This Privacy Policy describes how Trickifi Limited, a Colorado limited liability company (“Trickifi,” “we,” “us,” or “our”), collects, uses, shares, and protects information when you use trickifi.com, the Trickifi web application, and any related software, features, content, and services we provide (collectively, the “Service”).
We built Trickifi on a zero-knowledge encryption architecture. That means the bulk of what you create on Trickifi (your repertoire, journal entries, attachments, images, and other working notes) is encrypted on your device before it reaches our servers, and we cannot read it. This Privacy Policy distinguishes throughout between (a) information we can see and process, and (b) encrypted content we cannot.
The Cookie Policy in Appendix A is part of this Privacy Policy.
If you have questions about this Policy, contact privacy@trickifi.com.
1.Quick Summary#
This is a plain-English summary. The rest of the Policy controls if there is any conflict.
- What we see: your email, your Stagename, your subscription status and billing metadata, operational usage data (item counts, mastery tier metadata, XP totals, login records), the device and network signals our security and analytics tools collect, and the contents of any messages you send us.
- What we don’t see: the substance of your tricks, acts, routines, techniques, backstage records, journal entries, images, audio, video, attachments, and other repertoire content. These are encrypted on your device with keys we never hold.
- What we do with it: run the Service, keep your account secure, bill you for Trickifi+, communicate transactional and (with opt-in) marketing messages, comply with law, and improve the product.
- AI training: we do not use your content, encrypted or otherwise, to train artificial intelligence or machine-learning models, ours or anyone else’s.
- Who we share with: the service providers we engage to run the Service (see Section 6 for categories: hosting, payments, email, analytics, advertising, security) and anyone you explicitly share content with on the Service.
- Your rights: depending on where you live, you have rights to access, delete, correct, port, and opt out of certain processing. See Sections 9 and 11.
- Contact: privacy@trickifi.com.
2.What We Collect#
2.1 Account information
When you create an account, we collect your email address, your chosen Stagename, and the invite or Affiliate code you used to register. Your password is stored only as a one-way hash; we never see it in plain text. If you set up the optional six-word recovery phrase, the phrase itself never reaches our servers. If you enable two-factor authentication, we store the credential needed to verify your codes.
2.2 Subscription and payment information
If you subscribe to Trickifi+, our payment processor (Stripe) collects your payment method directly. We do not store full card numbers. Stripe shares back to us the metadata we need to run your account, including subscription status, plan tier, last four digits of your card, card brand, billing country, billing email (if different from your account email), and a Stripe customer identifier. For Affiliates, we also receive payout-related metadata (Stripe Connect account status, payout balance, tax-form status).
2.3 Encrypted content
The contents of your repertoire (tricks, acts, routines, techniques, backstage records such as magicians, literature, communities, events, props, stores, media, and websites, plus journal entries, scripts, photos, audio, video, and attachments) are encrypted on your device before they are uploaded. We store the resulting ciphertext, plus the nonces and identifiers needed to retrieve it, but we cannot read it. We refer to this category in this Policy as “Encrypted Content.”
2.4 Operational and usage data
To run the Service and the Mastery system, we collect and process unencrypted operational data, including:
- The number of items in your repertoire by type;
- Mastery tier counts, mastery progress markers, rehearsal counts, and similar progression metadata;
- Total practice minutes;
- XP totals, CardRank position, and similar progression metrics;
- Calendar and scheduling metadata associated with mastery sessions;
- Feature usage events (for example, whether you opened a given screen or used a specific feature); and
- Crash reports and error events necessary to diagnose problems.
This data is not Encrypted Content and we can see it. It is used to power features the encryption design cannot: leaderboards, analytics, scheduling, and recommendations that require aggregate signal.
If you opt in to syncing Trickifi with an external calendar (for example, Google Calendar or Apple Calendar), the titles of the repertoire items associated with your scheduled sessions are decrypted on our servers so they can be passed to your calendar provider with meaningful event names. Only the titles are exposed in this way; the body of each item remains encrypted. You can disable calendar sync at any time from Settings.
