Privacy Policy

Last updated 7 September 2026

TreeBranch is an AI communication and marketing assistant for event organizers. It is operated by Green Grove Holdings LLC, a Florida limited liability company doing business as TreeBranch (“TreeBranch”, “we”, “us”).

This policy describes what we actually do with data today. Where a protection is a design we have not finished building, we say so rather than implying otherwise.

Who this policy covers

Two different groups of people appear in TreeBranch, and they are worth separating:

  • Organizers — our customers. They create an account, connect their own channels, and control what the assistant does.
  • Attendees and other correspondents — the people who email an organizer, use an organizer’s chat widget, or message their social accounts. They are not our customers, and we handle their data on the organizer’s behalf.

For attendee data, the organizer decides what is collected and why. We process it to provide the service to them.

Information we collect

Organizer account information

Authentication is handled by Clerk. We store your email address, your name if you provide one, and the account identifier Clerk issues. We never receive or store your password. If you sign in with Google, we receive your email address and basic profile from that sign-in — that is all it grants, and it gives us no access to your Gmail.

Billing information

Payments are processed by Stripe. We do not receive, store or have access to your card number. What we store is the Stripe customer and subscription identifiers, your plan, your usage counters, and the dates that govern your billing cycle. Card details live with Stripe.

Content you give the assistant

Documents, links and text you add to an event’s knowledge base, plus your event details. This content is split into passages and converted into numerical embeddings so the assistant can find relevant answers.

Email sent to your event address

Each event gets its own TreeBranch email address. Mail sent to it — directly, or forwarded from an inbox you already use — arrives with us and is handled by the assistant. See Email below for the detail.

Facebook and Instagram messages

If you connect a Facebook Page or an Instagram account, we receive messages sent to it. See Facebook and Instagram data below, which describes exactly what Meta gives us and what we keep.

Attendee and correspondent data

When someone contacts an organizer through a channel TreeBranch handles, we store the message content, their email address, their display name if the message carries one, the subject line, and the provider’s message and thread identifiers. Where an organizer uses the chat widget’s contact capture, we store the email address and message the visitor submits. On Facebook and Instagram there is no email address and no name — see that section for what an identifier there actually is.

Waitlist

If you join a waitlist for an unreleased feature, we store the name, email address and optional organization you enter, and the date you submitted it.

What we do not collect

We do not run analytics, advertising or tracking scripts on our website, and we do not set tracking cookies. The only cookies we set are the ones that make the product work: your sign-in session, and a short-lived single-use token that protects the channel connection flow against cross-site request forgery.

Email

Each of your events has its own TreeBranch email address. You can publish that address directly, or keep using the inbox you already have and forward it on. Either way, mail reaches us only because it was addressed or forwarded to an address we host.

We no longer connect to Gmail or Outlook mailboxes. TreeBranch previously offered signing in with Google to grant access to your inbox. That option has been withdrawn, the Gmail permission has been removed from our Google account entirely, and we hold no mailbox access tokens under it. If you sign in to TreeBranch with Google, that is sign-in only: we receive your email address and basic profile, and nothing else.

What we store

  • The text content of messages sent to your event address
  • The sender's email address and display name
  • Subject lines
  • Message and thread identifiers, used to reply in the right thread and to avoid handling the same message twice

Attachments are never downloaded. If a message carries files, we record the filename, type and size so you can see what was sent, and nothing more — the contents are not stored, not opened, and never sent to an AI model.

What we do with it

Message content is used to work out what the person is asking and to draft an answer from your knowledge base. To do that, message text is sent to our AI providers (Anthropic and Voyage AI) for processing. It is not used to train any model. We do not sell it, we do not use it for advertising, and we do not use the content itself for any purpose other than running the assistant for you.

One thing sits alongside that, and we would rather name it than let you find it. Separately from the message itself, we record measurements about what happened: that a message arrived, that a reply was drafted or sent, whether it was edited before approval, a confidence score, how many knowledge-base passages were used. We use those to operate and improve the service, and they may be combined with other customers’ measurements into anonymous benchmarks.

The words are never part of that. No message text, no reply text, no knowledge-base content and no uploaded document goes into those measurements — only counts, scores, dates and true/false flags. So both statements on this page hold: the content is used for nothing but running the assistant for you, and the measurementsabout it help us make the product better. The Terms of Service set out the limits we accept on benchmarks, including that one is only published when it draws on at least 5 distinct events from at least 3 distinct organizers.

