Tend Privacy Policy
Last updated: September 13, 2026
This privacy policy describes the current Tend application. Tend provides automatic digital-wellbeing accounting for time away from apps and for app usage.
Data Tend Collects
Tend may collect or store:
- A locally generated user ID for this app install.
- A locally generated device ID and a backend-issued device sync secret.
- SHA-256 hashes of the locally generated device ID and account ID used to prevent one installation from operating multiple reward accounts. These ownership claims are retained for up to three years after their last use.
- Device-integrity and anti-abuse signals. On Android these may include Play Integrity request activity, device-recall flags, app-control risk, and Play Protect status. On iOS these include Apple App Attest keys, receipts, assertions, and counters. Tend may store risk summaries under hashed identifiers.
- App usage timing needed to detect mining and burn sessions.
- On Android, the apps selected for burn tracking and non-burning exceptions.
- On iOS, the number of non-burning exceptions and aggregate Screen Time activity needed to calculate mining and burn. Apple keeps selected app, category, and website identities private from Tend.
- Mining, burn, balance, streak, and achievement records.
- Backend sync status, pending proof records, and sync errors for testing.
- If you choose Google account linking, a one-way hash of your Google account subject identifier and the linking and authentication timestamps.
- If you enable notifications on iOS, an Apple Push Notification service token and its development or production environment.
Referrals
If referrals are used, Tend stores the referral code, the relationship between the referring and referred accounts, qualification status, and qualification timestamps. Registered device identifiers are compared to reject same-device referrals. Tend does not request or upload contacts for invitations.
Data Tend Does Not Collect
Tend does not read or collect:
- Messages.
- Photos or videos.
- Contacts.
- Passwords.
- Screen content.
- What you type.
- The content inside other apps.
Why App-Activity Access Is Needed
On Android, Tend uses Usage Access to detect which app is active and calculate mining and burn timing. On iOS, Tend uses Apple's Family Controls, Device Activity, and Managed Settings frameworks to receive aggregate Screen Time timing. Apple does not reveal the identities of privately selected apps, categories, or websites to Tend.
Backend Sync
Tend syncs proof records with the backend so balances can be confirmed and fake or duplicated rewards can be rejected. Backend sync may include:
- User ID.
- Device ID.
- Signed mining and burn session records.
- Android tracked-app settings or, on iOS, the count of private non-burning exceptions.
- Token balance, earned totals, burned totals, streaks, and goal status.
Device Registration
Each app install creates a device ID. The backend returns a device secret used to sign future sync requests. Tend uses Google Play Integrity on Android and Apple App Attest on iOS to help reject modified apps, unrecognized installations, duplicated rewards, and high-risk device activity.
Data Retention
Tend keeps raw backend mining and app-usage session proofs and detailed token ledger entries for 90 days for balance verification, duplicate prevention, and abuse investigation. After 90 days, those detailed records are deleted after they are verified against permanent daily earning, burn, net, and closing-balance summaries. Supply accounting events are retained for consistent global TEND accounting. Expired authentication challenges are deleted after seven days. Account records remain until the user deletes the account.
The Data Controls screen can export the account record held by the Tend backend. Exports exclude device authentication secrets and recovery-code hashes. The same screen can permanently delete the account. Deletion removes account records and invalidates registered devices; any remaining TEND balance is burned before the records are removed so global token accounting remains consistent.
User Control
You can stop or renew the 12-hour Tend mining window from the home screen. App-usage burn accounting continues after mining expires while the required Android Usage Access or iOS Screen Time authorization remains enabled. You can change app choices inside the app.
Optional Ads
Tend may show optional rewarded ads after a session ends. Ads do not change TEND balances, mining rates, burn rates, or token eligibility. A completed optional ad may unlock a local supporter badge that is not transferable and has no cash or crypto value. Ad providers may process device and advertising information according to their own privacy terms.
Backup And Recovery
Tend disables Android app-data backup so local device IDs, device sync secrets, and proof records are not silently copied to another phone. On iOS, device authentication secrets are stored in the Keychain and are not included in the account export. Tend can create a one-time account recovery code. The backend stores a SHA-256 hash of that code rather than the plain code. Successful recovery registers the replacement device, rotates the recovery code, and preserves the same backend account and balance.
You may optionally link a Google account for recovery. Google provides Tend with an ID token after you select an account. Tend verifies the token, stores a one-way hash of the stable Google account subject identifier, and does not store the ID token or your Google password. The link is used only to locate and authenticate the associated Tend account during recovery.
Registered devices are listed in Account settings. A current device may revoke another device, which removes that device's backend sync authorization. The current device cannot revoke itself through this screen. The current device may also rotate its backend sync secret. After rotation, the previous secret stops authorizing sync requests.
Where Google Play Device Recall is available, Tend uses its three limited recall bits only for fraud prevention: one records prior participation in Tend rewards, one is reserved for confirmed severe abuse, and one is reserved for manual review. Google retains recall bits for up to three years after their last read or write. Tend does not use them to fingerprint users, infer sensitive characteristics, or track location.
Current TEND Status
TEND currently has no monetary value and cannot be purchased, sold, transferred, withdrawn, exchanged, or redeemed. The current application has no wallet or blockchain functionality. Mining is automatic digital-wellbeing accounting, not cryptocurrency computation or payment for completing tasks. Ads do not award TEND or change mining or burn rates. Any future cryptocurrency plans would be separate from the current application and are not promised.
Contact
Contact: contact@tendapp.info