Privacy policy
Publisher: Jason Ferguson (Trovu)
Contact: [email protected]
Prepared: 25 September 2026; effective on publication.
Trovu Capture processes screenshots on your Mac. It does not operate a Trovu account or image-hosting service, and does not use advertising SDKs. Screenshots are uploaded only when you explicitly choose iCloud sharing or another sharing service. Optional crash and error reporting uses Sentry to improve app reliability.
Screen content
Trovu Capture requests macOS Screen Recording permission so it can capture the screen content you select. Captures may contain any information visible in the selected region, window, or display. The app captures still images; it does not record microphone audio.
Text extraction
Text recognition uses Apple's on-device Vision framework. Screenshots and selected image regions are processed locally; neither the image nor recognized text is sent to an OCR service. Text extracted from the editor remains in its results dialog until closed, unless you choose Copy All or Save Text. Separately, choosing Index Text in Library stores recognized text with capture titles, tags, and favorites in a hidden local SwiftData SQLite database (.trovu-library.store and its companion files) in the active capture folder so that searches work across launches. Local email and phone suggestions are shown for your review before redaction and may miss sensitive content. User-configured synchronization of the chosen capture or save folder is governed by that service's settings.
Purchases and local image tools
Apple StoreKit verifies the trial and full-unlock transactions. A local Keychain timestamp helps prevent the trial clock from moving backward. The app does not receive your payment-card details. QR decoding and foreground recognition run locally. QR results are copied automatically. Translation uses Apple's on-device framework on supported macOS versions; Apple may download language models.
Local storage and export
Original captures are stored in the capture folder selected in Settings, or the app’s default local library, until you delete their files. Library lists PNG captures and editable .trovucapture/.trovu projects in the active folder and supports confirmed deletion of individual or selected captures by moving their files to Trash. Library → Show Folder opens the location in Finder. Older captures are not automatically deleted.
Editable .trovucapture projects and autosave recovery data are stored locally; saved checkpoints may keep earlier versions. Editable .trovuguide files embed their images at the location you choose. Applying redaction covers the current rendered image, but older captures, projects, recovery files, checkpoints, and undo history may retain the original pixels. Use a newly flattened export for sharing redacted content. Native sharing and file drag create temporary PNGs on this Mac; the app retains these for at least 48 hours so receiving apps can import them, then removes older files during later sharing operations.
Choosing iCloud Link uploads the flattened screenshot to your iCloud storage and asks Apple to create a temporary download link. Anyone with the link can download that snapshot until it expires. Closing the dialog may leave an upload in progress; the copied file remains in iCloud Drive. No upload happens automatically when capturing or editing.
Keyboard shortcut, presentation, and annotation preset preferences are stored locally. New captures are automatically copied to the system clipboard. Decoded QR content is also copied automatically. Edited images can be copied to the system clipboard, shared through a macOS service, dragged to another app, or exported to a location you choose. Other apps with clipboard access may read images you copy, and recipients of shared or dragged images receive that image. If you choose a capture folder or export destination synchronized by a third-party service, that service's settings and privacy policy govern synchronization.
Trovu does not keep a publisher-controlled server copy of your captures. Your chosen iCloud shares are stored in your Apple account. Backups made by macOS or services you configure are controlled by their respective settings.
Crash and error diagnostics
When Settings → General → Send crash reports is enabled (the default), Trovu Capture sends crash reports and selected capture/export error reports to Sentry's US ingestion service. Reports include the app release/build, operating-system version, device model/architecture, error codes, and technical stack traces needed to investigate failures. Reports may be queued in the app's local cache until delivery is possible.
The app does not attach screenshots, extracted text, document contents, UI recordings, or user-entered filenames to these reports. Automatic breadcrumbs, logs, session/usage tracking, performance tracing, memory introspection, and default personally identifying fields are disabled. Before sending, the app strips user/request information, free-form error descriptions, extra fields, thread names and source-path directories. Sentry receives network connection metadata needed to deliver requests; the app does not set an IP address or user identity on events.
Turn reporting off in General settings to stop the SDK. Diagnostic data is retained according to the Sentry account’s configured retention settings. Access is limited to the publisher and authorized service providers. Contact [email protected] with privacy questions or requests about associated diagnostic data. Sentry’s service privacy terms also apply to its processing of diagnostic data.
Your choices
Revoke capture access in System Settings → Privacy & Security → Screen & System Audio Recording. You can clear or change keyboard shortcuts in Trovu Capture → Settings. Delete capture files through Library or Finder; recover or permanently remove trashed files using Finder. Remove exports, guides, projects, recovery/checkpoint files, and any copies stored by other apps or services separately. The hidden Library database and companion files in a chosen capture folder may also contain recognized text. Upgrades import the old .trovu-library.json file once and retain it unchanged as a migration backup, which can retain earlier titles, tags, and recognized text even after captures are deleted. Remove unwanted backups separately. SwiftData CloudKit synchronization is disabled.
Contact and changes
Contact [email protected] for privacy questions and requests. We may update this policy when the app’s features or data practices change.
Help pages and their sample screenshots are bundled with the app. Help search runs locally. The embedded WebKit viewer is restricted to the bundled Help page, and its content security policy blocks network resources. The sandbox network-client entitlement is included for WebKit’s renderer; Help itself does not load network content. The network entitlement also supports optional Sentry diagnostics, StoreKit, and explicit iCloud sharing.