Privacy Policy

Last updated 21 July 2026

TreeBranch is an AI communication and marketing assistant for event organizers. It is operated by Green Grove Holdings LLC, a Florida limited liability company doing business as TreeBranch (“TreeBranch”, “we”, “us”).

This policy describes what we actually do with data today. Where a protection is a design we have not finished building, we say so rather than implying otherwise.

Who this policy covers

Two different groups of people appear in TreeBranch, and they are worth separating:

  • Organizers — our customers. They create an account, connect their own channels, and control what the assistant does.
  • Attendees and other correspondents — the people who email an organizer, use an organizer’s chat widget, or message their social accounts. They are not our customers, and we handle their data on the organizer’s behalf.

For attendee data, the organizer decides what is collected and why. We process it to provide the service to them.

Information we collect

Organizer account information

Authentication is handled by Clerk. We store your email address, your name if you provide one, and the account identifier Clerk issues. We never receive or store your password. If you sign in with Google, we receive your email address and basic profile from that sign-in — this is separate from connecting a mailbox, described below.

Billing information

Payments are processed by Stripe. We do not receive, store or have access to your card number. What we store is the Stripe customer and subscription identifiers, your plan, your usage counters, and the dates that govern your billing cycle. Card details live with Stripe.

Content you give the assistant

Documents, links and text you add to an event’s knowledge base, plus your event details. This content is split into passages and converted into numerical embeddings so the assistant can find relevant answers.

Connected mailbox data

If you connect Gmail or Outlook, we read messages that arrive after you connect. See Google user data below for the detail.

Attendee and correspondent data

When someone contacts an organizer through a channel TreeBranch handles, we store the message content, their email address, their display name if the message carries one, the subject line, and the provider’s message and thread identifiers. Where an organizer uses the chat widget’s contact capture, we store the email address and message the visitor submits.

Waitlist

If you join a waitlist for an unreleased feature, we store the name, email address and optional organization you enter, and the date you submitted it.

What we do not collect

We do not run analytics, advertising or tracking scripts on our website, and we do not set tracking cookies. The only cookies we set are the ones that make the product work: your sign-in session, and a short-lived single-use token that protects the mailbox connection flow against cross-site request forgery.

Google user data

This section describes our handling of data obtained through Google APIs. It applies when you connect a Gmail account.

What we request

A single OAuth scope: gmail.modify. It lets us read messages, mark them as read, and send replies from your account. We previously requested two additional scopes and removed them because this one covers everything the product does — we ask for the narrowest set that works.

What we access

Only mail that arrives after you connect. When you connect a mailbox we record the moment of connection, and every request we make to Gmail is bounded by that timestamp. Messages already in your mailbox are never requested, never downloaded, never read, and never marked as read — including if your inbox has thousands of unread messages. Reconnecting moves the boundary forward; it does not open a window onto the period while you were disconnected.

Within that window we look at unread messages that are not from you. Automated, transactional and bulk mail — newsletters, receipts, shipping notifications, no-reply senders — is filtered out before the assistant ever sees it.

What we store

  • The text content of messages the assistant handles
  • The sender's email address and display name
  • Subject lines
  • The email address of the connected Gmail account
  • Gmail message and thread identifiers, used to reply in the right thread and to avoid handling the same message twice
  • OAuth access and refresh tokens, encrypted

We process the text content of emails; we do not extract or store file attachments.

What we do with it

Message content is used to work out what the person is asking and to draft an answer from your knowledge base. To do that, message text is sent to our AI providers (Anthropic and Voyage AI) for processing. It is not used to train any model. We do not sell it, we do not use it for advertising, and we do not use it for any purpose other than providing the features you connected the mailbox for.

Limited Use

TreeBranch’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting

You can disconnect a mailbox at any time from the channel settings for that event. When you do, we revoke the authorization with Google immediately and delete the stored tokens, so TreeBranch loses access at that moment rather than waiting for a token to expire. You can also revoke access directly from your Google account permissions.