2.5 Device, network, and security data
Your account security is paramount. We collect data needed to keep your account and our infrastructure secure, including IP address, browser type and version, device type and operating system, approximate location derived from IP, device fingerprint signals (including those provided by our bot and abuse-detection provider), session identifiers, login timestamps, and authentication-related events such as failed login attempts and password resets. Recent login activity is visible to you under Settings → Security → Recent Activity for the prior 30 days.
2.6 Communications
If you contact support, abuse, security, legal, billing, or privacy, we receive your message and any attachments, your email address, and metadata about the conversation. If you respond to a Trickifi survey, post a public review, or interact with our social channels, we receive what you submit.
2.7 Cookies, pixels, analytics, and advertising signals
We and our service providers use cookies, pixels, SDKs, and similar technologies on our marketing site and on portions of the Service to remember you, run analytics, deliver and measure advertising, and protect against fraud. See the Cookie Policy in Appendix A for details, including categories, providers, and how to opt out.
2.8 Information from third parties
We may receive limited information about you from third parties, including:
- Identity, anti-fraud, and bot signals from our security and abuse-prevention providers;
- Payment, tax-form, and Connect-account signals from Stripe;
- Email deliverability signals from our email delivery providers (for example, bounces and complaints);
- Advertising attribution and conversion signals from our advertising and analytics providers; and
- Public social-media metrics or sales data you submit (or authorize us to access) as part of your Affiliate application.
3.How We Use Information#
We use the information described in Section 2 to:
- Provide and run the Service, including creating your account, encrypting and storing Encrypted Content, syncing your repertoire across devices, scheduling rehearsals, computing mastery progress, awarding XP, and surfacing your data back to you.
- Authenticate and secure access, including verifying logins, detecting unusual or fraudulent activity, sending security notifications, supporting two-factor authentication, maintaining your 30-day login activity log, and enforcing rate limits.
- Process payments and Affiliate payouts, including managing subscriptions, processing renewals, calculating Affiliate commission, issuing payouts through Stripe Connect, and generating tax forms.
- Send transactional communications, such as signup confirmations, password resets, recovery-phrase notices, email-change confirmations, mastery training digests, regression alerts, billing receipts, and similar messages necessary to operate your account.
- Send marketing communications, only if you have opted in at signup or later in your preferences. You may unsubscribe at any time using the link in any marketing email or by emailing privacy@trickifi.com.
- Operate and improve the product, including diagnosing crashes, measuring feature adoption, running A/B tests on the marketing site and on unencrypted product surfaces, and conducting aggregated analyses.
- Run advertising, including measuring conversion and attribution for our marketing campaigns, and showing relevant ads to people who have visited Trickifi (subject to the consent and opt-out rules in the Cookie Policy and Section 9).
- Comply with law and protect rights, including responding to lawful requests, enforcing the Terms, protecting against fraud and abuse, and protecting the rights, property, and safety of Trickifi, our users, and the public.
3.1 Legal bases (EEA, UK, Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, our legal bases for processing personal data are:
- Contract: to perform the contract you have with us (the Terms of Use), for example to provide the Service and Trickifi+.
- Legitimate interests: to keep the Service secure, prevent fraud and abuse, operate and improve the product, conduct analytics on non-content data, and pursue Trickifi’s legitimate business interests, where those interests are not overridden by your rights.
- Consent: for marketing emails, optional analytics and advertising cookies, and similar optional processing. You can withdraw consent at any time.
- Legal obligation: to comply with applicable laws, including tax and financial-records obligations.
4.AI and Machine Learning#
We do not use Your Content, encrypted or otherwise, to train artificial intelligence or machine-learning models, ours or any third party’s, and we do not share Your Content with third-party model providers for that purpose.
If we ever introduce per-user AI features (for example, a personalized assistant that operates inside your encrypted session and retains lightweight memories scoped only to your account), we will design those features so that your repertoire content remains encrypted at rest and is processed only on your behalf while you are signed in. We will update Section 4 of the Terms and this Section 4 of the Privacy Policy, and provide advance notice under Section 17 of the Terms, before launching any such feature.
