Privacy policy

This policy says what DecisionBranch stores, which services process it, and how to get it deleted. DecisionBranch is operated by Tov Studios LLC (“we”). It is written to be read, not skimmed past.

Last updated 27 September 2026.

The short version

  • You can build, analyse and share a tree without an account. The tree lives in the link; we store nothing for it.
  • With an account we store your email address and the trees you save.
  • We use no advertising, no third-party tracking and no cookies other than the sign-in session.
  • Site analytics and embed walk analytics count events against a daily-salted hash. No raw IP addresses are stored, and the hash changes every day, so it cannot follow you.
  • Payments go through Stripe. We never see your card number.
  • Delete your account by emailing us from the account address. Everything you saved goes with it.

What we store, and why

Without an account

The editor keeps the tree in the page address after the #. That part of the address is not sent to our servers when the page loads, so an unsaved tree exists only in your browser and wherever you paste the link. Nothing is stored on our side.

With an account

  • Email address, for magic-link sign-in and to identify your account. If you sign in with Google we receive the email address and Google's account identifier, nothing else.
  • Trees you save: the outline text, the title, whether the tree is public, and timestamps. Public trees are visible to anyone with the link or the page address; private trees are visible only to you, enforced in the database.
  • Subscription state if you pay: your Stripe customer identifier, the plan, its status and the current period end. This is what turns Pro or Team features on.
  • AI builder usage: a count of builds per day, kept against your account (or a daily hash of your IP address when you are signed out) to apply the free daily limit.

Site analytics

We record product events such as a page view, a template opened, a demo interaction or a checkout started. Each event stores the event name, a few properties about the event itself (for example which template), the page path, the referring site's hostname, the account identifier if you are signed in, and a visitor hash. The visitor hash is a one-way hash of your IP address mixed with a salt that changes every day; we do not store the IP address, and the hash cannot be turned back into one. No cookie is set for analytics.

Embed walk analytics

When a flow tree is embedded on another site in walk mode, each walk is logged for the tree's owner: which questions and answers were reached, the referring site's hostname, and the same kind of daily-salted visitor hash. This is what powers the per-node funnel. It records what was clicked on the tree, not who clicked it.

Who processes it

We use a small number of services, each for one job. Each processes data under its own terms and security programme.

  • Supabase (database and authentication, hosted in the United States, us-east-1): accounts, trees, subscription state, events and walk analytics.
  • Stripe (payments): card details, billing address and invoices. Card numbers are entered on Stripe's pages and never reach our servers. Stripe tells us the outcome and the subscription status.
  • Anthropic (the AI builder): when you use "Describe your decision", the text you type, and the outline being repaired if a first attempt fails to parse, are sent to Anthropic's API to draft the tree. Your email address and account identifier are not sent. Anthropic processes API inputs under its commercial terms and does not use them to train its models.
  • Cloudflare (hosting, DNS and network): serves the site and keeps short-lived request logs for security and operations, as any host does.
  • Google only if you choose to sign in with Google, in which case Google's privacy policy covers that sign-in.

We do not sell personal data and we do not share it with advertisers. We disclose it only to these processors, or if the law requires us to.

Cookies

Signed-in users get a session cookie from Supabase so the site knows who you are; it is essential to the service and is removed when you sign out. There are no analytics cookies, no advertising cookies and no third-party cookies, which is why there is no cookie banner.

Public trees and embeds

Making a tree public publishes its title and outline at its own page address and makes it embeddable. Anything you put in a public tree, including notes after #, is visible to anyone. You can make it private again or delete it at any time; copies that others forked remain theirs.

Your rights, and how to delete your account

You can see and export every tree you saved from your trees page; the outline text is the complete record. To delete your account, email hello@decisionbranch.com from the address on the account. We delete the account, its trees, its walk analytics and its event history within 30 days and confirm by email. Invoices and payment records stay with Stripe for as long as tax and accounting law requires. If you are in the EEA, the UK or another jurisdiction with data-protection rights, you can also ask us for a copy of your data, a correction, or a restriction, and you have the right to complain to your local supervisory authority.

Our lawful basis for processing account data is the contract with you; for site and walk analytics it is our legitimate interest in understanding and improving the product, kept proportionate by the hashing described above; for payments it is the contract and our legal obligations.

Retention

  • Accounts and saved trees: until you delete them or the account.
  • Site events and walk analytics: up to 24 months, then deleted or aggregated.
  • AI builder inputs: not stored by us beyond the request. The daily build count is kept per calendar day and old days are cleared periodically.
  • Payment records: as required by law, held by Stripe.

Security

Data is encrypted in transit and at rest by the providers above. Row-level security in the database means a private tree can only be read by its owner, enforced by the database itself rather than by application code. Secrets live in the hosting platform, never in the code.

Children

DecisionBranch is not directed at children under 16 and we do not knowingly collect their data. Students using it in a course do so without an account unless their instructor arranges otherwise.

Changes

If this policy changes in a way that matters, the date at the top changes and account holders are told by email. The current version is always at decisionbranch.com/privacy/.

Contact

Tov Studios LLC, hello@decisionbranch.com. See also the terms of service and the refunds and cancellation policy.