Legal
Privacy Policy
Last updated: 2026-08-03
Tend is a gratitude journalling app. This policy explains what stays on your phone, what leaves it, who receives it, and what you can ask us to do about it. It describes what the app actually does today, not what we would like it to do.
Who is responsible
The data controller is Sara Meindl, Perchtoldsdorf, Austria. For anything in this policy, including any of the rights below, write to privacy@tendgratitude.app.
There is no account
Tend has no sign-up, no login and no user profile on any server. We cannot look up "your data" by name or email, because we hold no such record. What identifies a request to us is a random installation identifier, described below.
What stays on your phone
Everything you write and everything Tend writes back is stored in a database on your device and nowhere else:
- Your gratitude entries, affirmations and reflections
- Your onboarding answers, including the people you told Tend about
- Your streak, favourites, intentions and practice history
- Your settings
We keep no copy. Deleting the app, or using Delete all data in Settings, destroys it with nothing to restore from.
What leaves your phone, and why
Tend cannot write your gratitudes, affirmations, reflections, themes or sparks on the device — a language model does that, and it runs elsewhere. To produce them, Tend sends the material each feature needs to OpenAI, by way of a service we operate.
This includes your own words and the names of the people you told Tend about. Specifically:
- Every generation sends your onboarding profile, including the first names, relationships and pronouns of the people you listed.
- Themes sends up to 50 of your stored gratitudes and their affirmations.
- Shift sends up to 30, with the mood and emotion you tapped for each.
- Yesterday's reflection sends the entry it is reflecting on in full, up to 12 earlier entries, and your first name.
- Anything you type yourself in a custom option is sent as written.
We do not use this to build a profile of you on a server, and none of it is stored by us after the answer comes back.
Who else receives data
| Who | What they receive | Why |
|---|---|---|
| OpenAI, USA privacy policy |
The material above, as part of each request | Generating the text Tend shows you |
| Cloudflare, USA privacy policy |
Each request in transit, and its IP address | Hosting this site and carrying requests to OpenAI on our behalf |
| Sentry, Germany privacy policy |
Crash reports and performance measurements: error type, screen, timing, device model, app version, a per-install identifier | Finding out that Tend is broken or slow without waiting for a review |
| GitHub, USA privacy policy |
Feedback you send from Settings, as written | Recording it so it can be acted on |
| Apple Weather privacy policy |
An approximate location, only if you turn on local weather | Looking up the current weather |
| Open-Meteo, Germany terms and privacy |
The same approximate location, on iOS 15 and whenever Apple Weather cannot be reached | Looking up the current weather |
| Apple privacy policy |
Your subscription purchase | Taking payment. We never see your payment details. |
These are processors acting on our instructions, except Apple, which is a controller in its own right for payment. Transfers to the USA rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework, or on standard contractual clauses where it does not apply.
Location, only if you ask for it
Tend can colour what it offers you with the weather where you are. That is off until you turn it on, and it is the only thing Tend ever asks the operating system for.
- Your coordinates are rounded to about 11 kilometres before they are used — for the weather lookup and for the place-name lookup (Apple's geocoding service) alike. That is plenty for both, and far less identifying than a precise fix.
- The rounded pair goes to Apple Weather to look up the current conditions. If that cannot answer — on iOS 15, which is too old for Apple's weather service, or if the lookup fails — the same rounded pair goes to Open-Meteo instead. Nothing else about you goes with it — no entry, no name, no identifier beyond the IP address any direct connection carries.
- Your coordinates never reach the model. What can reach it, as context for the writing, is the weather as words like "cold" or "clear" — and the name of your town, as looked up from the rounded coordinates. If you would rather it did not know even that, leave location off.
- There is no fallback to guessing your location from your IP address. Without permission there is simply no weather.
Model training
The requests Tend makes on your behalf are configured so that OpenAI does not retain them for review and does not use them to train models. OpenAI may still retain data for a limited period for abuse monitoring under its own terms, which we do not control.
The installation identifier
Each install generates a random identifier and sends it with every request, so the server can stop one copy of the app from consuming the whole budget. It is not derived from your device, does not follow you across apps, and resets if you reinstall. It is never used for analytics or advertising.
Usage counts
If Help improve Tend is on in Settings, the app reports that an event happened — a flow was started, a practice was completed. These are counters. They carry no text, no identifier and nothing about you. You can turn them off at any time.
What we never do
- We never sell your data.
- We never use it for advertising, and there is no advertising in Tend.
- We never track you across other apps or websites.
- We never share your entries with anyone except the processors above.
Why we are allowed to do this
- Performing our contract with you (Art. 6(1)(b) GDPR) covers everything needed to run the app you asked for: storing your entries, generating text, and taking payment.
- Our legitimate interests (Art. 6(1)(f)) cover crash reporting, performance measurements and abuse limits — keeping Tend working and affordable to run.
- Your consent (Art. 6(1)(a)) covers usage counts and notifications, both of which you control and can withdraw.
How long anything is kept
- On your phone: until you delete it.
- On our server: nothing. Requests pass through and are not stored or logged.
- Crash reports and performance measurements: for the retention period of our Sentry plan, after which they are deleted automatically.
- Feedback: for as long as the issue it created is open.
- At OpenAI: per their terms, for abuse monitoring only.
Your rights
Under the GDPR you may request access to your data, correction, erasure, restriction, portability, and you may object to processing based on legitimate interests. Two honest notes about how that works here:
- Your entries are already in your hands. They are on your phone, and Settings deletes them. We cannot produce, correct or erase them for you, because we do not have them.
- We cannot identify you. With no account, we cannot connect a request to a person (Art. 11 GDPR). If you send us your installation identifier we can act on the little that is tied to it.
You may also complain to a supervisory authority. Ours is the Austrian Data Protection Authority (Datenschutzbehörde), dsb.gv.at.
Age
Tend is for people aged 16 and over. It is not directed at children, and we do not knowingly collect data from them.
Changes
If this policy changes, the date at the top changes with it. This page is the current version — the app links here rather than carrying its own copy, so there is never an out-of-date one in circulation.