Privacy, in plain language

Your words stay yours.

This policy explains how Treehole handles conversations, memory, cloud AI, notifications, subscriptions, speech input, and diagnostics.

Last updated 14 July 2026

No ads. No tracking. We do not sell personal data or use product interaction data to track you across apps or websites.
Cloud AI is your choice. Chat content is not sent to OpenRouter unless you explicitly enable cloud AI replies.
Controls stay in the app. You can change consent, memory, presence, and notification settings, export data, or permanently delete it.

Privacy Policy

1. Scope and who we are

This Privacy Policy explains how Treehole, operated by Madness Technology ("Treehole", "we", "us"), collects, uses, discloses, and protects information through the Treehole mobile app and its supporting services.

Treehole is a private, chat-first wellness companion for adults aged 18 and over. It provides everyday wellness support, not diagnosis or treatment. It is not a medical device, emergency service, crisis service, or substitute for professional care.

Important distinction: Treehole may store conversations on Treehole's servers to provide chat history and memory. Separately, sending chat content to OpenRouter for cloud AI replies is off until you explicitly consent.

2. Information we handle

CategoryExamplesWhy it is handled
Profile and preferencesPreferred/display name, language, timezone, companion identity and style, check-in window, memory, privacy, and notification choices.Personalise the companion and apply your settings.
Conversations and wellness contextYour messages, companion replies, feedback, conversation summaries, remembered facts or events, memory boundaries, and safety-level signals derived from message text.Provide replies, continuity, memory controls, and relevant safety resources.
Product interactionSession and message timing, daily usage/quota status, notification interactions, and, only if enabled, lightweight app-open timing signals. Presence events do not contain message text.Operate the service, enforce plan limits, and improve proactive check-in timing.
Identifiers and security dataPseudonymous user, session, device, authentication, and recovery identifiers; push notification token; request timestamps; and limited network/security logs such as IP address.Keep data associated with the correct installation, secure access, recover cloud memory, deliver notifications, and prevent abuse.
Purchase informationSubscription tier, product, transaction/subscription status, expiry, and a RevenueCat customer identifier.Process purchases, restore entitlements, and unlock paid features. We do not receive payment-card details.
DiagnosticsIf crash reporting is enabled in a release: app version, device/OS details, stack trace, and crash information.Diagnose reliability and security problems. Treehole disables default PII, screenshots, view hierarchy, interaction breadcrumbs, and performance tracing in Sentry.
Support communicationsYour email address and the content you send when contacting us.Respond to your request and keep necessary support records.

Treehole does not request precise location, contacts, photos, or camera access. Timezone is used for local timestamps, check-in timing, and region-appropriate support information.

3. How we use information

  • Provide chat, conversation history, optional memory, proactive check-ins, voice-to-text input, and account recovery.
  • Personalise language, tone, companion identity, and check-in timing according to your choices.
  • Detect high-risk language and show crisis or emergency resources. This automated signal is not a clinical assessment.
  • Deliver notifications, manage subscriptions and quotas, provide data export/deletion, and maintain service continuity.
  • Protect users and the service, investigate failures or misuse, comply with law, and enforce our terms.

4. Speech input

Speech input uses the speech-recognition service provided by your operating system. Treehole does not send raw microphone audio to its backend or store voice recordings. Apple or Google may process dictated audio under their own privacy terms and device settings. Recognised text appears in the composer and is handled as conversation content only when you send it.

5. Optional cloud AI sharing

Cloud AI sharing is disabled by default. Immediately before your first normal message would be sent for a cloud reply, Treehole shows an in-app disclosure and requires you to tap Agree and send. If you choose not to agree, the message is not sent and remains in the composer. When enabled, Treehole sends the current message, companion settings, relevant recent conversation, and relevant profile or memory context to OpenRouter. OpenRouter routes the request to the AI model provider selected by Treehole; the selected provider or model may change as the service evolves.

This transfer is used only to generate replies and related memory processing. You can withdraw permission at any time in Settings. Withdrawing stops future chat-content transfers to OpenRouter; normal messages are not sent for cloud processing until you explicitly agree again, and Treehole does not switch you to a basic or static reply mode. Deterministic local crisis resources may still be shown for urgent safety language. Withdrawal does not automatically delete content already stored by Treehole or previously processed by a provider; use the in-app memory and deletion controls for Treehole data, and consult the provider policies for their retention practices.