Note that the operational and usage data described in Section 2.4 (counts, tier metadata, XP totals, calendar metadata, and similar non-content signals) may be used in aggregated and de-identified form to improve the Service, including to inform product analytics and the design of forthcoming Mastery and matchmaking features such as CardRank.
5.How We Share Information#
We share information only as described in this Section.
5.1 With service providers
We use third-party service providers to host and operate the Service. They process information on our behalf under contracts that restrict their use of the information to the services they provide to us. See Section 6 for the categories of providers we engage.
5.2 With other magicians
When you share a record with another magician under Section 5 of the Terms, the recipient sees what you share. When you participate in Affiliate features, recipients of your Affiliate links receive the content you distribute and the Affiliate badge information you make public.
Your public profile information (Stagename, profile image, headshot, and anything else you have chosen to publish) is visible to other magicians inside the Service. As we launch additional social and community features (such as leaderboards, peer-to-peer messaging, Jam Sessions, and similar surfaces), portions of your account activity and public profile may be visible to other magicians in those contexts. We will describe the specific exposure for each feature in-product before you opt in, or in the Service as the feature launches.
5.3 With advertising and analytics partners
Subject to the consent rules in the Cookie Policy and Section 9, we share limited device, browser, and behavioral signals with our analytics and advertising providers to measure performance and to deliver ads. Some of these providers act as “selling” or “sharing” parties for purposes of state privacy laws; the Cookie Policy and Section 11 explain your opt-out rights.
5.4 For legal reasons
We may disclose information when we believe in good faith that disclosure is required by law (including in response to a valid subpoena, warrant, or court order), is necessary to protect the rights, property, or safety of Trickifi, our users, or the public, or is necessary to prevent fraud or abuse.
Because of our zero-knowledge architecture, our ability to respond to legal requests is structurally limited: we can produce the account-level metadata, billing data, and operational data we hold, but we cannot produce the contents of Encrypted Content because we cannot decrypt it. We will inform you of legal requests for your information unless we are prohibited from doing so or unless we believe doing so would risk serious harm.
5.5 In a corporate transaction
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of substantially all assets, information may be transferred to the successor or acquirer as part of that transaction, subject to a privacy commitment at least as protective as this Policy. In any such transaction, your Encrypted Content remains encrypted under the same zero-knowledge architecture; a successor or acquirer inherits ciphertext they cannot read.
5.6 With your consent
We share information for any other purpose with your consent.
We do not sell personal information in exchange for money. Some sharing with advertising partners may be considered a “sale” or “share” under certain state privacy laws; see Section 11.
6.Service Providers#
We use third-party service providers in the following categories to operate the Service:
- Hosting and infrastructure. Application hosting, database, authentication, content delivery, and storage providers that run our infrastructure.
- Payment processing. Stripe processes Trickifi+ subscription payments and Affiliate Connect payouts. Stripe collects payment-card data directly; we receive only the metadata we need to run your account (see Section 2.2).
- Email delivery. Providers that deliver transactional and (where you have opted in) marketing email on our behalf.
- Analytics and product measurement. Providers that help us understand how the marketing site and unencrypted product surfaces are used.
- Advertising. Providers that help us run advertising campaigns and measure their effectiveness.
- Security and abuse prevention. Providers that supply bot detection, anti-fraud signals, and similar safeguards.
We may engage additional providers in any of these categories as the Service evolves. Each provider processes information on our behalf under contracts that restrict their use of the information to the services they provide to us. For users in the EEA, UK, or Switzerland whose personal data would be transferred, we provide reasonable advance notice through the Service or by email before engaging a new provider in a category that materially affects how your personal data is processed.
We rely on contractual safeguards (including data processing addenda and, where required, standard contractual clauses) to protect personal data shared with these providers. For a current list of the specific sub-processors we use, contact privacy@trickifi.com.
7.International Data Transfers#
Trickifi is operated from the United States, and our sub-processors are based in the United States, the European Union, and other regions. When you use the Service, your information may be transferred to, stored in, and processed in countries other than your own, including the United States. Those countries may have data protection laws different from the laws in your country.
Where required, we rely on appropriate safeguards for international transfers, including the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), and we work with sub-processors that maintain equivalent safeguards. You may request a copy of the safeguards we use by emailing privacy@trickifi.com.
