Privacy Policy
For the Branch iPhone app (“branch collective”, installed as “branch.”) and this website.
Effective date: 30 September 2026
1. Who is responsible
Ferdinand Wittmann, trading as Artegrity, Grossweidenmühlstrasse 13, 90419 Nürnberg, Germany, is the operator and contact for personal data processed in operating this website, optional Branch app analytics and Branch support. Contact: ferdinand@artegrity.io.
Google Drive workspace owners, AI assistants and external services may have their own responsibilities for the information processed by their services. Our policy describes Branch’s data paths; it does not replace their privacy information.
2. What Branch does
Branch opens apps stored in Google Drive. App files and shared app data live in the selected owner’s Drive workspace, including a Google Doc containing shared data. People with access to those files can read that data. Branch does not create a separate hosted Branch account. Shared app records remain in Drive; the optional contact form uses a separate Firebase service to deliver support messages.
3. Google access and shared app data
Connecting Google uses your account name, email and account identifier to work with Drive content. Branch requests permission to read and manage Drive files so it can browse complete app folders, load app releases and save shared changes. The consent screen describes the requested access.
Google credentials stay within the Branch runner and its Google sign-in integration. They are not provided to the app code Branch opens. App code can access and update its own shared data through Branch. Use trusted apps and folders, and consider who can access a folder before entering personal information.
You choose which shared records to enter. Processing enables the app functions you request. Depending on the data and the workspace, the owner’s own obligations and legal bases also apply. Google processes data under its applicable service terms and Privacy Policy.
4. Information on your phone
Branch stores app references, setup and assistant preferences, appearance choices, downloaded app bundles and automatic-function recovery information on your device. The bundle cache keeps up to two complete app releases for recovery. A photo selected for a local app appearance is stored on the device rather than automatically uploaded to Drive by Branch.
These records support the app functions you request. Signing out leaves device settings and Drive files in place. Local recovery records may be needed to resolve a save or function whose result is uncertain.
5. Optional notifications
If you explicitly register a phone for an app’s notifications, Branch stores your account name and email, account identifier, device identifier and name, push token and registration time in a separate shared Google Doc for that app. People with access to the files can read this registry.
Notification destination tokens, title/body and app and folder identifiers pass through Expo’s push service; Apple delivers notifications on iPhone. Lock-screen display depends on your iPhone settings. Registration stays in the shared registry until removed or changed. Expo and Apple handle transport and service records under their own applicable terms and retention practices. See Expo’s privacy information and Apple’s privacy information.
You can remove the phone’s registration in the app’s Settings before signing out, and separately disable iOS notifications. Registration is optional and initiated by you.
6. AI assistants and external connections
Create new passes your entered idea to your chosen assistant through its website link. Edit passes the app’s Drive folder link. Initial setup may share the public Branch authoring skill. Information you provide to an assistant is subject to that assistant’s terms and privacy practices.
Apps can request connections to external HTTPS services. Branch shows the declared services and purposes for approval on your account and device. Approved app code can send information to those services. Review each explanation and the recipient’s privacy information before allowing access. Revoke a connection in that app’s Settings. Retention and deletion by the external service are controlled by that service.
7. Website hosting
This website is hosted using Google Firebase Hosting. Serving requests involves network information, including IP addresses. Google states that Firebase Hosting uses IP addresses to detect abuse and provide usage analysis, and retains IP data for a few months. This processing is distinct from optional Google Analytics. See Firebase’s privacy and security information.
We use hosting to deliver and protect the website, based on our legitimate interest in providing a reliable, secure public website (Article 6(1)(f) GDPR). Local fonts and images are served by this website. There is no signup. The optional contact form is described below.
8. Optional website analytics and privacy choices
Google Analytics is not currently enabled on this website. No Analytics tag, analytics cookies or advertising tracker is loaded. If we enable optional analytics, we will update this policy and ask for your permission before loading it.
A necessary local preference named branch.website.consent.v1 remembers your choice and time for up to six months. It is not used for tracking or sent to an analytics provider. This preference allows the website to remember and apply your requested privacy setting (§ 25(2)(2) TDDDG).
Use in the footer to review or change your decision. Withdrawing consent stops future analytics on this site, clears accessible first-party Analytics cookies and reloads the page. It does not erase data already received by Google. Declining does not affect use of the website.
9. Optional Branch app analytics
In versions offering “Help improve Branch?”, analytics starts only after you choose “Allow analytics”. Declining does not affect using Branch. You can turn it on or off in Account → Usage analytics. The website’s privacy choice is separate from the phone’s choice.