Because the address is public, we limit how many messages an event will process in an hour and in a day. Over that limit the message is still recorded and you are still told about it — we would rather you see a real question we did not answer than have it vanish.

Facebook and Instagram data

This section describes our handling of data obtained through Meta’s APIs. It applies when an organizer connects a Facebook Page or an Instagram professional account so the assistant can help answer the messages those accounts receive. Connecting is optional, is done by the organizer, and can be undone at any time.

What we ask Meta for

We request the narrowest set of permissions that makes the feature work, and we use every one of them:

  • Facebook Pages pages_show_list to show you which Pages you administer so you can choose one, pages_manage_metadata to subscribe to that Page’s message notifications, pages_messaging to read the messages people send the Page and reply to them, pages_read_user_content to read the comments people leave on your Page’s posts, pages_read_engagement because Facebook only includes the text of a comment in the notification it sends us when that permission is granted — without it we would be told a comment exists but not what it says, and business_management to confirm the Page belongs to your business.
  • Instagram instagram_business_basic for the account’s own username and ID, and instagram_business_manage_messages to read and reply to direct messages.

We do not request access to your ads, your audience data, your follower lists, your insights, or the profiles of the people who message you. We do not request permission to publish posts.

One of those permissions is broader than what we do with it, and we would rather say so. Facebook’s pages_read_engagement permission also covers reading the posts, photos and videos your Page itself has published. We do not read any of that. TreeBranch makes no request to Facebook for your Page’s own content, and stores none of it. We ask for the permission only because Facebook will not include the text of an attendee’s comment in the notification it sends us unless it is granted — a comment arrives saying nothing, and there is no answer to prepare.

What we access

Direct messages sent to the connected account, and only those that arrive after you connect. We record the moment of connection and ignore anything older, so your existing message history is never read. Messages the account itself sent — including replies you typed by hand in Meta’s own inbox — are recognised and skipped rather than treated as questions.

Reactions, likes, deleted messages, story replies, and messages that contain only media with no text are all skipped. We do not download or store photos, videos, voice notes or any other attachment sent to the account.

Comments on your Page’s own posts. When someone comments on a post from a connected Facebook Page, Meta notifies us, and we read the comment, match it against the knowledge base you gave us, and store it in your conversation history alongside your messages — the comment text, a page-scoped identifier for the person who wrote it, and Meta’s identifier for the comment. It is part of your account and is not visible to any other organizer. We never reply to a comment. The answer we prepare waits in your review queue; posting it publicly would need a permission we have not requested and Meta has not granted, and we do not message a commenter privately either. Comments on Facebook Event walls and on Instagram are not handled at all — those need separate permissions and separate work, and this policy will say so before that changes. Disconnecting the Page stops new comments arriving, but does not by itself delete the ones already handled — see Retention, below.

What we store

  • The text of messages sent to the connected account, and of the replies sent back
  • A page-scoped identifier for the sender — the ID Meta issues to identify that person to your account alone. It cannot be used to look them up on Facebook or Instagram, and it is different for every business they message.
  • Meta's message identifiers and timestamps, used to reply in the right conversation and to avoid handling the same message twice
  • The connected account's own ID, name and type — the Page or Instagram account you chose
  • Access tokens for the connected account, encrypted

We do not store the sender’s name, profile picture, profile link, email address, friend list or any other profile field. We do not ask Meta for them, and the assistant does not need them to answer a question about your event.

What we do with it

Message text is used to work out what the person is asking and to draft an answer from your knowledge base. To do that it is sent to our AI providers (Anthropic and Voyage AI) for processing. It is not used to train any model, it is not sold, it is not used for advertising, and it is not combined with data from any other source to profile the people who message you.

Every reply drafted for a Facebook or Instagram message is held for the organizer to review and approve before it is sent. Where a conversation is automated, the person is told so at the start of the thread.

Messages that look like complaints, or that touch on legal, medical, safety or refund matters, are never answered automatically — they are set aside for a human to handle.

Disconnecting and deletion

You can disconnect a Facebook or Instagram account at any time from the channel settings for that event, and hibernating your account disconnects them too. When you do, we de-authorise our app with Meta and destroy the stored tokens, so TreeBranch loses access at that moment rather than waiting for a token to expire. You can also remove our access yourself from your Facebook business integrations settings, or from Apps and Websites in your Instagram settings.

