Welcome to Treegram. This Privacy Policy explains how your personal data is collected, used, stored, and protected through the Treegram application ("Application", "Service").
Treegram is a mobile application that offers tree management and social networking features. By using our services, you agree to this Privacy Policy.
This policy has been prepared in accordance with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other relevant data protection legislation.
1. Data Controller
The data controller responsible for processing your personal data under this Privacy Policy:
| Information | Details |
|---|---|
| Title | The developer or operator operating the Treegram application |
| info@treegram.app |
2. Data We Collect
Treegram collects personal data in the following categories to provide its services:
2.1 Account and Identity Information
When you register for our application, we collect the following information:
| Data Type | Requirement | Description |
|---|---|---|
| Email Address | Required | Account creation and authentication |
| Password | Required | Account security (stored encrypted) |
| User ID (UID) | Automatic | System-generated unique identifier |
| Username | Required | Unique name for your profile |
Google Sign-In
If you sign up using Google Sign-In, the following information is retrieved from Google:
- Email address
- Name
- Google User ID
2.2 Profile Information
You may provide the following information when creating and updating your profile:
| Data Type | Requirement | Description |
|---|---|---|
| Name | Required | Your name displayed to other users |
| Username | Required | Your unique username |
| Profile Photo | Required | Photo displayed on your profile |
| Date of Birth | Required | Your birth date |
| Bio (About Me) | Optional | Short text describing yourself |
About Bio Field: You may optionally fill in the "Bio (About Me)" field on your profile. This field contains user-provided content. We recommend not sharing sensitive personal data. Bio information is visible to your friends and profile visitors.
2.3 Social Interaction Data
Social data generated while using the application:
- Posts: Text and images you share
- Comments: Comments you make on posts
- Likes: Content you like
- Friend List: Other users you connect with
- Friend Requests: Requests you send and receive
2.4 Family Tree Data
The following data is collected when using the tree feature:
- Tree Information: Tree name, creation date, ownership information
- Family Members: Full name, birth date, death information (if any), family relationships
- Member Photos: Images added to family members
- Family Media: Photos and documents uploaded to the tree
- Membership Information: Users invited to and joining the tree
- Tree Messages: Messages and notes shared within the tree
- Trees You're Invited To: Trees you've been invited to by others are stored as a list associated with your account (e.g., invitedTrees). This information is used to provide access to the relevant trees, manage invitation status, and facilitate in-app navigation.
Tree Permissions
Permissions within trees vary based on ownership status:
| Permission | Owner | Invited Member |
|---|---|---|
| Edit tree information | Yes | No |
| Add/edit family members | Yes | Yes |
| Add media | Yes | Yes |
| Write messages | Yes | Yes |
| Delete all media | Yes | No (only their own) |
| Delete all messages | Yes | No (only their own) |
| Invite members | Yes | No |
| Link members to friends | Yes | No |
| Delete the tree | Yes | No |
Responsibility for Third-Party Data
Users declare and undertake that they have obtained the necessary consent from living persons whose information (name, photo, birth date, etc.) they add to the tree.
Under GDPR, the person who uploads another person's personal data to the platform is responsible for obtaining that person's consent. Treegram cannot be held legally responsible for unauthorized sharing of third-party data uploaded by users.
2.5 Notification Data
For in-app and push notifications:
- Notification type and content
- Sender and recipient information
- Notification status (read/unread)
- Timestamp
- FCM Token: Device token for push notifications (stored per device)
2.6 Location Data
a) IP-Based Location Detection
Important: We use IP-based location detection. When you register or log in, we use your IP address to determine your approximate location (country and city level). This data is:
- Used to offer language preferences
- Not shared with third parties
- Stored at country/city level only (not precise coordinates)
- Can be viewed from your profile
We do not use continuous GPS location or real-time location tracking.
b) Grave Location (Optional)
Tree owners can mark the grave location of deceased family members on a map. This feature processes sensitive personal location data.
| Data Type | Requirement | Description |
|---|---|---|
| Grave Latitude | Optional | Latitude coordinate of grave location |
| Grave Longitude | Optional | Longitude coordinate of grave location |
Retention: Until tree is deleted or account is closed.
