Privacy Policy
Last updated on: 1 Sep 2026
Trees provides a remotely accessed, cloud-hosted publishing application under a usage-based software-as-a-service model. This Privacy Policy explains how Trees processes personal data when someone accesses the Platform, submits a Publication, pays for one use of its automated publishing workflow, uses Publication-management functions, reports content, or communicates with Trees.
Accepting the Terms of Service does not mean consenting to every processing activity. Trees relies on the legal bases described below.
1. Data controller
The controller responsible for personal data processed through Trees is:
Jonatan Linares Perez, trading as Trees
C/ Ausias Marc, 127, 08013, Barcelona, Spain
Email: info@trees.pub
Website: https://www.trees.pub
2. Scope of this Policy
This Policy applies to personal data processed through:
- trees.pub and its Publication pages;
- the publishing form and payment workflow;
- the Publication-listing and deletion functions;
- content reports, legal notices, and support communications; and
- technical operation, security, moderation, and service administration.
This Policy does not control independent websites reached through Publication links or Stripe’s separately hosted checkout. Those services process data under their own privacy information.
3. Publications must not contain personal data
Contributors must not include personal data in Publication text. This prohibition includes the Contributor’s own personal data, information about another person, information that is already public, data about children, private communications, confidential information, health data, financial-account information, and other sensitive data.
A Publication that passes moderation becomes publicly accessible worldwide. Its pages may be indexed, cached, copied, analyzed, modified, republished, or retained by readers, search engines, AI systems, archives, and other websites.
The Public License in the Terms of Service does not grant rights under data-protection, privacy, confidentiality, publicity, or personality laws. Anyone processing personal data found in a Publication must identify an independent lawful basis and comply with applicable law.
Trees does not display the operational Contributor email address as an author or Contributor field. However, any personal information included inside the submitted Publication text may become public if moderation does not detect it.
If a Publication contains your personal data, use its report button or contact info@trees.pub with the exact URL and an explanation.
4. Personal data Trees processes
| Category | Examples |
|---|---|
| Publishing-form data | The supplied email address, Publication text, form-submission time, and information showing acceptance of the Terms where recorded. |
| Payment and transaction data | Payment status, amount, currency, discount, tax information, transaction or checkout identifiers, and billing or location information that Stripe makes available to Trees. Full payment-card details are entered directly into Stripe’s hosted checkout and are not provided to Trees. |
| Workflow and Publication data | Publication status, automated moderation result and reason, page boundaries, titles, descriptions, contextual-link information, public URLs, publication timestamps, and restriction or deletion status. |
| Publication-management data | The email address and Publication URL entered in listing or deletion forms, deletion-link information, link-expiration data, request times, and confirmation status. |
| Communications and reports | Names, email addresses, message contents, URLs, evidence, legal allegations, rights-ownership information, delivery information, and correspondence with Contributors, reporters, authorities, or other contacts. |
| Technical and security data | IP address, request time, browser and device information, operating system, requested URL, referrer information where supplied by a browser, server and application logs, error information, security events, and fraud or abuse indicators. |
| Public data | Accepted Publication text, public page URLs, titles, descriptions, contextual links, and related public presentation information. |
Trees has no user registration system and does not collect an account password.
Technical, transaction, and operational data are not collected for marketing purposes.
5. Sources of personal data
Trees obtains personal data from:
- you when you submit a form, make a request, report content, or communicate;
- your browser, device, and network when you access the Platform;
- Stripe when it confirms or reports information about a transaction;
- OpenAI and other service providers when they return workflow, moderation, presentation, delivery, or technical results;
- another person who submits a report, legal notice, or communication concerning you or a Publication; and
- competent authorities, courts, advisers, or rights holders where legally relevant.
6. Purposes and legal bases for processing
| Purpose | Legal basis |
|---|---|
| Provide remote access to, operate, and administer the cloud-hosted Platform; receive a submission, send the payment link, process the order, publish an accepted Publication, provide hosting, and enable listing or deletion. | Taking steps requested before entering a contract and performing the publishing contract. |
| Process payments, calculate or record taxes, issue required transaction records, and maintain accounting information. | Contract performance and compliance with legal, tax, accounting, and Consumer-law obligations. |
| Send transactional emails concerning payment, publication, rejection, listing, deletion, legal notices, or important service information. | Contract performance, requested pre-contract steps, legal obligations, and Trees’ legitimate interest in operating and documenting the service. |
| Determine page presentation and assess Publications against legal, safety, policy, sanctions, and payment-partner restrictions. | Contract performance, compliance with legal obligations, and legitimate interests in preventing unlawful or harmful use and protecting Trees, service providers, users, and third parties. |
| Operate, secure, diagnose, maintain, and protect the Platform and prevent fraud, abuse, unauthorized access, or service disruption. | Trees’ legitimate interests in providing a reliable and secure service and, where applicable, compliance with legal security obligations. |
| Review reports and legal notices, enforce the Terms, protect rights, respond to authorities, and establish, exercise, or defend legal claims. | Legal obligations and legitimate interests in legal compliance, rights protection, dispute resolution, and policy enforcement. |
| Carry out processing for which Trees specifically asks for optional consent. | Consent, which may be withdrawn at any time without affecting earlier lawful processing. |
Where Trees relies on legitimate interests, it considers the purpose, necessity, and likely effect on the people concerned. You may object as described in Section 14.
