privacy policy

what tended actually collects, why, who it's shared with, and how to control or delete it — in plain language, not legal fog.

last updated july 20, 2026

tended is built around a pairing, not a single account. the app learns about you and your partner — through what you type, what you say out loud, and, if you turn it on, where you go — so it can quietly suggest thoughtful things to do for each other.

that means it holds genuinely personal information: journal entries, preferences, and (optionally) location. tap into any section below for the details.

what we collect
  • phone number — used to create your account and sign you in via SMS verification. before you sign up, the app checks whether your number is already registered by sending a one-way hash of it, not the number itself.
  • name and birthday — collected during onboarding, shown to your partner.
  • love language and onboarding answers — a short set of questions you answer when you join, used to start building your profile.
  • journal entries — anything you write or say about yourself, your partner, or the two of you together. entries can be marked private (see "what your partner can and can't see" below).
  • voice recordings — if you journal by voice, the audio is sent for transcription to text and is not kept as audio afterward.
  • preferences and wishlist items — things you or tended (from your journal entries) note that you or your partner like, want, or would appreciate.
  • memories — photos, notes, and dates you save together. these are always shared with your partner by design.
  • location — only if you turn it on. see the dedicated section below.
  • push notification token — a device identifier used to deliver notifications, not tied to any content.
  • billing information — see "payment information" below. we never see or store your full card number.
location, specifically

this is the most sensitive thing tended can collect, so we're being precise about it.

  • it's off by default for the feature to do anything — location-based suggestions only run once both you and your partner have turned location on. if either of you hasn't, nothing location-related happens between you.
  • while it's on, tracking runs in the background — not just when you open the app. the app periodically checks your position (roughly every 30 seconds or every 50 meters of movement while you're out) so it can notice when you're near somewhere relevant to your partner's preferences.
  • your coordinates are stored — your last known location is saved to your shared pairing record (visible to your partner while location is on), and a history of places you've stopped near is kept on your own account to help tended recognize meaningful patterns (like a coffee shop you visit often).
  • we send your location to google — when the app checks what's nearby, it queries the google places api with your coordinates to identify venues and store types around you.
  • we send location context to anthropic (our ai provider) — nearby venue names and your partner's relevant preferences are sent to claude to reason about whether a genuine match exists — never raw, continuous tracking data, just the relevant snapshot for that check.
  • you can turn it off anytime — from the app's settings. turning it off stops new tracking immediately; see "how long we keep it" for what happens to history already collected.
how ai is involved

tended uses ai to turn what you write, say, and where you go into thoughtful suggestions for your partner — that's the core of the product, not an add-on.

  • anthropic (claude) — processes non-private journal entries to extract lasting preferences and patterns, writes and updates your profile, reasons about location matches, and composes the actual suggestion text shown in the app.
  • openai — transcribes voice journal entries to text, and generates the underlying search embeddings used to retrieve relevant profile details when composing a suggestion.
  • private journal entries are never sent for profile-building — marking an entry private keeps its content out of the ai ingestion pipeline that would otherwise learn from it.
what your partner can and can't see

your partner never sees your raw journal entries. only you can read what you actually wrote.

what your partner does see is a summarized, ai-compiled version of your preferences and patterns — the distilled takeaways, not your original words. journal entries you mark private skip that process entirely and never inform anything your partner sees.

memories, dates, and wishlist items you both add are shared by design — that's the point of them.

who we share data with

we don't sell your data, ever. these are the service providers tended runs on.

  • firebase (google) — account sign-in, and storage for your profile, journal, memories, and photos.
  • railway — hosts tended's backend server and the database used for ai-search over your profile.
  • anthropic — processes journal content and generates suggestions, as described above.
  • openai — transcribes voice entries and generates search embeddings, as described above.
  • google places — identifies nearby venues when location is turned on.
  • stripe — processes shared-pairing subscription billing.
  • revenuecat — manages in-app purchase subscriptions through the app store.
payment information

when you subscribe, your card details go directly to stripe or, for in-app purchases, to the app store's own payment system. tended's servers never see or store your full card number — only a reference token used to process future charges.

how long we keep it, and deletion

we keep your data for as long as your account is active. location visit history and derived patterns are kept indefinitely while location is on, to help tended recognize genuine patterns over time — turning location off stops new collection but doesn't automatically erase history already gathered.

deleting your account is a shared decision, since tended is built around a pairing — both partners confirm it, and it's permanent once complete. the full process, timeline, and exactly what gets deleted (profile, journal, memories, suggestions, location history, and the accounts themselves, across every system tended uses) is laid out on our account deletion page.

your choices
  • location — turn it on or off anytime in the app; it's genuinely optional and the rest of tended works without it.
  • private journal entries — mark any entry private to keep it out of your partner-visible profile and out of ai processing for that purpose.
  • push notifications — controlled through your device's notification settings.
  • account deletion — see above. you can also reach us directly if you can't access the app.
  • access or questions about your data — email us; see "contact" below.
children

tended is meant for adults in a committed relationship and is not directed to children. we don't knowingly collect personal information from anyone under 13. if you believe a child has provided us with personal information, contact us and we'll remove it.

security

data in transit between the app and our servers is encrypted. no system is perfectly secure, and we can't guarantee absolute protection — but we take reasonable, industry-standard measures to keep your information safe, and we continue to review and improve them.

changes to this policy

if this policy changes in a meaningful way, we'll update the date at the top of this page and, for significant changes, let you know in the app.

if anything here is unclear, or you'd like to know more about your data, reach out directly.

← back to tended