TreeTalk Privacy Policy

Website, Windows and Android Applications
Version 1.2 - Last Updated: July 18, 2026

This Privacy Policy explains how TreeTalk handles personal data in connection with the TreeTalk website, TreeTalk Node for Windows, TreeTalk Node for Android, and related licensing, support, and distribution activities. TreeTalk Node is designed as a local-first, peer-to-peer application. Files, messages, and voice recordings are normally exchanged directly between user-selected devices over a local network, Wi-Fi network, or user-configured VPN, without being routed through TreeTalk servers.

1. Data Controller

The data controller for personal data received through the TreeTalk website, licensing infrastructure, sales records, and support channels is:

TreeTalk
Piazza Campitelli 2
00186 Rome (RM), Italy
VAT number: 15018041002
Privacy and support contact: https://tree-talk.com/contacts.html

TreeTalk does not currently designate a Data Protection Officer. Privacy requests are handled through the contact mechanism above.

2. Scope of This Policy

This Policy applies to:

The package identifiers above must match the final identifiers reserved in Google Play Console. If either identifier changes before publication, this Policy should be updated before the corresponding app is released.

3. Local-First Product Architecture

TreeTalk Node is designed to discover nearby TreeTalk Node devices and exchange content directly between devices. TreeTalk does not provide a cloud mailbox, content relay, hosted chat archive, or remote file-storage service for ordinary TreeTalk Node communications.

A sender chooses the recipient or group and initiates the transfer. The receiving device may store the received content locally. TreeTalk does not receive a copy of the transferred content and cannot remotely inspect, retrieve, delete, or restore it.

TreeTalk Node does not require an Android user account. A nickname, local settings, and an installation identifier may be stored on the device and used for local peer discovery. They do not create a TreeTalk cloud profile.

4. Data We Access or Receive

4.1 Information You Voluntarily Provide to TreeTalk

When you contact TreeTalk, request support, submit a form, join a mailing list, purchase or activate a Windows licence, or otherwise communicate with us, you may provide your name, email address, company name, phone number, country or region, order information, licence information, and the contents of your message. We collect only the information you submit or that is reasonably necessary to respond.

4.2 Website and Server Data

When you visit the Website, TreeTalk and its hosting or analytics providers may process IP address, browser and device information, operating system, referral source, pages viewed, actions taken, and access date and time. The Website may use Google Analytics, Google Tag Manager, consent-management tools, and ordinary web-server logs. Where required, non-essential analytics operate only after consent.

4.3 Windows Licence Activation and Validation

A paid Windows edition may transmit a licence key, a non-reversible device or hardware-derived identifier, software version, activation timestamp, and limited network information to TreeTalk or its designated licensing provider for activation, validation, fraud prevention, support, and licence administration. The portable/direct-download edition ordinarily provides a 14-day Premium evaluation. The Microsoft Store Windows edition ordinarily provides a 7-day Premium evaluation.

4.4 Windows Diagnostics

A Windows edition may transmit limited diagnostic information where the relevant diagnostic function is enabled or used, such as software version, error information, and aggregate feature or compatibility information. TreeTalk does not intentionally include file contents, message contents, voice recordings, or encryption passphrases in diagnostic reports. The Premium Offline Edition is designed to minimise or eliminate Internet-based communications after any required activation.

4.5 Android Local Profile and Peer Discovery Data

The Android apps may store a user-selected nickname, app settings, local instance identifier, trial state, selected folders, and connection preferences on the device. To find compatible devices, the app may broadcast or send limited peer-discovery metadata within the local network or user-configured VPN. Depending on the build and selected settings, this metadata may include nickname, local network address and port, application name and version, local instance identifier, network-interface label, and encryption status. Other devices on the same reachable network may receive this information. It is not sent to TreeTalk.

4.6 Messages, Files, and Other User Content

TreeTalk Node accesses content only to provide functions requested by the user. This may include text messages, files and documents, photos, videos, audio files, and other user-selected content. Content is processed locally and transmitted directly to the peer or peers selected by the sender. It is not uploaded to TreeTalk or to an analytics, advertising, crash-reporting, or social-login service.

Received content may be stored in the app’s private storage, in a user-selected folder, or in shared device storage, depending on platform, settings, and the storage location selected by the user. A copy received by another user remains under that recipient’s control.

4.7 Microphone and Voice Messages

When the user starts recording a voice message, the Android app requests access to the microphone through the Android runtime-permission system. Audio is recorded only for the requested voice-message feature, stored locally as needed, and sent directly to the selected peer or group when the user initiates sending. Cancelled recordings should not be sent. TreeTalk does not receive the recording.