6. Service providers and disclosures

ProviderData and purposePolicy
OpenRouter and routed AI providersConversation and relevant context, only after cloud AI consent, to generate AI replies or memory representations.OpenRouter Privacy Policy
Apple / Google speech servicesDictated audio, when you choose voice input, for operating-system speech recognition. Treehole receives recognised text, not the raw recording.Apple Privacy / Google Privacy
Apple Push Notification service / Firebase Cloud MessagingDevice push token, notification content or generic notification text, and delivery metadata to deliver notifications. Notifications are optional.Apple Privacy / Firebase Privacy
RevenueCat and Apple App Store / Google PlayPseudonymous app-user identifier and purchase/subscription records to process, validate, and restore entitlements.RevenueCat Privacy
SentryLimited crash diagnostics when crash reporting is configured, with privacy-reducing options described above.Sentry Privacy
CloudflareCookie-free page-load performance metrics and limited traffic/security data for this policy website. Cloudflare states that Web Analytics does not track individuals across sites.Cloudflare Privacy Policy

We may also disclose information when required by law, to protect safety or legal rights, or as part of a merger, financing, acquisition, or transfer of the service, subject to appropriate safeguards. Providers may process information in countries other than your own.

7. No advertising or cross-app tracking

We do not use product interaction data for tracking purposes. Treehole does not serve third-party ads, sell personal information, share it with data brokers, or link it with third-party data for targeted advertising or advertising measurement. Product interaction and optional presence timing are used for app functionality, quotas, reliability, and proactive timing only.

This policy website uses Cloudflare's cookie-free Web Analytics beacon for page-load performance measurement. It is separate from Treehole mobile-app product interaction data and is not used to identify or track people across websites.

8. Storage, retention, and security

Sensitive local profile, message, identity, authentication, and recovery data are stored using operating-system protected storage (iOS Keychain or Android encrypted storage). Data sent to Treehole is transmitted using HTTPS. We use access controls, per-user authentication, rate limiting, and operational safeguards, but no storage or transmission method is completely secure.

We retain data while needed to provide Treehole, honour your settings, protect the service, resolve disputes, or comply with law. Operational logs are kept only as reasonably necessary. When you use Delete all data, Treehole permanently deletes the cloud user record and associated conversations, memories, settings, safety events, presence events, push tokens, and subscription state from the active service, then clears the app's local Treehole data. Limited backups, security records, and transaction records held by app stores or service providers may remain for a restricted period or as legally required.

9. Your choices and rights

  • Cloud AI: grant permission immediately before the first cloud send, then review or withdraw OpenRouter sharing in Settings.
  • Presence timing: turn optional app-open timing signals off to stop future collection.
  • Memory: review remembered items, set boundaries, forget selected memory, or start fresh.
  • Notifications: disable them in Treehole or system settings and choose privacy-friendly generic notification text where available.
  • Speech: do not use voice input, or revoke microphone/speech permissions in system settings.
  • Access and portability: use Export my data to obtain a JSON export of connected cloud data.
  • Deletion: use Start fresh → Delete all data. If cloud deletion fails, the app leaves local data intact so you can retry.

You may also contact us to request access, correction, deletion, restriction, or other rights available under applicable law. We may need to verify the request using your Treehole recovery or account information.

10. Adults only

Treehole is intended for adults aged 18 and over and is not directed to children. If you believe a person under 18 has provided personal data, contact us so we can investigate and delete it where appropriate.

11. Changes to this policy

We may update this policy when Treehole, its providers, or legal requirements change. We will update the date above and provide additional notice in the app when a change materially affects your choices.

