TREE / Policies / 02
Privacy Policy
This Policy explains what information TREE handles, where it comes from, why it is used, who may receive it, how long it is kept, and your choices.
On this page 13 sections
- 1. Who is responsible
- 2. Information TREE handles
- 3. Where information comes from
- 4. Why TREE uses information
- 5. Who can see messages and Home information
- 6. Cookies, app storage, and permissions
- 7. Service providers and disclosures
- 8. Safety information and automated controls
- 9. Retention and deletion
- 10. Your choices and requests
- 11. Children and age information
- 12. International processing
- 13. Security, changes, and contact
1. Who is responsible
TREE is currently operated by Ali Elhussein Ali, an individual based in Egypt. TREE is a brand name and is not described here as an incorporated company. The operator is responsible for the personal information described in this Policy. This Policy covers TREE accounts and supported app features, the public TREE website, account-deletion requests, support and safety operations, and recovery copies used to keep the service available. Questions and privacy requests can be sent to tree.app.owner@gmail.com with “Privacy” in the subject. Do not send a password, sign-in code, MFA code, recovery code, or unnecessary identity document.
2. Information TREE handles
The information depends on the features you use and what you choose to provide. It can include: Account and security information: email address, TREE ID, username, password hash, gender selection, verification state, account status, recovery settings, MFA and session information, and verified recovery email or phone details where supported. Age and country information: date of birth, declared registration country, age-policy version, review state, and a country-level signal derived from the server network or, on Android as a fallback, the mobile network, SIM, or device region. TREE does not request GPS or precise-location permission for this country check. A birthday or verified email is not independent proof of identity or age. Profile, social, and Home information: display name, optional profile fields, biography, avatar, banner, visibility choices, relationships, Home membership, Home settings, roles, and presence or visit windows. Messages and shared activities: the content of direct and Home messages; sender, recipient or Home, timestamps, replies, attachments, delivery and read state; shared playback queue and position; and game or session state. Uploads: the file, original filename, format, detected type, size, uploaded parts, checksum, prepared playback or artwork, uploader, Home, inspection state, and upload-rights statement. Live communication: microphone, camera, or screen content you choose to transmit in real time, together with participant, room, session, connection, and track information needed to deliver and control the live activity. The current member product has no recording control. Using its report action keeps session and track context; that action does not itself create a hidden audio or video recording. If TREE later introduces routine server-side recording, it must provide clear notice and any consent or controls required before doing so. Reports, appeals, and support: reporter and target, category, explanation, relevant server-side context, evidence, decisions, appeals, correspondence, and reviewer activity. Technical and security information: IP address, user agent, browser and operating-system details, app version, sign-in and session times, delivery, crash or error events when the released build sends them, rate-limit and anti-abuse signals, and a random Android app-install identifier used as one input to abuse throttling. The install identifier is not an advertising ID or proof of identity. Policy records: the policy versions and statement accepted, method, server-recorded time, and request context. Older signing flows may also contain a submitted signature drawing and capture metadata. Website and early-access information: email address, language, confirmation, campaign or reward state, anti-bot and rate-limit information, and technical website-delivery events. Device-local information: authentication material, randomly generated client or visit identifiers, language, appearance, playback and notification preferences, limited caches, and locally hidden or acknowledged states. TREE does not collect every item from every member. Optional code or an unreleased feature does not mean the related information is collected. Store privacy declarations must match the exact released app, permissions, SDKs, configuration, and regions.
3. Where information comes from
Most information comes directly from you when you register, edit a profile, send a message, join a Home or activity, upload a file, report something, or contact us. Other members can provide information about you when they communicate with you, include you in shared content, or submit a report. Your device, network, app store, and service providers supply technical information needed to connect, secure, and deliver TREE. If TREE adds a materially new source of personal information, identity or age-assurance service, advertising system, analytics SDK, or content-analysis provider, this Policy and any required choice must be updated before that new use begins.
4. Why TREE uses information
TREE uses relevant information to: create, authenticate, secure, and recover accounts; decide eligibility and apply age-appropriate or country-related settings; show profiles, relationships, Homes, and presence according to their settings; deliver messages, games, uploads, playback, and live communication; preserve shared state so participants see the same current activity; remember device-local choices and reconnect an interrupted session; detect prohibited content and technical abuse, protect accounts, apply rate limits, investigate faults, and improve reliability; receive reports, preserve proportionate evidence, make and review safety decisions, and operate appeals; answer support, privacy, copyright, and security requests; keep policy-acceptance and important account-action records; send requested account, security, service, and early-access communications; create encrypted recovery copies and restore service after failure; and comply with applicable law and valid legal process. Where applicable law requires a legal basis, the basis depends on the purpose. Core account and communication functions may be necessary to provide the service. Security, fraud prevention, safety, and service improvement may rely on a legitimate and proportionate interest or another permitted basis. Some records may be legally required. Optional processing may require consent. Accepting TREE's Terms is not blanket consent to every possible use.
