identify you. You can delete it at any time, and it is deleted on account deletion. If Troi ever introduces genuine voice cloning or other biometric processing in the future, we would obtain your explicit consent and update this policy first.

13. Automated decision-making

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing (GDPR Art 22). AI features assist you — for example by drafting or summarizing — but a human remains responsible for any consequential decision. We do not use AI for automated employment, credit, or other high-stakes decisions.

14. Children

Troi is for adults aged 18 and over only. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has provided us data, contact info@kanah.app and we will delete it.

15. Sensitive-data notice — this is not healthcare

Troi Life is a consumer wellness and self-tracking tool. It is not a healthcare provider, covered entity, or HIPAA business associate; it is not a medical device; and it does not provide medical, mental-health, financial, tax, legal, or professional advice. For how we handle wellness data, see our separate Consumer Health Data Privacy Policy.

16. Cookies and similar technologies

Troi uses a small set of cookies and local storage — strictly-necessary (authentication and security) and functional preferences you set yourself (theme, language). We use no analytics, advertising, or third-party tracking cookies and do not sell or share data via cookies. Because we set no non-essential tracking cookies, we do not display a cookie-consent banner; if we ever add analytics or similar, we'll introduce a consent mechanism (and, for EU/UK visitors, a prior-opt-in banner) first. We honor the Global Privacy Control signal by not selling or sharing personal data. See our Cookie Policy for the full inventory.

17. California — we do not sell or share; limit sensitive PI

For California residents: we do not "sell" and do not "share" your personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding 12 months. Because we don't sell or share, there's no opt-out to exercise — but you retain the right to limit our use of your sensitive personal information to what's needed to provide the Service, which is already how we operate (sensitive Life data is consent-gated and used only for the feature you enable). To make a California request, email info@kanah.app or use the in-app controls.

18. Data protection contacts

  • Privacy / data-subject requests: info@kanah.app
  • Data Protection Officer (DPO): not currently appointed
  • EU Representative (GDPR Art 27): appointment in progress
  • UK Representative: appointment in progress
  • General / support: info@kanah.app · +1 (424) 291-5470

You also have the right to lodge a complaint with your local data protection authority (in the EU/UK) or your state Attorney General (in the US).

19. Changes to this policy

We may update this policy as the Service and the law evolve. We'll change the version and last-updated date at the top, and for material changes we'll give you notice (for example in-app or by email). Continued use after an update means you accept the revised policy, except where your consent is separately required.

20. Contact

Questions about this policy or your data? Email info@kanah.app or write to Kanah LLC at the address in Section 1.


Related documents: Cookie Policy · Consumer Health Data Privacy Policy · Terms of Service · Sub-Processor List (/legal/subprocessors).