← Back to home

Privacy Policy

Updated September 9, 2026

1. Who we are

Tendle (the "App", "we", "us", "our") is an iPhone app that helps a parent be present with their young child, plus this website. The data controller under Article 4(7) GDPR is:

Nils Schiwora, trading as Nils Schiwora Trading Services Ahornstr. 37 14547 Beelitz Germany

If you have questions about this policy or want to exercise your rights, write to support@tendle.me.

For our business address in Brandenburg, the competent supervisory authority is Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg (LDA Brandenburg). You can always file a complaint with the authority of your habitual residence (Art. 77 GDPR).

2. What the App does, and how it handles data

Tendle is local-first. During "kid time" it blocks the distracting apps you chose, using Apple's Family Controls (Screen Time). You earn your phone back by photographing an artefact of play — for example a block tower — which is checked on your device. The App keeps a streak and a count of present minutes.

There are no user accounts. Optional feedback and founder chat send only the support information described below. Photos, chosen blocked apps, streaks and present minutes stay on your device. Subscription services, product analytics and optional diagnostics are described separately below.

2.1 On your device only (never transmitted)

Data Where it lives
The photo of the play artefact you take during kid time Captured live by the camera and checked in memory; on a verified completion it is saved as a JPEG in the App's private container (excluded from iCloud backup) to show your Recap keepsake and History
Which apps you chose to block Stored by iOS as opaque Family Controls tokens that the App cannot read and that never leave your device
Your presence / streak ledger and present-minutes Stored on device (SwiftData)
Your settings (nickname, defaults, reminder preference, onboarding and paywall state) Stored on device (UserDefaults)

The camera is used only to photograph the play artefact during a kid-time unlock. A frame is captured live (no import from your photo library), checked on-device, and — on a verified completion — saved into the App's own private container. After the first confirmed photo, you can separately choose to add that photo and future confirmed photos to Apple Photos. Tendle requests add-only access and cannot view your library. If iCloud Photos is enabled, Apple may sync those copies across your devices. You can change this choice in Settings; denial never blocks a session. Tendle never uploads an artefact photo to its own or another provider's server. Sharing a Recap remains a separate, user-initiated action.

Family Controls (Screen Time) gives the App a way to shield apps you select. Your selection is represented by opaque OS tokens; the App cannot see which apps they are, and that selection never leaves your device.

2.2 Data handled by service providers

If you send feedback from Settings, we transmit your selected category, message, optional reply email, app version, locale, and current subscription status to our support inbox. The email address is used only to reply to that feedback. RevenueCat Customer Center may also collect one predefined cancellation reason; it does not ask for free-form cancellation text.

Data Purpose
Subscription transaction and entitlement state Processed by Apple and mirrored through RevenueCat to unlock paid features — see Section 4
Explicit product analytics events (e.g. app_started, paywall_viewed) Sent to PostHog while Product Analytics is enabled — see Sections 3 and 4
Masked mobile session replays Sent to PostHog while Product Analytics is enabled to diagnose navigation and usability problems; displayed text and text inputs are obscured before transmission, and camera or user-photo surfaces are excluded from capture
Crash and error diagnostics (stack trace, device/runtime metadata) Sent to Sentry only when crash reporting is enabled — see Section 4
Your message and email address, if you contact support Used only to answer you — see Section 4
Purchase-support data: coarse per-day session counts and your "Purchase support" setting Stored on our API (Cloudflare) so we can answer Apple's refund enquiries — see Sections 3 and 4
Our answer to Apple's refund enquiry (purchase delivered yes/no, trial shown yes/no, our recommendation) Sent to Apple only when you request a refund from Apple — see Sections 3 and 4

By design, no photo, file path, or artefact reference is ever sent to analytics or crash reporting — events carry only counts, durations, and enum outcomes. Analytics events are not linked to your identity.

2.3 Optional founder chat

When you start a conversation, we store your messages, an optional name you provide for yourself, and a random installation identifier. We also receive your language, timezone, app/build version and approximate country from the network connection, with capture dates. Country can reflect travel or a VPN. We do not attach child names, photos, missions or session details to support context.