5. Who can see messages and Home information
Profile visibility and Home membership determine who can see shared profile and Home information. Direct messages are available to their participants. Home chat follows recorded visits. A member can retrieve messages created while that member was present in the Home. Messages the member saw during an earlier visit can remain visible, but message bodies created after an explicit departure and before a later return are not added to that member's visible history. TREE may show only an aggregate count of activity during the gap. A brief connection interruption may remain part of the same visit while the app reconnects. Home owners and moderators do not bypass this visibility rule, and a reply preview is redacted when its earlier message is outside the viewer's visible visits. TREE still processes and retains Home messages, visit records, and aggregate gap counts for service, safety, reporting, moderation, recovery, and the retention purposes in this Policy. People present in a Home may receive activity and media shared there. Public information can be visible more widely than account or recovery details. Home owners control their own space but are not automatically TREE safety staff and cannot access platform-wide safety cases. Authorised TREE staff may access only information reasonably needed for support, safety, security, legal requests, and service operation. Access to restricted evidence is recorded. “Private” limits the intended audience; it does not mean TREE cannot process the content or that another participant cannot copy what they saw. TREE does not claim that messages or live communication are end-to-end encrypted.
6. Cookies, app storage, and permissions
TREE uses a necessary sign-in cookie on supported web and desktop sessions. Its configured maximum age is 30 days. It is HttpOnly, SameSite=Lax, and marked Secure when served over HTTPS. Signing out clears the cookie, but separate security or acceptance records can remain for their stated purposes. The website, desktop app, and Android app use local or session storage for necessary session state and limited preferences such as language, appearance, playback, notification, reconnect, and acknowledgement choices. Android also stores an encrypted refresh token and a random app-install anti-abuse identifier. Android platform backup is disabled for the current release. Clearing the app's storage or uninstalling it removes ordinary app-local state, subject to device and platform behaviour, but neither action deletes a TREE account or TREE's server records. Microphone, camera, notifications, and selected-media access depend on the feature and platform. TREE asks through the available device controls. The microphone is used when you start a voice note on a surface where that feature is enabled or choose to publish your audio in a live Talk or Stage. The current Android build uses it for live Talk or Stage; its native voice-note composer is not enabled. You can withdraw a device permission, although the feature needing it will stop working. TREE does not currently use cookies or the Android advertising identifier for behavioural advertising. Cloudflare can process necessary security, anti-bot, delivery, and performance signals when you use the public website. Any future non-essential analytics or advertising technology must be reviewed, disclosed, and offered with any choice required by the user's location before it is enabled.
7. Service providers and disclosures
TREE currently uses: Cloudflare for website delivery, network protection, tunnels, website functions, anti-bot checks, and related infrastructure; Resend for account, recovery, and service email; self-hosted LiveKit for live audio, camera, and screen-sharing transport; Google Drive, restic, and rclone for encrypted off-site recovery snapshots, where Google receives encrypted backup objects and storage metadata; and TREE's current application host, database, cache, and object storage operated from Egypt. Providers may process technical information and service data needed for their task. TREE selects and instructs service providers to handle information only for documented purposes and to apply the protections required by applicable law. TREE does not instruct them to use member content for unrelated advertising or general-purpose AI training. A provider can have separate legal duties for its own security, abuse prevention, or lawful requests; where that applies, its own public terms can also govern that independent processing. Optional diagnostics or moderation integrations present in source code do not receive data merely because code exists. If a moderation provider is activated, the Policy and store declarations must identify the real released data flow and provider purpose before TREE relies on it publicly. TREE may disclose limited information when required by applicable law or valid legal process, or when reasonably necessary and legally permitted to address a serious safety threat, fraud, security incident, or rights dispute. A report does not permit publication of the reporter's identity. TREE does not sell or rent personal information, and the current service does not share it for cross-context behavioural advertising. If a future business model changes that fact, TREE must update this Policy and provide any notice, choice, or opt-out required before the change begins.
8. Safety information and automated controls
A report can preserve the selected item and relevant server-side context. For a message, that can include the reported message and up to two messages before and two after it. An upload report can include the file or asset reference, uploader, Home, queue, and playback context. A live-media report keeps session and track context; it does not itself create a secret audio or video recording. TREE uses access rules, file and format checks, text or metadata checks, report signals, temporary containment, and human review. A report or automated control can be mistaken. Report counts alone do not prove a violation, and eligible decisions can be appealed. Where applicable law gives a person rights concerning a decision made solely by automated processing that produces a legal or similarly significant effect, TREE will provide the required information and route to obtain human review. TREE does not claim that its current local upload checks understand every image, video frame, or sound. An upload can begin playing before all later parts arrive, and prohibited material can still appear. Reports, rapid live revocation, and human decisions remain important. This section must be updated before a new provider, continuous live analysis, or materially different automated decision is enabled.
