Current privacy policy
Privacy Policy
Version: July 29, 2026 · Last updated: July 29, 2026
This is our current Privacy Policy. It describes the personal information TreeTales actually collects and how we handle it today. It is undergoing formal legal review before we launch paid products; some sections marked "being finalized" will be completed then. We will update the version and date above if anything material changes.
1. Introduction & scope
TreeTales helps families and friends collect Stories, photos, and voices about a person they love — the StoryOwner — and assemble them into a keepsake Memory Book. A StoryCollector creates and runs a Project and invites Contributors to submit Stories.
This policy explains what personal information TreeTales, operated by Oscar Garcia (sole proprietor) ("TreeTales," "we," "us") collects, why we collect it, how we use and share it, and the choices and rights you have. It covers our website and the TreeTales service. It does not cover third-party sites we link to. Your use of the service is also governed by our Terms of Service.
TreeTales is currently in a closed beta. This policy describes the practices we operate under today; where a practice is not yet in place or a period is not yet set, we say so plainly rather than overstate it.
2. Information we collect
We collect only what we need to run the service. By category and by the point in the flow where it is captured:
StoryCollector account & identity
- Email address — used to sign you in by magic link (passwordless; we do not collect or store a password).
- Anonymous-session identifier — created the first time you begin building, before you give us any email, so your work is saved as you go (ADR-0011). If you later add your email, it is attached to that same session.
Consent records (compliance)
When you give consent, we keep a record so we can prove it later. Each record includes:
- the email address that consented;
- a timestamp;
- the version of the policy consented to;
- the IP address and browser user-agent at the time of consent;
- the source of the consent — one of
collector-capture,contributor-submit, ornotify-opt-in.
Contributor information
- Display name and the Story content a Contributor submits.
- Contributor email — not collected today. In the current closed beta, invitations are share-a-link and we do not collect a Contributor's email at all — when a Contributor submits a Story, the system stores no email address for them. An optional "email me when the Book is ready" opt-in is planned, not live; if we add it, it will be off by default and described here before it turns on.
Information about the StoryOwner (third-party data)
A Project is about a StoryOwner, who is often not the person using TreeTales. We therefore hold personal information about a third party — their name, and the Stories and photos submitted about them by the StoryCollector and Contributors. If you are a StoryOwner, see "People whose data is submitted about them" below.
Print waitlist
If you ask to be notified about print, we store your email address and which print tier you are interested in.
Content you provide
The Stories, titles, and bylines you enter, and — as those features arrive — photos and audio recordings.
3. How we use your information
- to provide, save, and operate the service;
- to assemble your Stories into a Memory Book and, for print orders, to produce and ship it;
- to record and prove consent where the law requires it;
- to send you the sign-in link you request and other essential service messages; confirmation and "your Book is ready" emails are planned and will be sent only to people who opt in;
- to keep the service secure and prevent abuse.
TreeTales uses AI only to proofread and polish readability while preserving the author's own words — it never rewrites or ghostwrites a Story. Content you submit is processed to provide these features as part of operating the service.
4. Consent & legal basis
Our legal basis for processing is your consent. For StoryCollectors, sign-in uses a verified magic link: you enter your email and confirm by clicking the one-time link we email you. For the print waitlist and other "notify me" options, you opt in by entering your email and ticking an unticked consent box; these are optional and off by default. We record each consent with a timestamp and the policy version in force. You can withdraw consent at any time by contacting us (see Contact); withdrawal does not affect processing already carried out.
7. Data retention
We keep personal information for as long as needed to provide the service and for a reasonable period afterward, and longer only where the law requires (for example, keeping consent records as proof of consent). Specific retention periods are being finalized as part of our legal review; until then we keep personal information only as long as needed to provide the service and to retain proof of consent. When you delete content or a Project, or ask us to delete your data, we remove it as described in Right to delete.
8. Security
We take reasonable technical measures to protect your information. These include row-level security in our database (so a StoryCollector's data is not exposed across Projects) and encryption of data in transit. No method of storage or transmission is completely secure, and we cannot guarantee absolute security. We do not make any certification claim in this policy; any such claims will be reviewed and stated accurately before launch.
9. Your California privacy rights (CCPA)
If you are a California resident, the California Consumer Privacy Act gives you the following rights, subject to legal exceptions:
- Right to know / access — to request the categories and specific pieces of personal information we have collected about you, and how we use and share it.
- Right to delete — to request deletion of personal information we hold about you (see Right to delete).
- Right to opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of; the mechanism is nonetheless provided at Do Not Sell or Share My Personal Information.
- Non-discrimination — we will not discriminate against you for exercising any of these rights.
To exercise a right, email support@treetales.io. We will verify your request as required by law before acting on it. You may use an authorized agent where the law allows.
10. Right to delete & how to exercise it
Today, deletion and removal requests are handled manually. Email support@treetales.io and tell us what you would like removed — a single Story, a Contributor's data, or an entire Project. We review the request, verify it as required by law, and remove the data from our systems. You do not need an account to make a request, and a valid request is honored regardless of which StoryCollector created the Project.
We are building self-serve deletion so you can remove a Story, Contributor, or Project directly from your dashboard, along with a no-account "request removal" link on shareable pages. Those features are planned, not yet available (tracked in issue #7). Once they are live, this section will describe exactly how they work — including how removed content is purged from the database and any stored files. Until then, the email path above is how deletion happens.
11. People whose data is submitted about them
Much of the personal information in TreeTales is about a StoryOwner or is submitted by Contributors — people who may never use TreeTales themselves. If Stories or photos have been submitted about you, or by you, and you want access to them or want them removed, you can make a request even without an account by emailing support@treetales.io. We will verify and honor a valid request regardless of who created the Project. A no-account "request removal" link on shareable pages is planned (issue #7); until it ships, the email address above is how to reach us.
12. Children's privacy
TreeTales is intended for use by adults. Because Stories celebrate a person's life, submitted content may mention or depict minors (for example, childhood memories or family photos). We do not knowingly create accounts for children. How we handle children's data is being finalized. How we treat information about minors that appears within submitted content will be completed under legal review (issue #20). If you believe a child's information should be removed, contact support@treetales.io.
13. International users
TreeTales is operated from the United States and is currently offered to U.S. users. If you access it from outside the United States, your information will be processed in the United States.
GDPR coverage is being finalized. — This policy is written for CCPA / California compliance today. Rights and obligations for users in the European Economic Area, the United Kingdom, and other regions (such as GDPR data-subject rights, legal bases, international-transfer safeguards, and any representative or DPO details) are not yet covered and will be added here as a full section during legal review (issue #20). This stub marks where that coverage will go so the structure exists without our claiming coverage we do not yet provide.
14. Do Not Sell or Share My Personal Information
TreeTales does not sell your personal information, and does not share it for cross-context behavioral advertising (as those terms are defined under the California Consumer Privacy Act). Because we do not sell or share, there is no sale or sharing for you to opt out of.
You may still exercise your California rights — including the right to know and the right to delete — at any time. To make a request, or if you have any question about this, email support@treetales.io. If we ever begin selling or sharing personal information, we will update this section and provide an operative opt-out before doing so.
15. Changes to this policy
We may update this policy as the service and the law evolve. When we do, we will change the version and "Last updated" date at the top and, for material changes, provide a more prominent notice. The version you consented to is recorded in our consent records.
16. Contact
Questions or requests about this policy or your personal information:
- Email: support@treetales.io
- Entity: TreeTales, operated by Oscar Garcia (sole proprietor)
- Governing law: State of New York
This policy is current and operative; it remains under formal legal review before we launch paid products (issue #20).