TreeTales

Current privacy policy

Privacy Policy

Version: July 29, 2026 · Last updated: July 29, 2026

This is our current Privacy Policy. It describes the personal information TreeTales actually collects and how we handle it today. It is undergoing formal legal review before we launch paid products; some sections marked "being finalized" will be completed then. We will update the version and date above if anything material changes.

1. Introduction & scope

TreeTales helps families and friends collect Stories, photos, and voices about a person they love — the StoryOwner — and assemble them into a keepsake Memory Book. A StoryCollector creates and runs a Project and invites Contributors to submit Stories.

This policy explains what personal information TreeTales, operated by Oscar Garcia (sole proprietor) ("TreeTales," "we," "us") collects, why we collect it, how we use and share it, and the choices and rights you have. It covers our website and the TreeTales service. It does not cover third-party sites we link to. Your use of the service is also governed by our Terms of Service.

TreeTales is currently in a closed beta. This policy describes the practices we operate under today; where a practice is not yet in place or a period is not yet set, we say so plainly rather than overstate it.

2. Information we collect

We collect only what we need to run the service. By category and by the point in the flow where it is captured:

StoryCollector account & identity

  • Email address — used to sign you in by magic link (passwordless; we do not collect or store a password).
  • Anonymous-session identifier — created the first time you begin building, before you give us any email, so your work is saved as you go (ADR-0011). If you later add your email, it is attached to that same session.

Consent records (compliance)

When you give consent, we keep a record so we can prove it later. Each record includes:

  • the email address that consented;
  • a timestamp;
  • the version of the policy consented to;
  • the IP address and browser user-agent at the time of consent;
  • the source of the consent — one of collector-capture, contributor-submit, or notify-opt-in.

Contributor information

  • Display name and the Story content a Contributor submits.
  • Contributor email — not collected today. In the current closed beta, invitations are share-a-link and we do not collect a Contributor's email at all — when a Contributor submits a Story, the system stores no email address for them. An optional "email me when the Book is ready" opt-in is planned, not live; if we add it, it will be off by default and described here before it turns on.

Information about the StoryOwner (third-party data)

A Project is about a StoryOwner, who is often not the person using TreeTales. We therefore hold personal information about a third party — their name, and the Stories and photos submitted about them by the StoryCollector and Contributors. If you are a StoryOwner, see "People whose data is submitted about them" below.

Print waitlist

If you ask to be notified about print, we store your email address and which print tier you are interested in.

Content you provide

The Stories, titles, and bylines you enter, and — as those features arrive — photos and audio recordings.

3. How we use your information

  • to provide, save, and operate the service;
  • to assemble your Stories into a Memory Book and, for print orders, to produce and ship it;
  • to record and prove consent where the law requires it;
  • to send you the sign-in link you request and other essential service messages; confirmation and "your Book is ready" emails are planned and will be sent only to people who opt in;
  • to keep the service secure and prevent abuse.

TreeTales uses AI only to proofread and polish readability while preserving the author's own words — it never rewrites or ghostwrites a Story. Content you submit is processed to provide these features as part of operating the service.

5. How we share your information

We do not sell or share your personal information (as those terms are used under the California Consumer Privacy Act), and we do not use it for cross-context behavioral advertising. See Do Not Sell or Share My Personal Information.

We share information only with service providers who process it on our behalf, under contract, so we can run the service. By category:

  • Hosting, database & authentication — our infrastructure provider (Supabase) stores your data and runs sign-in.
  • Email delivery (planned) — when we enable confirmation and notification emails, a third-party email provider will send them on our behalf; today, sign-in emails are sent through our infrastructure provider.
  • Print-on-demand — for print orders only, a print/fulfillment provider receives what is needed to produce and ship your Book.

We may also disclose information if required by law, to protect our rights or users' safety, or in connection with a business transfer — in which case this policy will continue to govern the information transferred.

6. Cookies & tracking

We use only the cookies needed to keep you signed in — the authentication session cookies set by our sign-in provider. We do not currently run advertising trackers or third-party analytics, and we do not track you across other websites. If this changes, we will update this policy and this section before doing so.

