Tend Privacy Policy

Effective date: 30 June 2026 App: Tend (Android) Contact: support@tend.fit

Tend is a local-first wellness coach built to keep day-to-day wellness information on your device. This Privacy Policy explains what information Tend handles, what leaves your device only when you choose optional cloud features, the legal basis for each processing activity, and the rights you may have under privacy laws.

Controller identity

Tend is operated by an independent software developer based in India, under the name SHDAN. That developer is the operator and controller for the processing described in this Privacy Policy. Privacy questions and rights requests may be directed to support@tend.fit.

Our approach: local-first by design

Tend works without an account and without an internet connection for its core local features. Your day-to-day wellness records live on your device unless you choose a feature that requires a network connection, such as account sign-in, app-store subscription verification, optional Cloud AI coaching, optional encrypted cloud backup, food search, crash reporting, or opt-in analytics. Tend contains no advertising SDKs and no ad trackers. We do not sell or rent your personal data.

1. Data stored only on your device

The following information is created and stored locally on your phone. It is not transmitted to us for ordinary app use and we cannot see it:

  • Care anchors, routines, and completion history
  • Mood check-ins and journal entries
  • Meditation, breathing, sleep, focus, and other session activity
  • Notes reading progress
  • App settings and optional motivational profile, stored in encrypted on-device storage

You can export this data to a file yourself and import it back. That file is created only when you choose a destination and remains wherever you save it. Deleting the app, or using the in-app delete option, removes this local data from your device.

If you sign in and turn on cloud backup, a copy of this data is held on our servers only in encrypted form. With automatic recovery, Tend manages the encryption key for you; with a private phrase, only your phrase can unlock it and we cannot read it. See Cloud backup in §4.

If you connect Health Connect, Tend reads activity data (steps and active calories) and body measurement data (weight) to show it in the app and support wellness features. When you use features that record data, Tend may write entries you actively log (such as workouts with duration and calories, meal type and nutrition macros, or user-entered body measurements like weight and height) back to Health Connect at your request. Tend only writes data you enter, confirm, or explicitly ask the coach to log for you.

Health Connect data is used on your device for display and insights. It is never used for advertising and never sold. Health-related information is used solely to provide wellness features requested by you and is never used for advertising, profiling for advertising, or sold to third parties. It leaves your device only if you separately opt in to Cloud AI coaching and choose a consent tier that includes health context. Where health-related data is processed under EU/UK privacy law, the Health tier and any comparable health processing rely on your explicit consent under Article 9(2)(a) GDPR/UK GDPR where applicable. You can withdraw Health Connect access through Health Connect or Android settings, and you can turn off Cloud AI health consent in Tend.

Food search sends only the search term you type to a public food-database provider so matching foods can be returned. Your food diary, identity, and Health Connect data are not sent to that provider. Search happens only while you actively type in the food search.

Tend is a general wellness app. It does not provide medical treatment, clinical assessment, or emergency services.

3. Account

Tend creates an anonymous identity with a third-party cloud authentication provider so optional cloud features and security checks can work. This may include an app-integrity or installation identifier used to protect the service, and it is not linked to your name or email. If you choose to sign in with a platform sign-in provider or email and password, your account is managed by a third-party cloud authentication provider, which stores your email address, display name if provided, and a user identifier. We use this only to recognize your account and authorize cloud features. You can sign out at any time; Tend saves a final encrypted backup first (if cloud backup is on) and then clears the account’s data from this device, and the app keeps working locally.

When the app contacts Tend’s secure cloud service for cloud features, support, or security checks, Tend may keep limited account and service records needed to provide, secure, support, and maintain the service. These records do not include care anchor names, journal text, Health Connect values, nutrition entries, cloud backup plaintext, or AI prompts/replies.

To understand whether the service is being used, Tend also keeps a limited internal account-activity record: one daily, one-way keyed pseudonym for an authenticated account and whether that account was anonymous or signed in. It is used only for aggregate service measurement such as daily, weekly, and monthly active accounts. It does not store the raw anonymous account identifier, email address, routes used, wellness information, or AI text, and is retained for up to 13 months. This internal service record is separate from optional third-party usage analytics and does not enable that analytics setting.

