We built Tether because we believe your contact information belongs to you — and so does your data. We don't sell your personal data as a source of revenue. We don't use it for advertising. We take care in overseeing how your data is accessed and what it is used for. Our philosophy: only collect and process what is necessary to operate and improve the Service, and treat your data the way we would want someone to treat ours.
Specific examples of how this philosophy is built into the product:
| Topic | Short Answer |
|---|---|
| Do we sell your data? | No |
| Do we use advertising networks? | No |
| Do we share data with third parties? | Only service providers necessary to operate the app (see Section 4.2) |
| Do we collect health data? | Only what you choose to enter for your contacts |
| How is phone number matching done? | Via salted SHA-256 hashing — raw numbers never compared between users |
| How is email matching done? | Via salted SHA-256 hashing (normalized) — raw emails never compared between users |
| Do we use product analytics? | Yes — PostHog (events-only, no contact data, opt-out in Settings); see Section 4.2 |
| Do we strip EXIF/GPS from uploaded photos? | Yes — uploaded images are re-encoded to a normalized JPEG, which strips embedded EXIF/GPS metadata before storage (see Section 2.5) |
| Do we verify your phone number is a real mobile? | Yes — at signup we run a carrier lookup via Telnyx to confirm your number is a mobile line. Voice-over-IP, landline, and toll-free numbers are refused. The carrier name, line type, and country are stored to avoid re-paying for repeat lookups. See Section 2.9. |
| Do we detect compromised devices? | Yes — the app refuses to operate on jailbroken or rooted devices (see Section 3.8) |
| What happens when you change your phone or email? | A 24-hour revocation window with notifications to old phone, old email, and other devices (see Section 3.7) |
| Can you export your data? | Yes — vCard, CSV, or JSON via Settings |
| Can you delete your account? | Yes — Settings > Account > Delete Account |
| Who is our EU/UK GDPR representative? | See Section 7.2 |
Welcome to Tether ("we," "our," or "us"). Tether is a privacy-first professional contact management application that automatically keeps your contact information current through live updates and intelligent synchronization across your devices.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (collectively, the "Service"). Please read this policy carefully. If you do not agree, please do not access the Service.
We reserve the right to make changes to this Privacy Policy at any time. We will alert you about material changes by updating the "Last Updated" date and, for significant changes, by providing prominent in-app notice, email notification, or both. Your continued use of the Service after the effective date of any revised Policy constitutes acceptance.
Account Information:
phone_verified_at, email_verified_at) — see Section 2.7locked_at, deleted_at, deletion-cooling-period status)Contact Data: You may choose to store the following information about your contacts:
shared_family_members (a list of additional family-member sketches with name, relationship, contact type, and an optional link to a Tether user); contact-to-contact family relationshipsisLinked, linkedUserId, connectionStatus (active or stale)Event Data: When you create or participate in events:
Privacy Circle Assignments:
Directory and Shared Circle Data:
Communication Preferences:
Device Information:
Usage Data:
Technical Data:
Contact Import Services: With your explicit permission, we may import contact data from:
devicegooglemicrosoftvcardcsv or event_spreadsheetpast_event_invitescannetworkmanualImport lineage is preserved on each contact record (import source, batch ID, and fingerprint) for deduplication, undo, and audit purposes.
When you authorize these integrations, we receive all contact information stored in those services, metadata about when contacts were created or last modified, and contact groupings and labels. We only request the minimum permissions necessary to provide our services. We do not access your emails, documents, or other data unrelated to contact management. Calendar access is a separate, optional feature with its own permission — see Section 2.10.
Data About You from Others: Just as you may provide information about your contacts when you sync your device contacts, others may provide limited information about you when they do the same. For example, another Tether user may save your phone number in their address book, and that information may be used to suggest a mutual connection between you, subject to the Autoconnect policies in Section 3.1.
