Privacy Policy
1. Scope and who we are
This Privacy Policy explains how Treehole, operated by Madness Technology ("Treehole", "we", "us"), collects, uses, discloses, and protects information through the Treehole mobile app and its supporting services.
Treehole is a private, chat-first wellness companion for adults aged 18 and over. It provides everyday wellness support, not diagnosis or treatment. It is not a medical device, emergency service, crisis service, or substitute for professional care.
2. Information we handle
| Category | Examples | Why it is handled |
|---|---|---|
| Profile and preferences | Preferred/display name, language, timezone, companion identity and style, check-in window, memory, privacy, and notification choices. | Personalise the companion and apply your settings. |
| Conversations and wellness context | Your messages, companion replies, feedback, conversation summaries, remembered facts or events, memory boundaries, and safety-level signals derived from message text. | Provide replies, continuity, memory controls, and relevant safety resources. |
| Product interaction | Session and message timing, daily usage/quota status, notification interactions, and, only if enabled, lightweight app-open timing signals. Presence events do not contain message text. | Operate the service, enforce plan limits, and improve proactive check-in timing. |
| Identifiers and security data | Pseudonymous user, session, device, authentication, and recovery identifiers; push notification token; request timestamps; and limited network/security logs such as IP address. | Keep data associated with the correct installation, secure access, recover cloud memory, deliver notifications, and prevent abuse. |
| Purchase information | Subscription tier, product, transaction/subscription status, expiry, and a RevenueCat customer identifier. | Process purchases, restore entitlements, and unlock paid features. We do not receive payment-card details. |
| Diagnostics | If crash reporting is enabled in a release: app version, device/OS details, stack trace, and crash information. | Diagnose reliability and security problems. Treehole disables default PII, screenshots, view hierarchy, interaction breadcrumbs, and performance tracing in Sentry. |
| Support communications | Your email address and the content you send when contacting us. | Respond to your request and keep necessary support records. |
Treehole does not request precise location, contacts, photos, or camera access. Timezone is used for local timestamps, check-in timing, and region-appropriate support information.
3. How we use information
- Provide chat, conversation history, optional memory, proactive check-ins, voice-to-text input, and account recovery.
- Personalise language, tone, companion identity, and check-in timing according to your choices.
- Detect high-risk language and show crisis or emergency resources. This automated signal is not a clinical assessment.
- Deliver notifications, manage subscriptions and quotas, provide data export/deletion, and maintain service continuity.
- Protect users and the service, investigate failures or misuse, comply with law, and enforce our terms.
4. Speech input
Speech input uses the speech-recognition service provided by your operating system. Treehole does not send raw microphone audio to its backend or store voice recordings. Apple or Google may process dictated audio under their own privacy terms and device settings. Recognised text appears in the composer and is handled as conversation content only when you send it.
5. Optional cloud AI sharing
Cloud AI sharing is disabled by default. Immediately before your first normal message would be sent for a cloud reply, Treehole shows an in-app disclosure and requires you to tap Agree and send. If you choose not to agree, the message is not sent and remains in the composer. When enabled, Treehole sends the current message, companion settings, relevant recent conversation, and relevant profile or memory context to OpenRouter. OpenRouter routes the request to the AI model provider selected by Treehole; the selected provider or model may change as the service evolves.
This transfer is used only to generate replies and related memory processing. You can withdraw permission at any time in Settings. Withdrawing stops future chat-content transfers to OpenRouter; normal messages are not sent for cloud processing until you explicitly agree again, and Treehole does not switch you to a basic or static reply mode. Deterministic local crisis resources may still be shown for urgent safety language. Withdrawal does not automatically delete content already stored by Treehole or previously processed by a provider; use the in-app memory and deletion controls for Treehole data, and consult the provider policies for their retention practices.
6. Service providers and disclosures
| Provider | Data and purpose | Policy |
|---|---|---|
| OpenRouter and routed AI providers | Conversation and relevant context, only after cloud AI consent, to generate AI replies or memory representations. | OpenRouter Privacy Policy |
| Apple / Google speech services | Dictated audio, when you choose voice input, for operating-system speech recognition. Treehole receives recognised text, not the raw recording. | Apple Privacy / Google Privacy |
| Apple Push Notification service / Firebase Cloud Messaging | Device push token, notification content or generic notification text, and delivery metadata to deliver notifications. Notifications are optional. | Apple Privacy / Firebase Privacy |
| RevenueCat and Apple App Store / Google Play | Pseudonymous app-user identifier and purchase/subscription records to process, validate, and restore entitlements. | RevenueCat Privacy |
| Sentry | Limited crash diagnostics when crash reporting is configured, with privacy-reducing options described above. | Sentry Privacy |
| Cloudflare | Cookie-free page-load performance metrics and limited traffic/security data for this policy website. Cloudflare states that Web Analytics does not track individuals across sites. | Cloudflare Privacy Policy |
We may also disclose information when required by law, to protect safety or legal rights, or as part of a merger, financing, acquisition, or transfer of the service, subject to appropriate safeguards. Providers may process information in countries other than your own.
7. No advertising or cross-app tracking
We do not use product interaction data for tracking purposes. Treehole does not serve third-party ads, sell personal information, share it with data brokers, or link it with third-party data for targeted advertising or advertising measurement. Product interaction and optional presence timing are used for app functionality, quotas, reliability, and proactive timing only.
This policy website uses Cloudflare's cookie-free Web Analytics beacon for page-load performance measurement. It is separate from Treehole mobile-app product interaction data and is not used to identify or track people across websites.
8. Storage, retention, and security
Sensitive local profile, message, identity, authentication, and recovery data are stored using operating-system protected storage (iOS Keychain or Android encrypted storage). Data sent to Treehole is transmitted using HTTPS. We use access controls, per-user authentication, rate limiting, and operational safeguards, but no storage or transmission method is completely secure.
We retain data while needed to provide Treehole, honour your settings, protect the service, resolve disputes, or comply with law. Operational logs are kept only as reasonably necessary. When you use Delete all data, Treehole permanently deletes the cloud user record and associated conversations, memories, settings, safety events, presence events, push tokens, and subscription state from the active service, then clears the app's local Treehole data. Limited backups, security records, and transaction records held by app stores or service providers may remain for a restricted period or as legally required.
9. Your choices and rights
- Cloud AI: grant permission immediately before the first cloud send, then review or withdraw OpenRouter sharing in Settings.
- Presence timing: turn optional app-open timing signals off to stop future collection.
- Memory: review remembered items, set boundaries, forget selected memory, or start fresh.
- Notifications: disable them in Treehole or system settings and choose privacy-friendly generic notification text where available.
- Speech: do not use voice input, or revoke microphone/speech permissions in system settings.
- Access and portability: use Export my data to obtain a JSON export of connected cloud data.
- Deletion: use Start fresh → Delete all data. If cloud deletion fails, the app leaves local data intact so you can retry.
You may also contact us to request access, correction, deletion, restriction, or other rights available under applicable law. We may need to verify the request using your Treehole recovery or account information.
10. Adults only
Treehole is intended for adults aged 18 and over and is not directed to children. If you believe a person under 18 has provided personal data, contact us so we can investigate and delete it where appropriate.
11. Changes to this policy
We may update this policy when Treehole, its providers, or legal requirements change. We will update the date above and provide additional notice in the app when a change materially affects your choices.