Tend.
Privacy Policy
Last updated: August 5, 2026
Tend is a private place for two people. This policy describes, in plain
language, exactly what the app collects, where it goes, and what you can
do about it. Tend is made and operated by Malek Doss, an independent
developer, who is responsible for the information described here. You can
reach us any time at
1999.aldoss@gmail.com.
What Tend is
Tend is a daily ritual for couples: each of you privately picks one word
for how the day felt, and once you've both logged, it's revealed to each
other. You can also share gratitudes, moments, flags, and plans with your
partner, and look back on the two of you over time. This policy explains
what information that requires and what we do with it.
Information we collect
Your account
- A display name, which your partner sees.
- An email address, only if you choose to save your account with Apple, Google, or email and password. Accounts start anonymous and stay that way until you save one.
- What you told us you're looking for during setup, so the app's copy fits you.
What you write
- Your daily word and when you logged it.
- Gratitudes, moments, and flags, including the free text you write and any love language you tag.
- Trips, plans, and milestones you add to your timeline.
- About us details, if you fill them in: your anniversary, how you met, a favorite memory, each partner's birthday and love language.
Your couple
- Your partner's display name and the invite code used to connect your accounts.
- Your couple's timezone, so the app knows when your shared day starts and ends, and your streak history.
Your device
- A push notification token, if you turn notifications on. It lets your partner's phone send you a nudge, and it's released when you sign out or delete your account.
- Basic device and app details that come with a crash report: device model, operating system version, and the version of Tend you're running.
Your subscription
- Whether Tend Plus is active, which plan it is, whether you're in a trial, when it renews, and which store it came from.
- We never see or store your card details. Payment happens entirely inside Apple's or Google's systems, and they only tell us whether a subscription is active.
Diagnostics
- Crash reports, error logs, and performance traces, so we can find and fix what breaks.
- When the app hits an error, a short replay of the screens leading up to it, with every piece of text and every image masked out. We see the shape of what happened, not what you wrote.
- We turn off the collection of IP addresses and device identifiers in our diagnostics tool.
How the app is used
- Which screens you open and which actions you take — that you logged a word, added a gratitude, paired with a partner, or opened the Plus screen. We record that these happened, never what you wrote in them.
- A random identifier for your app install, so we can tell one person's visit from another's without knowing who either of you is. It's reset if you delete and reinstall the app.
- We use this to see where people get stuck — for example, how many people finish setting up but never pair with a partner. It's how a very small app decides what to fix next.
Tend has no advertising SDK, no tracking pixels, no data brokers,
and no location collection. We don't build a profile of you, and
we don't follow you across other apps or websites. Our analytics is
configured with advertising identifiers switched off on
both iOS and Android, along with ad personalisation and ad measurement —
so none of this can be used to target you, here or anywhere else.
How we use it
- To run Tend's core ritual: matching your and your partner's daily words and revealing them to each other once you've both logged.
- To show the two of you your shared history: the calendar, streaks, gratitudes, moments, flags, and timeline.
- To generate your recaps, including the AI-written narrative described in the next section.
- To send the notifications you've opted into: a daily reminder to tend, an alert when your partner has logged, and reminders for plans and dates you've added.
- To keep your subscription accurate across both partners' devices.
- To fix crashes and keep the app working.
- To respond to you when you write to us.
We do not use your information for advertising, we do
not sell it, and we do not share it with
anyone for their own marketing.
Recaps and AI
Your weekly, monthly, and yearly recaps have two halves, and they work
differently.
-
Every number is computed by us. Agreement rates,
streaks, recovery patterns, and which weekday runs roughest are all
calculated by our own server from your logs. No AI is involved in
producing a figure, so nothing is invented.
-
The written narrative is generated by AI. To write it,
we send a compact summary of your period to Google's Gemini API. That
summary can include: your first names, your word patterns day by day,
counts and streaks, short excerpts of your gratitudes, moments, and
flags, the names of trips and milestones in that period, and your about
us details. It's sent when a recap is generated for your couple, and the
generated text is returned and saved to your couple's record.
This is the one place your written entries leave our own systems. Google
processes that content to produce the recap and returns it to us; their
handling is governed by the terms of the Google AI service we use. We do
not use your content to train any model of our own, and we don't send it
to any other AI provider. If you'd rather no recap is ever generated for
you, email us and we'll turn generation off for your couple.