Contact Import Authentication: When you authorize Google or Microsoft for contact import, we receive basic profile information to authenticate the connection, a provider-specific user identifier, and an account timestamp. These connections are used solely for contact import — they are not used for Tether authentication (Tether uses Phone OTP only).
If you enable biometric authentication (Face ID, Touch ID, fingerprint): we do not collect, store, or transmit your biometric data; authentication is processed entirely on your device using the secure enclave; we only receive a success/failure signal; your biometric templates never leave your device.
When you upload photos or images to the Service (including profile photos, contact photos, event photos, and life-update photos), the image is automatically re-encoded to a normalized JPEG before storage. This re-encoding strips embedded EXIF metadata — including GPS coordinates, camera make and model, device serial numbers, and timestamps — so that metadata is not retained on our servers or shared with other users.
Photos you upload may be visible to other users in accordance with your privacy-tier and circle settings. Note that metadata stripping happens at upload only; if you share an original image file outside Tether by other means, that copy may still contain its embedded metadata.
We collect approximate location data derived from your IP address for security and fraud prevention purposes. This is imprecise location (city or region level) and is not GPS location. We do not collect precise GPS location from your device unless you explicitly turn on our optional location-sharing feature, which shares your current coordinates with the specific connections you choose. This sharing is foreground and user-initiated only: coordinates are sent while you have sharing active, and we do not track your location in the background. You can stop sharing at any time. If you choose to include a physical address in your profile or contacts, that address data is stored and subject to your privacy circle permissions.
Each account in the Service has, at any point in time, zero or one "verified" status for the user's email address and zero or one "verified" status for the user's phone number. Verification is performed by sending a one-time code to the identifier and requiring the user to enter that code in the app.
We process verified-identifier status for the following purposes:
The timestamps email_verified_at and phone_verified_at are stored on your account record. Verification status does not result in publication of your email or phone to other users (Autoconnect and the discovery handshake operate on hashes, not raw identifiers — see Section 3.1).
Being listed as someone's family member. If another Tether user lists you as a family member on their contact card and you are a Tether user, the people they share that card with may see that you are on Tether and may send you a connection request. As with all connection requests, this is governed by your connection-request settings, and you can decline any request. Your phone number and email address are never disclosed to those people through the other user's card.
Each time the app launches, it queries a device-integrity signal from the operating system and from the jail-monkey native module. The signal is a Boolean indicating whether the device is jailbroken (iOS) or rooted (Android). We do not store the signal server-side and we do not transmit the signal to our analytics or error-tracking providers; the signal is evaluated locally and, where positive, causes the app to render a lockout screen and refuse to operate. See Section 3.8 for how we use this signal and Section 2.10 of the Terms of Service for your obligations.
Early-access request form (tetherup.app/request-access). During our soft-launch period, anyone may submit a request for access by entering their name, mobile phone number, email address, and (optionally) where they heard about us. We also record the request's IP address and user-agent string for abuse prevention. Until an account is created, this information is stored in our access_requests table with the request's review status (pending, approved, or denied). When you create an account using the same phone number, the request remains in our records as part of the eligibility audit trail. You may request deletion of an unfulfilled request at any time by emailing [email protected].
Phone-number carrier verification. Before sending an SMS one-time code to a new phone number, we run a carrier lookup via Telnyx (see Section 4.2) to confirm the number is served by a recognized mobile carrier. We refuse to send codes to voice-over-IP, landline, and toll-free numbers because those line types are the dominant vector for automated account-creation abuse. The carrier name, line type (e.g., mobile, voip, landline), country code, and validity flag returned by Telnyx are stored in our phone_intel table keyed by the SHA-256 hash of the phone number — once per number, lifetime — so we do not re-incur a paid lookup if you later change phones or sign back up. This data is not linked to your account record; it is keyed by phone-number hash so it survives account deletion (the carrier facts are about the line, not about you). If you believe a legitimate mobile number was misclassified, email [email protected] and we will manually allow it.
