Privacy Policy
Last updated: 13 August 2026
Treely is a private, family-only place to keep your family's tree, photos and stories. This policy explains what we collect, why, who can see it, and how you get it back or get rid of it. Plain language, no dark patterns.
Treely is operated by Xplat Solutions LLC, 100 Merrick Rd, Ste 400E, Rockville Centre, NY 11570-4882, United States ("Treely", "we"). For privacy questions or requests, write to hello@xplatsolutions.com.
Our principle
Your family's tree is not a product we sell. We do not sell or rent your personal information, we do not run advertising, and we do not use your family's photos, stories or relationships to train machine-learning models. There is no public feed and no algorithmic distribution — content is visible only to the family members you invite.
What we collect
Account and identity. You sign in with Google or Apple. We receive your email address, your name and (from Google) your profile picture, plus the provider's user identifier. We never receive your Google or Apple password. If you use Apple's Hide My Email, we only ever see the relay address.
What you add to your tree. People (names, relationships, dates of birth and death, and any details you choose to record), photos, videos, written stories, captions, comments, reactions and albums. This content is often about other people — see "Information about other people" below.
Invitations. When you invite a relative, we store the invitation and its link token so we can let the right person in, and record who accepted.
Device and app information. Device model, operating system version, app version, language and region, network availability, and — if you turn on notifications — a push token from Apple or Google so we can deliver them.
Product analytics. We record which screens are opened and which actions are taken (for example "a memory was added"), tied to your account identifier so we can tell one person's journey from another's. We do not record your screen, we do not capture the contents of your tree, and we do not use session replay.
Crash diagnostics. When something goes wrong we receive the error, the code path and basic device details. Crash reports are configured to carry no personal information — your account identifier only — and are filtered before sending to strip anything else.
Purchases. Paid plans are billed by Apple or Google, not by us. We never see your card number. We receive a purchase receipt and your plan status so we can unlock the right features.
The treely.family website. If you join the early-access list, we store your email address, which page you signed up from, and your browser's user-agent string, so we can tell you when Treely launches. Nothing else on the public site requires an account.
Information about other people
A family tree is, by nature, information about other people — living relatives, children, and people who have died. You are responsible for the information you add about others. Only add details you have the right to share, and be especially careful with information about children and with sensitive details such as health or religion. If a relative asks you to remove something about them, please do — and any family member can contact us at hello@xplatsolutions.com if they need help getting information about themselves corrected or removed.
Children's data
Treely is built for families, and children naturally appear in a family tree — as people added by an adult relative, not as account holders. You must be at least 13 to hold a Treely account — and if you live somewhere that sets a higher age for consenting to online services (16 in several EU and EEA countries), you must be at least that age. We do not knowingly create accounts for anyone below it. A parent or guardian is responsible for information added about their child, and can ask us to remove it at any time by writing to hello@xplatsolutions.com.
Treely is not directed to children, and we do not knowingly collect personal information from a child under 13. If we learn that we have, we will delete it promptly. If you believe a child has given us information directly, write to hello@xplatsolutions.com and we will act on it.
Google Drive backup, and our Limited Use commitment
If you turn on backup, Treely asks for permission to use Google Drive with the drive.file scope — the narrowest Drive permission Google offers. It lets Treely see and manage only the files Treely itself creates in your Drive. Treely cannot see, open or list any other file in your Google Drive. Ever.
Backups are written to your own Google Drive, under your own Google account, and they remain yours: you can open, copy or delete them at any time from Drive itself. If you choose weekly backups, we store a Google authorisation token in encrypted server-side storage so the scheduled backup can run when your phone is not involved. Turning weekly backup off stops the schedule, and revoking Treely's access from your Google account settings ends it immediately.
Treely's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we use what we collect
To run the service: to show your family's tree, store and deliver your photos and videos, deliver invitations and notifications, keep the service secure and working, unlock the plan you have paid for, and support you when you ask. We use analytics and crash data only to understand whether features work and to fix what breaks.
Where GDPR applies, our lawful bases are the contract with you (running the service you signed up for), our legitimate interests (keeping Treely secure, preventing abuse, and improving it through de-identified analytics), your consent where we ask for it (notifications, Google Drive backup), and legal obligations where they apply.
