← Back to home

Privacy Policy

Updated June 26, 2026

1. Who we are

Tendle (the "App", "we", "us", "our") is an iPhone app that helps a parent be present with their young child, plus this website. The data controller under Article 4(7) GDPR is:

Nils Schiwora, trading as Nils Schiwora Trading Services Ahornstr. 37 14547 Beelitz Germany

If you have questions about this policy or want to exercise your rights, write to support@tendle.me.

For our business address in Brandenburg, the competent supervisory authority is Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg (LDA Brandenburg). You can always file a complaint with the authority of your habitual residence (Art. 77 GDPR).

2. What the App does, and how it handles data

Tendle is local-first. During "kid time" it blocks the distracting apps you chose, using Apple's Family Controls (Screen Time). You earn your phone back by photographing an artefact of play — for example a block tower — which is checked on your device. The App keeps a streak and a count of present minutes.

There are no user accounts and Tendle runs no backend of its own. The substance of what you do in the App — the photo you take, the apps you chose to block, your streak and present-minutes — stays on your device. The only data that leaves your device is what is needed to run subscriptions and, where enabled, anonymous product analytics and crash diagnostics, as described below.

2.1 On your device only (never transmitted)

Data Where it lives
The photo of the play artefact you take during kid time Captured live by the camera and checked in memory; on a verified completion it is saved as a JPEG in the App's private container (excluded from iCloud backup) to show your Recap keepsake and History
Which apps you chose to block Stored by iOS as opaque Family Controls tokens that the App cannot read and that never leave your device
Your presence / streak ledger and present-minutes Stored on device (SwiftData)
Your settings (nickname, defaults, reminder preference, onboarding and paywall state) Stored on device (UserDefaults)

The camera is used only to photograph the play artefact during a kid-time unlock. A frame is captured live (no import from your photo library), checked on-device, and — on a verified completion — saved into the App's own private container. It is never written to the iOS Photos library and never uploaded. Sharing a Recap photo is a separate, explicit, default-off action and is the only path off the device for an artefact photo.

Family Controls (Screen Time) gives the App a way to shield apps you select. Your selection is represented by opaque OS tokens; the App cannot see which apps they are, and that selection never leaves your device.

2.2 Data handled by service providers

Data Purpose
Subscription transaction and entitlement state Processed by Apple and mirrored through RevenueCat to unlock paid features — see Section 4
Product analytics events (e.g. screen_view, paywall_viewed) Sent to PostHog only when analytics is enabled, with a lawful basis — see Sections 3 and 4
Crash and error diagnostics (stack trace, device/runtime metadata) Sent to Sentry only when crash reporting is enabled — see Section 4
Your message and email address, if you contact support Used only to answer you — see Section 4

By design, no photo, file path, or artefact reference is ever sent to analytics or crash reporting — events carry only counts, durations, and enum outcomes. Analytics events are not linked to your identity.

3. Why we process it (legal bases)

Purpose Legal basis (Art. 6(1) GDPR)
Running the App's core features on your device Performance of a contract — Art. 6(1)(b)
Processing your App Store subscription Performance of a contract — Art. 6(1)(b)
Sending local streak reminders you turned on Consent — Art. 6(1)(a). Scheduled on-device; see Section 4.
Product analytics (if enabled) to understand which features work Legitimate interest — Art. 6(1)(f). You can object at any time (Section 7).
Crash diagnostics to keep the App stable Legitimate interest — Art. 6(1)(f)
Answering a support request you send us Performance of a contract / our legitimate interest — Art. 6(1)(b)/(f)
Meeting legal retention duties (tax, accounting) Legal obligation — Art. 6(1)(c)

4. Service providers and recipients

We use a small number of processors. Because Tendle is local-first, most of what you do never reaches any of them.