The Public License is a copyright and reuse permission. It is not itself a legal basis for processing personal data.
7. Data required to use the publishing service
A valid email address, Publication text, acceptance of the Terms, and successful payment are required to purchase the publishing process. Without them, Trees cannot process or publish the Publication.
Stripe may require billing, tax, payment, location, identity, fraud-prevention, or sanctions information before accepting payment. Failure to provide information required by Stripe may prevent the transaction.
Technical request information is processed automatically when a device communicates with the Platform. A person reporting content must provide enough information for Trees to locate and assess the reported material.
8. Automated processing and moderation
After payment confirmation, the Publication text is sent to OpenAI. The automated system is instructed to:
- select page boundaries;
- select representative title and description excerpts from the submitted text;
- select contextual navigation links between pages in the same Publication; and
- assess the entire Publication against the Platform’s content policies.
The system is not instructed to generate, rewrite, paraphrase, summarize, reorder, or add Publication text. Presentation output may nevertheless contain errors.
The initial moderation result is made automatically and results in either acceptance or rejection of the entire Publication. It does not intentionally assess the Contributor’s personal characteristics; it assesses the submitted text against legal, safety, policy, and payment-partner categories.
A Contributor may contest an automated rejection and request human review by emailing info@trees.pub with the publishing email and available submission or payment information.
Where applicable data-protection law gives a right not to be subject to a solely automated decision producing legal or similarly significant effects, Trees will provide the safeguards required by that law, including an opportunity to express a view, contest the result, and request human intervention.
Stripe may separately use automated fraud, sanctions, identity, or payment controls under Stripe’s own privacy information and legal responsibilities.
9. Service providers and other recipients
Trees uses third-party providers to operate the Platform. These providers may process personal data on Trees’ behalf. Trees requires providers acting on its behalf to process data only as necessary to provide their services and in accordance with applicable data-protection requirements.
| Recipient | Function and relevant data |
|---|---|
| Supabase | Database infrastructure for email addresses, Publication text, workflow data, presentation information, statuses, and management records. |
| Vercel | Application hosting and delivery, including network requests, IP addresses, technical logs, and application data needed to serve the Platform. |
| Vercel Workflows | Workflow orchestration for submitted Publication text and publishing status. |
| OpenAI | Automated presentation and moderation after payment. OpenAI receives the Publication text and task instructions, but Trees does not intentionally send the operational email address unless the Contributor has improperly included it in the Publication text. |
| Stripe | Hosted checkout, payment processing, tax calculation, fraud prevention, sanctions controls, transaction records, and related payment services. Stripe receives payment and billing data directly on its own domain and may act as an independent controller for some processing. |
| Resend | Transactional email delivery, including recipient email addresses, message contents, delivery status, and technical delivery information. |
| Pushover | Operational push notifications and alerts, including the limited information included in those notifications. |
| Legal and professional recipients | Courts, competent authorities, law enforcement, tax authorities, legal or technical advisers, insurers, auditors, rights holders, or affected parties where disclosure is required by law or reasonably necessary to protect rights, investigate reports, or handle claims. |
Providers may use approved subprocessors where permitted by their agreements and applicable law.
When a report or legal notice concerns a Contributor, Trees may share enough of the notice with the Contributor to explain the allegation and allow a response. Trees may withhold or redact reporter information where necessary for privacy, safety, or legal reasons.
10. International transfers and worldwide public access
Trees is established in Spain. Some service providers may process data outside Spain or the European Economic Area.
Where a restricted international transfer occurs, Trees will use a transfer mechanism permitted by applicable data-protection law and any supplementary safeguards required in the circumstances. You may contact Trees for information about or a copy of the relevant safeguards, subject to appropriate redactions.
Accepted Publications are intentionally made accessible worldwide. Readers, search engines, AI systems, archives, and other websites outside the European Economic Area may access and copy them. Contributors must therefore not include personal data in a Publication.
11. Retention periods
Trees keeps personal data only for as long as necessary for the purposes described in this Policy, ongoing hosting, legal obligations, security, dispute handling, and the establishment, exercise, or defense of legal claims.
| Data | Retention |
|---|---|
| Unpaid submissions | The payment link expires after seven days. |
| Published Publications | Publication text, presentation data, public URLs, and the management email are retained while ongoing hosting and management are provided. After a verified deletion, the Publication is deleted from the active database unless retention or unpublishing is required for a legal, policy, or safety reason. |
| Payment, tax, and contractual records | Retained for the periods required by applicable tax, accounting, payment, Consumer, and limitation laws, and for handling charge disputes or legal claims. |
| Deletion links and management tokens | A deletion link expires after one hour. |
Data may be kept longer where required by law, a court or authority, an active investigation, fraud or safety concerns, or a legal claim. When possible, access will be restricted during that additional period.
