This privacy notice for Ad Prospera, Inc ("we," "us," or "our"), the data controller responsible for your personal information, describes how and why we might collect, store, use, and/or share ("process") your information when you use our services ("Services"), such as when you:
- Download and use our mobile application (GPTree), or any other application of ours that links to this privacy notice
- Visit our website at gptree.io
- Engage with us in other related ways, including any sales, marketing, or events
Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at founders@parthenox.com.
Summary of Key Points
This summary provides key points from our privacy notice, but you can find out more details about any of these topics by reading the full policy below.
- What personal information do we process? Your account information (name and email from Apple or Google sign-in), the chat messages you send and the responses you receive, anything you attach to a message, any content you create in the App to organize your chats, gamification data (such as your virtual forest and streaks), subscription status, and usage analytics.
- Do we process any sensitive personal information? We do not ask for sensitive personal information, and the App's memory feature is instructed to exclude sensitive categories from what it saves. Your chat content is yours — we process it only to run the service, and we ask you not to include information you would not want stored.
- What does the App ask permission for? Two things, and only when you use the feature: the microphone, so you can dictate instead of typing, and the camera, if you want to photograph something to attach to a message. Where your language supports it, dictation is turned into text on your device and the audio never leaves it. Attached documents are converted to text on your device too, so the file itself never reaches us. Attached images do go to our servers, are described once by an AI model, and are then deleted. We never ask for your contacts and we never collect your location.
- How is your chat content handled? Chats live only in your account. To generate each response, your messages and attachments are sent to OpenRouter, the third-party AI service that runs the models answering you. Every one of those requests carries a no-retention instruction: OpenRouter routes it only to model endpoints whose data policies commit to not storing your content and not training on it. We never sell your chats and never use them for advertising. The App explains this and asks for your agreement before your first message.
- Does the App remember things about you? Yes. It keeps a limited set of short notes about you so the assistant has context across conversations. These are written both when you ask it to remember something and automatically, from your recent messages. You can view, edit, and delete every note, or turn Memory off entirely, in the App's settings.
- How do we process your information? To operate the App — generate AI responses, sync your chats and forest across devices, enforce usage limits, manage subscriptions — and to improve and secure the Services.
- In what situations and with which parties do we share personal information? With the service providers that run the Services — backend hosting, authentication, website hosting, AI model providers, analytics, and subscription management. The specific providers are listed on our Subprocessors page.
- Do we sell or share personal information? We do not sell personal information or share it for cross-context behavioral advertising.
- What are your rights? Depending on where you are located, you may have rights to access, correct, or delete your data. You can delete your account and chats directly in the App.
1. What Information Do We Collect?
Personal information you disclose to us
In Short: We collect the information needed to run an account-based AI chat service.
- Account information. When you sign in with Apple or Google (through our authentication provider), we receive your name, email address, and an account identifier. With Sign in with Apple you can hide your real email address.
- Chat content. The messages you send and the AI responses you receive are stored in your account so your conversations are available across sessions and devices.
- Attachments. The files and images you choose to attach to a message. What reaches us differs by type, and is set out under "Attachments, camera, and microphone" below.
- Voice input. If you dictate a message, the audio recorded while you are dictating. Wherever your language allows it, that audio is turned into text on your device and is never sent to us.
- Gamification data. Your virtual forest, streaks, and related in-app progress.
- Support communications. If you contact us, we may collect your email address, message content, and any information you choose to provide.
- Consent records. The date you agreed to the App's AI-processing disclosure, kept with your account as evidence of that agreement.
Attachments, camera, and microphone
In Short: The App asks for exactly two device permissions — the microphone, for dictation, and the camera, if you want to photograph something to attach. Neither is used unless you start it, and what leaves your device depends on what you attach.
Microphone. The App asks for microphone access the first time you dictate a message, and records only while you are dictating. Where Apple provides an on-device speech model for the language you are speaking, your speech is turned into text on your iPhone or iPad and the audio never leaves the device — we never receive it. For languages with no on-device model available, the recording is sent to our backend and transcribed by a third-party AI provider, and that clip is deleted immediately afterwards on every path: whether the transcription succeeded, was rejected, or failed. We do not keep your audio and we do not use it to identify you.
Camera. The App asks for camera access only if you choose the camera when attaching something to a message — for example to photograph a document. The photo you take is attached to that message and handled like any other image, described below. The App never opens the camera on its own.
Photos. Attaching an image from your library opens Apple's system photo picker. That picker runs outside the App, which is why iOS shows no permission prompt for it and why we ask for none: the App receives only the specific images you pick and has no access to the rest of your photo library.