Who can see your content
Only members of your family tree, according to the visibility rules the tree's owner sets. Access is enforced at the database level, not merely in the app. Photos and videos are served through short-lived signed links, so a URL cannot be passed around indefinitely. Treely staff do not browse family content; we access it only where you ask us to for support, or where we are legally required to.
Safety checks happen on your device. When you add a photo, Treely screens it for explicit content locally on your phone. The image is not uploaded anywhere for that check.
If a family member reports content, the report and the reported item are reviewable by us so we can act on it, and you can appeal a decision.
Where your information lives, and who processes it
Treely uses a small number of service providers. Each is contractually bound to process data only on our instructions.
| Provider | What it does | What it can see |
|---|---|---|
| Supabase | Database, authentication, file storage, backend functions | Your account, your family's content and files |
| Google (Sign-In, Drive, Firebase Cloud Messaging) | Sign-in, optional Drive backup, push delivery | Sign-in identity; Treely-created Drive files only; push tokens and message payloads |
| Apple (Sign in with Apple, App Store, push) | Sign-in, billing, push delivery | Sign-in identity; purchase records; push tokens |
| RevenueCat | Subscription and receipt management | Your account identifier and purchase status — no card details |
| PostHog | Product analytics | Events tied to your account identifier — no tree content, no screen recording |
| Sentry | Crash and error reporting | Errors and device details, with personal information stripped |
| Lovable | Hosting for the treely.family website | Website visits and early-access sign-ups |
Your family's data is stored in the United States (our database, file storage and backend run in a US region), and the providers above are US-based or operate globally. If you are outside the United States, using Treely means your information is transferred there.
Where GDPR or UK GDPR applies, we rely on the European Commission's Standard Contractual Clauses — together with the UK International Data Transfer Addendum for UK transfers and the Swiss addendum where relevant — and, for providers certified under it, the EU–US Data Privacy Framework. We apply supplementary measures including encryption in transit and at rest and access controls at the database level. You can ask us for details of the safeguards in place at hello@xplatsolutions.com.
How long we keep things
Your account and your family's content are kept for as long as your account exists — a family tree is meant to last. Crash and analytics data are kept for a limited period by the providers above and are not used to build a profile of you. Early-access emails are kept until launch or until you ask us to remove yours.
Your rights
You can ask us to give you a copy of your information, correct it, delete it, restrict or object to how we use it, or receive it in a portable form. Treely also has a built-in export, so you can take a full copy of your family's tree and memories whenever you like — no request needed. Where GDPR applies you may also complain to your local data-protection authority. Where the CCPA applies, note again that we do not sell or share personal information as those terms are defined. We do not discriminate against anyone for exercising these rights.
Deleting your account
You can delete your Treely account from Account → Delete account in the app. Here is exactly what happens, because the honest answer is not "everything vanishes":
- If you own a family tree, you must hand ownership to another member first. Deleting an owner would otherwise take the whole family's tree with them.
- Your personal information is deleted: your profile, your sign-in identity, your membership, your settings and your notification tokens.
- Content you contributed to a shared family tree — people, photos, stories that other members rely on — is detached from you and kept for the family, without your identity attached. This is deliberate: your relatives' tree should not lose its history because you left.
- Backups already written to your own Google Drive stay in your Drive. Delete them there if you want them gone.
- Deletion is permanent and cannot be undone.
If you want your contributed content removed as well as your account, write to hello@xplatsolutions.com before deleting and we will handle it as an erasure request.
Security
Access to family data is enforced by row-level security in the database, so a request that is not yours returns nothing — the app is not the only gate. Traffic is encrypted in transit and data is encrypted at rest. Backup authorisation tokens are held in encrypted server-side storage. No system is perfect; if a breach ever affects you, we will tell you and the relevant regulator as the law requires.
Changes to this policy
If we change this policy materially we will update the date above and tell you in the app before the change takes effect.
Contact
hello@xplatsolutions.com — privacy questions, access, correction and erasure requests. We answer within 30 days.