If you enable Tether's calendar availability feature, the app reads your device calendar — using the calendar permission you grant your operating system — to determine when you are busy or free. We store only the start and end times of your busy periods on our servers; we do not receive or store event titles, locations, attendee lists, descriptions, notes, or any other content from your calendar entries. Calendar entries are read on your device, and only the resulting busy/free time ranges are transmitted to us.
When you enable the calendar availability feature, your busy/free times are shared by default with the circles you create from Tether's standard templates — Close, Community, and Professional circles each include calendar availability in their default shared fields. You can change what any individual circle sees through that circle's Edit Permissions screen, stop sharing with a circle, or turn off calendar access entirely in the app's settings, at any time. Circles see time ranges only — never the underlying calendar entries. Turning the feature off deletes the busy-block data we have stored for you. We do not sell your calendar data, share it with third parties, or use it for advertising.
.mobileconfig configuration profile that enables iOS to read your Tether contacts as a read-only address-book source. The token expires 30 minutes after issuance and is consumed atomically on first use; once consumed (or expired), the token cannot be reused. We do not push contacts to your device-native address book; CardDAV is a one-way read from Tether to your device.We do not make solely automated decisions about you that have significant legal or similarly significant effects, except for security measures (such as rate limiting or account suspension for abuse), which you may appeal by contacting [email protected].
We do not use your personal contact data for advertising targeting. We do not sell your data or share it for cross-context behavioral advertising.
When you change the phone number or email address associated with your account, we process additional categories of data for security purposes:
(a) Pending-change records. We create a short-lived "pending account change" record containing: the change type (phone or email), the prior identifier, the new identifier, an "expires at" timestamp 24 hours in the future, and a one-way hash (SHA-256) of a one-time revocation token. The raw token is not stored — only its hash — so a database snapshot cannot be used to forge a revocation link.
(b) Multi-channel notifications. We attempt to deliver security notifications on a fire-and-forget, best-effort basis. The set of channels depends on the change type:
For a phone-number change, we fan out to up to three channels: (i) SMS to the prior phone number (via Telnyx); (ii) email to your verified email address, if any (via Resend); and (iii) push notifications to any other devices currently signed in to your account (via Expo Push).
For an email-address change, we fan out to up to four channels: (i) email to your prior verified email address, if any (via Resend); (ii) email to the new email address (via Resend); (iii) SMS to your verified phone number, where applicable (via Telnyx); and (iv) push notifications to any other devices currently signed in to your account (via Expo Push).
Each notification contains a masked summary of the change and a single-use revocation link. We do not guarantee delivery of any individual notification. SMS notifications to the prior phone number depend on the availability of our SMS provider and on regulatory approvals (including, currently, Toll-Free Verification with the carriers); if the SMS provider is unavailable or unconfigured, the SMS leg silently fails while the other channels continue.
(c) Session revocation. A phone change triggers a global sign-out of all sessions across all devices (including the device on which you initiated the change), implemented by calling Supabase Auth's signOut(user_id, 'global'). An email change triggers a sign-out of all other devices but, by design, preserves the session on the device from which you initiated the change.
(d) Revocation processing. If the revocation link is clicked within 24 hours, we (i) revert the change, (ii) lock the account by setting accounts.locked_at, and (iii) broadcast a Realtime force_logout event followed by a deferred global sign-out, in that order, so subscribed clients receive the broadcast before their sessions are terminated.
(e) Cleanup. Terminal pending-change records (those that have committed or been revoked) are purged by the daily maintenance job, no fewer than 30 days after the terminal event. Live (in-window) records are preserved until terminal.
(f) Audit. Each pending change, notification attempt, and revocation event is logged for security audit purposes. Audit logs are retained per the schedule in Section 6.1.
(g) Source-of-authentication gate for email changes. If you are signed in via an email-only OTP session, the Service refuses to allow you to change your email until you sign in via phone OTP. This gate exists to defeat attackers who have compromised your email but not your phone.
