Tend Privacy Policy

Last updated: September 13, 2026

This privacy policy describes the current Tend application. Tend provides automatic digital-wellbeing accounting for time away from apps and for app usage.

Data Tend Collects

Tend may collect or store:

Referrals

If referrals are used, Tend stores the referral code, the relationship between the referring and referred accounts, qualification status, and qualification timestamps. Registered device identifiers are compared to reject same-device referrals. Tend does not request or upload contacts for invitations.

Data Tend Does Not Collect

Tend does not read or collect:

Why App-Activity Access Is Needed

On Android, Tend uses Usage Access to detect which app is active and calculate mining and burn timing. On iOS, Tend uses Apple's Family Controls, Device Activity, and Managed Settings frameworks to receive aggregate Screen Time timing. Apple does not reveal the identities of privately selected apps, categories, or websites to Tend.

Backend Sync

Tend syncs proof records with the backend so balances can be confirmed and fake or duplicated rewards can be rejected. Backend sync may include:

Device Registration

Each app install creates a device ID. The backend returns a device secret used to sign future sync requests. Tend uses Google Play Integrity on Android and Apple App Attest on iOS to help reject modified apps, unrecognized installations, duplicated rewards, and high-risk device activity.

Data Retention

Tend keeps raw backend mining and app-usage session proofs and detailed token ledger entries for 90 days for balance verification, duplicate prevention, and abuse investigation. After 90 days, those detailed records are deleted after they are verified against permanent daily earning, burn, net, and closing-balance summaries. Supply accounting events are retained for consistent global TEND accounting. Expired authentication challenges are deleted after seven days. Account records remain until the user deletes the account.

The Data Controls screen can export the account record held by the Tend backend. Exports exclude device authentication secrets and recovery-code hashes. The same screen can permanently delete the account. Deletion removes account records and invalidates registered devices; any remaining TEND balance is burned before the records are removed so global token accounting remains consistent.

User Control

You can stop or renew the 12-hour Tend mining window from the home screen. App-usage burn accounting continues after mining expires while the required Android Usage Access or iOS Screen Time authorization remains enabled. You can change app choices inside the app.

Optional Ads

Tend may show optional rewarded ads after a session ends. Ads do not change TEND balances, mining rates, burn rates, or token eligibility. A completed optional ad may unlock a local supporter badge that is not transferable and has no cash or crypto value. Ad providers may process device and advertising information according to their own privacy terms.

Backup And Recovery

Tend disables Android app-data backup so local device IDs, device sync secrets, and proof records are not silently copied to another phone. On iOS, device authentication secrets are stored in the Keychain and are not included in the account export. Tend can create a one-time account recovery code. The backend stores a SHA-256 hash of that code rather than the plain code. Successful recovery registers the replacement device, rotates the recovery code, and preserves the same backend account and balance.

You may optionally link a Google account for recovery. Google provides Tend with an ID token after you select an account. Tend verifies the token, stores a one-way hash of the stable Google account subject identifier, and does not store the ID token or your Google password. The link is used only to locate and authenticate the associated Tend account during recovery.

Registered devices are listed in Account settings. A current device may revoke another device, which removes that device's backend sync authorization. The current device cannot revoke itself through this screen. The current device may also rotate its backend sync secret. After rotation, the previous secret stops authorizing sync requests.

Where Google Play Device Recall is available, Tend uses its three limited recall bits only for fraud prevention: one records prior participation in Tend rewards, one is reserved for confirmed severe abuse, and one is reserved for manual review. Google retains recall bits for up to three years after their last read or write. Tend does not use them to fingerprint users, infer sensitive characteristics, or track location.

Current TEND Status

TEND currently has no monetary value and cannot be purchased, sold, transferred, withdrawn, exchanged, or redeemed. The current application has no wallet or blockchain functionality. Mining is automatic digital-wellbeing accounting, not cryptocurrency computation or payment for completing tasks. Ads do not award TEND or change mining or burn rates. Any future cryptocurrency plans would be separate from the current application and are not promised.

Contact

Contact: contact@tendapp.info