Cloud AI coaching is off by default. It works only if you are signed in, have an active Tend Pro subscription, and have explicitly turned it on. The app lets you choose how much context the AI Coach can use. Each optional tier remains off until you enable it:

  • Aggregate only: counts and categories, such as how many care anchors are due or done, time of day, and a mood-trend flag. Care anchor names, journal text, and identifiers are not included in this tier. The words you type into an AI feature, such as a goal, need, or chat message, are sent for that request.
  • Patterns: adds which care anchors or routines you tend to keep or skip, rhythm shapes, and mood trends over time. Journal text and saved free-text history are not included unless a reflection feature clearly asks and you opt in. Typed prompts and messages are sent when you submit them.
  • Health: adds Health Connect activity and body metrics, and the meals and workouts you log, so coaching can be activity-aware. Recent values may be included for your reply and are not stored as prompt or reply content by our cloud service.
  • Reflections: reserved for reflection features that clearly ask to use journal context. Journal text is not sent automatically in v1.

The request is sent through Tend’s secure cloud service to a cloud AI processing provider to generate a reply. The service checks your account, subscription status, and consent before AI runs. We keep limited service records needed to provide and protect Cloud AI, but we do not store prompts or AI replies. Tend does not use your prompts or replies to train its own AI models. Third-party AI providers may process requests according to their own contractual commitments and privacy policies. Cloud AI processing providers may temporarily process or retain requests for security, abuse prevention, service delivery, or legal compliance in accordance with their own policies and contractual commitments.

Cloud backup (optional, free): Cloud backup stores an encrypted copy of your app data so you can restore it on another device. Your app data is encrypted on your device before upload. Our servers receive and store only encrypted app data and related security information, never readable plaintext and never your private phrase. Cloud backup requires a signed-in account and explicit opt-in in the app; it does not require a subscription. You choose automatic recovery (Tend manages the encryption key for you) or a private phrase only you know. You can turn cloud backup off at any time to stop new uploads. Signing out keeps the stored copy so you can restore it when you sign back in; the stored copy is deleted when you delete your account.

5. Telemetry

Tend uses a third-party crash reporting provider for crash reports and a third-party analytics provider for optional usage analytics.

Crash reporting is on by default with an opt-out switch in You → Privacy. Crash reports may include error reports, diagnostics, device and app information needed to understand and fix app problems, and an installation identifier. Crash reporting is processed on the basis of legitimate interests for app stability, security, and error repair, with an always-available opt-out. Do not include care anchor names, journal text, Health Connect values, nutrition entries, or AI prompts/replies in crash reports.

Usage analytics is off by default. It turns on only if you choose to enable it — through the one-time prompt shown after you finish setting up Tend, or later in You → Privacy. Analytics is processed on the basis of consent and is used to understand aggregate app usage and improve Tend. Advertising identifiers and ad-personalization signals are turned off, and Tend has no advertising or third-party tracking software.

6. Lawful basis for processing

Where GDPR, UK GDPR, or a similar privacy law applies, our legal basis depends on what we are doing. Each of these applies only where the law requires it:

  • On-device data stays on your device; we do not process it on our servers unless you choose a cloud feature.
  • Account sign-in and subscription checks: to provide the optional cloud features you ask for (performance of a contract).
  • Cloud AI coaching: your explicit choice to turn it on (consent), together with providing the feature (contract). The Health and Reflections options rely on your explicit consent.
  • Encrypted cloud backup: to provide the optional cloud backup you turn on (contract).
  • Crash reports: our legitimate interest in a stable, secure app, with an opt-out.
  • Usage analytics: your consent (off by default).
  • Food search: our legitimate interest in returning matching foods, using only the term you type.
  • Service and security records: to run, secure, support, and measure the service at an aggregate level, and to meet legal obligations.

7. Subscriptions and app-store billing

Tend Pro subscriptions are processed by the app-store billing provider. Payments and billing details are handled by that provider; we do not receive or store your payment card or bank details. Your subscription status is tied to your app-store account. When you use cloud features, the app sends subscription proof to Tend’s cloud service so we can verify that Tend Pro is active for the correct Tend account.

