§ Legal
Privacy Policy
Effective August 30, 2026. Trevo reads code, crawls pages you point it at, and measures experiments — so we are specific here about what we collect, what we do with it, and what we will never do with it. The Terms of Service govern use of the platform itself.
1. Scope and roles
This policy covers the Trevo websites, dashboard, APIs, SDKs, GitHub App, and site scanner (the “Service”), operated by Trevo Labs, Inc. For account data, billing data, and anything you do on our own sites, we are the data controller. For the experiment events our SDKs collect from the users of your product (“End User Data”), we act as your processor: we handle it under your instructions and our data processing addendum, and your privacy policy governs it. If you are an end user of a product that uses Trevo, the company behind that product is the right first contact for privacy requests, and we will help them fulfill yours.
2. What we collect
Account data: name, email, password (stored as a hash), workspace membership and role, and authentication data from providers you sign in with such as GitHub. Repository data: when you connect a repository, we read and snapshot its contents — code, configuration, and metadata — to analyze it and write pull requests. Event data: exposure and conversion events sent by the SDKs, containing an experiment key, event name, timestamp, properties you choose, and the identifiers you assign (a user ID and/or an anonymous ID stored in a first-party cookie). Scan data: the domain you submit, the publicly reachable pages we crawl, and the email address you verify to receive the report. Usage data: logs of dashboard and API activity, device and browser information, and an append-only record of experiment decisions (who approved, paused, or called what, and when). Billing data: plan and invoice records; payment details are collected and held by our payment processor, and card numbers do not touch our servers. Communications: support requests and emails you send us.
3. How we use it
We use data to operate the Service: analyzing connected sites and repositories, generating experiment proposals and pull requests, resolving assignments, computing experiment statistics, sending the emails the product requires (verification codes, scan reports, experiment notifications), billing, support, and security. We also use aggregated or de-identified usage data to understand and improve the product. We do not sell personal data, and we do not use it for third-party advertising.
4. AI processing — and what we never do
Repository snapshots and scanned pages are processed by large language models to produce observations, experiment proposals, and variant code, and every generated claim is checked against the source it cites. We send model providers only what the analysis needs, under agreements that prohibit them from training on it. We do not use your repository contents or your event data to train machine-learning models, ours or anyone else’s. A secret-scanning step blocks credentials and tokens from being written into the pull requests Trevo creates; independent of that, keep secrets out of source control — anything committed to a connected repository is part of what gets analyzed.
5. Cookies
Our own sites use a session cookie to keep you signed in and a first-party trevo_id cookie to keep experiment assignment stable for a visitor. We use our own product to run experiments on our own sites, so that cookie also powers experiments you may be part of on trevosdk.com. We do not use third-party advertising cookies. Products built by our customers set their own cookies under their own policies.
6. Sharing and subprocessors
We share data only with: service providers that host and operate the platform (cloud infrastructure and database hosting, email delivery, payment processing); GitHub, to read the repositories you connect and open pull requests; model providers (currently Anthropic) for the AI processing described above; analytics destinations you explicitly connect, such as your own PostHog project; professional advisers and authorities where the law requires; and a successor in a merger or acquisition, under this policy. Subprocessors are bound by data protection terms, and a current list is available at hello@trevosdk.com.
7. Retention
Account and workspace data are kept while your account is active. Repository snapshots are refreshed as your code changes and removed when you disconnect the repository or delete the workspace. Event data is kept while the workspace is active so long-running experiments stay measurable. When you delete data or close your account, records are flagged as deleted immediately and purged from production systems on a scheduled basis, then age out of backups; the append-only audit record of experiment decisions is retained as an integrity and accountability measure. We keep what the law requires us to keep (for example invoices) for the statutory period.
8. Security
Data is encrypted in transit; access to production systems is restricted, logged, and scoped to what operating the Service requires; repository access uses the GitHub App permission model with writes confined to trevo/* branches; API keys are workspace-scoped and revocable in the dashboard. No system is perfectly secure — if we learn of a breach affecting your data we will notify you without undue delay. Report security issues to hello@trevosdk.com.
9. International transfers
We operate from the United States and process data there and in the regions our infrastructure providers use. Where data protection law requires safeguards for transfers (for example from the EEA, UK, or Switzerland), we rely on standard contractual clauses and equivalent mechanisms with our subprocessors.
10. Your rights
Depending on where you live, you may have rights to access, correct, export, delete, or restrict the processing of your personal data, to object to processing, and to complain to a supervisory authority. You can exercise most of them directly: edit account details and revoke access in the dashboard, or email hello@trevosdk.com and we will respond within the time the law requires. We do not discriminate against you for exercising privacy rights. For End User Data, we forward requests to the customer whose product collected it.
11. Children
The Service is built for professional use and is not directed at children. We do not knowingly collect personal data from anyone under 16; if you believe a child has provided us data, contact us and we will delete it.
12. Changes and contact
We will update this policy as the Service evolves. Material changes will be announced by email or in the dashboard at least 14 days before they take effect, and the effective date above always reflects the current version. Questions and requests: hello@trevosdk.com.