Important Information About Grave Location Data
- Coordinates are manually selected on a map by the tree owner, no automatic GPS tracking is used
- Only the tree owner can add, edit, or remove grave locations
- Only tree members (owner and invited members) can view grave locations
- Navigation apps (Google Maps, Apple Maps, Yandex Navi) redirect on user request
- Data is permanently deleted when tree or account is deleted
2.7 Usage Statistics
We collect usage statistics to improve the application:
| Data | Purpose | Storage |
|---|---|---|
| Daily usage duration | Service improvement | Locally on device + server |
| Session count | Performance analysis | Locally on device + server |
| First/Last seen | Account activity tracking | Server |
This data is stored locally on your device (Hive database) and periodically sent to the server. While this data can be associated with your user ID, it is not used for individual behavior analysis or marketing purposes. It is only used to generate aggregate statistics for overall application performance.
2.8 Activity Records
We keep references of your activities within the application for account management and data deletion purposes:
- Posts and media you've created
- Trees you own or are a member of
- Comments you've made
- Friend connections
- Reports and support requests you've submitted
These references are used only for account management and complete data deletion upon request.
2.9 Technical Data
Automatically collected for application operation:
- Device type and operating system
- Application version
- Session information
- Error logs (anonymous)
- Language preference
2.10 Direct Messaging Data
When you use the direct messaging feature to communicate with other users:
- Message text and sending time
- Sender and recipient user information (user ID, name)
- Conversation metadata (last message preview, read status, unread message count)
- Rate limiting data (to prevent abuse, temporary, automatically deleted)
This data is used to provide the messaging service (read status, conversation ordering, notification delivery) and to prevent abuse (rate limiting). Messages are stored on Google Firebase (Cloud Firestore) infrastructure.
Encryption: Your direct messages are encrypted during transmission (TLS) and while stored on our servers. However, end-to-end encryption (E2EE) is not implemented. This means that message content is technically accessible on the server side.
2.11 Poll Data
When you use the poll feature within trees:
- Poll question and options
- Vote information (user ID and selected option)
- Poll duration and creation time
- Poll creator user information
This data is used to provide the poll service and display results. Poll data is only viewable by tree members.
2.12 Event Data
When you create events in the tree gallery:
- Event name and creation time
- References to photos linked to the event
- Event creator user information
This data is used to provide the photo grouping service.
2.13 Life Timeline Data
When you add important moments to tree members' cards:
- Milestone title and date
- Optional description text
- Related person information (reference to another member within the tree)
- Milestone creator user information
This data is used to provide the life timeline feature. Life timeline data is only viewable by tree members.
Reminder Preferences: Milestone anniversary reminder preferences are stored only locally on your device (SharedPreferences). This data is not sent to our servers and is not stored in Firestore.
2.14 Data We Do Not Collect
Treegram does not collect the following data:
- Continuous GPS/location tracking (Note: For manually added grave location coordinates, see Section 2.6b)
- Contacts/Address Book
- Search history
- SMS or call records
- Financial information (credit card, bank account)
- Health data
- Biometric data
3. Data Collection Methods
3.1 Data We Collect Directly From You
- Information you provide during account creation
- Information you enter during profile editing
- Content you provide when creating posts, comments, and shares
- Information you enter when creating and editing trees
- Information you share during customer support communication
- Reports and feedback you submit
3.2 Automatically Collected Data
- Timestamps generated during application use
- Login/logout records
- Authentication data generated by Firebase Authentication
- FCM tokens for push notifications
- IP-based location data (country/city level)
- Grave location coordinates (only manually added by tree owner, not automatically collected)
- Usage statistics
3.3 Data Received From Third Parties
When you register using Google Sign-In:
- Email and name from Google account
4. Purposes of Data Use
We process your personal data for the following purposes:
4.1 Service Delivery
- Creating and managing your account
- Verifying your identity and ensuring your security
- Providing tree features
- Enabling social networking features
- Sending notifications (in-app and push)
- Determining language preferences (using location data)
4.2 Communication
- Informing you about important service updates
- Sending account security alerts
- Responding to your support requests
- Sending email for account operations (password reset, account deletion confirmation)
4.3 Development and Improvement
- Monitoring and improving application performance
- Detecting and fixing errors
- Improving user experience
- Developing new features
- Analyzing usage statistics
4.4 Security and Compliance
- Preventing fraud and abuse
- Detecting suspicious activities
- Complying with legal obligations
- Enforcing terms of use
- Rate limiting (bot protection)
4.4.1 Content Moderation and Safety
To maintain a safe environment, Treegram provides features that allow users to report content and block other users, helping to moderate user-generated content.