12. Contact us

Privacy questions or requests: [email protected]
App Store contact: [email protected]

私隱政策

1. 適用範圍與我們的身份

本私隱政策說明由 Madness Technology 營運的 Treehole(「Treehole」、「我們」)如何透過 Treehole 流動應用程式及相關服務收集、使用、披露及保護資料。

Treehole 是為 18 歲或以上成人而設的私密對話式身心健康陪伴工具,提供日常身心健康支援,而非診斷或治療。Treehole 並非醫療裝置、緊急服務、危機支援服務,亦不能取代專業照護。

兩者有明確分別:Treehole 可將對話儲存在 Treehole 伺服器,用於聊天記錄與記憶功能;至於將對話內容傳送至 OpenRouter 生成雲端 AI 回覆,則預設關閉,直至你明確同意。

2. 我們處理的資料

類別例子處理目的
個人資料與偏好稱呼/顯示名稱、語言、時區、陪伴者身份與風格、關心時段,以及記憶、私隱和通知選擇。個人化陪伴體驗並套用你的設定。
對話與身心健康脈絡你的訊息、陪伴者回覆、意見回饋、對話摘要、記住的事實或事件、記憶界線,以及從訊息文字得出的安全風險級別訊號。提供回覆、連貫對話、記憶控制及適切的安全資源。
產品互動資料對話及訊息時間、每日使用量/配額狀態、通知互動;如你另行啟用,亦包括輕量的開啟 app 時間訊號。存在時間事件不包含訊息文字。營運服務、執行方案限制及改善主動關心時機。
識別碼與安全資料假名化的用戶、對話、裝置、驗證及復原識別碼;推送通知權杖;請求時間;以及 IP 位址等有限網絡/安全記錄。將資料連結至正確的安裝、保障存取、復原雲端記憶、傳送通知及防止濫用。
購買資料訂閱級別、產品、交易/訂閱狀態、到期日及 RevenueCat 客戶識別碼。處理購買、恢復權益及啟用付費功能。我們不會收到付款卡資料。
診斷資料如發佈版本啟用崩潰報告:app 版本、裝置/作業系統資料、堆疊追蹤及崩潰資料。診斷可靠性及安全問題。Treehole 在 Sentry 關閉預設個人識別資料、螢幕截圖、畫面結構、互動歷程及效能追蹤。
客服通訊你聯絡我們時提供的電郵地址及訊息內容。回應你的要求及保存必要的支援記錄。

Treehole 不會要求精確位置、通訊錄、相片或相機權限。時區只用於顯示本地時間、安排關心時機及提供地區適用的支援資料。

3. 我們如何使用資料

  • 提供聊天、對話記錄、可選記憶、主動關心、語音轉文字及帳戶復原。
  • 按你的選擇個人化語言、語氣、陪伴者身份及關心時機。
  • 識別高風險字句並顯示危機或緊急支援資料;這項自動訊號並非臨床評估。
  • 傳送通知、管理訂閱與配額、提供資料匯出/刪除及維持服務運作。
  • 保障用戶及服務、調查故障或濫用、遵守法律及執行條款。

4. 語音輸入

語音輸入使用作業系統提供的語音辨識服務。Treehole 不會將原始麥克風音訊傳送至 Treehole 後端,亦不會儲存錄音。Apple 或 Google 可能按其私隱條款及你的裝置設定處理聽寫音訊。辨識出的文字會先顯示在輸入框,只有在你傳送後才按對話內容處理。

5. 可選的雲端 AI 資料分享

雲端 AI 資料分享預設停用。當你首次準備傳送一般訊息以取得雲端回覆時,Treehole 會先顯示 app 內說明,並要求你按「同意並傳送」。如你不選擇同意,訊息不會傳送,並會保留在輸入欄。開啟後,Treehole 會將當前訊息、陪伴者設定、相關近期對話脈絡及相關個人/記憶脈絡傳送至 OpenRouter。OpenRouter 會把請求轉交 Treehole 選定的 AI 模型供應商;服務更新時,所選供應商或模型可能改變。

資料只用於生成回覆及相關記憶處理。你可隨時在「設定」撤回同意;撤回後,之後的對話內容不會再傳送至 OpenRouter,一般訊息亦不會送往雲端處理,直至你再次明確同意。Treehole 不會因此切換至基本或靜態回覆模式;遇到緊急安全語句時,app 仍可能在本機顯示預設危機支援資訊。撤回同意不會自動刪除 Treehole 已儲存的內容或供應商過往已處理的資料;Treehole 資料請使用 app 內記憶及刪除控制,供應商的保留做法則請參閱其政策。