We process this data on the legal bases of contract performance and legitimate interest in the security of the Service. You cannot opt out of the 24-hour revocation window, multi-channel notification fan-out, or session-revocation behaviors; these are core security features of the Service.
At app launch, the Service evaluates device-integrity signals (jailbreak/root detection) via the jail-monkey native module. If the device is detected as compromised, the app renders a lockout screen and does not function. The Boolean result of the check is not transmitted off-device, is not stored on Tether's servers, and is not sent to our analytics or error-tracking providers. We process this signal on the legal basis of legitimate interest in the security of the Service and the protection of contact data stored on the device.
We may, in the future, add additional integrity signals (e.g., emulator detection, debug-build detection, OS-version freshness checks). Such additions will be reflected in an update to this Section.
We operate a server-side process called "mutual contact auto-link," which periodically scans for cases in which two users have each other's verified phone numbers (or, where supported, verified emails) saved in their address books, using salted SHA-256 hashes for the comparison. When a mutual match is found and the relevant configuration toggle is set to auto, the Service automatically creates a connection between the two users, subject to each user's default tier setting. When the toggle is set to suggest, the Service queues a suggestion for the user to confirm. When the toggle is set to off, no auto-link is performed.
You can adjust your participation in auto-link in Settings > Privacy > Connections, and you can remove any individual connection that was created via this process at any time.
With Other Tether Users (Sharing Tier Settings): When you connect with another Tether user, you control what they see through your sharing-tier settings. There are three tiers — Close, Community, and Professional — and each has a default set of fields that are shared. You can override the defaults on a per-circle basis from Settings > Privacy > Tier Defaults. The default-shared fields for each tier, as currently configured in the app, are:
The defaults are encoded in apps/mobile/src/constants/circleTypeDefaults.ts; they may be revised in future releases of the Service, in which case this Section will be updated.
Family members on your card. When "family members" is among the fields you share with a circle, the connections in that circle may see, for each family member you have linked: their name, your relationship to them, and contact type. For a family member who is not a Tether user, this may also include that person's primary phone number and email address as stored in your address book. For a family member who is a Tether user, their phone and email are never shared through your card — instead, your connection may see that the person is on Tether and may send them a connection request directly (subject to that person's own connection-request settings). Children's direct contact details (phone and email) are never shared through your card. Because this shares information about other people, you are responsible for having any consents required by law to do so (see our Terms of Service).
Unassigned contacts. When a new connection is created and you have not yet assigned the connected user to a circle, a separate "Unassigned Defaults" setting determines what is shared until you make an assignment. The Unassigned Defaults are configured in Settings > Privacy > Tier Defaults and are distinct from the Community tier defaults above.
Data on Disconnect: When you block or remove a connection, all information received through that connection is automatically removed from your device. Live data is treated as "on loan" and does not persist after disconnection.
Events and Co-hosts: Co-hosts can see only the display name and email address you attached to each guest invitation (captured as a per-RSVP snapshot at invite time) — not any other information from your private address book. When a host or co-host reuses a past event's guest list for a future event, guests not already in the inviter's address book may be saved as new contacts from the snapshotted name and email, tagged with import source past_event_invite.
We share information with third-party service providers who perform services on our behalf. All service providers are contractually required to use your information only for specified services, implement appropriate security measures, comply with applicable data protection laws, and not sell or share your information with third parties.