8.Retention and Deletion#
8.1 Operational retention
We retain personal data only as long as needed for the purposes described in this Policy, after which we delete or de-identify it. Specific timelines:
- Encrypted Content is retained while your account is active. On account deletion, the encrypted rows are deleted from our database and the keys that could decrypt them are destroyed; both happen at the same time, and neither can be reversed.
- Operational and usage metrics (item counts, mastery metadata, XP totals, login activity) are retained for up to 30 days after account deletion to support security investigations and analytics integrity, after which they are deleted or aggregated to a non-identifiable form.
- Financial and transaction records (invoices, payment records, tax records, Affiliate payouts) are retained for at least 7 years to comply with U.S. tax and financial-records requirements.
- Security and audit logs are retained for at least 12 months to support fraud, abuse, and security investigations.
- Support communications are retained for up to 24 months after the last interaction.
- Marketing-consent records are retained for as long as we may need to demonstrate compliance with applicable marketing laws.
8.2 Account deletion
You may delete your account at any time from Settings. On deletion:
- Your Stagename is released and may be claimed by another user.
- Your Encrypted Content is deleted, and the keys that protected it are destroyed; both happen together and neither is reversible.
- Your unencrypted operational data is deleted or aggregated as described in Section 8.1.
- Financial records and security logs are retained for the periods described above, but cannot be used to access or recover Encrypted Content.
Account deletion is irreversible. There is no grace period during which a deleted account can be recovered.
8.3 Backup expiry
Encrypted Content and operational data may persist briefly in backups after deletion (typically up to 30 days) before backup expiry purges them. Backups cannot be used to recover deleted accounts.
9.Your Rights and Choices#
You have choices about your data. Many controls are available directly inside Settings. For others, contact privacy@trickifi.com.
9.1 Access and portability
You can view your account information and unencrypted activity in Settings. On request, we will provide a copy of the unencrypted personal data we hold about you in a structured, commonly used, machine-readable format. We cannot include the substance of your Encrypted Content because we cannot decrypt it.
9.2 Correction
You can update your email, Stagename, password, recovery phrase, public profile information, and account preferences in Settings. For other corrections, contact privacy@trickifi.com.
9.3 Deletion
You can delete your account in Settings or by contacting privacy@trickifi.com. See Section 8.2 for what happens on deletion.
9.4 Marketing opt-out
You can unsubscribe from marketing email at any time using the link in any marketing email or by emailing privacy@trickifi.com. Transactional messages (signup confirmations, security alerts, billing notices, mastery digests for which you have signed up) continue while your account is open.
9.5 Cookies, analytics, and advertising
You can manage non-essential cookies and similar tracking through the cookie banner shown on first visit and through the cookie preferences link in the site footer. Where required by law, we will not load non-essential cookies until you consent. See Appendix A for details, including provider-specific opt-out links.
9.6 Account controls inside the Service
You can enable two-factor authentication, view recent login activity, sign out of other sessions, rotate your recovery phrase, and change your email or password from Settings → Security.
9.7 Region-specific rights
See Section 11 for additional rights available to residents of the EEA, UK, Switzerland, California, Colorado, Virginia, Connecticut, Utah, and other jurisdictions with applicable privacy laws.
10.Security#
Trickifi is built for defense in depth. We protect your account with industry-standard security practices, including encryption of your repertoire content on your device, encryption in transit between your device and our infrastructure, two-factor authentication, automated bot and abuse detection, rate limiting on sensitive endpoints, internal access controls, and continuous monitoring.
Your repertoire is encrypted on your device with keys we never see. We give you tools to keep your account secure, including a 30-day login activity log, optional two-factor authentication, and an optional recovery phrase that gives you a backup path if you ever lose your password.
No system is perfectly secure. You are responsible for keeping your password, recovery phrase, and devices safe. If you believe your account has been compromised, contact security@trickifi.com.
10.1 Breach notification
If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the relevant authorities within the timeframes required by law (for example, within 72 hours under the GDPR), and we will notify affected users without undue delay where required by law or where we believe it is in your interest.
