Back to Home

Privacy Policy

How we protect and handle your data

Last updated: January 4, 2026
This privacy policy describes how Trollspace ("we", "us", or "our") collects, uses, and protects your personal information. This policy applies to Trollspace at app.trollefsen.com and any related services where it is linked.

🌐 Overview

Trollspace is a personal content organization and management platform. We are committed to protecting your privacy and being transparent about how we handle your data. This policy explains what information we collect, why we collect it, and how you can manage your data.

By using Trollspace, you agree to the collection and use of information in accordance with this policy.

🏢 Who We Are (Data Controller)

Trollspace is operated by Daniel Tollefsen, established in Norway. For the purposes of the EU/EEA and UK data protection laws (including the GDPR), we act as the data controller for the personal data described in this policy.

You can contact us at support@trollefsen.com for any privacy-related questions.

💾 Information We Collect

Account Information

Content You Create

Integration Data

Usage Information

Cookies and Local Storage

We only use cookies and local storage that are strictly necessary to operate the application:

We do not use third-party analytics, tracking cookies, or advertising cookies. No cookie consent banner is required as we only use essential cookies necessary for the service to function.

👁 How We Use Your Information

We use the information we collect to:

We do not sell your personal information to third parties.

Legal Bases for Processing (EEA/UK Users)

If you are located in the EEA or UK, we process your personal data on the following legal bases under the GDPR:

We do not currently send marketing emails or newsletters. If we add this in the future, we will obtain your consent where required (Art. 6(1)(a)) or rely on our legitimate interests with the ability to opt out.

🤝 Third-Party Services

Trollspace integrates with various third-party services. When you connect these services, they may collect and process your data according to their own privacy policies.

Processor vs Controller: Some providers act as our data processors (sub-processors) and only process your data on our behalf (for example, Supabase). Others act as independent controllers (for example, Google, Spotify, or Binance), where their own privacy policies govern how they use your data in addition to this policy.

Infrastructure and Storage (Data Processor)

Artificial Intelligence (Data Processors)

AI providers receive only the content you actively submit to AI features. We do not use AI for automated decision-making with legal or significant effects on you. AI recommendations and insights are purely assistive and you remain in control of all decisions.

Content and Media (Independent Controllers)

When you connect these services, they process your data as independent controllers under their own privacy policies:

Google Services (Independent Controller)

When you connect your Google account, Google acts as an independent controller for your Google data. We request specific permissions based on the features you use. These permissions (OAuth scopes) include:

For more information, see Google's Privacy Policy.

Your Data, Your Control: OAuth tokens are encrypted using AES-256-GCM encryption and stored securely in your account. Only you can access Google services through your connected account — we never access your Google data on your behalf without your direct action within the application. You can revoke access at any time from the Integrations page or directly from your Google Account settings.

Financial Data (Independent Controllers)

For cryptocurrency integrations, we store only API keys and position/balance data that you choose to sync. These services process trading data as separate controllers under their own policies:

Maps and Location

All third-party integrations are optional. You control which services you connect and can disconnect them at any time from the Integrations page.

🔒 Data Security

We implement industry-standard security measures to protect your data:

While we strive to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

🛡 Your Rights

If you are located in the EEA or UK, you have the following data protection rights under the GDPR:

How to Exercise Your Rights

You can exercise many of these rights directly in Trollspace:

For any other requests, contact us at support@trollefsen.com. We aim to respond within 30 days.

📁 Data Retention

We retain your data for as long as your account is active or as needed to provide you services. Specifically:

Upon account deletion request, we will permanently delete your data within 30 days, except where retention is required by law.

👶 Children's Privacy

Trollspace is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@trollefsen.com.

🌍 International Data Transfers

We primarily host Trollspace on Supabase infrastructure. Our primary database is located in Frankfurt, Germany (EU). However, some of our providers (including Supabase and its sub-processors, AI providers, and other integrations) may process your data from other countries.

When personal data is transferred outside the EEA/UK to a country without an adequacy decision, we rely on appropriate safeguards such as:

You can contact us at support@trollefsen.com to learn more about the specific regions and safeguards we use.

Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any changes by:

Your continued use of Trollspace after such modifications constitutes your acknowledgment and acceptance of the modified policy.

Contact Us

If you have any questions about this privacy policy or our data practices, please contact us:

Email: support@trollefsen.com
Website: trollefsen.com

We aim to respond to all privacy-related inquiries within 30 days.