4.8 File and Folder Access on Android

The Android app uses Android system file or folder selection mechanisms where available and accesses only the files or locations selected or authorised by the user. TreeTalk Node does not require access to a user’s complete photo library or all files merely to send a selected file. The final Android manifest and permission declarations must remain consistent with this statement.

4.9 Android Free-Edition Evaluation Data

TreeTalk Node for Android - Free Edition ordinarily includes a 7-day, per-installation evaluation of selected Pro features. The app stores the evaluation start time and local counters on the device. During the evaluation, the current design permits up to 30 sent voice messages and up to 30 individual files sent through the multi-file feature. Each allowance ends when it is exhausted or when the 7-day period ends, whichever occurs first.

Evaluation records are not sent to TreeTalk. The Android app is intended to exclude evaluation-state records from Android cloud backup where supported. Clearing the app’s storage or reinstalling the app may create a new local installation state; behaviour can also depend on Android or device-manufacturer backup and migration functions.

4.10 Android Pro Purchase and Distribution

TreeTalk Node Pro for Android is a separate paid app distributed through Google Play. Google processes the purchase and payment under Google’s terms. The Android app does not receive full payment-card details. Google may make limited order, payout, tax, country, refund, or support information available to TreeTalk through Play Console or related merchant records as necessary for transaction administration, accounting, legal compliance, or user support.

4.11 Cookies

For information about cookies and similar technologies used on the Website, see https://tree-talk.com/cookie-policy.

5. Android Components and SDK Disclosure

The Android apps are built with the components listed below. These components run as part of the app. They are not advertising or analytics services and are not independent recipients of user content merely because their code is included in the app.

Category Components / versions Privacy role
AndroidX / Jetpack and Material androidx.webkit 1.14.0; androidx.appcompat 1.7.1; androidx.activity:activity-ktx 1.10.1; androidx.core:core-ktx 1.13.1; androidx.documentfile 1.0.1; com.google.android.material 1.12.0 Application compatibility, UI, activity lifecycle, WebView integration, and user-authorised document access.
Tauri / Rust application framework Tauri 2.10.3; wry 0.54.4; tao 0.34.8; jni 0.21.1; tokio 1.x; socket2 0.5; if-addrs 0.13; serde / serde_json 1.x; chrono 0.4; rand 0.8; dirs 5.0; url 2; libc 0.2; anyhow 1.0; Tauri plugins dialog, fs, opener, and os 2.x Local app runtime, native integration, local networking, serialisation, files, dialogs, and operating-system integration.
WebView UI bundle Svelte 5; SvelteKit 2; @tauri-apps/api 2 Packaged user interface running in the app-controlled WebView.
Cryptography First-party AES-256-CTR, HMAC-SHA-256, and PBKDF2 implementation in the TreeTalk C++ core Protects content when encryption is enabled and properly configured. No third-party cryptography SDK is used.
Not included No advertising, analytics, tracking, attribution, crash-reporting, social-login, Firebase, or Google Play Services SDK The Android app does not transmit telemetry or user content to these services because they are not integrated.

Build environment: target API level 36 (Android 16), minimum API level 24 (Android 7.0), compile SDK 36, Android NDK r27 (27.0.12077973), arm64-v8a, Android Gradle Plugin 8.11.0, Kotlin 1.9.25, and Gradle 8.14.3. Build tools are development infrastructure and are not, by themselves, data recipients inside the installed app.

6. How TreeTalk Uses Personal Data and Legal Bases

The legal bases below apply to information that TreeTalk actually receives. Local peer-to-peer content that never reaches TreeTalk is controlled by the participating users and organisations rather than by TreeTalk.

Purpose Data Typical legal basis under GDPR Article 6
Respond to inquiries and provide support Contact details, correspondence, voluntarily supplied logs or attachments Contract steps, contract performance, and legitimate interests
Windows licence activation and administration Licence key, device-derived identifier, software version, activation and support records Contract performance and legitimate interests
Google Play / Microsoft Store transaction administration Limited order, refund, tax, payout, country, and support records made available by the distributor Contract performance, legal obligation, and legitimate interests
Website security and operation IP address, server logs, device and request information Legitimate interests and legal obligation
Website analytics Analytics and usage information Consent where required; otherwise legitimate interests where permitted
Product diagnostics and compatibility Limited Windows diagnostic data where enabled or submitted Legitimate interests and, where required, consent
Marketing communications Email address and preferences Consent
Legal compliance and dispute handling Relevant transaction, support, licence, and legal records Legal obligation and legitimate interests

TreeTalk does not sell personal data and does not use Android-app data for behavioural advertising, cross-context advertising, profiling, or data brokerage.

