Tend Privacy Policy

Last updated: July 29, 2026

This privacy policy describes the current Tend prototype. Tend is designed to reward time away from scroll-heavy apps while reducing rewards when selected apps are used.

Data Tend Collects

Tend may collect or store:

Referrals

If referrals are used, Tend stores the referral code, the relationship between the referring and referred accounts, qualification status, and qualification timestamps. Registered device identifiers are compared to reject same-device referrals. Tend does not request or upload contacts for invitations.

Data Tend Does Not Collect

Tend does not read or collect:

Why Usage Access Is Needed

Tend uses Android Usage Access to detect which app is active. This is required to know when a selected burn app is being used and when no burn app is active. Tend uses that timing to calculate mining and burn records.

Backend Sync

Tend syncs proof records with the backend so balances can be confirmed and fake or duplicated rewards can be rejected. Backend sync may include:

Device Registration

Each app install creates a device ID. The backend returns a device secret used to sign future sync requests. Tend also uses Google Play Integrity signals to help reject modified apps, unrecognized installations, duplicated rewards, and high-risk device activity.

Data Retention

Tend keeps raw backend mining and app-usage session proofs and detailed token ledger entries for 90 days for balance verification, duplicate prevention, and abuse investigation. After 90 days, those detailed records are deleted after they are verified against permanent daily earning, burn, net, and closing-balance summaries. Supply accounting events are retained for global token integrity. Expired authentication challenges are deleted after seven days. Account records remain until the user deletes the account.

The Data Controls screen can export the account record held by the Tend backend. Exports exclude device authentication secrets and recovery-code hashes. The same screen can permanently delete the account. Deletion removes account records and invalidates registered devices; any remaining TEND balance is burned before the records are removed so global token accounting remains consistent.

User Control

You can stop or renew the 12-hour Tend earning window from the home screen. Selected-app burn tracking continues after earning expires while Usage Access remains enabled. You can also change tracked app choices inside the app.

Optional Ads

Tend may show optional rewarded ads after a session ends. Ads do not change TEND balances, mining rates, burn rates, or token eligibility. A completed optional ad may unlock a local supporter badge that is not transferable and has no cash or crypto value. Ad providers may process device and advertising information according to their own privacy terms.

Backup And Recovery

Tend disables Android app-data backup for this prototype so local device IDs, device sync secrets, and proof records are not silently copied to another phone. Tend can create a one-time account recovery code. The backend stores a SHA-256 hash of that code rather than the plain code. Successful recovery registers the replacement device, rotates the recovery code, and preserves the same backend account and balance.

You may optionally link a Google account for recovery. Google provides Tend with an ID token after you select an account. Tend verifies the token, stores a one-way hash of the stable Google account subject identifier, and does not store the ID token or your Google password. The link is used only to locate and authenticate the associated Tend account during recovery.

Registered devices are listed in Account settings. A current device may revoke another device, which removes that device's backend sync authorization. The current device cannot revoke itself through this screen. The current device may also rotate its backend sync secret. After rotation, the previous secret stops authorizing sync requests.

Where Google Play Device Recall is available, Tend uses its three limited recall bits only for fraud prevention: one records prior participation in Tend rewards, one is reserved for confirmed severe abuse, and one is reserved for manual review. Google retains recall bits for up to three years after their last read or write. Tend does not use them to fingerprint users, infer sensitive characteristics, or track location.

Prototype Notice

Tend is currently a prototype. Privacy terms, retention periods, and these account controls must be reviewed before public release.

Contact

Contact: contact@tendapp.info