6. 服務供應商與披露

供應商資料與用途政策
OpenRouter 及其轉接的 AI 供應商只在你同意雲端 AI 後,接收對話及相關脈絡,用於生成 AI 回覆或記憶表示。OpenRouter 私隱政策
Apple/Google 語音服務當你使用語音輸入時,接收聽寫音訊以提供作業系統語音辨識。Treehole 收到的是辨識文字,而非原始錄音。Apple 私隱Google 私隱
Apple Push Notification service/Firebase Cloud Messaging裝置推送權杖、通知內容或通用通知文字及傳送資料,用於提供可選通知。Apple 私隱Firebase 私隱
RevenueCat 及 Apple App Store/Google Play假名化 app 用戶識別碼及購買/訂閱記錄,用於處理、驗證及恢復權益。RevenueCat 私隱政策
Sentry在設定崩潰報告時接收有限崩潰診斷資料,並採用上述減少私隱資料的設定。Sentry 私隱政策
Cloudflare為本政策網站處理不使用 Cookie 的頁面載入效能指標及有限流量/安全資料。Cloudflare 表示 Web Analytics 不會跨網站追蹤個別人士。Cloudflare 私隱政策

如法律要求、為保障安全或法律權利,或服務進行合併、融資、收購或轉讓時,我們亦可能在採取適當保障措施下披露資料。供應商可能在你所在國家或地區以外處理資料。

7. 不作廣告或跨 app 追蹤

我們不會使用產品互動資料作追蹤用途。Treehole 不會提供第三方廣告、出售個人資料、向資料經紀分享資料,亦不會把資料與第三方資料連結作定向廣告或廣告成效量度。產品互動及可選的存在時間資料只用於 app 功能、配額、可靠性及主動關心時機。

本政策網站使用 Cloudflare 不使用 Cookie 的 Web Analytics 訊標,量度頁面載入效能。此資料與 Treehole 流動 app 的產品互動資料分開,亦不會用於識別個別人士或跨網站追蹤。

8. 儲存、保留與安全

敏感的本機個人資料、訊息、身份、驗證及復原資料會儲存在作業系統保護的儲存空間(iOS Keychain 或 Android 加密儲存)。傳送至 Treehole 的資料使用 HTTPS。我們採用存取控制、逐用戶驗證、速率限制及營運保障措施;但任何儲存或傳輸方式均不能保證絕對安全。

我們會在提供 Treehole、遵從你的設定、保障服務、解決爭議或履行法律要求所需期間保留資料,並只在合理必要期間保存營運記錄。當你使用「刪除全部資料」,Treehole 會從使用中的服務永久刪除雲端用戶記錄及相關對話、記憶、設定、安全事件、存在時間事件、推送權杖與訂閱狀態,然後清除 app 的本機 Treehole 資料。有限的備份、安全記錄,以及 app 商店或服務供應商持有的交易記錄,可能在受限期間或法律要求下繼續保留。

9. 你的選擇與權利

  • 雲端 AI:在首次雲端傳送前給予同意,之後可在「設定」查看或撤回 OpenRouter 分享同意。
  • 存在時間:關閉可選的開啟 app 時間訊號,以停止往後收集。
  • 記憶:查看已記住內容、設定界線、忘記指定記憶或重新開始。
  • 通知:在 Treehole 或系統設定停用通知,並在提供選項時選擇保障私隱的通用通知文字。
  • 語音:不使用語音輸入,或在系統設定撤回麥克風/語音辨識權限。
  • 查閱與可攜性:使用「匯出我的資料」取得已連接雲端資料的 JSON 匯出檔。
  • 刪除:使用「重新開始 → 刪除全部資料」。如雲端刪除失敗,app 會保留本機資料,讓你稍後重試。

你亦可聯絡我們,行使適用法律下的查閱、更正、刪除、限制或其他權利。我們可能需要使用你的 Treehole 復原或帳戶資料核實要求。

10. 只供成人使用

Treehole 為 18 歲或以上成人而設,並非面向兒童。如你相信未滿 18 歲人士提供了個人資料,請聯絡我們,以便調查並在適當情況下刪除資料。

11. 政策變更

當 Treehole、服務供應商或法律要求改變時,我們可能更新本政策。我們會更新頁首日期;如變更對你的選擇有重大影響,亦會在 app 內提供額外通知。

12. 聯絡我們

私隱查詢或要求:[email protected]
App Store 聯絡人:[email protected]

