Tendia · Privacy
Privacy Policy
The short version
Outside the Pact, everything you write in Tendia stays on your phone. There is no account, no advertising, no data broker, and no one selling anything about you.
Two things do leave your phone, and this page says exactly what they are:
- Anonymous usage statistics and crash reports. Counts of which features get used, with no name, no email, no device advertising ID, and none of your content. On by default; one switch in Settings turns them off.
- The Pact, if you choose to pair with someone. The items you put under a pact — their names, each day's done, rested or missed, and any proof note or photo — are shared with your one partner through our server in the EU, under a random ID that is not your identity. Ending the pact deletes them.
That's the whole list.
This policy applies from Tendia 1.5.0. Earlier versions send nothing off the phone and have no Pact; for those, the policy dated July 1, 2026 still describes what happens.
1. At a glance
| Data | Leaves your phone? | Linked to you? | Why | Can you stop it? |
|---|---|---|---|---|
| Your habits, logs, quests, reflections, journal, notes, Heartwood values, Tree, forest | No | — | It is the product | Delete anything in-app; Settings → Erase everything |
| Screen Time (Focus, Moonlight) | No | — | Handled on-device by Apple's framework; we never see which apps you use | Turn Focus / Moonlight off |
| Anonymous usage statistics | Yes, to Google Firebase Analytics | No | To see which features work, which quests get finished, where people get stuck | Settings → Your data → Send anonymous usage data |
| Crash reports | Yes, to Google Firebase Crashlytics | No | To fix crashes | Same switch |
| The Pact: your chosen items, each day's done / rested / missed, proof photos or notes, the name you type | Yes, to our server (Google Firebase, Frankfurt, EU) and to your one partner | To a random ID, not to your identity | So your partner can see and confirm your day | Never starts unless you pair; End the pact or Erase everything deletes it |
| Push notification token | Only if you use the Pact and allow notifications | To the same random ID | To deliver pact notifications | Deny notifications, or turn each pact push off in Settings |
| Purchases | Handled by Apple | Apple knows; we don't | Tendia Pro | — |
| Email you send us | Yes, to our mailbox | Yes | To reply | Don't email, or ask us to delete the thread |
2. What stays on your phone
All of your content: habits and their schedules, every Done and Rest, quests and their progress, the Tree and the forest, Light and levels, days on the road, the Run, the Dailies deck, Reflections, the Journal, notes, the Traveler's Log, Heartwood values, the Almanac, cosmetics, Focus sessions and Moonlight settings. It is stored in the app's local database and never sent to us — with one exception you choose: an item you place under a pact, and any proof note or photo you attach to it, goes to the server and to your partner (section 5).
- Backups. If you use iCloud Backup or a computer backup, your Tendia data is inside it, encrypted, under Apple's terms. We have no access to it.
- Widgets, the Lock Screen and Live Activities read a small copy of today's items stored on the device, in a container only Tendia's own extensions can open.
- Screen Time. Focus and Moonlight use Apple's Screen Time framework to shield the apps you choose. Which apps you pick, and how long you use them, never leaves the device and is not part of the usage statistics.
- Reminders (per-habit nudges, the evening line, the morning line) are scheduled on the device. They are not push notifications and involve no server.
3. Anonymous usage statistics
What it is. When you use a feature, the app sends a short event to Google Firebase Analytics. An event is a name and a few coded values. Real examples of what is sent:
- a quest with the catalog id
ground-sprint-the-foundation-protocolwas begun, from the catalog - the day closed: 4 items asked, 2 done, 1 rested, 1 unanswered
- the Settle picker was used: energy low, feeling heavy, and the body register was opened
- the paywall was shown from the habit limit, and dismissed
- a share card for "habits formed" was rendered
The full list of event types is bundled inside the app and enforced by automated tests, so the app cannot send an event that is not on the list.
What is never in it. Nothing you type. Custom habit
names are sent as the word custom. Notes, reflections,
journal entries, Heartwood values, pact item names, partner names,
proof photos, victory statements, and the names of apps you shield are
never sent. There is no test that fails more loudly in our codebase
than the one that checks this.
