Privacy Policy

Last updated: July 21, 2026

The short version

Tendi is built to keep your journal private.

What the Tendi app stores locally

Tendi stores the data you create in the app on your device, including mood entries, notes, activities, photos, voice notes, Important Days, settings, reminders, import/export state, and insights calculated from your entries. This data is used to run the app and show your journal, charts, summaries, marked dates, and reminders.

Tendi does not send your journal entries, note text, photos, voice notes, or local insight details to Tendi servers.

Widgets and Apple Watch complications use small cached summaries for quick check-in state. When App Lock is off, iPhone widgets may show your total check-in count and the last logged mood or emoji; App Lock hides those widget summaries. A watch-face complication may show whether you logged today and decorative mood-derived color, but it does not show the mood value, totals, notes, prompts, transcripts, photos, HealthKit details, exact locations, or other private journal content.

Optional iCloud sync

If you enable iCloud sync, Tendi uses Apple's servers through your personal iCloud account. Your data syncs between your Apple devices through Apple's infrastructure. Tendi does not receive, host, or read your synced journal data.

You can turn iCloud sync off in Tendi settings. You can also manage iCloud data through Apple's iCloud settings.

HealthKit

If you grant Apple Health access, Tendi can read supported HealthKit data such as sleep, steps, and workouts for local insights, and can write supported state-of-mind samples where available. If you turn on Cycle Insights, Tendi also requests access to menstrual-flow records for local insights.

HealthKit access is optional and controlled by iOS. HealthKit data is processed on device. Tendi does not send HealthKit samples to Tendi servers or analytics providers.

Photos, voice notes, and imports

Photos, voice notes, and imported journal data are stored locally in your device's protected app storage. If iCloud sync is enabled, this content may sync with Apple's servers through your personal iCloud account. Tendi does not upload this content to Tendi servers.

Journaling Suggestions

If you use Apple's Journaling Suggestions picker, Tendi may process details you select, such as reflection prompts, media references, activity context, workout summaries, place names, and photos, on device. Only details you add or keep—such as selected activities, saved photos, or a prompt—become part of the saved entry. Saved details remain local unless you choose to export them or enable iCloud sync.

Optional analytics

Tendi uses TelemetryDeck for optional app analytics. Analytics are off by default. If you enable them, Tendi may send categorical product-interaction events and a random, resettable app analytics identifier so we can understand which app areas are used and whether errors occur.

Analytics events do not include journal text, mood notes, photos, voice recordings, HealthKit samples, email addresses, precise location, or advertising identifiers. Analytics are not used for tracking or advertising.

This website

The Tendi website does not include client-side analytics scripts. Cloudflare may process limited operational data for hosting, security, caching, and abuse prevention.

If you join the launch-updates list, your email address is sent to Buttondown so we can email you about Tendi's launch. We use that address for launch updates only. You can unsubscribe using the link in any email.

The website includes an optional Buy Me a Coffee link. If you choose to leave a tip, you leave tendijournal.app and Buy Me a Coffee handles the payment under its own terms and privacy policy.

Feedback site

The feedback link opens a separate public Fider Cloud site operated by Northern App Labs Ltd and hosted through Amazon Web Services in the United States. If you submit feedback or sign in there, Fider and any authentication provider you choose may process feedback content, account or authentication information, and operational data such as your IP address and device or browser details.

Fider's current privacy policy, processor list, and security policy describe its practices. Do not include journal text, health information, photos, exact locations, or anything private in public feedback.

Support emails and bug reports

If you contact us by email or send an in-app bug report, we receive your email address and any information you choose to include. In-app bug reports prefill the app version, build number, device model, and operating-system version so we can troubleshoot the issue; you can edit the message before sending it.

Please do not include sensitive journal content unless you want us to see it. Product and app support goes to support [at] tendijournal [dot] app. Privacy, security, and legal matters go to hello [at] twodesks [dot] app.

Crisis support resources

If you choose to open crisis support resources in the app, Tendi may open Find a Helpline in your browser. Find a Helpline is operated by a third party and may process information according to its own privacy policy.

Tendi does not send your journal content, mood entries, HealthKit data, photos, voice notes, or analytics identifiers to Find a Helpline.

Third-party services

Tendi currently uses Apple platform services, including iCloud/CloudKit, HealthKit, and Journaling Suggestions where you enable or invoke them; TelemetryDeck for optional app analytics; and Find a Helpline for user-initiated crisis support resource links. The website is hosted through GitHub Pages with Cloudflare in front of tendijournal.app. Buttondown processes email addresses submitted through the website launch-updates form. Buy Me a Coffee handles optional website tips if you choose to leave one. Fider operates the separate public feedback site, including feedback submission and optional account or authentication features.

Journal content is never sent to Buttondown, Buy Me a Coffee, Find a Helpline, Fider, or the launch-updates list by the Tendi app.

We do not share Tendi journal content with advertising networks or data brokers.

Your choices

Who we are

Tendi is built by Two Desks. Product and app support: support [at] tendijournal [dot] app. Privacy, security, and legal contact: hello [at] twodesks [dot] app. Public non-sensitive feedback: feedback.tendijournal.app.

Changes to this policy

If we change this policy, we will update the date at the top of this page.