隐私政策

1. 适用范围与我们的身份

本隐私政策说明由 Madness Technology 运营的 Treehole(“Treehole”、“我们”)如何通过 Treehole 移动应用及相关服务收集、使用、披露和保护信息。

Treehole 是为 18 岁或以上成年人设计的私密对话式身心健康陪伴工具,提供日常身心健康支持,而非诊断或治疗。Treehole 不是医疗设备、紧急服务、危机支持服务,也不能替代专业照护。

两者有明确区别:Treehole 可将对话存储在 Treehole 服务器,用于聊天记录和记忆功能;而将对话内容发送给 OpenRouter 生成云端 AI 回复则默认关闭,直到你明确同意。

2. 我们处理的信息

类别示例处理目的
个人资料与偏好称呼/显示名称、语言、时区、陪伴者身份与风格、关心时段,以及记忆、隐私和通知选择。个性化陪伴体验并应用你的设置。
对话与身心健康上下文你的消息、陪伴者回复、意见反馈、对话摘要、记住的事实或事件、记忆边界,以及从消息文字得出的安全风险级别信号。提供回复、连贯对话、记忆控制及适当的安全资源。
产品互动数据对话及消息时间、每日使用量/配额状态、通知互动;如你另行启用,也包括轻量的打开 app 时间信号。存在时间事件不包含消息文字。运营服务、执行方案限制及改善主动关心时机。
标识符与安全数据假名化的用户、对话、设备、验证及恢复标识符;推送通知令牌;请求时间;以及 IP 地址等有限网络/安全日志。将数据关联至正确的安装、保护访问、恢复云端记忆、发送通知及防止滥用。
购买信息订阅等级、产品、交易/订阅状态、到期日及 RevenueCat 客户标识符。处理购买、恢复权益及启用付费功能。我们不会收到支付卡信息。
诊断数据如发布版本启用崩溃报告:app 版本、设备/操作系统信息、堆栈跟踪及崩溃信息。诊断可靠性及安全问题。Treehole 在 Sentry 关闭默认个人身份信息、屏幕截图、界面结构、互动历史及性能跟踪。
客服通信你联系我们时提供的电子邮箱地址及消息内容。回复你的请求及保存必要的支持记录。

Treehole 不会请求精确位置、通讯录、照片或相机权限。时区仅用于显示本地时间、安排关心时机及提供地区适用的支持信息。

3. 我们如何使用信息

  • 提供聊天、对话记录、可选记忆、主动关心、语音转文字及账户恢复。
  • 按照你的选择个性化语言、语气、陪伴者身份及关心时机。
  • 识别高风险语句并显示危机或紧急支持信息;这项自动信号不是临床评估。
  • 发送通知、管理订阅与配额、提供数据导出/删除及维持服务运行。
  • 保护用户及服务、调查故障或滥用、遵守法律及执行条款。

4. 语音输入

语音输入使用操作系统提供的语音识别服务。Treehole 不会将原始麦克风音频发送至 Treehole 后端,也不会存储录音。Apple 或 Google 可能根据其隐私条款及你的设备设置处理听写音频。识别出的文字会先显示在输入框中,只有在你发送后才作为对话内容处理。

5. 可选的云端 AI 数据共享

云端 AI 数据共享默认停用。当你首次准备发送普通消息以获取云端回复时,Treehole 会先显示 app 内说明,并要求你点击“同意并发送”。如果你不选择同意,消息不会发送,并会保留在输入框。开启后,Treehole 会将当前消息、陪伴者设置、相关近期对话上下文及相关个人/记忆上下文发送给 OpenRouter。OpenRouter 会把请求转交 Treehole 选定的 AI 模型提供商;服务更新时,所选提供商或模型可能改变。

数据仅用于生成回复及相关记忆处理。你可随时在“设置”撤回同意;撤回后,之后的对话内容不会再发送给 OpenRouter,普通消息也不会发送到云端处理,直到你再次明确同意。Treehole 不会因此切换到基本或静态回复模式;遇到紧急安全语句时,app 仍可能在本机显示预设危机支持信息。撤回同意不会自动删除 Treehole 已存储的内容或提供商过去已处理的数据;Treehole 数据请使用 app 内记忆及删除控制,提供商的保留做法请参阅其政策。