Disconnecting stops further access. Messages already handled remain in the organizer’s TreeBranch account so their conversation history stays intact. To have them deleted, follow our data deletion instructions, which cover Meta-sourced data specifically and explain what we need in order to find your conversation.

Platform terms

TreeBranch’s use of information received from Meta’s APIs adheres to the Meta Platform Terms and Developer Policies, including their restrictions on how platform data may be used, transferred and retained.

How we use information

  • To run the assistant: understanding questions and drafting answers from your knowledge base
  • To deliver messages on the channels you connect, on your instruction
  • To notify you when something needs your review
  • To operate your account: authentication, plans, usage limits, billing
  • To keep the service secure and to prevent abuse
  • To respond to you when you contact us

We do not sell personal information. We do not share it with advertisers. We do not use your content, or your attendees’ content, to train AI models.

Who we share it with

We use third-party providers to run the service. They receive only what they need, and only to perform work for us:

  • Supabase — database hosting, where your data is stored
  • Vercel — application hosting
  • Clerk — sign-in and account management
  • Stripe — payment processing
  • Anthropic — AI model that drafts answers; receives message and knowledge base content
  • Voyage AI — converts your knowledge base and questions into embeddings
  • Resend — receives mail sent to your event address, and sends our notification emails and your replies
  • Meta — where you connect a Facebook Page or Instagram account. We receive messages from Meta and send your approved replies back through it; we transfer nothing else to them.
  • Apify and Google Places — used when you ask us to gather public information about your event or venue

We may also disclose information where the law requires it, or to protect our rights or the safety of others. If the business is sold or merged, information may transfer as part of that transaction.

Security

OAuth access and refresh tokens for your connected accounts are encrypted by TreeBranch before being written to the database, using AES-256-GCM with a key held outside the database.

Other data — including message content, subject lines and sender addresses — is stored in our database without a second layer of TreeBranch-applied encryption. It is protected by the encryption at rest that our database provider applies to its storage, by encryption in transit, and by access controls that scope every query to the owning organizer’s account. We are describing this precisely because “everything is encrypted” would be a stronger claim than the one we can make.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your data, we will notify you as required by law.

Retention

While your account is active, we keep your data so the product works: your knowledge base, conversation history, and settings persist until you delete them or close your account.

If you hibernate your account, everything is deliberately preserved — that is the point of hibernation — and the assistant simply stops running.

When an account is cancelled, we record a deletion date 24 months out and retain the data until then, so that an organizer who returns for next year’s event still has their knowledge base.

Stated plainly: that 24-month deletion date is currently recorded but not yet enforced automatically — the scheduled job that performs the deletion has not been built. Until it is, data past that date is deleted on request rather than on a timer. We would rather tell you this than imply an automatic deletion that does not yet happen.

Messages received from Facebook and Instagram follow the same retention as everything else in the organizer’s account: they are kept while the account is active and are removed when the account or the conversation is deleted. Disconnecting the social account stops new messages arriving but does not by itself delete the ones already handled — our data deletion instructions are how those are removed.

Waitlist entries are kept until the feature launches or you ask us to remove you.

Your choices and rights

You can export your data at any time from your account settings, as a ZIP file containing your account details, events, knowledge base, conversations and corrections.

You can ask us to correct or delete your personal information, ask what we hold about you, or ask us to stop processing it. Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA. We honour these requests regardless of whether a particular law applies to you.

Account deletion is currently handled by contacting us rather than by a button in the product. Email info@treebranch.com and we will confirm once it is done.

If you are an attendee who contacted an organizer and you want your data removed, contact that organizer — it is their account and their data. If you cannot reach them, contact us and we will help.

Step-by-step instructions for every one of these, including deletion of data we received from Facebook and Instagram, are on our Data Deletion page.

Children

TreeBranch is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, contact us and we will delete it.

Changes to this policy

If we change this policy we will update the date at the top. If a change materially affects how we handle your data, we will tell account holders directly rather than relying on you to notice.

Contact

Questions, requests, or anything in this policy that does not match what you are seeing:

info@treebranch.com
Green Grove Holdings LLC, d/b/a TreeBranch
6314 98th St E
Bradenton, FL 34202
United States

See also our Terms of Service and Data Deletion instructions.