What happens to what you attach. Documents — PDFs and similar files — are converted to text on your device, and only that text is sent along with your message; the file itself never reaches our servers. Images are different. An image you attach, whether picked from your library or taken with the camera, is uploaded to our backend and passed once to a third-party AI model that describes it and reads any text in it. That description travels with your message, and the image itself is deleted once it has been processed. From that point on, the text or description drawn from an attachment is part of your conversation and is handled exactly like the rest of your chat content, as described in section 3.
The App does not request access to your contacts, and it neither asks for nor collects your device location. You can review or revoke the microphone and camera permissions at any time in the iOS Settings app; the App simply loses those features if you do.
Memory
In Short: The App remembers a short list of facts about you, drawn automatically from your chats, and you can view, edit, or delete every one of them.
So that the assistant does not start from nothing in every conversation, the App keeps a limited set of short notes about you — for example the name you like to be called, a stated preference, a standing constraint, or a project you are working on. These notes are written in two ways: when you ask the assistant to remember something, and automatically, when a background process reads your recent messages and records a fact that looks durable. You do not have to ask for a memory to be saved.
Memory is on by default and you are in control of it. The App's settings list everything currently stored, where you can edit or delete any entry individually or clear them all at once. Turning Memory off stops the App both from reading and from writing memories; it does not delete what is already stored, so you can turn it back on and find your list intact. Deleting a memory removes it from your account, and deleting your account removes all of them.
Memory is scoped to where it was learned. Notes recorded while you work within a particular area of the App are used only there and are deleted along with it, while durable facts about you personally are kept separately so they remain available across your chats.
We instruct the models that write these notes to exclude sensitive categories — such as health, religion, ethnicity, political opinions, sexual orientation, criminal history, precise location, and trade union membership — unless you explicitly ask for something specific to be remembered. They are also instructed not to record facts about other people or content taken from files you attach. These are instructions to a language model rather than guarantees, which is why the full list is always visible and editable in the App.
Information automatically collected
In Short: Some information — such as device characteristics and usage patterns — is collected automatically when you use our Services.
- Device and Log Data. Device type, operating system and version, app version, language, time zone, and general device characteristics.
- IP address. Your IP address is processed whenever the App connects to our backend and whenever you visit our website. In the App it is also received by our analytics provider, which uses it to derive an approximate location (typically country or region level). On the website it is processed by our hosting provider to serve and protect the site, and is not sent to any analytics provider. We do not collect precise device location.
- Usage Data. How you interact with the App — features used, actions taken, message counts, and model-routing metadata (such as which model tier served a request and estimated token usage). We use this in aggregate to improve the Services and to enforce usage limits.
- Subscription metadata. Subscription status and entitlement events from the App Store and our subscription management provider. We never see your payment card details.
Usage analytics are collected through our analytics provider and are linked to your account identifier, never to your name or email address. We do not use advertising trackers, the App does not request access to your contacts, and we do not collect your device location — though your IP address lets our analytics provider infer an approximate country or region. The only device permissions the App asks for are the microphone and the camera, both only when you use the feature that needs them, as described above. If you would prefer not to be included in product analytics, email us and we will exclude you and delete your analytics records.
2. How Do We Process Your Information?
In Short: We process your information to run the App, generate AI responses, and improve the Services.
- To deliver the service. Storing and syncing your chats, generating AI responses, and rendering your forest.
- To generate AI responses. Your messages are transmitted to OpenRouter, the third-party AI service that routes them to AI model providers, solely to produce the response you asked for. The App discloses this and asks for your agreement before your first message, and we record when you gave it.
- To enforce usage limits. Counting messages against the free allowance and applying fair-use limits.
- To manage subscriptions and entitlements. Confirming access to paid features.
- To respond to inquiries and offer support.
- To maintain safety and security. Keeping the Services secure, preventing fraud and abuse, and enforcing our policies.
- To identify usage trends and improve the Services. Aggregate analytics only.
- To comply with legal obligations.
Legal bases for processing (EEA/UK)
If you are in the EEA, UK, or Switzerland, we process your information when it is necessary to perform our contract with you (running your account and generating responses), to comply with legal obligations, to pursue our legitimate interests (such as improving and securing the Services), and with your consent where required. You can withdraw consent at any time.
3. How Is Your Chat Content Handled?
In Short: Chats live only in your account — never sold, never shared for advertising, never used to train models.
- Your conversations are stored in your account on our backend, hosted in the United States, and are visible only to you.
- To generate each response, the relevant conversation content is sent through OpenRouter, our AI routing service, to a third-party AI model provider. Doing that — including describing an image you attached, or transcribing dictated audio when your device cannot — is the only reason your content leaves our infrastructure.