6. 服务提供商与披露

提供商数据与用途政策
OpenRouter 及其转接的 AI 提供商仅在你同意云端 AI 后,接收对话及相关上下文,用于生成 AI 回复或记忆表示。OpenRouter 隐私政策
Apple/Google 语音服务当你使用语音输入时,接收听写音频以提供操作系统语音识别。Treehole 收到的是识别文字,而不是原始录音。Apple 隐私Google 隐私
Apple Push Notification service/Firebase Cloud Messaging设备推送令牌、通知内容或通用通知文字及发送数据,用于提供可选通知。Apple 隐私Firebase 隐私
RevenueCat 及 Apple App Store/Google Play假名化 app 用户标识符及购买/订阅记录,用于处理、验证及恢复权益。RevenueCat 隐私政策
Sentry在配置崩溃报告时接收有限崩溃诊断数据,并采用上述减少隐私数据的设置。Sentry 隐私政策
Cloudflare为本政策网站处理不使用 Cookie 的页面加载性能指标及有限流量/安全数据。Cloudflare 表示 Web Analytics 不会跨网站跟踪个人。Cloudflare 隐私政策

如法律要求、为保护安全或法律权利,或服务进行合并、融资、收购或转让时,我们也可能在采取适当保护措施的情况下披露信息。提供商可能在你所在国家或地区以外处理信息。

7. 不用于广告或跨 app 跟踪

我们不会使用产品互动数据进行跟踪。Treehole 不提供第三方广告、出售个人信息、向数据经纪商分享信息,也不会把信息与第三方数据关联用于定向广告或广告效果衡量。产品互动及可选的存在时间信息仅用于 app 功能、配额、可靠性及主动关心时机。

本政策网站使用 Cloudflare 不使用 Cookie 的 Web Analytics 信标衡量页面加载性能。此信息与 Treehole 移动 app 的产品互动数据分开,也不会用于识别个人或跨网站跟踪。

8. 存储、保留与安全

敏感的本地个人资料、消息、身份、验证及恢复数据会存储在操作系统保护的存储空间(iOS Keychain 或 Android 加密存储)。发送至 Treehole 的数据使用 HTTPS。我们采用访问控制、逐用户验证、速率限制及运营保护措施;但任何存储或传输方式都不能保证绝对安全。

我们会在提供 Treehole、遵从你的设置、保护服务、解决争议或履行法律要求所需期间保留信息,并仅在合理必要期间保存运营日志。当你使用“删除全部数据”时,Treehole 会从正在使用的服务中永久删除云端用户记录及相关对话、记忆、设置、安全事件、存在时间事件、推送令牌与订阅状态,然后清除 app 的本地 Treehole 数据。有限的备份、安全记录,以及 app 商店或服务提供商持有的交易记录,可能在受限期间或法律要求下继续保留。

9. 你的选择与权利

  • 云端 AI:在首次云端发送前给予同意,之后可在“设置”查看或撤回 OpenRouter 共享同意。
  • 存在时间:关闭可选的打开 app 时间信号,以停止今后的收集。
  • 记忆:查看已记住内容、设置边界、忘记指定记忆或重新开始。
  • 通知:在 Treehole 或系统设置停用通知,并在提供选项时选择保护隐私的通用通知文字。
  • 语音:不使用语音输入,或在系统设置撤回麦克风/语音识别权限。
  • 访问与可携性:使用“导出我的数据”取得已连接云端数据的 JSON 导出文件。
  • 删除:使用“重新开始 → 删除全部数据”。如云端删除失败,app 会保留本地数据,让你稍后重试。

你也可以联系我们,行使适用法律下的访问、更正、删除、限制或其他权利。我们可能需要使用你的 Treehole 恢复或账户信息核实请求。

10. 仅供成年人使用

Treehole 为 18 岁或以上成年人设计,不面向儿童。如你认为未满 18 岁的人士提供了个人信息,请联系我们,以便调查并在适当情况下删除信息。

11. 政策变更

当 Treehole、服务提供商或法律要求改变时,我们可能更新本政策。我们会更新页首日期;如变更对你的选择有重大影响,也会在 app 内提供额外通知。

12. 联系我们

隐私咨询或请求:[email protected]
App Store 联系人:[email protected]