Disconnecting stops further access. Messages already handled remain in your TreeBranch account so your conversation history stays intact — see Retention for how to have them removed.

Microsoft Outlook

Connecting an Outlook mailbox works the same way: only mail arriving after you connect is read, and the same filtering applies. Disconnecting deletes our stored tokens, which ends our access. Microsoft does not offer a server-side revocation endpoint, so unlike Google we cannot revoke the grant on your behalf — you can remove it from your Microsoft account settings.

How we use information

  • To run the assistant: understanding questions and drafting answers from your knowledge base
  • To deliver messages on the channels you connect, on your instruction
  • To notify you when something needs your review
  • To operate your account: authentication, plans, usage limits, billing
  • To keep the service secure and to prevent abuse
  • To respond to you when you contact us

We do not sell personal information. We do not share it with advertisers. We do not use your content, or your attendees’ content, to train AI models.

Who we share it with

We use third-party providers to run the service. They receive only what they need, and only to perform work for us:

  • Supabase — database hosting, where your data is stored
  • Vercel — application hosting
  • Clerk — sign-in and account management
  • Stripe — payment processing
  • Anthropic — AI model that drafts answers; receives message and knowledge base content
  • Voyage AI — converts your knowledge base and questions into embeddings
  • Resend — sends our notification emails
  • Google and Microsoft — where you connect a mailbox
  • Meta — where you connect Facebook or Instagram
  • Apify and Google Places — used when you ask us to gather public information about your event or venue

We may also disclose information where the law requires it, or to protect our rights or the safety of others. If the business is sold or merged, information may transfer as part of that transaction.

Security

OAuth access and refresh tokens for your connected accounts are encrypted by TreeBranch before being written to the database, using AES-256-GCM with a key held outside the database.

Other data — including message content, subject lines and sender addresses — is stored in our database without a second layer of TreeBranch-applied encryption. It is protected by the encryption at rest that our database provider applies to its storage, by encryption in transit, and by access controls that scope every query to the owning organizer’s account. We are describing this precisely because “everything is encrypted” would be a stronger claim than the one we can make.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your data, we will notify you as required by law.

Retention

While your account is active, we keep your data so the product works: your knowledge base, conversation history, and settings persist until you delete them or close your account.

If you hibernate your account, everything is deliberately preserved — that is the point of hibernation — and the assistant simply stops running.

When an account is cancelled, we record a deletion date 24 months out and retain the data until then, so that an organizer who returns for next year’s event still has their knowledge base.

Stated plainly: that 24-month deletion date is currently recorded but not yet enforced automatically — the scheduled job that performs the deletion has not been built. Until it is, data past that date is deleted on request rather than on a timer. We would rather tell you this than imply an automatic deletion that does not yet happen.

Waitlist entries are kept until the feature launches or you ask us to remove you.

Your choices and rights

You can export your data at any time from your account settings, as a ZIP file containing your account details, events, knowledge base, conversations and corrections.

You can ask us to correct or delete your personal information, ask what we hold about you, or ask us to stop processing it. Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA. We honour these requests regardless of whether a particular law applies to you.

Account deletion is currently handled by contacting us rather than by a button in the product. Email info@treebranch.com and we will confirm once it is done.

If you are an attendee who contacted an organizer and you want your data removed, contact that organizer — it is their account and their data. If you cannot reach them, contact us and we will help.

Children

TreeBranch is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, contact us and we will delete it.

Changes to this policy

If we change this policy we will update the date at the top. If a change materially affects how we handle your data, we will tell account holders directly rather than relying on you to notice.

Contact

Questions, requests, or anything in this policy that does not match what you are seeing:

info@treebranch.com
Green Grove Holdings LLC, d/b/a TreeBranch
6314 98th St E
Bradenton, FL 34202
United States

See also our Terms of Service.