When a user reports content or blocks another user:
- The reported or blocked content may be reviewed by our moderation team.
- We may store certain information related to reports or blocking actions, including user identifiers and timestamps, for safety and abuse prevention purposes.
- These actions are used solely to enforce our community guidelines and protect users from harmful behavior.
- This information is not used for advertising or marketing purposes.
4.5 Legal Basis
| Purpose | Legal Basis |
|---|---|
| Account management | Performance of contract |
| Security measures | Legitimate interest |
| Legal compliance | Legal obligation |
| Location detection | Legitimate interest (service improvement) |
| Usage statistics | Legitimate interest (service improvement) |
| Marketing (if any) | Consent |
5. Data Storage and Security
5.1 Data Security Measures
We implement the following security measures to protect your data:
Technical Measures:
- Data transfer with TLS/SSL encryption
- Password protection with hash algorithms
- Access control with Firebase Security Rules
- Secure authentication mechanisms
- hCaptcha bot protection on web forms
- Rate limiting for API requests
Administrative Measures:
- Restricting data access permissions
- Regular review of security policies
- Security assessment of third-party service providers
- Administrative audit logs
5.2 Rate Limiting
To prevent abuse, we implement rate limiting on specific operations:
- Account deletion requests: 3 requests per hour per IP
- Support requests: 5 requests per hour per IP
- Contact form submissions: 10 requests per day per IP
For rate limiting, your IP address is stored in hashed form and automatically deleted after the limit period.
5.3 Data Storage Location
Your data is stored on Google Firebase infrastructure. Firebase runs on Google Cloud Platform, and data may be stored in the following locations:
- United States
- European Union (if Firebase EU region is selected)
5.4 In Case of Security Breach
If a data breach is detected:
- We will immediately assess the breach
- We will make necessary legal notifications (within 72 hours under GDPR)
- We will inform affected users
- We will take necessary measures to minimize damage
6. Data Sharing and Third Parties
6.1 Service Providers
We work with the following third-party service providers to deliver our services:
| Service Provider | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|
| Google Firebase | Authentication, database, file storage, push notifications | All user data | Firebase Privacy |
| Google Cloud Platform | Infrastructure services | All user data | Google Privacy |
| ipwho.is | IP-based location detection | IP address only | ipwhois.io |
| Firebase Crashlytics | Crash and error reporting | Device info, crash logs, app version | Firebase Privacy |
| Resend | Email delivery | Email address | Resend Privacy |
| hCaptcha | Bot protection | Browser data, IP address | hCaptcha Privacy |
| Google AdMob | In-app advertising | Device info, advertising ID (IDFA/GAID) | Google Privacy |
| Apple | Sign in with Apple | Apple ID, name, email | Apple Privacy |
| Google Maps API | Grave location map display | Grave location coordinates transferred on user request | Google Privacy |
| Google Places API | Grave location search (autocomplete) | Search text typed by the user | Google Privacy |
| Apple Maps | Navigation redirect on user request (iOS) | Grave location coordinates | Apple Privacy |
| Yandex Navi | Navigation redirect on user request | Grave location coordinates | Yandex Privacy |
6.2 Sharing With Other Users
The following information may be visible to other users:
- Public: Your name, username, profile photo (in search results)
- With Friends: Your posts, comments, profile information
- With Tree Members: Information within the tree, shared media, messages
- With Users You Message: Your direct messages are visible only to the recipient. Third parties cannot access your message content.
