Privacy Policy
Last updated: July 23, 2026 · Effective: July 23, 2026
Plain-language summary: Tether is a private app. We collect only what we need to run the service. We do not sell your data, show you ads, or share your responses with anyone other than your bonded partner. You can delete your account and all your data at any time from within the app.
1. Who We Are
Tether ("Tether," "we," "our," or "us") is a mobile application operated by Timothy Williams, an individual developer based in North Carolina, USA. Tether can be reached at privacy@tetherco.app.
This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use the Tether iOS and Android applications and related services (collectively, the "Service"). Please read it carefully. If you do not agree with the terms of this policy, do not use the Service.
2. Information We Collect
2.1 Information You Provide Directly
- Account information: When you create an account, we collect your display name, email address, and date of birth. Your date of birth is used to verify age eligibility and to tailor age-appropriate content within the app. It is never shared publicly.
- Prompt responses: Your answers to shared prompts — which may be submitted as text, voice recordings, photos, drawings, or song selections. These are private and visible only to you and your bonded partner.
- Bond nicknames: Optional nicknames you assign to your bonds.
- Profile information: Any profile details you choose to add.
- Communications: If you contact us by email, we retain that correspondence.
2.2 Information Collected Automatically
- Device information: Device model, operating system version, unique device identifiers, and mobile network information.
- App usage data: Events such as completing onboarding, creating a bond, sharing a reveal card, or installing the home screen widget. These events are anonymized and do not include the content of your responses.
- Log data: IP address, app crash reports, and diagnostic information collected to maintain service reliability.
- Push notification tokens: A device token used to deliver push notifications. You can revoke this permission at any time in your device settings.
2.3 Information from Third Parties
- Sign in with Apple: If you choose this option, Apple provides a verified email address and a unique identifier. We do not receive your Apple ID password.
- Sign in with Google: If you choose this option, Google provides your name, email address, and profile picture. We do not receive your Google password.
We do not collect your phone number, precise geolocation, device contacts, browsing history, or financial information.
3. How We Use Your Information
| Purpose | Data Used |
| Create and manage your account | Email, display name, date of birth, authentication token |
| Deliver the core Tether experience | Prompt responses, bond data, profile information |
| Provide age-appropriate prompts | Date of birth (to determine an age band) |
| Send push notifications | Push notification token, account ID |
| Prevent fraud and enforce our Terms of Service | Account info, device identifiers, usage patterns |
| Detect and remove illegal content (including CSAM) | Uploaded images and media, processed by automated systems |
| Improve the app through aggregate analysis | Anonymized usage events via PostHog |
Microsoft PhotoDNA (Privacy Policy) — automated scanning of uploaded images against known child sexual abuse material hashes.
Apple (iTunes Search API) (Privacy Policy) — song search. Only your search text is sent; no account or personal data.
Spotify (Privacy Policy) — optional, and only if you choose to connect your Spotify account for song search.
| Respond to support requests | Email correspondence |
| Comply with legal obligations | Account data as required by law |
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, our legal bases for processing your personal data are:
- Contract performance: Processing necessary to provide the Service you signed up for.
- Legitimate interests: Improving the Service through anonymized analytics, preventing fraud, and maintaining security.
- Legal obligation: Complying with applicable laws, including mandatory reporting of CSAM.
- Consent: Sending push notifications (you may withdraw consent at any time via device settings).
5. How We Share Your Information
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
5.1 With Your Bonded Partner
By design, your bonded partner can see your display name, your prompt responses (once both of you have answered), and bond milestones. You control who you bond with and can dissolve any bond at any time.
5.2 Service Providers
- Supabase (Privacy Policy) — database, authentication, and server-side functions. SOC 2 Type II certified.
- PostHog (Privacy Policy) — product analytics. Anonymized usage events only; response content is never included.
- Expo / Expo Push Notification Service (Privacy Policy) — push notification delivery.
- Apple (Privacy Policy) — iOS distribution, Sign in with Apple, APNs.
- Google (Privacy Policy) — Android distribution, Sign in with Google, FCM.
5.3 Legal Requirements and Safety
We may disclose your information to: (a) comply with a legal obligation or government request; (b) protect the rights, property, or safety of Tether, our users, or the public; or (c) report illegal content, including CSAM, to NCMEC and law enforcement as required by 18 U.S.C. § 2258A.
5.4 Business Transfers
If Tether is acquired or its assets transferred, your data may be part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
6. Data Retention
We retain your personal data for as long as your account is active. When you delete your account:
- Your profile, display name, date of birth, and prompt responses are permanently deleted within 30 days.
- Your email address is retained for up to 90 days for fraud prevention, then deleted.
- Anonymized, aggregated analytics data may be retained indefinitely.
- Log data for security purposes is retained for up to 12 months.
- Content flagged as apparent CSAM, and related records, are preserved for 90 days as required by law (18 U.S.C. § 2258A) and reported to NCMEC. Law enforcement may request an extension of this period.
- If you block someone, we retain that person's email address even after their account is deleted, so that the block remains effective if they register again. It is kept for as long as your block stands.
7. Data Security
- All data in transit is encrypted using TLS/HTTPS.
- All data at rest is encrypted using AES-256 on Supabase infrastructure.
- Access to your prompt responses is restricted by row-level security — only you and your bonded partner can read your responses, and only after you have both answered.
- Authentication tokens are stored securely and never exposed in plaintext.
No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
8. Children's Privacy
Tether is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe we may have information from or about a child under 13, please contact us at privacy@tetherco.app.
9. Your Privacy Rights
9.1 All Users
- Access: Request a copy of the personal data we hold about you.
- Correction: Update inaccurate information in your profile within the app.
- Deletion: Delete your account from Settings → Delete Account, or by emailing privacy@tetherco.app.
- Opt out of push notifications: Disable at any time in your device settings.
9.2 California Residents (CCPA / CPRA)
California residents have the right to Know, Delete, Correct, and Opt Out of Sale or Sharing. We do not sell or share your personal information for cross-context behavioral advertising. To exercise your rights, email privacy@tetherco.app with the subject line "California Privacy Request." We will respond within 45 days.
9.3 EEA and UK Residents (GDPR / UK GDPR)
EEA and UK residents may access, correct, erase, restrict, or port their data, and may withdraw consent or lodge a complaint with their local supervisory authority. Email privacy@tetherco.app. We will respond within 30 days.
10. International Data Transfers
Tether is operated from the United States. By using the Service, you consent to your data being transferred to, stored, and processed in the United States. We use contractual safeguards where required.
11. Push Notifications
With your permission, we send push notifications to inform you of new prompts, your partner's activity, and pending bond invites. You can turn them off at any time in your device's Settings app without affecting core Tether features.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the date at the top and, where appropriate, by in-app notification or email. Continued use after changes become effective constitutes acceptance of the revised policy.
13. Contact Us