8. Third-party processors and provider categories

We use third-party processors only to deliver features you request or to operate and secure the service. These include:

  • Account authentication providers
  • App-store billing and Tend Pro verification processors
  • Cloud hosting and database providers
  • Network, security, and content-delivery providers
  • Crash reporting and optional analytics providers
  • Cloud AI processing providers
  • Public food-search data providers
  • Professional advisors and service providers where needed for legal, accounting, security, or compliance purposes

These processors may process personal data only for the purposes described in this policy and under appropriate contractual, technical, and organizational safeguards. We do not sell personal data or share personal data for advertising. We do not sell personal information or share personal information for cross-context behavioral advertising.

If Tend undergoes a merger, acquisition, reorganization, asset sale, or similar transaction, personal data may be transferred as part of that transaction subject to applicable law and this Privacy Policy.

9. International transfers

Some processors may process personal data outside your country of residence. Where transfers are restricted by law, we use appropriate safeguards required by applicable law.

10. What Tend does not collect

Tend does not access your location, contacts, messages, calendar, microphone, camera, photo library, advertising identifier, or browsing activity. If you send a problem report from the app, it includes your message, basic diagnostic and device information, and any screenshot you choose to attach; these are sent to our support system and stored to help resolve the issue, and can be deleted on request. Apart from a screenshot you deliberately attach, Tend does not collect your photos or files. Telemetry does not include care anchor names, journal text, Health Connect values, nutrition entries, or AI prompts or replies.

11. Data retention, deletion, and privacy rights

On-device data stays on your device until you delete it in the app, uninstall the app, or restore a different backup.

You can delete your account in the app, use the account deletion page, or contact support@tend.fit. After a verified deletion request, we delete or de-identify account records, active encrypted cloud backup data, and current Cloud AI consent records within the period required by applicable law and platform policy, unless retention is needed for security, fraud prevention, accounting, dispute resolution, legal compliance, or enforcing service limits. Backup copies and service records are overwritten or deleted on normal retention cycles unless earlier action is legally required. We may require reasonable verification of account ownership before processing certain requests.

Crash reports and analytics records are retained according to configured service controls and only for as long as needed for app stability, security, aggregate product measurement, legal compliance, or another purpose described in this policy.

The pseudonymous internal account-activity record described in §3 is retained for up to 13 months. When we process a verified account deletion, we remove that account’s corresponding current account-activity entries along with the other applicable account records.

Depending on where you live, you may have the right to request access to your personal data, correction, deletion, restriction of processing, portability in a structured machine-readable format, objection to legitimate-interests processing, and withdrawal of consent. Withdrawal of consent does not affect processing that occurred before withdrawal. If GDPR or UK GDPR applies, we will respond to a verifiable request within one calendar month, extendable by up to two further months for complex requests with notice. If CCPA/CPRA or similar US state privacy law applies, you may have rights to know, access, correct, delete, opt out of sale or sharing, and non-discrimination. Tend does not sell personal data.

You may also have the right to lodge a complaint with the data protection supervisory authority in your country of residence. To exercise rights, contact support@tend.fit.

12. Automated decision-making

Tend does not make solely automated decisions that produce legal or similarly significant effects on you. AI Coach replies and pattern insights are suggestions and observations. Meaningful AI actions require preview and confirmation before anything changes in your local app data. Quick, reversible logs you ask the coach to record may apply immediately and can be undone.

13. Data breach notification

If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant data protection supervisory authority within 72 hours where required by law. If a breach is likely to result in a high risk to your rights and freedoms, we will notify affected users without undue delay using the contact information associated with the account or an in-app notice where available.

14. Security

On-device sensitive data is protected using platform security controls, and cloud features use technical and organizational safeguards designed to protect data in transit and at rest. Cloud requests are subject to access controls appropriate to the feature. While we use reasonable safeguards, no method of storage, transmission, or security measure is completely secure. We cannot guarantee absolute security.

15. Children

Tend is intended for adults. You must be at least 18 years old, or the minimum age required by applicable law in your jurisdiction, to use Tend. If you believe a person below the applicable age has provided personal data through Tend, contact support@tend.fit and we will take appropriate steps to delete that data.

16. Changes to this policy

If we change this policy, we will update the effective date and post the new version at the same URL. Material changes will be reflected before the new practices take effect.

17. Contact

Privacy questions and rights requests may be sent to support@tend.fit.