Tree Content Visibility
Content visibility in trees works as follows:
- Trees you own: Tree members can see all added media and messages
- Trees you're invited to: Media and messages you add can be seen by other members who are not your friends
- Linking tree members: You can link members in your tree to your friends
6.3 Legal Requirements
We may share your data with authorities in the following situations:
- Legal obligation (court order, prosecutor's request)
- Protection of public safety
- Fraud or crime prevention
- Protection of our rights
6.4 Sale or Merger
In the event of sale, merger, or acquisition of our company, your data may be transferred as part of this transaction. We will inform you in advance in such cases.
6.5 Data We Do Not Sell
We never sell your personal data to third parties or share it for advertising purposes under any circumstances.
7. Cookies and Similar Technologies
7.1 Local Storage
The Treegram mobile application uses the following local storage methods instead of cookies:
| Technology | Purpose | Data |
|---|---|---|
| Shared Preferences | Application settings | Theme, language preference |
| Firebase Auth Token | Session management | Authentication token |
| Hive Local Database | Usage statistics | Daily activity records |
Hive Database Details: To improve application performance and user experience, we may store certain usage metrics locally on your device (e.g., pending minutes, session count, first/last seen time, last activity time, and inactivity threshold for session separation). This data is periodically transferred to the server and can be cleared through app settings or account deletion.
7.2 Website Cookies
The Treegram website (treegram.app) uses the following cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| Firebase Auth | User session | Session |
| hCaptcha | Bot protection | Session |
Password reset links are processed on the treegram.app/auth/action page; when this page is opened, the Firebase Authentication SDK is loaded to complete the reset.
7.3 Analytics and Crash Reporting
We use Firebase Analytics to improve app performance and user experience. This tool collects app usage statistics (page views, feature usage, error reports, etc.). The collected data is used for aggregate analysis and helps us improve service quality.
We also use Firebase Crashlytics to detect and fix app crashes and errors. Crashlytics collects technical data such as device model, operating system version, app version, and crash logs (stack traces) at the time of a crash. This data is used solely for debugging and improving app stability; it is not used for identity profiling or marketing.
8. Your Rights
8.1 Your Rights Under GDPR
If you reside in the European Union, you have the following rights under GDPR:
- Right to Information: Learn whether your personal data is being processed
- Right of Access: Request access to your processed personal data
- Right to Rectification: Request correction of incomplete or incorrect data
- Right to Erasure: Request deletion of your personal data
- Right to Data Portability: Receive your data in a structured format
- Right to Restriction: Request temporary suspension of processing
- Right to Object: Object to automated processing results
- Right to Withdraw Consent (GDPR Art. 7(3)): Withdraw your consent at any time for processing based on consent. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal
- Right to Lodge Complaint: Apply to the competent data protection authority
How to Withdraw Consent
- Push notifications: Disable notification permission in your device settings
- Location permission: Remove the app's location permission in your device settings
- Personalized ads: Via your device's ad settings (iOS: Tracking permission, Android: Ad personalization)
- All other consent-based processing: By emailing info@treegram.app
Consent withdrawal requests are processed within 30 days at the latest.
8.2 Your Rights Under CCPA (California Residents)
If you are a California resident, you have additional rights:
- Right to Know: Learn what personal data is collected and how it's used
- Right to Delete: Request deletion of your personal data
- Right to Opt-Out: Opt out of sale of personal data (Note: We do not sell data)
- Right to Non-Discrimination: Receive equal service regardless of privacy choices
8.3 How to Exercise Your Rights
To exercise your rights:
- Email: info@treegram.app
- In-App: Settings > Account > Privacy options
Your request will be answered within 30 days at the latest. We may request additional information to verify your identity.