Third parties that independently copied a public Publication determine their own retention periods. Trees cannot delete data from systems it does not control.
12. Publication listing, deletion, and correction
A Contributor can request a list of Publication URLs associated with an email address at https://www.trees.pub/list-publications. The list is sent to that email address.
A Contributor can request deletion at https://www.trees.pub/delete-publication. Trees sends a one-hour deletion link to the original publishing email. Using the link permanently removes the Publication from public access and deletes it from the active database, subject to a legal-retention or restriction requirement.
Trees may unpublish rather than immediately erase information where retention is required for a legal obligation, investigation, claim, safety matter, or policy enforcement. Unpublished information is not publicly accessible unless disclosure is legally required.
Publications cannot normally be edited. However, this product restriction does not limit a data subject’s mandatory rights. Where personal data must legally be corrected, restricted, or erased, Trees may remove or restrict the relevant Publication or take another legally appropriate action.
Deletion from Trees cannot remove copies, caches, quotations, adaptations, AI outputs, or republications controlled by independent third parties.
13. Security
Trees uses technical and organizational measures intended to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction, appropriate to the nature and risks of the processing.
Publication-management information is sent to the original publishing email. Deletion links expire after one hour. Contributors are responsible for keeping their email accounts secure and for not forwarding deletion links to unauthorized persons.
No internet transmission, provider, email system, or storage system can be guaranteed completely secure. If a personal-data breach occurs, Trees will notify the relevant authority and affected people where applicable law requires.
14. Data-protection rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- obtain confirmation of whether Trees processes your personal data;
- access your personal data and related processing information;
- correct inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests, including an objection based on your particular situation;
- receive personal data you supplied in a structured, commonly used, machine-readable format and transmit it to another controller where portability applies;
- withdraw consent at any time where processing is based on consent; and
- contest an applicable solely automated decision and request human intervention.
To exercise a right, email info@trees.pub. Include enough information to locate the relevant data, such as the publishing email and Publication URL. Trees may request proportionate proof of identity or authority before acting on a request.
Trees will respond within the period required by applicable law. Under the GDPR this is normally one month, although it may be extended where legally permitted for a complex or numerous request. Requests are normally free, but Trees may charge a lawful reasonable fee or refuse a manifestly unfounded or excessive request.
Rights may be limited where processing is required for tax records, legal claims, freedom of expression, the rights of others, fraud or security investigations, or another legal obligation or exception.
Removing a Publication from Trees does not allow Trees to control copies retained by independent third parties. You may need to contact those third parties directly.
15. Children and sensitive data
The publishing service is only available to people who have reached the age of legal majority. Trees is not intended for children, and Contributors must not submit personal data about children.
Contributors must not submit special-category, sensitive, private, confidential, health, biometric, genetic, criminal-record, financial-account, payment, credential, or similar personal data in a Publication.
If Trees learns that prohibited child or sensitive personal data has been submitted, it may reject, unpublish, restrict, or delete the relevant Publication and take any action required by law. A person who believes such data is present should contact info@trees.pub promptly with the exact URL.
16. Cookies and browser storage
Trees does not use cookies on the trees.pub domain. Trees also does not use browser local storage or session storage on that domain.
The absence of cookies does not prevent servers and hosting providers from processing ordinary connection information such as IP addresses, request times, browser information, URLs, errors, and security logs. Trees does not use this technical information for marketing purposes.
Stripe’s checkout is hosted on Stripe’s own domain. Stripe may use cookies or similar technology under its own privacy and cookie information. External websites reached through Publication links may also use their own cookies or storage. Trees does not control those domains.
17. External links and independent third parties
Web addresses in Publication text may be presented as clickable links. They are configured to open separately with no-referrer protection, but the destination website will still receive information needed to establish a connection, such as the visitor’s IP address.
External websites, search engines, AI systems, archives, and other parties that independently collect or reuse public information are responsible for their own processing. Their privacy practices are not controlled by this Policy.
18. Changes to this Policy
Trees may revise this Policy to reflect legal, technical, provider, or operational changes. The current version is published at https://www.trees.pub/privacy-policy.
If a change materially affects how existing personal data is processed, Trees will provide any notice or obtain any consent required by applicable law before applying the change.
19. Questions and complaints
Questions, privacy requests, and complaints may be sent to:
Jonatan Linares Perez, trading as Trees
C/ Ausias Marc, 127, 08013, Barcelona, Spain
Email: info@trees.pub
You also have the right to complain to the Spanish Data Protection Agency: https://www.aepd.es, or to another competent supervisory authority in the country where you live, work, or believe a data-protection infringement occurred.