- Attachments follow the same route. An image you attach is sent to a model provider once so it can be described. Dictated audio is sent to one only when your language has no on-device speech model. Neither is kept after it has been processed, and text extracted from a document on your device is simply part of your message.
- We do not sell chat content, share it for advertising, or use it to train our own models, and we do not grant OpenRouter or any model provider a right to train on your messages.
- Every chat request we send to OpenRouter carries an explicit no-retention instruction. With it, OpenRouter routes your content only to model endpoints whose data policies commit to not storing prompts and not training on them, and OpenRouter itself does not use your content to train models. Through these commitments, the parties that process your chat content are required to protect it to a standard equal to this policy.
- The App presents this arrangement to you in plain language — what is sent and to whom — and asks for your agreement before your first message. We record the date you agreed.
- Saved memories are derived from your chats, and the ones relevant to a given message are included in the prompt sent to the model provider on the same terms as the rest of that conversation.
- Deleting a chat removes it from your account. Deleting your account removes your chats and associated data from our systems. Deleting a chat does not delete memories already saved from it — those are managed separately in the App's settings.
- Please avoid including sensitive personal information (such as health or financial details) in your chats.
4. When and With Whom Do We Share Your Personal Information?
In Short: We share information only with the service providers that operate the App.
- Service Providers. We share information with providers who perform services on our behalf, in the following categories:
- Backend hosting and data storage (United States)
- Hosting and delivery of the gptree.io website
- Authentication and account management
- AI model providers, and the routing service that reaches them, for generating responses from your messages
- Analytics and product insights
- Paywall and subscription entitlement management
- App store distribution and in-app purchases
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
- Legal Obligations. We may disclose your information where we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process.
- Vital Interests and Legal Rights. We may disclose your information where we believe it is necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, or situations involving potential threats to the safety of any person.
5. Do We Use Cookies and Other Tracking Technologies?
In Short: No. The App does not use cookies, and this website sets no cookies and runs no analytics.
Our mobile application does not use cookies. The gptree.io website serves static pages; it sets no cookies, runs no analytics, and embeds no third-party trackers, though our hosting provider processes request data such as your IP address in order to serve and protect the site. We do not use cookies for advertising or cross-site tracking anywhere in our Services.
6. How Long Do We Keep Your Information?
In Short: For as long as you keep your account.
Your chats, forest, and account data are retained while your account exists. Deleting a chat removes it from your account, and deleting your account (available in the App's settings) removes your account data from our systems, after which residual copies are purged from backups on a rolling basis.
Dictated audio and attached images are the exception: we do not retain them at all. A recording sent for transcription is deleted as soon as the attempt finishes, and an uploaded image is deleted as soon as it has been through the model — in both cases whether the attempt succeeded or not. Only the resulting text stays in your chat.
Saved memories are retained until you delete them or delete your account. Turning Memory off stops new memories being written and stops existing ones being used, but does not delete them. The list is capped in size, and older entries may be retired to make room for new ones.
Analytics events are retained according to our analytics provider's data retention policies. They carry no name, email address or message content — only an account identifier and product usage. Once your account is deleted that identifier no longer corresponds to anyone, so what remains is not identifiable. If you would still like the analytics records themselves removed, email us. Subscription records are retained as necessary for entitlement management and financial record-keeping. Support communications are retained as long as needed to address your request, unless a longer retention period is required by law.
7. How Do We Keep Your Information Safe?
In Short: We aim to protect your personal information through a system of organizational and technical security measures.
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process — including transport encryption (TLS) for all traffic between the App, our backend, and our providers. However, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Transmission of personal information to and from our Services is at your own risk.
8. International Data Transfers
In Short: Your data is processed in the United States and other countries.
Our backend is hosted in the United States, and our service providers may process data in the United States, the European Union, or other countries. If you access the Services from the EEA, UK, or Switzerland, your information will be transferred to countries that may not have the same data protection laws as your jurisdiction. Where required by law, we rely on appropriate safeguards such as standard contractual clauses for these transfers.
9. What Are Your Privacy Rights?
In Short: Depending on your location, you may have certain rights regarding your personal information.
In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; (iv) if applicable, to data portability; and (v) not to be subject to automated decision-making. In certain circumstances, you may also have the right to object to the processing of your personal information.
European Economic Area (EEA), United Kingdom (UK), and Switzerland
If you are a resident in the European Economic Area, United Kingdom, or Switzerland, you have the right to:
- Request access to your personal data
- Request correction of your personal data
- Request erasure of your personal data
- Object to processing of your personal data
- Request restriction of processing your personal data
- Request transfer of your personal data
- Withdraw consent at any time
If you wish to exercise any of these rights, please contact us at founders@parthenox.com. We will respond to your request within 30 days.
