Privacy Policy
Last updated: September 28, 2026
Version notice
Privacy behavior in Tendi 1.0 (17) to (20). Builds 17 to 19 were available through internal TestFlight, and Tendi 1.0 (20) is the external TestFlight candidate.
The build-specific privacy section below describes the protections in builds 17 to 20. It does not mean TestFlight build 16 or older installations have gained those consent, cache-filtering, warning, or on-device-AI protections.
The short version
Tendi is built to keep your journal private.
- Your mood entries, recordings and transcripts, notes, activities, photos, imports, exports, and insight data are stored on your device by default.
- You do not need a Tendi account to use the app.
- We do not sell your data, share it with advertisers, or use your journal content to train AI models.
- If you turn on iCloud sync, Tendi syncs through your personal Apple iCloud account. Tendi cannot read your iCloud data.
- Optional analytics are off by default and, if enabled, do not include journal text, mood notes, photos, voice recordings, HealthKit samples, or precise personal content.
What the Tendi app stores locally
Tendi stores the data you create in the app on your device, including mood entries, notes, activities, photos, voice notes, Important Days, settings, reminders, import/export state, and insights calculated from your entries. This data is used to run the app and show your journal, charts, summaries, marked dates, and reminders.
Tendi does not send your journal entries, note text, photos, voice notes, or local insight details to Tendi servers.
Widgets and Apple Watch complications use small cached summaries for quick check-in state. When App Lock is off, iPhone widgets may show your total check-in count and the last logged mood or emoji; App Lock hides those widget summaries. A watch-face complication may show whether you logged today and a color associated with the last logged mood. It does not show mood text, emoji, a numeric mood value, totals, notes, prompts, transcripts, photos, HealthKit details, exact locations, or other private journal content, but the color remains a visible mood signal.
Optional iCloud sync
If you enable iCloud sync, Tendi uses Apple's servers through your personal iCloud account. Your data syncs between your Apple devices through Apple's infrastructure. Tendi does not receive, host, or read your synced journal data.
You can turn iCloud sync off in Tendi settings. You can also manage iCloud data through Apple's iCloud settings.
HealthKit
If you grant Apple Health access, Tendi can read supported HealthKit data such as sleep, steps, and workouts for local insights, and can write supported state-of-mind samples where available. If you turn on Cycle Insights, Tendi also requests access to menstrual-flow records for local insights.
HealthKit access is optional and controlled by iOS. HealthKit data is processed on device. Tendi does not send HealthKit samples to Tendi servers or analytics providers.
Photos, voice notes, and imports
Photos, voice notes, and imported journal data are stored locally in your device's protected app storage. If iCloud sync is enabled, this content may sync with Apple's servers through your personal iCloud account. Tendi does not upload this content to Tendi servers.
Journaling Suggestions
If you use Apple's Journaling Suggestions picker, Tendi may process details you select, such as reflection prompts, media references, activity context, workout summaries, place names, and photos, on device. Only details you add or keep—such as selected activities, saved photos, or a prompt—become part of the saved entry. Saved details remain local unless you choose to export them or enable iCloud sync.
Optional on-device AI
On supported iPhones and languages, you can optionally turn on AI features that improve related Journal search results and create adaptive journaling prompts. This setting is off by default.
When it is on, Tendi may give Apple's on-device System Language Model limited details from the current check-in, selected Journaling Suggestions context, recent local summaries, or one saved entry. Depending on the feature, those details can include mood or energy bands, feeling and activity names, note text, completed voice transcripts, photo captions, and saved prompt text. AI inference runs on your iPhone. Tendi does not send model inputs or generated output to Tendi servers, TelemetryDeck, or a server-side AI provider, and does not use journal content to train AI models. Using journal content as model input does not change that content's existing storage, optional iCloud sync, export, backup, or sharing behavior.