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase Inc. | Database, auth, file storage, real-time sync, edge functions (AWS, United States) | All user data stored in database |
| Cloudflare, Inc. | Edge network, DNS, web/landing pages, CardDAV reverse-proxy, and serverless workers (e.g., the RevenueCat webhook relay) | HTTP request metadata, web analytics beacons, CardDAV-profile delivery |
| Sentry | Error tracking and performance monitoring (PII auto-redacted before transmission) | Crash logs, error events (no raw contact data) |
| PostHog | Product analytics (events-only, opt-out in Settings; no contact data; PII denylist enforced at the SDK boundary) | Event names, allowlisted user traits (subscription tier, signup date, contact count, circle count, cohort week), Supabase user ID as distinct_id, app version, environment |
| RevenueCat | Subscription billing via App Store / Google Play, webhook fan-out to our backend | Subscription status, purchase events, billing issue events |
| Telnyx | SMS OTP delivery; SMS notification to the prior number when phone changes; pre-signup carrier lookup (Number Lookup API) to confirm the number is a real mobile line (see Section 2.9) | Phone number, OTP body, security-notification body, carrier-lookup query (phone number only — response cached locally) |
| Resend | Transactional email (event invitations, event reminders, RSVP notifications, circle invites, contact-card broadcasts, vCard email exports, phone-change and email-change security notifications, and similar) | Email addresses, sender/recipient metadata, and the content you choose to send |
| Expo | Push notification delivery (Expo Notifications service) | Push tokens, notification payloads |
| Microsoft | Contact import from Outlook / Microsoft 365 via OAuth 2.0 + Microsoft Graph API — only when you choose to connect a Microsoft account | Your Microsoft sign-in (OAuth) and the Outlook contacts you import via the Contacts.Read scope: names, phone numbers, emails, addresses, and notes |
| jail-monkey (on-device) | Device-integrity check (jailbreak / root detection) | None — the check runs locally and the result is not transmitted off-device |
| Apple Inc. / Google LLC | App distribution, in-app purchase, push-notification transit; contact import (Apple Contacts / Google People API on connect); map tiles and address geocoding when you view or save a location | Per their respective developer terms and privacy policies; for contact import, the contacts you choose to import; for maps, approximate location/viewport coordinates |
We use the following analytics and monitoring tools:
Sentry (Error & Performance Monitoring): Sentry receives crash reports, error events, and performance traces. Our Sentry configuration automatically redacts PII (names, phone numbers, email addresses, contact data) before transmission. No personally identifiable contact data is transmitted. Governed by Sentry's Data Processing Agreement.
PostHog (Product Analytics — Events Only): PostHog receives product-analytics events (for example, when a user views the paywall, completes onboarding, or imports contacts). Our PostHog integration enforces a PII denylist at the source-code level: properties whose keys are email, phone, phoneNumber, phone_number, firstName, lastName, fullName, displayName, middleName, contactName, contact_name, address, street, city, postalCode, zip, avatarUrl, password, token, accessToken, refreshToken, secret, message, notes, or note are dropped before send, and only primitive values (strings, numbers, booleans) are transmitted. Identification uses your Supabase user ID as a stable opaque distinct_id together with a small allowlist of traits: subscription tier (free / tether_plus / lifetime / unknown), signup date, contact count, circle count, and cohort week (ISO YYYY-WW). PostHog session replay is not enabled and we do not capture screen contents. PostHog event capture is gated on a privacyStore.settings.analyticsOptedOut toggle in the app — when you opt out, all identify and capture calls become no-ops at the SDK boundary and the SDK's own opt-out machinery is also engaged. Default hosting region is PostHog's U.S. cloud (us.posthog.com); the integration is governed by PostHog's Data Processing Agreement.
RevenueCat (Subscription Analytics): RevenueCat receives purchase events and subscription status updates necessary to process transactions and provide subscription analytics (conversion rates, churn, subscription lifecycle events). No contact data is shared with RevenueCat beyond what is necessary to process transactions.
Cloudflare Web Analytics (Web Properties): Our tetherup.app web properties use Cloudflare's privacy-respecting RUM analytics, which does not use cookies and does not build behavioral user profiles. No data from the mobile app passes through Cloudflare Web Analytics.
We do not use Google Analytics, Facebook Pixel, TikTok Pixel, Meta Audience Network, or any advertising-oriented analytics or attribution SDK in the Tether mobile app. We do not place advertising cookies or tracking pixels on our website. We do not use Apple's App Tracking Transparency-gated identifiers (IDFA) and the app declares "No, app does not use advertising ID" on Google Play.
