Privacy Policy
Last updated: 2 September 2026
Who we are
Tre (tre-app.com) is operated by Teralabs LLC, 1111B S Governors Ave, STE 52993, Dover, DE 19904, USA. Teralabs LLC is the data controller for the personal data described here. Contact: support@tre-app.com.
What we collect
Account data. When you sign in with Google we receive and store your name, email address and avatar image. Google sign-in is the only authentication method; we never see or store a password.
Content. Everything you or your AI agents create in Tre — workspaces, boards, lists, cards, checklists, comments, and card description history — is stored so we can provide the service. Content belongs to the workspace it was created in.
Activity. Tre keeps a log of what changes in a workspace: who did it, on which board and card, and through which surface — the app, the REST API or MCP — including the name of the API token an agent used. Entries carry short extracts of what changed, never whole documents. It is what lets a person or an agent catch up on what happened while they were away, and each entry is readable by the members who can already read that board. Entries are kept no longer than 90 days of activity, or the most recent 10,000 entries per workspace, whichever comes first. Cleanup runs as the workspace is written to, not on a timer and not on every write, so entries in a quiet workspace can outlive that window — and a workspace that stops being written to altogether keeps them until the workspace itself is deleted.
Billing data. If a workspace subscribes to a paid plan, payment is processed by Stripe. We store the subscription state and Stripe’s identifiers for it; your card details go to Stripe directly and never reach our servers.
Technical data. Server logs and error reports may include your IP address, user-agent and request identifiers. We use them to operate, secure and debug the service — not for advertising. Tre uses no advertising or analytics trackers.
Cookies. Tre sets only cookies that are strictly necessary to run the service: your session, and small preferences such as your last-used workspace and theme. There is no tracking or marketing cookie, which is why there is no cookie banner.
Why we process it (legal bases)
We process account data and content to perform our contract with you (GDPR art. 6(1)(b)); technical logs and abuse prevention rest on our legitimate interest in running a secure service (art. 6(1)(f)); billing records are kept to meet legal obligations (art. 6(1)(c)).
Where your data lives
The application and its database run in the United States (Virginia). Every subprocessor below is a US company or operates a global network, so personal data of users in the EU/EEA is transferred outside it. For those transfers we rely on the Standard Contractual Clauses together with a transfer impact assessment; where a subprocessor is also certified under the EU–US Data Privacy Framework, that certification is an additional layer rather than the one we depend on.
Subprocessors
| Provider | Purpose | Notes |
|---|---|---|
| Vercel Inc. (US) | Application hosting and serving | Functions pinned to US East (Virginia) |
| Neon Inc. (US) | Postgres database hosting | US East (Virginia) |
| Cloudflare Inc. (US) | Realtime relay (live board updates) | Global edge network |
| Upstash Inc. (US) | Rate-limit counters and retry-dedup keys | Transient request metadata only |
| Functional Software Inc. (Sentry) (US) | Error monitoring and performance tracing | Error diagnostics |
| Stripe Inc. (US) | Subscription billing and payments | Card data never reaches Tre |
How long we keep it
Your data is kept for as long as your account or workspace exists. Deleting a card, a list, a workspace or your account deletes the underlying rows immediately and permanently — Tre’s deletes are real deletes, not flags. Boards are the one exception: deleting a board archives it — the board leaves the listings and its rows are kept, so its content is deleted only when the workspace is. One qualification: deleting content removes the rows, and the activity log described above keeps a bounded trace of what happened — a deleted card’s key, title and the list it was in, a deleted list’s title and how many cards it took down, the text of a deleted checklist item or subtask, and the capped extracts of earlier edits — for no longer than 90 days of activity, or the most recent 10,000 entries per workspace, whichever comes first, pruned as the workspace is used. Database backups are taken daily and expire after 7 days, after which deleted data is gone from backups too. Invoices and billing records are retained as long as tax law requires.
Your rights
Under the GDPR you can ask for access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interest. Two of these are built into the product: from Settings → Account you can export your data as JSON and delete your account entirely (workspace owners can likewise rename, transfer or delete a workspace from its settings page). For anything else, write to support@tre-app.com. You also have the right to lodge a complaint with your local supervisory authority.
Note on shared content: deleting your account removes your profile, sessions, API tokens and comments, and detaches your name from cards you created. Cards and checklist items themselves belong to the workspace and remain there, no longer associated with you. Your comments are deleted, but the short extracts of them (up to 280 characters) already recorded in the activity log stay in other members’ feeds for no longer than 90 days of activity, or the most recent 10,000 entries per workspace, whichever comes first, pruned as the workspace is used — shown as the work of a former member. That severs the account link: entries point to no profile of yours. It does not erase your name everywhere in the ledger, though. The name you gave an API token is kept as written on the events that token produced, and a name or email recorded inside a past board-membership event you were part of — someone added you to a board, changed your role on it, or removed you from it — remains part of other members’ activity records.
Changes
If this policy changes materially we will update this page and its date. Continued use of the service after a change means the updated policy applies.
See also the Terms of Service.