8.4 Account Deletion
To delete your account and all your data:
Via App:
- Go to Settings > Account > Delete Account
- Re-authenticate (password or Google)
- Select a reason (optional)
- Confirm the request
Via Website:
- Visit treegram.app/delete-account
- Enter your email and username
- Click the link in the confirmation email
Account Deletion Process
30-Day Waiting Period: For your security, there is a 30-day waiting period for account deletion requests.
During the Waiting Period:
- You can cancel the deletion request within 15 days if you change your mind
- Your trees and profile cannot be accessed
- Your posts remain visible to your friends
After Canceling Deletion Request: If you cancel your deletion request, a short waiting period (e.g., 1-8 hours) may be applied before you can submit a new deletion request, to prevent abuse and ensure system security.
After Account Deletion:
The following data is permanently deleted:
- Your profile information and account data
- All your posts and photos
- Trees you own (including all members, media, and messages)
- All media files you uploaded
- Your notifications and friend list
- Your support requests and reports
The following data is not deleted, but anonymized:
- Media and messages you added to others' trees
- Comments you made on others' posts
- Your usage statistics (total minutes, session count) - separated from your identity and retained as anonymous statistics
Anonymization means the content is preserved but your identifying information (name, profile photo, user ID) is removed. This content will be shown as "Deleted User".
Access After Account Deletion: Once the account deletion process is complete, authentication credentials associated with your account are disabled and your access to in-app data is blocked by security rules.
9. Children's Privacy
9.1 Age Limit
You must be at least 16 years old to use Treegram services. Use of the platform by persons under 16 is prohibited.
9.2 Protection of Children's Data
We do not knowingly collect personal data from anyone we know or reasonably suspect is under 16.
If we discover that a person under 16 is using the platform, we will immediately delete the account and related data.
9.3 Children's Information in Trees
In the tree feature, users can enter children's information (name, birth date) as family members. This information:
- Is only visible to tree members
- Is entered by adult users
- Can be deleted or updated at any time
10. International Data Transfer
10.1 Transfer Mechanisms
Your data may be transferred outside the European Economic Area (EEA) due to Google Firebase infrastructure. For these transfers:
- Google's compliance with Standard Contractual Clauses (SCC)
- EU-US Data Privacy Framework certification
- Appropriate security measures
10.2 Third-Party Services Location
| Service | Location | Safeguards |
|---|---|---|
| Firebase/GCP | USA/EU | SCC, Privacy Framework |
| ipwho.is | Various (outside EEA possible) | HTTPS, only the IP address is sent |
| Resend | USA | SCC, Privacy Framework |
| hCaptcha | USA | SCC |
| Google AdMob | USA/EU | SCC, Privacy Framework |
| Apple | USA | SCC, Privacy Framework |
10.3 Protection Level
For transfers outside the EEA, we take necessary measures to ensure your data is processed at the protection level specified in this policy.
11. Data Retention Periods
11.1 General Principles
We retain your personal data for the period required by the collection purpose or within legal obligations.
11.2 Category-Based Retention Periods
| Data Category | Retention Period |
|---|---|
| Account Information | Until account is deleted + 30 days waiting period |
| Profile Information | Until account is deleted |
| Posts | Until user deletes or account closes |
| Comments | Until user deletes or account closes |
| Tree Data | Until tree is deleted or owner account closes |
| Grave Location Coordinates | Until tree is deleted or account is closed |
| FCM Tokens | Until logout or device change |
| Location Data | Until account is deleted |
| Usage Statistics | 1 year (anonymous aggregate data may be kept longer) |
| Rate Limit Records | 1 hour (IP hashes) |
| Deletion Request Tokens | 1 hour |
| Direct Messages | Until account is deleted (sender info is anonymized upon deletion) |
| Message Rate Limit Data | 1 hour (automatically deleted) |
| Backups (disaster recovery) | Up to 90 days — may persist in backups for this period after account deletion |
| Connection and Activity Records (IP address, date-time, device information) | 1 year (legal obligation — Turkish Law No. 5651, Art. 5/3) |
11.3 Retention in Backups
Regular backups are taken to ensure service continuity and prevent data loss. When you delete your account, your data is removed from live systems immediately; however, it may remain in backups taken before that point for up to 90 days. Those backups are deleted automatically at the end of this period.