9. Retention and deletion
TREE keeps information only for the service, safety, security, recovery, dispute, or legal purpose that applies. Different records have different lifecycles: a necessary web sign-in cookie has a configured maximum age of 30 days; Home and direct messages are normally kept while the relevant account, conversation, or Home history remains available. Available deletion or Home moderation controls can remove or hide content, while a bounded safety copy may remain when it is part of a report, appeal, dispute, or lawful hold; ordinary profile and Home media are normally kept until replaced, removed, or deleted with the relevant account or Home, subject to asynchronous object cleanup, active safety or legal holds, and recovery copies; an incomplete Watch upload session normally expires after 1 hour, and temporary prepared Watch media normally expires after about 13 hours. Cleanup is asynchronous and can be delayed by an active hold; a confirmed account-deletion request normally has a 14-day cancellation period before processing begins; standard safety evidence is protected while its case or appeal is open and is normally eligible for expiry 90 days after final resolution. Restricted evidence can be held for up to 365 days or another justified period required by law or a documented serious incident; a deleted username normally has a 90-day cooldown, and a limited retired TREE ID marker may remain so an old identifier is not reassigned; routine local recovery archives use a 14-day rotation and routine encrypted off-site snapshots use a 30-day retention cycle; and device-local identifiers, preferences, and caches normally remain until they expire, are cleared by the app, the user clears app data, or the app is uninstalled. Related server-side security events follow the retention purpose that applies to those events. Security, support, case, audit, delivery, and dispute records are kept for the period reasonably needed for their purpose, legal obligations, and protection against abuse, not as permission to keep a full account indefinitely. Database deletion, snapshot expiry, and physical removal of unused encrypted storage blocks are separate steps. Provider copies, failed jobs, lawful holds, and restored recovery copies can take longer to reconcile. TREE will explain a material retention exception when required and will periodically review records that do not have a fixed period.
10. Your choices and requests
Account and profile settings let you correct editable details and control visibility. A disputed birthday or protected recovery detail may need review. Blocking, hiding, reporting, clearing local app data, signing out, and deleting an account are different actions. Depending on the law where you live, you may have rights to access, correct, delete, receive, restrict, or object to processing; withdraw consent; and complain to an appropriate authority. These rights can have lawful limits, which TREE will explain when they apply. Use in-app controls or email tree.app.owner@gmail.com with “Privacy” in the subject. TREE may use proportionate checks so one person cannot read, change, or delete another person's account. Do not send unnecessary identity documents. The public account-deletion route is https://welcometotree.com/account-deletion. TREE will confirm a request and respond within the period required by the law that applies. If TREE cannot fulfil all or part of a request, it will explain the reason and any available complaint or appeal route unless the law prevents that explanation. Privacy requests are not charged for merely because they exercise a right, although applicable law may allow a proportionate response to manifestly unfounded or excessive repeat requests.
11. Children and age information
TREE does not allow anyone under 13 to create an account. The minimum shown at registration may be higher depending on location, release, or safety status. If local law requires parental permission or another process TREE does not support, the person cannot register by entering a false age. TREE uses safer defaults and feature limits for younger eligible members. Exact birth dates and registration countries are private account data, not public profile fields. Suspected underage accounts and child-safety concerns can be reported. The Child Safety Standards apply whether or not an account was eligible.
12. International processing
TREE is operated from Egypt and may be used by people in different countries. Providers and other participants may process or receive information outside your country. Before TREE offers a release where applicable law requires a transfer safeguard, TREE will identify the real provider, destination, and role and put an available lawful mechanism in place, such as an adequacy basis, approved contractual protection, consent where valid, or another permitted exception. TREE will not describe a safeguard as active until it is actually in place. The provider and region description will be updated before a future hosting migration is placed into public service. Mandatory rights under the law that applies to you are not removed by this Policy.
13. Security, changes, and contact
TREE uses safeguards including password hashing, protected sessions, access controls, MFA options, restricted safety evidence, transport security, and encrypted off-site recovery snapshots. No online service can promise absolute security, and these safeguards are not a claim that every stored file or live communication is end-to-end encrypted. Material changes to data use, providers, or member choices will receive a new policy version and appropriate notice. Additional consent will be requested when required. Contact tree.app.owner@gmail.com with “Privacy” in the subject.