7. Data Sharing and Recipients

TreeTalk may disclose limited personal data to:

A user-initiated transfer to another TreeTalk Node device is not a disclosure by TreeTalk. It is a direct transfer initiated and controlled by the sender. TreeTalk does not select the recipient or receive a server-side copy.

8. International Data Transfers

Website analytics, hosting, store-distribution, email, licensing, or support data may be processed outside the European Economic Area. Where required, TreeTalk relies on an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism. Direct local-network content transfers occur between the devices and networks selected by users and are not international transfers performed by TreeTalk.

9. Retention and Deletion

Data category Typical retention
Android local settings, nickname, peer cache, and evaluation counters Until deleted in the app, cleared through Android settings, or removed with app data; some exported or shared-storage content may remain after uninstall.
Messages, files, and voice recordings stored on a user device Until the user or device administrator deletes them. Copies already delivered to another device remain under the recipient’s control.
Contact and support correspondence Duration of the relationship plus up to 3 years, unless a longer period is required for a dispute or legal obligation.
Windows licence activation records Duration of the licence plus up to 5 years, or longer where required for tax, fraud prevention, or legal claims.
Device-derived Windows activation identifier Duration of the associated licence and necessary fraud-prevention or support period.
Website analytics Normally 14 to 26 months, depending on configuration and consent.
Server and security logs Normally 6 to 12 months, subject to security incidents and legal requirements.
Newsletter subscription Until unsubscribe or withdrawal of consent.
Google Play / Microsoft Store order and accounting records For the period required by accounting, tax, consumer-protection, fraud-prevention, and limitation rules.
Limited Windows diagnostic data Normally up to 12 months, then deleted or aggregated, unless needed for an unresolved issue.

The Android apps do not create a TreeTalk cloud account. Therefore, the Google Play account-deletion requirement is not triggered by ordinary use of the apps. Users can delete local app data through in-app controls where available or through Android Settings > Apps > TreeTalk Node > Storage > Clear storage. Files saved outside private app storage may need to be deleted separately with the system file manager.

To request access, correction, or deletion of personal data actually held by TreeTalk, use https://tree-talk.com/contacts.html. TreeTalk may retain information that must be kept for tax, accounting, fraud prevention, legal claims, or other lawful purposes.

10. Your Privacy Rights

Subject to applicable law, you may request access, rectification, erasure, restriction, portability, or objection, and may withdraw consent for processing based on consent. Withdrawal does not affect processing that was lawful before withdrawal. TreeTalk does not use solely automated decision-making that produces legal or similarly significant effects.

EU/EEA users may complain to their national supervisory authority. In Italy, the competent authority is the Garante per la protezione dei dati personali.

11. Security and Encryption

TreeTalk applies reasonable technical and organisational measures to systems under its control, including access controls, HTTPS for web services, system hardening, software updates, and restricted access to operational records.

TreeTalk Node supports first-party AES-256-CTR encryption with HMAC-SHA-256 authentication and PBKDF2-based key derivation. Protection depends on the user enabling encryption where applicable, replacing any default or shared passphrase with a strong unique passphrase, keeping it secret, and configuring all participating devices consistently. A default, weak, reused, or disclosed passphrase must not be treated as secure.

Encryption does not protect content after it is decrypted on a compromised or improperly secured endpoint. Users should verify peers, protect receiving folders, maintain backups, and inspect received files before opening them.

12. Children and Target Audience

TreeTalk Node is designed for adult users, professionals, organisations, and supervised business or institutional environments. It is not directed to children. TreeTalk does not knowingly collect personal data from children through the Android apps. If you believe a child has submitted personal data directly to TreeTalk through a support or website channel, contact us so that we can review and delete it where appropriate.

13. User-Generated Content and Safety Controls

Users can exchange messages and files with other reachable peers. Users must not send unlawful, abusive, infringing, malicious, or unwanted content. The Android apps should provide a readily discoverable way to block or ignore a peer. Where a user chooses to report a peer or content to TreeTalk, the report and any attachment are sent only after the user’s affirmative action and are handled as support correspondence under this Policy.

TreeTalk does not proactively monitor local communications because it does not receive them. Blocking a peer affects the local installation and does not erase content already delivered to another device.

14. External Services and Links

The Website and apps may link to Google Play, Microsoft Store, support pages, licence-purchase pages, or other third-party services. Their privacy practices are governed by their own policies. TreeTalk is not responsible for third-party services that it does not control.

15. Changes to This Policy

TreeTalk may update this Policy to reflect product, legal, security, or operational changes. Material changes will be communicated through the Website, app, store listing, or email where appropriate. The current version will be published at https://tree-talk.com/privacy-policy.html.

16. Contact

TreeTalk - Privacy Office
Piazza Campitelli 2
00186 Rome (RM), Italy
https://tree-talk.com/contacts.html