What identifies the data. Each install gets a random app instance ID generated by Firebase. It is not your name, your Apple ID, your phone number, or your device's advertising identifier. It is not connected to the Pact's ID. If you erase the app's data, it is reset. We do not set a user ID, so nothing in the statistics can be tied to a person.
What Google adds on receipt. Google records the device model, OS version, app version, app language, and an approximate country derived from the network address at the time the event arrives. Google does not give us the network address.
Advertising. Off, entirely: no advertising identifier (IDFA), no ad personalization, no ad storage, no cross-app tracking. The app never shows Apple's "Allow tracking" prompt because it does not track.
Where and for how long. Google processes this data on its own servers, which may be outside the EU and outside your country. Event-level data is kept for 14 months, then only aggregate totals remain. We also keep a raw export of the events in Google BigQuery, in the EU, so we can ask questions the standard reports don't answer. The export is under the same random IDs and contains nothing more than the events.
The switch. Settings → Your data → Send anonymous usage data. It is on by default. Turning it off stops all events and crash reports immediately, in the same session. Erase everything also resets the app instance ID.
Why on by default. These statistics are how we find out whether a quest gets finished, whether reminders help, and where new users get lost. An opt-in sample would be too small and too self-selected to answer any of that. Because nothing personal is in it, we think default-on with a real off switch is the honest trade, and we say so here rather than burying it.
4. Crash reports
If the app crashes, Google Firebase Crashlytics sends a report: the stack trace, device model, OS version, app version, free memory and disk at the time, whether the app was in the foreground, and a random Crashlytics installation ID. No custom keys, no user ID, no logs, and none of your content. Google keeps crash data for 90 days. The same Settings switch turns this off.
5. The Pact
The Pact is optional. Nothing in this section applies until you pair with someone by exchanging an invite code. If you never pair, the app never creates an identity on our server.
5.1 The identity
When you first create or accept an invite, the app signs in anonymously with Firebase Authentication. You get a random ID. No email, no phone number, no password, no name is asked for or stored. Our server cannot tell who you are, and neither can we.
You type a name for your partner to see. Use a first name or a nickname; we suggest not using your full name. It is the only human-readable thing about you on the server.
Moving to a new phone. A short code from Settings moves this random ID to your new phone, so your pact, your name and the streak carry over. The code works once, for ten minutes, and the server stores only a hash of it. Nothing else travels through our server: your habits, Tree, forest and reflections reach a new phone only through your own iCloud or computer backup.
5.2 What is stored on our server, and what your partner sees
Stored per person: the display name you typed, your time zone, your app language, your push notification token if you allowed notifications, which pact you are in, and the time of your last pact activity.
Stored per pact, and visible to your partner:
- the names of the habits, quests and dailies you chose to put under the pact, with their schedules, and the icon and colour you gave them;
- for each day of the pact, whether each of those items was done, rested, or missed — the Calendar shows this per day and per item, for both of you;
- when an item leaves the pact, and why — the habit formed, you released it, or the quest ended or was abandoned;
- for items you set to With proof: the photo and/or the note you attach;
- your partner's confirmations of your dones, and yours of theirs;
- the pact's streak, grace days, whether a day was kept or missed, and whether the pact is active, sleeping, or ended;
- the mode (together, in turns, or with a witness) and the date it started.
What your partner never sees: anything you did not put under the pact — your Tree, Light, level, days on the road, the Run, your notes, reflections, journal, Heartwood, and every habit, quest and daily you kept out of it. What they do see, for every pacted item on every day of the pact, is done, rested or missed. That is what the Pact is for, so choose the items with that in mind.
Item names are yours and can be sensitive ("No drinking", "Therapy homework"). Choose what you share with that in mind. Only your partner can read them.
5.3 Where it is stored and who can read it
In Google Cloud Firestore and Cloud Storage in Google's Frankfurt (europe-west3) region, in the European Union. Access rules enforced by the database allow a pact's content to be read only by the two members of that pact. Our server code can read it to run the pact (closing days, applying grace, sending notifications). We do not read pact content by hand except to investigate a problem you report to us.
5.4 Notifications
Pact notifications ("Sam is done for today", "Ana nudged you: Run isn't done yet") travel through Google's Firebase Cloud Messaging and Apple's push service. Their text can include your partner's display name and an item name. We keep a log of the pact notifications we sent you (which kind, when, the text) for 30 days, to check that the app never sends the ones it promises not to. Each pact push can be switched off in Settings → Notifications.