To understand usage and improve setup, consenting installations send Branch opens, successfully loaded sub-app opens, setup-card impressions and button taps, × taps, steps successfully saved as done, and successful Google Drive connection grants. Events include a random installation ID, a session ID, time, operating system, app version/build, whether Drive is connected and a hashed sub-app identifier. These identifiers group activity from an installation; they are not your Google identity or an advertising ID.
Events go to PostHog, Inc.’s US Cloud. The network IP address is processed to estimate country and first-level region, then discarded from stored event data. The project removes city, postal code, coordinates and more detailed location fields. IP-derived regions can be wrong, for example when using a VPN. Branch does not request GPS or precise device location for analytics.
We do not send Google credentials, names or email addresses, Drive folder links, app titles, app content, assistant prompts or push tokens in these events. We do not enable screen recordings, automatic click capture or advertising tracking. Transmission is best effort, with no saved event queue; failed events are dropped.
The legal basis for optional app analytics is your consent (Article 6(1)(a) GDPR and § 25(1) TDDDG for the optional device identifier). Processing uses a US service; PostHog’s Privacy Policy and Data Processing Agreement describe its processing and international transfer provisions. The on-device preference remembers and applies your requested choice.
Turning analytics off stops future requests and removes the local analytics ID. Events already received are not automatically erased. If you want access or removal, copy the analytics ID shown in Account before turning it off and contact ferdinand@artegrity.io. We do not maintain a Google-account-to-analytics-ID lookup. On our current free plan, PostHog provides one year of event retention; we may remove records earlier when no longer needed. Re-enabling analytics creates a new ID, and deleting app-container storage removes the local preference.
10. Support messages
If you contact ferdinand@artegrity.io, we use the information you send to answer your request and investigate an issue. Email is handled through Microsoft Outlook. See Microsoft’s Privacy Statement. Access is limited to people who need to deal with the request.
If you use the contact form on the website or inside Branch, your name, reply email and message pass through a Python Firebase Cloud Function to the operator’s private Telegram chat. Telegram handles delivery under its Privacy Policy. The server keeps delivery status and keyed hashes for duplicate prevention and submission limits in Firestore; it does not store your message body there. These records expire after 24 hours and are removed by Firebase’s asynchronous expiry process. Contact messages in Telegram are kept while needed to handle the enquiry.
When you tap Send, Firebase App Check and Google reCAPTCHA Enterprise perform a security check, which can process browser/device and network information and store a security token locally. This protects the form from abuse; it is separate from optional analytics. See Firebase’s privacy information and Google’s Privacy Policy. You can use email instead. The bot accepts analytics commands only from the operator’s verified private Telegram account. Form submissions cannot choose another recipient.
Processing is based on taking steps at your request or fulfilling a contract (Article 6(1)(b) GDPR), or our legitimate interest in answering general enquiries and maintaining the service (Article 6(1)(f) GDPR). We retain correspondence while needed for the enquiry, related claims or applicable legal retention duties, and remove it when these purposes no longer apply. Please send only the information needed to help you.
11. Retention and deletion
Drive owners control stored files, shared records and sharing permissions. Manage or delete these in Google Drive, subject to your permissions and Google’s trash, version and retention behavior. If someone else owns an app, contact them about removal. Signing out or deleting Branch does not delete Drive files or other people’s copies.
Revoke Branch’s Google access in your Google Account connections. Remove a notification registration separately before signing out. Deleting the app removes app-container files, but Google sign-in credentials may require revoking Google access separately. There is no complete in-app local-data reset. Our support page describes the available controls.
Google, Expo, Apple, Microsoft, PostHog, chosen assistants and approved external services may retain data under their own service terms and legal obligations. A request to the Branch operator cannot automatically delete records held by other workspace owners or independent services.
12. Your rights
Where the GDPR applies, you may request access, correction, erasure, restriction or portability of your personal data, and object to processing based on legitimate interests. You may withdraw consent at any time, without affecting earlier lawful processing. Contact ferdinand@artegrity.io; we may need information to verify your identity. You can also complain to a supervisory authority, including the Bavarian State Office for Data Protection Supervision (BayLDA).
Some features depend on information needed for them, such as Google access for a connected app. Optional app and website analytics and phone notification registration are not required to browse the website or use other Branch features. We do not use website/support data for automated decisions that produce legal or similarly significant effects.
13. Changes
We publish updates on this page and change the effective date. Changes to optional app or website analytics will be reflected in the consent choice and policy before the changed collection starts.