Generated search themes are stored only in a local cache. They are not stored in Core Data, synced through iCloud, included in Tendi exports or iPhone backups, or sent to analytics. Turning On-device AI off stops new generation and makes Journal search ignore cached AI themes; it does not delete that cache. Delete All Data removes it. Generated prompts are optional. Selecting one can store it in the protected local composer draft before the entry is saved; that draft does not sync or enter exports or backups. Once the entry is saved, its prompt becomes journal content and follows the same storage, optional iCloud sync, export, and backup rules as other saved entry details. Tendi falls back to curated prompts when the on-device model is unavailable or disabled.
Optional analytics
Tendi uses TelemetryDeck for optional app analytics. Analytics are off by default. If you enable them, Tendi may send categorical product-interaction events and a random, resettable app analytics identifier so we can understand which app areas are used and whether errors occur.
Analytics events do not include journal text, mood notes, photos, voice recordings, HealthKit samples, email addresses, precise location, or advertising identifiers. Analytics are not used for tracking or advertising.
Privacy behavior in Tendi 1.0 (17) to (20)
Builds 17 to 19 were available through internal TestFlight. Build 18 added a clearer in-app on-device-AI disclosure. Builds 19 and 20 keep this privacy behavior and add restore and interface fixes; build 20 is the external TestFlight candidate. The general policy above continues to apply; this section describes the additional protections in these builds.
In Tendi 1.0 (17) to (20), analytics are optional and off by default. They measure permitted app interactions and technical operation. They do not send journal text, photos, recordings or HealthKit samples.
Tendi 1.0 (17) to (20) use TelemetryDeck for optional app-use and technical-operation measurements. You can use Tendi without enabling analytics. You can change your choice using the existing control in Settings or onboarding.
If you enable analytics, Tendi may send event names and coarse information about app navigation, completed check-ins, whether details were added, insight use, reminders, imports and exports, and technical outcomes. Some events include bounded counts or durations. They also carry random session identifiers, event times, app version and build, operating-system and platform information, distribution context, and the analytics SDK version. A random, resettable installation identifier is hashed before transmission and allows events to be associated over time. It is not your email address, an account ID or an advertising identifier. Hashing alone does not make every event anonymous.
Hide and Restore analytics record submitted actions without the insight category or subject. These counts do not confirm that the requested change was saved.
The app does not send journal text, selected mood or emotion values, activity names, search text, photos, recordings, transcripts, HealthKit samples, health measurements, cycle dates, or precise locations in these analytics payloads. Tendi does not use analytics for advertising or sell analytics data.
Analytics require a valid saved consent record for this installation. An old enabled setting by itself does not enable analytics. If no valid record exists, analytics stay off until you explicitly opt in; no additional prompt is forced. Valid current choices are preserved. Importing a Tendi backup preserves the current local analytics choice, including an opt-out, regardless of the backup's analytics setting.
Turning analytics off immediately blocks new analytics transmissions controlled by Tendi in the current session. When that choice is successfully saved, previously queued events become ineligible for transmission, including after restart or a later opt-in. If Tendi cannot save your choice, it displays a warning and a retry control. Transmissions remain blocked in that session, but the previous saved choice may return after restart. The warning remains when leaving onboarding or reopening Settings, and clears only after a successful save. Please retry before closing the app.
A request already released to the network may still complete. Turning analytics off prevents subsequent retries of withdrawn events; it cannot retract an earlier transmission. Turning analytics off or resetting the analytics identifier does not erase analytics already held by TelemetryDeck.
This version suppresses health and cycle setting and authorization events, health and cycle insight-category interactions, Health-history processing diagnostics, wellbeing-offer actions, breathing and grounding usage events, and crisis-resource-open events. It also suppresses the shared context-opening event in Week Review and the pattern library, including group routes. Matching events queued by an earlier version are excluded before dispatch, while permitted events in the same batch remain eligible subject to consent. General navigation, permitted insight use and journal-workflow events remain optional; they may still reveal app-use context.
HealthKit sample values and the local health-summary cache are not included in analytics payloads. Apple Health access and analytics consent are separate choices.