Cloudflare Workers, Durable Objects and D1 provide the chat. To help answer subscription questions, we may verify signed Apple purchase evidence against RevenueCat and retain a minimal, dated plan/status snapshot. This does not create an account, link another conversation, or require Product Analytics. Raw purchase evidence is verified transiently, not retained.

If you enable reply notifications, Apple APNs receives your device token and a generic reply alert. We receive only a coarse active/idle kid-time state to reduce interruptions; background delivery cannot be guaranteed to stop while offline. Operator alerts through PurelyMail and browser push providers contain no message text, name or subscription details.

Messages and associated delivery/event records expire after 90 days. Idle support context and names are removed after 90 days; inactive parent push targets also expire. The on-device cache holds at most 500 messages, for up to 90 days; unsent messages remain until delivered, discarded or deleted. Conversation settings let you delete the conversation and disable reply notifications. Offline deletion clears local content immediately and visibly waits for connection to finish server deletion. A content-free revocation record prevents replay from recreating deleted content. No chat content is sent to analytics or session replay.

3. Why we process it (legal bases)

Purpose Legal basis (Art. 6(1) GDPR)
Running the App's core features on your device Performance of a contract — Art. 6(1)(b)
Processing your App Store subscription Performance of a contract — Art. 6(1)(b)
Sending local streak reminders you turned on Consent — Art. 6(1)(a). Scheduled on-device; see Section 4.
Minimized product analytics to understand which features work Our legitimate interest — Art. 6(1)(f). You can object at any time in Settings (Section 7).
Crash diagnostics to keep the App stable Legitimate interest — Art. 6(1)(f)
Answering a support request you send us Performance of a contract / our legitimate interest — Art. 6(1)(b)/(f)
Meeting legal retention duties (tax, accounting) Legal obligation — Art. 6(1)(c)
Answering Apple's refund enquiries and protecting against refund abuse Our legitimate interest — Art. 6(1)(f), Recital 47. You can object at any time in Settings ("Purchase support", Section 7).

4. Service providers and recipients

We use a small number of processors. Because Tendle is local-first, most of what you do never reaches any of them.

Provider Role Region Notes
Apple Inc. App distribution and App Store subscription processing USA (with EU sub-processors) Apple receives purchase and refund metadata directly from you under Apple's own privacy policy. Family Controls (Screen Time) is an Apple system; your app selection is held by iOS as opaque tokens.
RevenueCat Managing the subscription entitlement and exposing it back to the App USA We use RevenueCat as the subscription source of truth. It processes App Store transaction metadata, the product identifier, the entitlement status, and a RevenueCat-issued app-user identifier. While Product Analytics is enabled, immediately before checkout it also receives the coarse paywall placement and configured variant so we can compare purchase surfaces. It receives no PostHog or per-presentation identifier. It does not receive your photos.
PostHog Product analytics for the iOS App and this website EU — eu.i.posthog.com The iOS App sends explicit pseudonymous product events and masked session replays by default under our legitimate interest. Replays reconstruct App screens, taps, and navigation to help us identify usability problems; displayed text and text inputs are obscured before transmission, camera and user-photo surfaces are excluded from capture, and replay logs and network telemetry are disabled. App-owned decorative artwork may remain visible. You can object at any time by switching off Product Analytics in Settings. Screen/lifecycle/element autocapture and the RevenueCat identity join remain disabled. Events are associated with an anonymous, install-scoped profile so PostHog can show coarse country/region and standard device context. We do not add a name, account identity, RevenueCat identifier, child data, or free text to that profile. No photo, child name, custom text, file path, or artefact reference is included. This website does not use session replay.
Sentry Crash and error diagnostics for the iOS App EU Used only when crash reporting is enabled. Receives stack traces and limited device/runtime metadata, with sensitive and media values stripped before they are sent.
Vercel Inc. Hosting for this website Vercel Edge Network globally Standard request data (IP address, user agent) flows through Vercel logs for abuse prevention.
Cloudflare Tendle API, minimized purchase-attribution storage, and support delivery Global infrastructure Cloudflare Workers and D1 store the RevenueCat transaction lineage, coarse paywall placement, and configured variant for up to 730 days only when Product Analytics was enabled at checkout. The snapshot contains no RevenueCat App User ID, PostHog ID, or presentation identifier. Cloudflare Email Service receives a feedback message and optional reply address only when you press Send. None of this data is used for advertising.

