Troofrnd · Legal

Privacy Policy

What Troofrnd collects, why we have it, who else touches it, and what you can make us do about it.

Effective 26 August 2026.

1 Who is responsible for your data #

Punyakriya Industries Private Limited (CIN U46202MH2024PTC428245), of Shop No. 4, Building No. 2, Tilak Nagar, Shramik CHS, Chembur West, Mumbai, Maharashtra 400089, India, is the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023, and the data controller under the UK and EU GDPR, for personal data processed through Troofrnd.

For anything in this policy, including a request to see or delete your data, write to privacy@troofrnd.com. Our Grievance Officer is named on the contact page.

2 What we collect #

  • Account data. Your name, email address and password hash. We never store your password itself.
  • LinkedIn identity. When you connect LinkedIn we receive exactly four things: a stable member identifier, your name, your profile picture URL and your locale. That is the entire contents of the sign-in scopes we request. Your access token is encrypted at rest.
  • What you tell us about your work. The topics, opinions, positioning and writing samples you enter to train your Content Brain.
  • Content. Drafts, edits, approvals, generated images, schedules, and posts published through us.
  • Post performance. Metrics for your own posts, either from LinkedIn’s analytics API or from our browser extension reading your own analytics page.
  • Audience composition. Aggregate counts only, if you upload a LinkedIn data export. Clause 6 explains this one properly.
  • Usage and technical data. Log data, IP address, browser and device type, pages viewed, actions taken, and errors.
  • Billing data. Plan, invoices, transaction identifiers and GST details. Card numbers go to our payment gateway and never reach our servers.

We do not ask for and do not want government identifiers, financial account details, health data, or any other sensitive category of personal data. Please do not put them into drafts.

3 Why we process it, and on what basis #

  • To provide the service — the necessary basis for performance of our contract with you, and the legitimate use of processing data you have voluntarily given us for a purpose you asked for.
  • To publish to LinkedIn on your instruction — your consent, given per post when you approve it and revocable by disconnecting LinkedIn.
  • To take payment and meet tax obligations — contract, and our legal obligations under Indian tax law.
  • To keep the service secure and debug it — our legitimate interests in a service that works and is not abused.
  • To send you service messages — contract. Marketing email, if we send it, goes only with your consent and every message carries an unsubscribe link.

We do not sell personal data. We do not share it with data brokers. We do not use it for advertising, and we do not use your content to train foundation models.

4 Where your profile information comes from #

There is no LinkedIn API, at any tier or price, that returns a member’s headline, About section, skills, positions, industry or connections. Anyone offering to “just fetch your profile” is describing scraping.

So your profile information reaches us by exactly two routes, both of which you start: you upload the data export LinkedIn gives you about yourself, or our browser extension reads a page you have open in front of you. There is no third route, and we do not scrape LinkedIn.

5 The browser extension #

The extension is covered by its own policy, which is narrower than this one and is the version the Chrome Web Store reviews: the extension privacy policy. In short: it reads the figures LinkedIn already shows you on your own post analytics page, sends those numbers and nothing else, cannot act as you, and holds a credential whose only power is to report metrics for your own posts.

6 Your connections are other people’s personal data #

If you upload a LinkedIn data export, it contains a Connections.csv naming hundreds of real people — their employer, their job title, the day they connected to you. Those people never agreed to be in our database.

We treat that file as follows, and this is enforced by the schema, not by policy:

  • It is parsed in memory and reduced to counts before anything is written down. We store how many of your connections are in a given industry, seniority band, company, location or job title — never who they are.
  • There is no table in our database with a column that could hold an individual connection. Storing one would take a deliberate schema migration, not an oversight.
  • For free-text groupings such as company and job title, any bucket containing a single person is discarded before storage. A bucket of one is a person.
  • We keep only the largest groupings per category and discard the long tail.

Your total connection count is stored as a single number. Uploading an export is entirely optional, and you can delete the resulting aggregates at any time.

7 The research corpus is not your personal data #

Troofrnd crawls published news and public source material once, for an industry, and scores it for each user. That corpus is shared and is not linked to any user account — the tables holding it have no user column by design.

One consequence is worth stating plainly: deleting your account removes your data, but it does not delete published news articles from the shared corpus, because those articles were never your personal data. What is deleted is everything connecting you to them — your scores, your drafts, your citations.

8 Who else processes it #

We use a small number of infrastructure providers, each processing data only on our instructions and under contract. The current list, what each does, and where it processes data is published at /legal/subprocessors.

Beyond those, we disclose personal data only where the law requires it, to enforce our terms or protect rights and safety, or to a successor in a merger or sale of the business — in which case you will be told, and this policy continues to apply until replaced by one you are given notice of.

9 Transfers outside India #

Some of our providers process data outside India, including in the United States and the European Union. Where we transfer personal data internationally we rely on contractual protections with each provider, including the European Commission’s Standard Contractual Clauses where they apply, and we transfer only to countries not restricted by the Central Government under the DPDP Act.

10 How long we keep it #

  • Account and content data — for as long as your account exists.
  • Post metrics — for as long as your account exists, because their whole purpose is to show change over time.
  • Logs and technical data — normally up to 12 months, longer only where needed for security investigation.
  • Invoices and tax records — for the period Indian tax and company law requires, which is longer than your account may last and which we cannot shorten at your request.

Delete your account and we delete or irreversibly anonymise the rest within 30 days, save for backups, which expire on their own cycle within 90 days.

11 Security #

Access to your data is enforced at the database, not merely in application code: every table holding your data denies access by default and permits it only to you. LinkedIn access tokens are encrypted at rest. Traffic is served over HTTPS. Access to production systems is limited to those who need it.

No service can promise perfect security. If a breach affects your personal data we will notify you and the Data Protection Board of India as the DPDP Act requires.

12 Your rights #

As a Data Principal under the DPDP Act — and as a data subject under GDPR, where it applies to you — you may:

  • ask what personal data we hold about you and get a copy of it;
  • have inaccurate or incomplete data corrected, updated or completed;
  • have your data erased, and delete your account yourself at any time;
  • withdraw a consent you gave, as easily as you gave it;
  • nominate another person to exercise these rights if you die or are incapacitated;
  • and, under GDPR, additionally object to or restrict processing, and receive your data in a portable format.

Write to privacy@troofrnd.com. We respond within 30 days. If you are unhappy with our answer you may complain to the Data Protection Board of India, or to your local supervisory authority if you are in the UK or EU.

Your duties matter too. Under the DPDP Act you must not give false particulars or impersonate someone else when exercising these rights, and you must not raise a frivolous grievance.

13 Cookies #

What we set and why is in the Cookie Policy.

14 Children #

Troofrnd is not for anyone under 18. We do not knowingly process a child’s personal data, and we do not do behavioural tracking or targeted advertising of any kind, to anyone. If you believe a child has given us data, write to us and we will delete it.

15 Changes to this policy #

We will post any change here and update the effective date. For material changes we will tell you by email or in the product before they take effect.