I'm Tristan. I built NeeTree on my own, and I'm the only person with access to what it stores. This page is the honest version of what that is — written plainly, because that's how I'd want to read it.
The short answer: most of what you log never leaves your phone, and I collect nothing I don't need to make the app work.
What stays on your device
Your areas, habits, main quests, completions and settings are stored in a database inside the app, on your device. If you never sign in, none of that reaches me or anyone else.
One thing leaves either way: a crash report. If the app breaks — the screen goes blank, or something throws an error it wasn't expecting — it sends me a short note about it, so that a bug on your phone isn't something I only find out about if you happen to write to me. The note is the error message, the stack trace that says which line of my code broke, the name of the screen you were on (like “today” or “life”), the app's version number, and whether you were in the iPhone app or a browser. Nothing you've written or logged goes with it — not a habit name, not a completion. If you're signed in, it's attached to your account, so I can tell one person's five reports from five people's one. If you're not, it's attached to nothing. The app sends at most five per launch, drops them silently if you're offline, and doesn't retry. I keep them for 30 days, then a nightly cleanup deletes them.
Since version 2.0, the iPhone app asks for one permission: notifications, for the daily reminder. It asks only when you turn the reminder on, in Settings or from the one-time offer on Today. The reminder is scheduled on your phone. If you're signed in, whether it's on and the time you picked sync with the rest of your settings, so a new phone picks it up too. The app asks for nothing else — no location, no contacts, no photos, no calendar.
Deleting the app deletes that data with it.
What an account adds
An account exists for one reason: so your history survives a new phone. If you sign in, here is everything I hold.
- Your email address, and the day the account was made. It's how you sign in, and it's the only thing that identifies you. There's no password and no profile.
- A sign-in code, stored hashed, for the ten minutes it's valid.
- A session token, stored hashed, so you stay signed in. It expires after 90 days without use.
- The same records your device holds — habits, quests, completions and settings, copied as they are, so a second device can catch up. If you used an older version of the app, that includes the programs you'd started and any paths you wrote, words included.
- What an older version left behind, if you used one: a record of a past purchase, and the answers you gave the nutrition finder. Both are spelled out in the section on versions before 2.0, further down.
- Your IP address, briefly, as a rate-limit key on four things: asking for a sign-in code, entering one, sending a crash report, and joining my email list. Those are there so nobody can use my server to spam other people's inboxes, bury me in fake reports, or push strangers onto my list. Each count rolls over within the hour, the row holding it is cleared by a nightly cleanup, and none of them is attached to your account.
- Request logs. Cloudflare, which runs my server, keeps a short log of each request to it for a few days, including the IP address, a rough location and the browser or device type. I only look at it to find and fix problems.
- Any crash reports your devices sent, if the app has broken on one — attached to your account, so repeated breakage looks different from a one-off. What's in one is described above, and they're deleted after 30 days either way.
- A short trail of server logs. Every request to my API leaves a line on Cloudflare — the time, which endpoint it hit, and, when something breaks, the account it broke for. It's how I find a bug I can't reproduce. Nothing you've logged travels into it, and it ages out on its own.
That's the list. No location, no contacts, no photos, no advertising identifier, nothing read from other apps.
One thing inside those settings is worth naming on its own, since it only looks like an ordinary setting: if you give the app a name to greet you by, it's stored with the rest of your settings. It doesn't exist unless you entered it.
My email list
The app offers to add you to my email list — once in the intro when you first open it, and any time after that from Settings. It's optional and it never unlocks or changes anything in the app. Only if you tick the box does your email address go to Flodesk, the service I send my emails with, which sends you my free starter guide and the emails I write after it. There's no confirmation step — ticking the box is the yes. The app sends the address to my server, along with which of the two places you ticked it in. My server adds the address to Flodesk, marked as coming from the app, and the place never leaves my server. The guide form on this website sends your address to Flodesk directly.
So nobody can push someone else's address onto the list over and over, my server counts joins for an hour, by IP address and by email address. The email counter holds a one-way hash of the address, never the address itself. Those counters aren't attached to an account, and the nightly cleanup deletes them. My server keeps no copy of the address. It goes straight to Flodesk.
Every one of those emails carries an unsubscribe link, and one tap ends them. Leaving the list doesn't touch your account or anything you've logged.