Provider Role Region Notes
Apple Inc. App distribution and App Store subscription processing USA (with EU sub-processors) Apple receives purchase and refund metadata directly from you under Apple's own privacy policy. Family Controls (Screen Time) is an Apple system; your app selection is held by iOS as opaque tokens.
RevenueCat Managing the subscription entitlement and exposing it back to the App USA We use RevenueCat as the subscription source of truth. It processes App Store transaction metadata, the product identifier, the entitlement status, and a RevenueCat-issued app-user identifier. It does not receive your photos.
PostHog Product analytics for the iOS App and this website EU — eu.i.posthog.com Used only when analytics is enabled. Events are limited to product usage (e.g. screen_view, paywall_viewed, feature interactions) and are not linked to your identity. No photo, file path, or artefact reference is ever included.
Sentry Crash and error diagnostics for the iOS App EU Used only when crash reporting is enabled. Receives stack traces and limited device/runtime metadata, with sensitive and media values stripped before they are sent.
Vercel Inc. Hosting for this website Vercel Edge Network globally Standard request data (IP address, user agent) flows through Vercel logs for abuse prevention.

We do not sell your data and we do not use it for personalised advertising.

4.1 This website

When analytics is enabled, this website loads PostHog product analytics (EU region, eu.i.posthog.com) behind cookie consent. Nothing is loaded or sent until you accept the cookie banner. If you decline, no PostHog cookie is set and no events are sent. We do not load session recording, autocapture, advertising, or any other third-party tracking, and the PostHog project is configured to discard client IP addresses. Captured events are limited to page views, App Store CTA clicks, language switches, and FAQ expansions. Your browser also sends standard request data (IP address, user agent, referrer) to our hosting provider on every page request.

5. International transfers

Apple and RevenueCat are based in or operate from the United States. PostHog runs on its EU region (eu.i.posthog.com) for both the iOS App and this website, so PostHog event data does not leave the EU, and Sentry stores this project's crash-report data in its EU region. The processor terms for the non-EU processors have been confirmed for launch. Transfers to non-EU recipients rely on Standard Contractual Clauses adopted by the European Commission, plus supplementary measures where required by Schrems II. Where a provider participates in the EU-US Data Privacy Framework, we also rely on its current certification as an additional safeguard.

6. How long we keep your data

Category Retention
Artefact photos, streak ledger, settings (on device) Until you clear them with "Delete local data" in Settings, or delete the App
Subscription and entitlement records (Apple / RevenueCat) Held by Apple's account records and RevenueCat for subscription history until deletion is requested
Product analytics events Controlled by the configured PostHog project retention policy
Crash reports Controlled by the configured Sentry project retention policy
Support correspondence Only as long as needed to resolve your request and to meet legal obligations
Subscription and invoicing records Up to 10 years where required by German tax and commercial law (§ 147 AO, § 257 HGB)

7. Your rights

Under the GDPR you can:

  • Ask for confirmation of what we process about you and a copy of it (Art. 15)
  • Have inaccurate data corrected (Art. 16)
  • Have your data deleted (Art. 17), subject to legal retention duties
  • Restrict processing while a dispute is open (Art. 18)
  • Receive your data in a portable, machine-readable format (Art. 20)
  • Object to processing based on legitimate interest, including analytics (Art. 21)
  • Withdraw any consent you gave us at any time, with effect for the future (Art. 7(3))
  • Lodge a complaint with a supervisory authority (Art. 77)

Because Tendle is local-first, you control most of your data directly: Settings → Delete local data removes the artefact photos, streak ledger, and settings stored on your device. To exercise any other right, email support@tendle.me. We aim to respond within 30 days (Art. 12(3)). See the Support page for the practical steps.

8. Children

Tendle is a tool for the parent and is not directed at children under 16. We do not knowingly process data of users under 16 without verifiable parental consent (Art. 8 GDPR). The App does not ask a child to create an account or hand over personal data. If you believe a child has used the App in a way that gave us their data, write to support@tendle.me and we will delete it.

9. Security

The App's sensitive content — your photos, app selection, and streak — stays on your device. We use HTTPS for all traffic to our service providers, rely on Apple's app sandbox and on iOS keychain/secure storage where applicable, and limit internal access on a need-to-know basis. No system is perfectly secure. If you become aware of a vulnerability, please report it to support@tendle.me.

10. Changes to this policy

We will post material changes here and, where the change affects you (for example, a new processor handling your data), notify you in the App at least 14 days before the change takes effect. The date at the top of this page shows when it was last revised.

11. Contact

For all privacy questions and rights requests:

Nils Schiwora trading as Nils Schiwora Trading Services Ahornstr. 37 14547 Beelitz Germany Email: support@tendle.me

ImprintTerms of UseSupport
© 2026 Tendle