Privacy
Privacy Policy
1. Who we are
This Privacy Policy explains how Mclean Systems Research Group, LLC ("MSRG", "we", "us", or "our") handles information when you use the Treetor desktop app, the Treetor website, account pages, downloads, support, billing flows, and related services.
Questions about this policy can be sent tosupport@treetor.app.
2. Local-first storage
Treetor is a local-first desktop app. The books, branches, items, notes, and files you write or import are stored on your own machine, in your normal user folder. If you turn on optional sync and backup, your content is encrypted on your device before anything is uploaded. We store only encrypted copies and cannot read, sell, or analyze your content. If you never turn sync on, nothing you write is uploaded to the sync service.
Treetor requires an account, which is how your trial and licence are identified. Beyond signing in and checking for updates, a Treetor that is not syncing makes no network requests. If you use sync and your machine is offline, a paid account keeps syncing for up to 14 days after its latest successful account refresh and an active trial through its trial end; after that, sync pauses and local editing carries on. You are responsible for backing up files that are important to you.
3. Encrypted sync and backup (optional)
When you enable sync, Treetor encrypts your trees and pictures on your device using a master key protected by your recovery code. We store the encrypted data, its approximate size and hashes, revision timestamps, and device names so your devices can stay in sync, restore a workspace, and show version history. We cannot see tree titles, note text, or pictures in readable form.
We do not receive or hold your recovery code. If you lose it and no connected device can unlock your sync data, we cannot decrypt or recover that data for you. Your local files remain on your devices. Older encrypted revisions may be retained for a limited period to provide version history, conflict recovery, and service reliability.
4. Information we collect
Account information. An account is required to open Treetor. We receive the email address and account identifiers needed to authenticate you and connect your Free, Pro, trial, or Sync entitlement to the desktop app. Treetor currently uses Supabase Auth for sign-in.
Trial and subscription information. We store the minimum entitlement information needed to know whether your account's Pro tools or Sync service are active, covered through a date, or paused.
Billing information. Payments are processed by Lemon Squeezy as Merchant of Record. Lemon Squeezy collects payment details directly. We receive subscription status, customer identifiers, order or invoice metadata, and related billing event data. We do not see or store your full card number or CVV.
Support information. If you email support, we receive the information you include in that message, such as your email address, app version, operating system, screenshots, recordings, or details about the issue.
Newsletter information. If you submit the newsletter form, we store your email address and the page where you signed up so we can send release updates.
5. What we do not collect from the desktop app
The Treetor desktop app does not send analytics or telemetry. It contacts our backend to sign you in and to verify your trial or licence, and it checks for updates. It does not send the content of your trees unless you enable optional sync, which uploads that content only in end-to-end encrypted form as described above. Those requests never include readable tree content.
5a. Subscription milestones we count
To understand how many people who start a Treetor Pro trial go on to purchase or subscribe, our own servers record two milestones for an account: when its 30-day Pro trial is activated, and when a subscription first becomes paid. Each record holds only an internal event identifier, the milestone name, the environment, which of our own systems recorded it, the server timestamp, your account identifier, and the plan and billing period. No email address, IP address, device or browser information, campaign parameters, or anything from your trees is stored with them.
These are derived from account and billing activity we already process to provide the service, not from tracking. There is no third-party analytics service and no advertising pixel. If you only download and never sign in, no such record can exist. We report these milestones only as counts.
6. How we use information
- To create, authenticate, and secure your account.
- To start and enforce your 30-day Treetor Pro trial.
- To confirm Free, Pro, and Sync status and issue desktop entitlement tokens.
- To provide encrypted sync, backup, restore, version history, and storage limits.
- To process billing events and customer portal links.
- To respond to support requests.
- To send release emails only if you signed up for them.
- To comply with legal, tax, payment, fraud-prevention, and security obligations.
7. Service providers
We use service providers to operate Treetor. They may process information only as needed to provide their services to us.
- Supabase for authentication and account-related records.
- Cloudflare for the Treetor API, encrypted sync storage, and marketing website.
- Lemon Squeezy as Merchant of Record for payments, taxes, receipts, and invoices.
We do not sell personal information. We do not share readable Treetor content with advertisers or data brokers.
8. Website tracking
The Treetor marketing website does not run Google Analytics, Facebook pixels, or similar advertising trackers. The site makes third-party requests needed for authentication, newsletter signup, account status, hosting, and billing.
9. Data retention and deletion
We keep account and entitlement records while your account is active or as long as needed for legitimate business, security, legal, tax, billing, or dispute-resolution purposes. Payment records may be retained by Lemon Squeezy according to its legal and tax obligations.
If you enable sync, encrypted current data and a limited set of older encrypted revisions are retained to operate sync, backup, version history, and conflict recovery. Deleting a synced tree creates a deletion record so the change can reach your other devices; older encrypted revisions and unreferenced storage are removed according to the service's retention and cleanup schedule.
To request account deletion, emailsupport@treetor.appfrom the email address on your account. Deleting your account removes server-side account records under our control; it does not delete local files already stored on your machine.
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or export personal information we hold about you. To exercise those rights, emailsupport@treetor.app from the address on your account.
11. Children
Treetor is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
12. Terms, refunds, and billing
Product use is governed by our Terms of Service. Refund requests are governed by our Refund Policy. Lemon Squeezy's buyer terms may also apply to the payment transaction at checkout.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page and, where appropriate, communicated by email.
14. Contact
Questions about this Privacy Policy? Emailsupport@treetor.app or visit thesupport page.