7. Data retention

We keep personal information for as long as needed to provide the service and for a reasonable period afterward, and longer only where the law requires (for example, keeping consent records as proof of consent). Specific retention periods are being finalized as part of our legal review; until then we keep personal information only as long as needed to provide the service and to retain proof of consent. When you delete content or a Project, or ask us to delete your data, we remove it as described in Right to delete.

8. Security

We take reasonable technical measures to protect your information. These include row-level security in our database (so a StoryCollector's data is not exposed across Projects) and encryption of data in transit. No method of storage or transmission is completely secure, and we cannot guarantee absolute security. We do not make any certification claim in this policy; any such claims will be reviewed and stated accurately before launch.

9. Your California privacy rights (CCPA)

If you are a California resident, the California Consumer Privacy Act gives you the following rights, subject to legal exceptions:

  • Right to know / access — to request the categories and specific pieces of personal information we have collected about you, and how we use and share it.
  • Right to delete — to request deletion of personal information we hold about you (see Right to delete).
  • Right to opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of; the mechanism is nonetheless provided at Do Not Sell or Share My Personal Information.
  • Non-discrimination — we will not discriminate against you for exercising any of these rights.

To exercise a right, email support@treetales.io. We will verify your request as required by law before acting on it. You may use an authorized agent where the law allows.

10. Right to delete & how to exercise it

Today, deletion and removal requests are handled manually. Email support@treetales.io and tell us what you would like removed — a single Story, a Contributor's data, or an entire Project. We review the request, verify it as required by law, and remove the data from our systems. You do not need an account to make a request, and a valid request is honored regardless of which StoryCollector created the Project.

We are building self-serve deletion so you can remove a Story, Contributor, or Project directly from your dashboard, along with a no-account "request removal" link on shareable pages. Those features are planned, not yet available (tracked in issue #7). Once they are live, this section will describe exactly how they work — including how removed content is purged from the database and any stored files. Until then, the email path above is how deletion happens.

11. People whose data is submitted about them

Much of the personal information in TreeTales is about a StoryOwner or is submitted by Contributors — people who may never use TreeTales themselves. If Stories or photos have been submitted about you, or by you, and you want access to them or want them removed, you can make a request even without an account by emailing support@treetales.io. We will verify and honor a valid request regardless of who created the Project. A no-account "request removal" link on shareable pages is planned (issue #7); until it ships, the email address above is how to reach us.

12. Children's privacy

TreeTales is intended for use by adults. Because Stories celebrate a person's life, submitted content may mention or depict minors (for example, childhood memories or family photos). We do not knowingly create accounts for children. How we handle children's data is being finalized. How we treat information about minors that appears within submitted content will be completed under legal review (issue #20). If you believe a child's information should be removed, contact support@treetales.io.

13. International users

TreeTales is operated from the United States and is currently offered to U.S. users. If you access it from outside the United States, your information will be processed in the United States.

GDPR coverage is being finalized. — This policy is written for CCPA / California compliance today. Rights and obligations for users in the European Economic Area, the United Kingdom, and other regions (such as GDPR data-subject rights, legal bases, international-transfer safeguards, and any representative or DPO details) are not yet covered and will be added here as a full section during legal review (issue #20). This stub marks where that coverage will go so the structure exists without our claiming coverage we do not yet provide.

14. Do Not Sell or Share My Personal Information

TreeTales does not sell your personal information, and does not share it for cross-context behavioral advertising (as those terms are defined under the California Consumer Privacy Act). Because we do not sell or share, there is no sale or sharing for you to opt out of.

You may still exercise your California rights — including the right to know and the right to delete — at any time. To make a request, or if you have any question about this, email support@treetales.io. If we ever begin selling or sharing personal information, we will update this section and provide an operative opt-out before doing so.

15. Changes to this policy

We may update this policy as the service and the law evolve. When we do, we will change the version and "Last updated" date at the top and, for material changes, provide a more prominent notice. The version you consented to is recorded in our consent records.

16. Contact

Questions or requests about this policy or your personal information:

  • Email: support@treetales.io
  • Entity: TreeTales, operated by Oscar Garcia (sole proprietor)
  • Governing law: State of New York

This policy is current and operative; it remains under formal legal review before we launch paid products (issue #20).