Backups are kept solely for disaster recovery; access to them is restricted and the data is not used for any other purpose or shared with third parties.
11.4 Connection and Activity Records (Traffic Data)
Treegram qualifies as a hosting provider under Turkish Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications. Article 5/3 of that law imposes a legal obligation to retain traffic data relating to the service and to ensure its accuracy, integrity and confidentiality.
Accordingly, the following data is recorded:
- Connection records: Your IP address, connection date and time, application version, operating system and device model when you sign in
- Activity records: Information about who performed a content-creation action (post, comment, photo, tree message, direct message) and when
- File fingerprint: A mathematical digest (SHA-256) of images you upload. The image itself cannot be reconstructed from this digest; it only serves to verify the identity of a file
Important: These records do not store the content itself. The text or image of your posts, photos and messages is not included in these records.
Retention period: 1 year. Records are automatically deleted once this period expires.
Access: Only authorized personnel may access these records, and every access is itself logged. Records are not shared with third parties in the absence of a duly issued court order, prosecutor's request, or an official request that expressly states its legal basis.
Legal basis: For users located in Türkiye, Article 5/2-(a) of the Turkish Personal Data Protection Law (KVKK) — expressly provided for by law. For users located in the European Union, Article 6(1)(f) GDPR — legitimate interests (platform security and the ability to respond to lawful requests).
11.5 After Account Deletion
When your account is deleted:
- Immediately deleted: Profile information, account data, FCM tokens, trees you own
- Anonymized: Comments, likes in others' content, usage statistics, and direct messages (sender info changed to "Deleted User", message history remains for the other party)
- May be retained: De-identified statistical data
- Retained for the statutory period: The connection and activity records described in Section 11.3, together with the minimum identity information needed to make those records meaningful (user ID, email address, username, account creation and deletion dates). This data is automatically deleted at the end of the 1-year period required by Law No. 5651. Your photos, posts and content are not retained under this provision; they are deleted.
12. Authorized Personnel Access
12.1 Administrative Panel
Our management team, by default, only views aggregate statistics (total user count, daily registration count, etc.). Individual user data is only accessed for the following legitimate reasons:
- Responding to support requests
- Reviewing and resolving reports
- Processing account deletion requests
- Investigating security incidents
- Responding to legal requests
12.2 Data Accessible by Admins
| Data Type | Purpose |
|---|---|
| Profile information | Support and account verification |
| Reports | Reviewing reported content |
| Support requests | Responding to your requests |
| Account deletion requests | Processing deletion process |
| General statistics | Service improvement |
12.3 Audit Logs (Admin Action Logs)
For security and abuse prevention purposes, certain actions performed through the admin panel may be recorded in audit logs:
- Content removal or editing
- User warnings or bans
- Report review and resolution
- Access permission changes
- Processing of account deletion requests
These logs may contain action type, date-time, the authorized account performing the action, and related record references. Audit logs are accessed and retained only for security and legal compliance purposes.
12.4 Security Measures
- Admin access is controlled via Firebase Custom Claims
- All admin actions are logged
- Least privilege principle is applied
12.5 Proactive Moderation
To enforce our community guidelines and protect users from harmful content, authorized personnel may proactively review not only reported content but also publicly visible or shared content (posts, comments, tree media, profile information) that raises suspicion of a rules violation. Within this scope:
- Review is limited to content moderation and safety purposes (see Section 4.4.1 equivalent provisions)
- Content found in violation may be removed, and the related account may be warned or suspended
- Moderation actions are recorded in audit logs (see Section 12.3)
- Content of a private nature (e.g., direct messages) is not subject to proactive scanning; it may only be reviewed upon a report or where legally required
13. Policy Changes
13.1 Update Procedure
We may update this Privacy Policy from time to time. When changes are made:
- We will change the "Last Updated" date
- We will inform via email if necessary
13.2 Effective Date of Changes
The updated policy takes effect on the date of publication. Continuing to use the service after changes means you accept the updated policy.