Who we share it with
- Your partner: the person you're paired with sees your logged word once you've both logged, never before, plus anything you share as a gratitude, moment, flag, plan, or about us detail. That's the whole point of the app. Please treat everything you write in Tend as something your partner will read.
- Google Firebase and Google Cloud: the infrastructure that stores your data, runs sign-in, and hosts our server code. They process it on our behalf.
- Google (Gemini): for the recap narrative, as described above.
- Apple or Google Sign-In: only if you choose to save your account with them, to verify who you are.
- Expo: the service that delivers push notifications to your device. It receives your push token and the text of the notification. Those are deliberately thin: usually just your partner's first name and what kind of thing they added. Your daily word is never in a notification. The seal holds until you've both logged. The one exception is a trip, plan, or milestone, where the name you gave it appears in the alert so it's useful on the lock screen.
- Apple App Store, Google Play, and RevenueCat: to process and keep track of Tend Plus subscriptions.
- Sentry: the service that receives our crash reports and diagnostics.
- Google Analytics for Firebase: receives the app-usage events described above — which screens were opened and which actions were taken, never their contents. Advertising identifiers and ad personalisation are turned off, so this data isn't used to advertise to you.
- Legal requests: we may disclose information if we're legally required to, or if it's necessary to protect someone's safety. We'd tell you unless we're prohibited from doing so.
- No ad networks. No data brokers. No one else.
Where your data is stored
Tend runs on Google Cloud infrastructure in the United States, and our
subscription and diagnostics providers also operate there. If you use Tend
from outside the US, your information is transferred to and stored in the
US, which may have different privacy laws than your country.
Security
Your data is encrypted in transit and encrypted at rest by our
infrastructure provider. Database rules restrict every couple's records so
that only the two people in that couple can read them. Server-only values
like your subscription state can't be written by an app at all.
To be straight with you: Tend is not end-to-end encrypted.
That means we could technically access what's stored, and we would if we
had to for a support request you sent us, a legal obligation, or a safety
issue. We don't read couples' entries otherwise. No system is perfectly
secure, and we can't promise absolute security.
How long we keep it, and what deleting does
We keep your information for as long as your account exists. Deleting your
account from Settings does all of this immediately:
- Ends your couple, so your partner isn't left paired to an account that no longer exists.
- Deletes your account record, including your name, email, goals, and push token.
- Deletes your sign-in credentials, so the account can't be recovered.
- Cancels the reminders scheduled on your device.
What stays: your couple's shared history, the days you
both logged, gratitudes, moments, flags, timeline entries, and past recaps,
remains stored on the ended couple record and stays visible to your
partner. It belongs to both of you, and we don't erase one person's half
of a shared memory without the other knowing. If you want that shared
record erased too, email us and we'll take care of it.
Deleting your account does not cancel your subscription. Cancel that
through the App Store or Google Play, as described in our
Terms of Service.
Diagnostic data such as crash reports is kept for a limited period,
typically around 90 days, and then deleted automatically.
Step-by-step instructions are on our
account deletion page.
Your choices and your rights
In the app, any time:
- Delete your account from Settings.
- Unpair from your partner without deleting your own account.
- Turn off notifications in Settings or in your device's system settings.
- Edit or remove the about us and profile details you've filled in.
By email, at 1999.aldoss@gmail.com,
you can ask us to give you a copy of your information, correct something
that's wrong, delete your account or your couple's shared record, or stop
generating recaps for you. We'll respond within 30 days, and we won't
treat you differently for asking.
If you're in the UK or the European Economic Area
We process your information to perform our agreement with you (running the
app and your subscription), on the basis of your consent (notifications,
and any optional details you choose to add), and for our legitimate
interest in keeping Tend working and secure (diagnostics and abuse
prevention). You have the right to access, correct, delete, restrict, or
object to our processing of your information, to receive it in a portable
form, and to withdraw consent at any time. You also have the right to
complain to your local data protection authority.
If you're in California
We do not sell your personal information, and we do not share it for
cross-context behavioral advertising. You have the right to know what we
collect, to request deletion or correction, and not to be discriminated
against for exercising those rights. Use the email above to make a
request.
Children's privacy
Tend is not directed at children. We don't knowingly collect information
from anyone under 13, or under 16 where local law sets that bar. If you
believe a child has given us information, email us and we'll delete the
account.
Changes to this policy
If anything material changes about what we collect or how we use it, we'll
update the date at the top of this page and, where the change is
significant, tell you in the app before it takes effect.