We do not sell your data and we do not use it for personalised advertising.

4.1 This website

When analytics is enabled, this website loads PostHog product analytics (EU region, eu.i.posthog.com) behind cookie consent. Nothing is loaded or sent until you accept the cookie banner. If you decline, no PostHog cookie is set and no events are sent. We do not load session recording, autocapture, advertising, or any other third-party tracking, and the PostHog project is configured to discard client IP addresses. Captured events are limited to page views, App Store CTA clicks, language switches, and FAQ expansions. Your browser also sends standard request data (IP address, user agent, referrer) to our hosting provider on every page request.

5. International transfers

Apple and RevenueCat are based in or operate from the United States. PostHog runs on its EU region (eu.i.posthog.com) for both the iOS App and this website, so PostHog event data does not leave the EU, and Sentry stores this project's crash-report data in its EU region. The processor terms for the non-EU processors have been confirmed for launch. Transfers to non-EU recipients rely on Standard Contractual Clauses adopted by the European Commission, plus supplementary measures where required by Schrems II. Where a provider participates in the EU-US Data Privacy Framework, we also rely on its current certification as an additional safeguard.

6. How long we keep your data

Category Retention
Artefact photos, streak ledger, settings (on device) Until you clear them with "Delete local data" in Settings, or delete the App
Subscription and entitlement records (Apple / RevenueCat) Held by Apple's account records and RevenueCat for subscription history until deletion is requested
Minimized purchase-attribution snapshots (Tendle / D1) Up to 730 days
Product analytics events PostHog currently reports a provider-controlled retention window of up to 84 months; we are working to shorten it
Masked mobile session replays Up to 30 days in PostHog
Crash reports Controlled by the configured Sentry project retention policy
Support correspondence Only as long as needed to resolve your request and to meet legal obligations
Subscription and invoicing records Up to 10 years where required by German tax and commercial law (§ 147 AO, § 257 HGB)

7. Your rights

Under the GDPR you can:

  • Ask for confirmation of what we process about you and a copy of it (Art. 15)
  • Have inaccurate data corrected (Art. 16)
  • Have your data deleted (Art. 17), subject to legal retention duties
  • Restrict processing while a dispute is open (Art. 18)
  • Receive your data in a portable, machine-readable format (Art. 20)
  • Object to processing based on legitimate interest, including analytics (Art. 21)
  • Withdraw any consent you gave us at any time, with effect for the future (Art. 7(3))
  • Lodge a complaint with a supervisory authority (Art. 77)

Because Tendle is local-first, you control most of your data directly: Settings → Delete local data removes the artefact photos, streak ledger, and settings stored on your device. To exercise any other right, email support@tendle.me. We aim to respond within 30 days (Art. 12(3)). See the Support page for the practical steps.

8. Children

Tendle is a tool for the parent and is not directed at children under 16. We do not knowingly process data of users under 16 without verifiable parental consent (Art. 8 GDPR). The App does not ask a child to create an account or hand over personal data. If you believe a child has used the App in a way that gave us their data, write to support@tendle.me and we will delete it.

9. Security

The App's sensitive content — your photos, app selection, and streak — stays on your device. We use HTTPS for all traffic to our service providers, rely on Apple's app sandbox and on iOS keychain/secure storage where applicable, and limit internal access on a need-to-know basis. No system is perfectly secure. If you become aware of a vulnerability, please report it to support@tendle.me.

10. Changes to this policy

We will post material changes here and, where the change affects you (for example, a new processor handling your data), notify you in the App at least 14 days before the change takes effect. The date at the top of this page shows when it was last revised.

11. Contact

For all privacy questions and rights requests:

Nils Schiwora trading as Nils Schiwora Trading Services Ahornstr. 37 14547 Beelitz Germany Email: support@tendle.me

ImprintTerms of UseSupport
© 2026 Tendle