TelemetryDeck describes additional server-side hashing, rounding stored event times to the nearest hour and not storing incoming IP addresses for app analytics. We rely on its published technical description and privacy FAQ for those service-side practices. Events can still be associated through analytics and session identifiers. We do not join these analytics to identifiable support or customer records.
TelemetryDeck does not guarantee a deadline for deleting analytics in cold storage and says analytics may remain after we close our publisher account. We therefore do not promise a fixed analytics-deletion period. Disabling analytics or resetting its identifier in Tendi does not request deletion of data already held by TelemetryDeck. We cannot promise that historical analytics can be identified as yours or deleted individually. For privacy questions, contact hello [at] twodesks [dot] app.
This website
The Tendi website does not include client-side analytics scripts. Cloudflare may process limited operational data for hosting, security, caching, and abuse prevention.
If you join the launch-updates list, your email address is sent to Buttondown so we can email you about Tendi's launch. We use that address for launch updates only. You can unsubscribe using the link in any email.
The website includes an optional Buy Me a Coffee link. If you choose to leave a tip, you leave tendijournal.app and Buy Me a Coffee handles the payment under its own terms and privacy policy.
Feedback site
The feedback link opens a separate public Fider Cloud site operated by Northern App Labs Ltd and hosted through Amazon Web Services in the United States. If you submit feedback or sign in there, Fider and any authentication provider you choose may process feedback content, account or authentication information, and operational data such as your IP address and device or browser details.
Fider's current privacy policy, processor list, and security policy describe its practices. Do not include journal text, health information, photos, exact locations, or anything private in public feedback.
Support emails and bug reports
If you contact us by email or send an in-app bug report, we receive your email address and any information you choose to include. In-app bug reports prefill the app version, build number, device model, and operating-system version so we can troubleshoot the issue; you can edit the message before sending it.
Please do not include sensitive journal content unless you want us to see it. Product and app support goes to support [at] tendijournal [dot] app. Privacy, security, and legal matters go to hello [at] twodesks [dot] app.
Crisis support resources
If you choose to open crisis support resources in the app, Tendi may open Find a Helpline in your browser. Find a Helpline is operated by a third party and may process information according to its own privacy policy.
Tendi does not send your journal content, mood entries, HealthKit data, photos, voice notes, or analytics identifiers to Find a Helpline.
Third-party services
Tendi currently uses Apple platform services, including iCloud/CloudKit, HealthKit, Journaling Suggestions where you enable or invoke them, and Apple's on-device Foundation Models framework when you turn On-device AI on; TelemetryDeck for optional app analytics; and Find a Helpline for user-initiated crisis support resource links. The website is hosted through GitHub Pages with Cloudflare in front of tendijournal.app. Buttondown processes email addresses submitted through the website launch-updates form. Buy Me a Coffee handles optional website tips if you choose to leave one. Fider operates the separate public feedback site, including feedback submission and optional account or authentication features.
Journal content is never sent to Buttondown, Buy Me a Coffee, Find a Helpline, Fider, or the launch-updates list by the Tendi app.
We do not share Tendi journal content with advertising networks or data brokers.
Your choices
- Use Tendi without an account.
- Keep analytics disabled, or disable analytics later in Settings.
- Turn iCloud sync off in Settings.
- Manage HealthKit permissions in iOS Settings.
- Export your data from Tendi.
- Delete individual entries or use Delete All Data for app-managed Tendi data. Deleting the app removes its local copy but does not necessarily delete data already synced to iCloud; synced data may remain or resync and must be managed through Delete All and/or Apple's iCloud data controls as applicable.
- Ask us to delete launch-list or support-email records by contacting us.
Who we are
Tendi is built by Two Desks. Product and app support: support [at] tendijournal [dot] app. Privacy, security, and legal contact: hello [at] twodesks [dot] app. Public non-sensitive feedback: feedback.tendijournal.app.
Changes to this policy
If we change this policy, we will update the date at the top of this page.