01Who we are and what this covers
This policy explains how [Treepie registered company name] (“Treepie”, “we”), of [registered address], handles personal data when you visit treepie.co, use our cloud products — Flow, Nest, Loop, Desk, Books, Growth and Pulse — or use our desktop apps for Mac: Flow Desktop, Growth Desktop and Scout.
It applies to visitors, trial users, customers and the people whose data our customers store in Treepie. Where we process data on a customer’s behalf, the customer’s own privacy notice also applies.
02What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email, company, role, password hash, sign-in history | You, when you sign up or are invited |
| Customer content | Deals, employees, projects, tickets, invoices, pages and files you add to cloud products | You and your team |
| Usage data | Pages and features used, device and browser type, IP address, error logs | Collected automatically |
| Billing data | Billing contact, address, tax number, plan and payment status (card numbers are held by our payment processor, not us) | You and our payment processor |
| Website data | Pages visited, referrer, form submissions, cookie choices | Collected on treepie.co |
| Support data | Messages, call notes and screenshots you send us | You |
03Desktop apps: your data stays on your device
Desktop apps store their data in an encrypted vault on your own computer (in ~/Library/Application Support/Treepie on your Mac). We do not receive, host or back up that vault.
We only receive:
- your email address and licence key, to issue and verify your licence;
- a licence check about once a month (licence key, app version and an anonymous device identifier) — you can activate offline with a licence file instead;
- update checks (app version and operating system);
- crash reports, only if you turn them on.
If you choose to sync a desktop app with a Treepie cloud product, the data you select is then handled as customer content under this policy. Requests a desktop app makes to the internet on your instruction — for example loading a company website in Scout or a page in Growth Desktop — go directly from your computer to that site.
04How we use data, and why we’re allowed to
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Providing and operating the products | Contract |
| Security, fraud prevention and abuse detection | Legitimate interests |
| Billing, tax and accounting records | Contract; legal obligation |
| Support and service messages | Contract |
| Improving the products using aggregated usage data | Legitimate interests |
| Marketing emails | Consent, which you can withdraw at any time |
We do not use customer content to train AI models, and we do not sell personal data or share it for cross-context behavioural advertising.
05Pulse and other AI features
- Pulse reads records at the moment a question is asked, applying the asker’s existing roles and field rules.
- Questions and answers are processed in the region your workspace uses.
- Where we use an AI model provider to generate answers, they act as our sub-processor under contract, may not retain your content beyond the request, and may not use it for training.
- On the Complete plan, questions, answers and sources are logged for your admins, with retention you set.
07Where data is stored and transferred
Cloud workspaces are hosted in the region chosen at setup: United States, United Kingdom, European Union, UAE or India. Customer content stays in that region except where a sub-processor needs access to deliver a service, such as support tooling.
Where personal data leaves the UK, EU, UAE or India, we rely on adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or other mechanisms permitted by local law.
08How long we keep it
| Data | Kept for |
|---|---|
| Customer content | While your subscription is active; 30 days after it ends for export; removed from backups within a further 35 days |
| Account data | While your account is active, then up to 90 days |
| Billing records | As long as tax law requires — typically 6 to 8 years |
| Usage and security logs | Up to 13 months |
| Desktop app vaults | Never held by us |
| Marketing preferences | Until you unsubscribe, then a suppression record so we don’t email you again |
09How we protect it
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Staff access to customer content only when needed to provide support you requested, logged and reviewed.
- Role-based permissions and field-level rules that every product enforces.
- Regular penetration tests and independent audits; reports available under NDA.
- If a breach affects your personal data, we notify affected customers without undue delay and regulators where required.
10Your rights
Pick your region to see your rights. Email privacy@treepie.co to use any of them; we reply within one month, or sooner where local law requires.
- Access, correct, delete or export your data
- Object to or restrict processing based on legitimate interests
- Withdraw consent at any time
- Not be subject to solely automated decisions with significant effects
- Complain to the ICO or your EU supervisory authority
If your data sits in a customer’s Treepie workspace — for example you are their employee or their customer — please contact that organisation first. We will help them respond.
12Controller and processor
Treepie is the controller of account, billing, website and usage data. For customer content stored in the cloud products, the customer is the controller and Treepie is the processor, acting only on the customer’s instructions under our Data Processing Addendum.
13Children
Our products are not directed at anyone under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
14Changes to this policy
We post every version at treepie.co/privacy with its effective date. For material changes we email account owners at least 30 days in advance.
15Contact us
- Email: privacy@treepie.co
- Data Protection Officer: dpo@treepie.co
- Post: [registered address]
- UK and EU representatives: [representative details, if required]
You can also complain to your local data protection authority — for example the ICO in the UK, your EU supervisory authority, the UAE Data Office, or India’s Data Protection Board.