5.5 How long it is kept
- While the pact is active: everything in 5.2.
- Proof photos: deleted automatically within 15 days of upload, whether or not the pact continues.
- Proof notes: kept with that day's record for as long as the pact lasts, and deleted with it.
- Invite codes: expire after 72 hours, then deleted.
- Move-to-a-new-phone codes: valid for 10 minutes, stored only as a hash, deleted when used or expired.
- When a pact ends (either partner can end it, at any time, with no confirmation from the other): all items, all days, all confirmations, all proof photos and notes are deleted from the server. What remains is a record with no content: that a pact existed, when it started and ended, and the two time zones. Your own phone keeps its own record of that pact's days, the Calendar; Erase everything removes it.
- Erase everything (Settings → Your data): ends your pact for both of you, deletes your display name, token, invites and codes, and deletes the anonymous identity itself. After that there is nothing on the server about you.
5.6 Security
Traffic to the server is encrypted in transit. Server functions check that the caller is a signed-in member of the pact they touch, and limit how often each identity may call them. Proof photos are readable only by the two members via the same rules.
5.7 Analytics and the Pact
The usage statistics in section 3 include pact events (a pact formed, a day kept, a day missed, a confirmation) as counts only. They carry no item names, no partner name, and are not connected to your pact ID.
6. Purchases
Tendia Pro is sold through Apple. Apple handles payment, receipts, subscriptions and refunds under Apple's terms. We never receive your payment details. The app verifies your subscription with Apple on the device. The usage statistics record which screen led to a purchase and the plan chosen, under the anonymous app instance ID.
7. The website
gettendia.com sets no cookies and runs no analytics. If you email us, we keep the email to reply and delete it on request.
8. Your choices and rights
- Turn statistics and crash reports off: Settings → Your data.
- Delete your content: delete items in the app, or Settings → Your data → Erase everything. This is also the server-side deletion request for the Pact.
- End a pact: from the Pact tab, at any time.
- Notifications: iOS Settings, and per-push switches in Tendia's Settings.
- See what the server holds about you: for the Pact, what you see in the Pact tab and its History is the complete content. There is no hidden profile.
If you are in the EU/EEA, the UK, or another place with data-protection rights, you have the rights to access, correct, delete, restrict, and object, and to complain to your local authority. Because we cannot identify you from our data, the app's own controls (above) are the way to exercise them. If you cannot use the app, email privacy@gettendia.com and we will help. Our legal bases: the Pact is the service you asked for; statistics and crash reports are our legitimate interest in running a working product, with the off switch as your objection; notifications are your consent.
9. How this appears on the App Store privacy label
- Linked to you, only in the sense of the random Pact ID and only if you use the Pact (section 5): Name (the first name or nickname you type), User ID (the anonymous account), Photos (proof) and Other user content (what you keep in the pact, its done times, proof notes).
- Not linked to you: Device ID (the push token and the analytics instance ID), Product interaction (the usage events, section 3) and Crash data (section 4).
- Not used for tracking. No data is used for advertising or shared with data brokers. The app's bundled privacy manifest declares the same list.
10. Third parties
Google LLC (Firebase: Authentication, Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, Analytics, Crashlytics, BigQuery) processes data on our behalf under Google's data-processing terms. Apple Inc. handles purchases, push delivery, backups and App Store analytics under Apple's terms. No one else receives your data. We do not sell it, and we do not share it for advertising.
11. Children
Tendia is for adults and is not directed at children under 13 (or the age of digital consent where you live). We do not knowingly collect data from children.
12. Changes
We will not add a new kind of data collection without updating this page first. Features that send more of your data off the phone will, like the Pact, only start when you choose to use them. Previous versions: July 1, 2026 (on-device only, no analytics).
13. Contact
Tendia is made by Azamat Nogmanov, an independent developer in Kazakhstan, who is the data controller for the little that leaves your phone.
- Anything about your data: privacy@gettendia.com
- Everything else: hello@gettendia.com
Effective date: September 20, 2026. Replaces the policy dated July 1, 2026. ‹ Back to Tendia