Tend Privacy Policy
Last updated: July 29, 2026
This privacy policy describes the current Tend prototype. Tend is designed to reward time away from scroll-heavy apps while reducing rewards when selected apps are used.
Data Tend Collects
Tend may collect or store:
- A locally generated user ID for this app install.
- A locally generated device ID and a backend-issued device sync secret.
- SHA-256 hashes of the locally generated device ID and account ID used to prevent one installation from operating multiple reward accounts. These ownership claims are retained for up to three years after their last use.
- Play Integrity risk signals such as recent integrity-request activity, device-recall flags, app-control risk, and Play Protect status. Tend stores daily risk summaries under hashed identifiers.
- App usage timing needed to detect mining and burn sessions.
- Selected tracked apps and excluded apps.
- Mining, burn, balance, streak, and achievement records.
- Backend sync status, pending proof records, and sync errors for testing.
- If you choose Google account linking, a one-way hash of your Google account subject identifier and the linking and authentication timestamps.
Referrals
If referrals are used, Tend stores the referral code, the relationship between the referring and referred accounts, qualification status, and qualification timestamps. Registered device identifiers are compared to reject same-device referrals. Tend does not request or upload contacts for invitations.
Data Tend Does Not Collect
Tend does not read or collect:
- Messages.
- Photos or videos.
- Contacts.
- Passwords.
- Screen content.
- What you type.
- The content inside other apps.
Why Usage Access Is Needed
Tend uses Android Usage Access to detect which app is active. This is required to know when a selected burn app is being used and when no burn app is active. Tend uses that timing to calculate mining and burn records.
Backend Sync
Tend syncs proof records with the backend so balances can be confirmed and fake or duplicated rewards can be rejected. Backend sync may include:
- User ID.
- Device ID.
- Signed mining and burn session records.
- Selected tracked app settings.
- Token balance, earned totals, burned totals, streaks, and goal status.
Device Registration
Each app install creates a device ID. The backend returns a device secret used to sign future sync requests. Tend also uses Google Play Integrity signals to help reject modified apps, unrecognized installations, duplicated rewards, and high-risk device activity.
Data Retention
Tend keeps raw backend mining and app-usage session proofs and detailed token ledger entries for 90 days for balance verification, duplicate prevention, and abuse investigation. After 90 days, those detailed records are deleted after they are verified against permanent daily earning, burn, net, and closing-balance summaries. Supply accounting events are retained for global token integrity. Expired authentication challenges are deleted after seven days. Account records remain until the user deletes the account.
The Data Controls screen can export the account record held by the Tend backend. Exports exclude device authentication secrets and recovery-code hashes. The same screen can permanently delete the account. Deletion removes account records and invalidates registered devices; any remaining TEND balance is burned before the records are removed so global token accounting remains consistent.
User Control
You can stop or renew the 12-hour Tend earning window from the home screen. Selected-app burn tracking continues after earning expires while Usage Access remains enabled. You can also change tracked app choices inside the app.
Optional Ads
Tend may show optional rewarded ads after a session ends. Ads do not change TEND balances, mining rates, burn rates, or token eligibility. A completed optional ad may unlock a local supporter badge that is not transferable and has no cash or crypto value. Ad providers may process device and advertising information according to their own privacy terms.
Backup And Recovery
Tend disables Android app-data backup for this prototype so local device IDs, device sync secrets, and proof records are not silently copied to another phone. Tend can create a one-time account recovery code. The backend stores a SHA-256 hash of that code rather than the plain code. Successful recovery registers the replacement device, rotates the recovery code, and preserves the same backend account and balance.
You may optionally link a Google account for recovery. Google provides Tend with an ID token after you select an account. Tend verifies the token, stores a one-way hash of the stable Google account subject identifier, and does not store the ID token or your Google password. The link is used only to locate and authenticate the associated Tend account during recovery.
Registered devices are listed in Account settings. A current device may revoke another device, which removes that device's backend sync authorization. The current device cannot revoke itself through this screen. The current device may also rotate its backend sync secret. After rotation, the previous secret stops authorizing sync requests.
Where Google Play Device Recall is available, Tend uses its three limited recall bits only for fraud prevention: one records prior participation in Tend rewards, one is reserved for confirmed severe abuse, and one is reserved for manual review. Google retains recall bits for up to three years after their last read or write. Tend does not use them to fingerprint users, infer sensitive characteristics, or track location.
Prototype Notice
Tend is currently a prototype. Privacy terms, retention periods, and these account controls must be reviewed before public release.
Contact
Contact: contact@tendapp.info