If you believe we are unlawfully processing your personal information, you have the right to complain to your local data protection supervisory authority. If you are in the EEA, the European Data Protection Board publishes contact details for every national supervisory authority here: https://www.edpb.europa.eu/about-edpb/our-members_en.
Account Information
You can manage your data directly in the App:
- Delete individual chats: Delete any conversation from your chat list
- Delete your account: Account deletion in the App's settings removes your chats, forest, and account data
- Opt out of analytics: Email us and we will exclude you from product analytics and delete your analytics records
- Anything else: Contact us at founders@parthenox.com
10. Controls for Do-Not-Track Features
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this privacy notice.
11. Do California Residents Have Specific Privacy Rights?
In Short: Yes, if you are a resident of California, you are granted specific rights regarding access to your personal information.
Categories of personal information we collect
- Identifiers — name, email address, account identifier, and IP address. Collected to create and secure your account. Retained while your account exists.
- Commercial information — subscription status and entitlement events. Collected to manage paid access. Retained as needed for entitlement and financial record-keeping.
- Internet or network activity — app usage, features used, message counts, and model-routing metadata. Collected to run, secure, and improve the Services. Retained per our analytics provider's retention policy.
- Audio and visual information — dictated audio, and images you attach to a message. Collected only when you use those features, to turn speech into text and to describe an image for the assistant. Not retained: deleted as soon as it has been processed, leaving only the resulting text in your chat.
- Other information you provide — your chat messages, the responses you receive, text extracted from files you attach, your virtual forest and streaks, and any support correspondence. Collected to deliver the Services. Retained while your account exists.
We do not create voiceprints, faceprints, or any other biometric identifier from the audio or images you send, and we do not collect precise geolocation, government identifiers, or the categories of sensitive personal information that require an opt-out under California law. We have not sold or shared personal information in the preceding twelve months, and we do not knowingly sell or share the personal information of consumers under 16 years of age.
California Civil Code Section 1798.83, also known as the "Shine The Light" law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided below.
We do not sell or share personal information as defined by California law, and we do not use sensitive personal information for purposes that require an opt-out.
CCPA Privacy Notice
If the California Code of Regulations' definition of "resident" applies to you, we must adhere to certain rights and obligations regarding your personal information.
Your rights with respect to your personal data:
- Right to know what personal data we collect and how we use it
- Right to request deletion of your data
- Right to correct inaccurate personal data
- Right to opt out of the sale or sharing of your personal information (Note: We do not sell or share personal information)
- Right to limit the use and disclosure of sensitive personal information (Note: We do not use sensitive personal information for these purposes)
- Right to non-discrimination for exercising your privacy rights
We may need to verify your request before completing it. Authorized agents may submit requests on your behalf if they provide proof of authorization.
12. Do Virginia and Other US State Residents Have Specific Privacy Rights?
In Short: Yes, if you are a resident of Virginia or certain other US states, you may be granted specific rights regarding access to and use of your personal information.
Under the Virginia Consumer Data Protection Act (VCDPA), Virginia residents have the right to:
- Know whether we are processing your personal data
- Access your personal data
- Correct inaccuracies in your personal data
- Request deletion of your personal data
- Obtain a copy of your personal data in a portable format
- Opt out of targeted advertising, sale of personal data, or profiling
To exercise these rights, please contact us at founders@parthenox.com. Residents of Colorado, Connecticut, and Utah may have similar rights, and we will honor applicable requests in accordance with those laws.
13. Do We Collect Information from Minors?
In Short: We do not knowingly collect data from or market to children under 13 years of age (or the age of digital consent in your jurisdiction).
We do not knowingly solicit data from or market to children. The Services require users to be at least 13 years old. If you are in the European Economic Area, the United Kingdom, or Switzerland, you must be at least 16, or the age of digital consent set by your country if it is lower, unless a parent or guardian consents to your use of the Services on your behalf.
By using the Services, you represent that you meet the applicable age requirement, or that you are the parent or guardian of such a minor and consent to that minor's use of the Services. If we learn that personal information has been collected from a user below the applicable age, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from a child, please contact us at founders@parthenox.com.
14. Do We Make Updates to This Notice?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this privacy notice from time to time. The updated version will be indicated by an updated "Last updated" date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification.
15. How Can You Contact Us About This Notice?
If you have questions or comments about this notice, or wish to review, update, or delete the personal information we hold about you, you may email us at founders@parthenox.com or contact us by post at:
Ad Prospera, Inc
390 NE 191st St
Miami, FL 33179-3899
United States
Some analytics data is aggregated across users, or has been stripped of identifiers, and can no longer be reasonably linked back to you. We may be unable to isolate and delete that data on request, though it no longer identifies you.