13.3 Previous Versions
Access to previous versions of this policy can be provided upon request.
14. Contact
14.1 For Your Questions
If you have questions about our privacy policy or data processing practices:
- Email: info@treegram.app
- Contact Form: treegram.app/contact
14.2 Right to Complain
If you are not satisfied with our data processing practices, you have the right to file a complaint with the competent data protection authority:
- European Union: Data Protection Authority in your country
- United Kingdom: Information Commissioner's Office (ICO)
- United States: Federal Trade Commission (FTC)
Firebase (Google)
- Service: Authentication, database, file storage, push notifications (FCM)
- Data Processed: All user data, FCM tokens
- Privacy Policy: https://firebase.google.com/support/privacy
- Data Processing Agreement: https://firebase.google.com/terms/data-processing-terms
Google Cloud Platform
- Service: Infrastructure, Cloud Functions
- Data Processed: All user data
- Privacy Policy: https://policies.google.com/privacy
- Security: https://cloud.google.com/security
ipwho.is
- Service: IP-based location detection (HTTPS)
- Data Processed: IP address (temporary, not stored)
- Website: https://ipwhois.io
Firebase Crashlytics (Google)
- Service: Crash and error reporting
- Data Processed: Device model, OS version, app version, crash logs (stack traces)
- Privacy Policy: https://firebase.google.com/support/privacy
Resend
- Service: Email delivery
- Data Processed: Email address
- Privacy Policy: https://resend.com/legal/privacy-policy
Google AdMob (Google)
- Service: In-app advertising
- Data Processed: Device info, advertising ID (IDFA/GAID), app usage data
- Privacy Policy: https://policies.google.com/privacy
- Ad Preferences: https://adssettings.google.com
Apple Sign-In (Apple)
- Service: Sign in with Apple (iOS and Android)
- Data Processed: Apple ID, name, email (can be hidden by user)
- Privacy Policy: https://www.apple.com/legal/privacy/
hCaptcha
- Service: Bot protection
- Data Processed: Browser data, IP address (temporary)
- Privacy Policy: https://www.hcaptcha.com/privacy
Google Maps API (Google)
- Service: Grave location map display and navigation
- Data Processed: Grave location coordinates (latitude, longitude) on user request
- Privacy Policy: https://policies.google.com/privacy
Google Places API (Google)
- Service: Location search and autocomplete when adding a grave location
- Data Processed: Search text typed by the user
- Privacy Policy: https://policies.google.com/privacy
Google Sign-In
- Service: Authentication
- Data Processed: Email, name
- Privacy Policy: https://policies.google.com/privacy
Android Permissions
| Permission | Purpose | When Requested |
|---|---|---|
| INTERNET | Server connection | Always required |
| CAMERA | Taking photos | When adding photos |
| READ_EXTERNAL_STORAGE | Gallery access | When selecting photos |
| POST_NOTIFICATIONS | Push notifications | On first use (optional) |
| ACCESS_FINE_LOCATION | Grave location map starting point | When adding grave location (optional) |
| ACCESS_COARSE_LOCATION | Grave location map starting point | When adding grave location (optional) |
Note: The POST_NOTIFICATIONS permission is optional. If you don't grant this permission, you won't receive push notifications, but you can continue to use the app with all other features.
Note: Location permissions are optional. Used only for map starting point when adding grave location. Your device location is never stored.
iOS Permissions
| Permission | Purpose | When Requested |
|---|---|---|
| Camera | Taking photos | When adding photos |
| Photo Library | Gallery access | When selecting photos |
| Notifications | Push notifications | On first use |
| Location When In Use | Grave location map starting point | When adding grave location (optional) |
© 2026 Treegram. All rights reserved.