11.Region-Specific Disclosures#
11.1 California (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what categories of personal information we have collected, the sources, the purposes, and the categories of recipients;
- Access and receive a copy of the specific pieces of personal information we hold;
- Request deletion of personal information we have collected, subject to legal exceptions;
- Correct inaccurate personal information;
- Opt out of “sale” and “sharing” of personal information for cross-context behavioral advertising;
- Limit the use of “sensitive personal information,” to the extent we use it for purposes that trigger this right; and
- Be free from discrimination for exercising any of these rights.
To exercise these rights, email privacy@trickifi.com or use the “Do Not Sell or Share My Personal Information” link in the site footer. We will verify requests by matching the request against information associated with your account. You may use an authorized agent; we may require written authorization.
Categories collected, sources, purposes, recipients. In the prior 12 months we have collected the following categories of personal information for the purposes described in Section 3, from the sources described in Section 2, and shared them with the categories of recipients listed in Sections 5 and 6: identifiers (email, account ID, IP address); commercial information (subscription, payment, Affiliate earnings); internet activity (usage, device, log data); geolocation (approximate, from IP); audio, electronic, or visual information (uploaded media, in encrypted form); inferences from operational data; and professional or employment information (Affiliate status). Sensitive personal information collected is limited to account credentials.
Selling and sharing. We do not sell personal information for money. We do share online identifiers with our advertising and analytics providers to deliver and measure advertising. You may opt out as described above.
11.2 Colorado, Virginia, Connecticut, Utah, and similar U.S. state laws
If you are a resident of Colorado (Colorado Privacy Act), Virginia, Connecticut, Utah, or another state with a comprehensive privacy law, you have rights similar to those described for California, including the rights of access, deletion, correction (where applicable), portability, and opt-out of targeted advertising, sale, and certain profiling. To exercise these rights, email privacy@trickifi.com. You may appeal a decision regarding your request by replying to our response and clearly stating that you are appealing.
11.3 European Economic Area, United Kingdom, Switzerland (GDPR / UK GDPR)
If you are in the EEA, the UK, or Switzerland, the GDPR or UK GDPR applies to our processing of your personal data. Our legal bases are described in Section 3.1. In addition to the rights described in Section 9, you have the right to:
- Object to processing based on legitimate interests, including profiling;
- Request restriction of processing in certain circumstances;
- Withdraw consent (where consent is the legal basis), without affecting the lawfulness of prior processing; and
- Lodge a complaint with your local supervisory authority.
The controller of your personal data is Trickifi Limited. To exercise your rights, contact privacy@trickifi.com.
11.4 Brazil (LGPD)
If you are in Brazil, the LGPD applies. You have rights of confirmation, access, correction, anonymization, blocking or deletion, portability, information about sharing, and withdrawal of consent. To exercise these rights, contact privacy@trickifi.com.
11.5 Other jurisdictions
If a privacy law in your jurisdiction provides rights similar to those described in this Section 11, we will honor those rights to the extent the law requires.
12.Children's Privacy#
The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided us with personal information, contact privacy@trickifi.com and we will delete it.
If you are between 13 and the age of majority in your jurisdiction, you may use the Service only with the consent of a parent or legal guardian. We may require additional verification before activating accounts of users we believe to be minors.
13.Do Not Track#
Some browsers send a “Do Not Track” signal. There is no industry consensus on how to respond to this signal, and the Service does not currently respond to it. Where applicable U.S. state law provides effect to global privacy control signals (such as the Global Privacy Control), we honor those signals as a valid opt-out of “sale” and “sharing.”
14.Changes to This Policy#
We may update this Policy from time to time. If we make material changes, we will notify you by email and through the Service, and we will post the updated Policy with a new “Last Updated” date.
For changes that materially affect how your encrypted content is processed, stored, or protected (including changes to the encryption design, the zero-knowledge architecture, or the conditions under which we or any third party may access your encrypted content), we will provide at least 90 days’ advance notice before the change takes effect, and the change will apply only to encrypted content you create or modify after that effective date.
For other material changes, we will provide at least 30 days’ advance notice before the change takes effect.
Continued use of the Service after the applicable effective date constitutes acceptance of the updated Policy.