What I don't do
- No analytics inside the app. There's no analytics SDK in it, so I can't see which screens you open or how often you use it. The one exception is the crash report above: it names the screen that broke, and only when it broke. The website and the browser version of the app do sit behind Cloudflare's page-view counter — how many people landed on a page, roughly where they came from, how quickly it loaded. It sets no cookie and can't follow you anywhere. The iOS app isn't behind it at all.
- No advertising, no ad networks, nothing that follows you around other apps and websites.
- No selling or sharing your data — not with data brokers, not with anyone.
- No training any model on what you log.
- No purchases. NeeTree is free, so nothing about a card or a payment reaches the app or me. Older versions took payments, and what those left behind is covered further down.
Other people
There aren't any. NeeTree has no feed, no friends list, no leaderboard, and no way for one person to see another's habits, completions, or email address. Until August 2026 there was one small exception — a Season showed a count of how many people were walking the same program as you. It was only ever a number, and it's gone now.
Who else touches it
I keep this list short on purpose. Each one does a single job.
- Cloudflare — hosts the app, the API, the database, and this page.
- Resend — sends the sign-in email. It sees your address and the code.
- Flodesk — sends the starter guide and my emails, only to the addresses that asked for them, in the app or on this website. Their script loads on the website pages with the guide form for everyone who opens them, before anything is typed. An address reaches them only when you send the form or tick the box in the app.
Nobody else in version 2.0 — the older versions had a few more, and they're in the next section. The database is mine, running on Cloudflare, and I'm the only one who can reach it.
If you used NeeTree before 2.0
NeeTree used to sell a subscription and carry training programs. Version 2.0 took both out, but a little of what they left behind is still around, and version 1.0 keeps working on a phone that never updates. So here's that part too.
- Whether you had Premium. If you ever subscribed or started a trial, my server still holds that record — which store it came through, when it started, and when it ended. It unlocks nothing now. Delete account erases it with everything else.
- Your nutrition finder answers. If you used the nutrition finder, your weight, height, age, sex, activity level and goal are stored inside your settings, and they sync with them. Version 2.0 never shows or reads them. It carries them along so a 1.0 phone on the same account doesn't lose them. Delete account erases them too.
- Past payments. Purchases went through Apple in the iPhone app, or through RevenueCat's web checkout (with Stripe) on the web. I never saw a card number. They keep their own records of those payments, under their own policies: Apple, RevenueCat, Stripe.
- RevenueCat, on version 1.0. Every 1.0 iPhone install still checks in with RevenueCat when it opens, signed in or not, and whether or not anyone ever bought. Signed out, it uses an anonymous identifier RevenueCat makes up. Signed in, it uses your account's identifier — that's how it used to tell my server who had Premium. Version 2.0 doesn't talk to RevenueCat at all.
- Calendar access, on version 1.0. If you use “Add to calendar” on a training program, the 1.0 iPhone app asks for calendar access so it can write that program's workouts into the calendar you pick. The only events it reads back are the ones it made itself, and nothing about your calendar reaches me.
- My content server, on version 1.0. About once a day the 1.0 app asks it whether there are new programs or videos, and it fetches the demo clips and photos from there. Those requests see an IP address and a browser version, the way any request to any website does. They aren't tied to an account.
How long it's kept
Your records stay as long as your account does — that's the point of them. A sign-in code stops working after ten minutes, and a session after 90 days without use. The rows themselves, and the rate-limit counters beside them, are swept by a cleanup that runs once a night, so a dead one can sit there for up to a day before it's actually gone.
Deleting your account
You can do it yourself: Settings → Account → Delete account erases the account and everything attached to it from my servers, right away and for good. Or email me at support@neetree.app from the address you signed in with, and I'll do the same and confirm when it's done. Being on my email list is separate — unsubscribe from any email, or ask me and I'll remove you. To clear the copy on your device, delete the app — or use Reset in Settings, which wipes it and starts you fresh.
Your rights
Depending on where you live, you may have the right to see the data I hold about you, correct it, get a copy of it, or have it deleted. Email me and I'll do it — there's no form and no process. It's a short list to begin with.
Where it lives
Cloudflare's network is global, so your data may be stored or processed outside the country you're in, including the United States, where I am.
Children
NeeTree isn't built for or directed at children under 13, and I don't knowingly collect anything from them.
Changes
If any of this changes, I'll update this page and the date at the top.
Questions
support@neetree.app. I read them myself. If you'd rather write on paper: 322 Culver Blvd #1004, Playa Del Rey, CA 90293, United States.