15.Contact#
- Privacy and data-rights requests: privacy@trickifi.com
- Security reports: security@trickifi.com
- Copyright (DMCA) notices: dmca@trickifi.com
- Abuse reports: abuse@trickifi.com
- Billing questions: billing@trickifi.com
- General questions: hello@trickifi.com
- Legal notices: legal@trickifi.com
- Mailing address:
Appendix A
Cookie Policy#
This Cookie Policy explains how Trickifi uses cookies, pixels, software development kits, and similar technologies (collectively, “Cookies”) on our marketing site (trickifi.com) and within the Service. It supplements and is part of the Privacy Policy.
A.1 What Cookies are
A Cookie is a small piece of data placed on your device when you visit a website or use a web application. Cookies allow the site to remember you, your preferences, and your previous activity, and to enable analytics and advertising features. Pixels and SDKs are similar technologies that achieve the same goals through different mechanisms; we use the term “Cookies” to refer to all of them in this Policy.
A.2 Categories we use
A.2.1 Strictly necessary
These Cookies are required for the Service to function. They support authentication (keeping you signed in), session management, security (CSRF protection, bot detection through reCAPTCHA Enterprise), load balancing, and remembering your cookie preferences. They cannot be turned off, and we do not require consent for them under applicable law.
A.2.2 Functional
These Cookies remember preferences such as theme, language, layout choices, and form inputs. They are not strictly necessary but improve the experience. Where required by law, we will not load them until you consent.
A.2.3 Analytics
These Cookies help us understand how the marketing site and the unencrypted parts of the Service are used so we can improve them. Providers currently include Google Analytics 4. Analytics signals include page views, feature events, device and browser metadata, approximate location from IP, referrer URLs, and session duration. Where required by law, we will not load analytics Cookies until you consent.
A.2.4 Advertising
These Cookies allow us and our advertising partners to deliver and measure advertising for Trickifi, including on search engines, social platforms, ad networks, and (as those products become available) on AI assistant and large-language-model advertising surfaces. Providers currently include Google Ads, Meta (Facebook and Instagram) Pixel and Conversions API, and other ad-network or attribution providers we may engage. Advertising signals may include device and browser identifiers, conversion events (for example, signups or Trickifi+ purchases), page-level event data, and hashed identifiers we share with advertising providers for matching and measurement. Where required by law, we will not load advertising Cookies until you consent.
We may add, change, or remove analytics and advertising providers over time. Material changes will be posted with a new “Last Updated” date on this Policy and reflected in the cookie banner.
A.3 Your choices
A.3.1 Cookie banner and preferences
On your first visit, you’ll see a cookie banner allowing you to accept all Cookies, reject non-essential Cookies, or customize your choices. You can change your choices at any time using the “Cookie Preferences” link in the site footer.
A.3.2 Global Privacy Control
We honor the Global Privacy Control signal as an opt-out of “sale” and “sharing” under applicable U.S. state laws.
A.3.3 Provider opt-outs
You may also opt out directly through some of our providers:
- Google Analytics: install the Google Analytics opt-out browser add-on at https://tools.google.com/dlpage/gaoptout.
- Google Ads: adjust your ad personalization at https://adssettings.google.com.
- Meta (Facebook/Instagram): adjust your ad preferences in your Meta account settings.
- Digital Advertising Alliance / Network Advertising Initiative / European Interactive Digital Advertising Alliance: industry opt-out tools available at https://optout.aboutads.info, https://optout.networkadvertising.org, and https://www.youronlinechoices.eu respectively.
A.3.4 Browser controls
Most browsers let you block or delete Cookies through their settings. Blocking strictly necessary Cookies will break parts of the Service.
A.4 Sensitive contexts and the encrypted product
Cookies described in this Appendix operate on the marketing site and on unencrypted parts of the Service (account, billing, settings, marketing pages, and similar surfaces). Cookies are not used to undermine the zero-knowledge encryption of your repertoire content. Encrypted Content is not exposed to analytics or advertising providers.
A.5 Updates
We may update this Cookie Policy from time to time. Changes take effect when posted, with a new “Last Updated” date on the Privacy Policy.