We do not sell your personal data to advertisers. We do not share your personal data with advertising networks for behavioral targeting. We do not receive compensation for your data from any advertising partner. Tether generates revenue through subscription fees only.
If Tether is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of company assets, your information may be transferred as part of the transaction. We will provide at least 30 days' notice before your information becomes subject to a materially different privacy policy.
We may disclose your information if required by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, national security or law enforcement requests). We may also disclose when we believe in good faith that disclosure is necessary to comply with applicable law, enforce our Terms, protect against fraud or security risks, or protect the rights or safety of Tether, our users, or the public.
When permitted by applicable law and not prohibited by the legal demand itself, we will: provide you with prompt notice of any legal demand for your data; review requests for legal sufficiency; and, where appropriate, challenge overbroad or improper requests.
We may disclose personal information to professional advisors (lawyers, auditors, bankers, insurers) where necessary in the course of professional services they render to us, subject to confidentiality obligations.
We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you, for business purposes including research, service improvement, and industry reporting.
We may share your information for any other purpose with your explicit, informed consent.
Encryption:
Authentication Security:
supabase.auth.signInWithOtp flow and the email-verify-otp edge function), and is the recovery path if you lose access to your phone numberAccess Controls:
Cross-User Isolation (Wipe-on-Logout): On sign-out, we execute a three-step wipe of all locally stored user data from your device, including all application state, service caches, and encrypted storage keys. This ensures no contact data survives a logout and eliminates any possibility of a subsequent user on the same device accessing prior user data.
Operational Security:
jail-monkey native module; if so, the app renders a lockout screen and refuses to operate. See Section 3.8.In the event of a security breach involving your personal information, we will:
If we determine that a breach does not require notification under applicable law, we will retain records of our assessment.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
| Data Category | Retention Period |
|---|---|
| Contact data | While account is active; until contact is deleted |
| Account information | While account is active |
| Sync history | 90 days |
| Change logs (audit) | 90 days |
| Soft-deleted contacts | 60 days, then auto-hard-deleted (daily maintenance job, 09:31 UTC). A contact you merged into another contact is kept for as long as that surviving contact exists, so the merge stays reversible; it is hard-deleted on a later run of the same job once the surviving contact is itself deleted. |
| Dead-letter queue (failed sync ops) | 30 days, then auto-purged |
| Abandoned sync transactions | Cleaned daily (2:00 AM UTC) |
| Event RSVP records | Per subscription tier retention period; deleted with account |
| Push tokens | Until device access revoked or account deleted |
| Error/crash logs (Sentry) | 90 days (PII redacted) |
| Product-analytics events (PostHog) | Per PostHog Cloud retention (currently 7 years for events; subject to PostHog's then-current retention settings) — opt-out at any time |
| CRM communication logs | While account is active |
| Health sharing consents | Retained as immutable audit records per legal requirements |
| Pending account-change records (phone / email / sign-in notice) | Live records: up to 24 hours (revocation window). Terminal records (committed or revoked): purged by the daily maintenance job, no fewer than 30 days after the terminal event. |
| Revocation-link tokens | Stored only as SHA-256 hashes; deleted when the parent pending-change record is purged. |
| Account-lockout records | While account is locked; preserved in audit log after recovery for security and forensics purposes |
| Transactional records | 7 years (tax and accounting purposes) |
When you request account deletion (Settings > Account > Delete Account):
Immediate Actions:
After 30-Day Cooling Period:
execute_pending_deletions)Data We Retain After Deletion:
Most data is permanently erased at the end of the 30-day cooling period. A limited set of records is deliberately retained for the lawful purposes below. Where a record is kept, it is de-identified wherever de-identification still serves the purpose:
Third-Party Processor Residuals. Data already transmitted to our subprocessors before you deleted your account is deleted according to each subprocessor's own retention schedule, which we do not directly control. On deletion we delete the subscription-processor customer record associated with your account (RevenueCat), and we record the residual-cleanup status for each processor. Residuals may include: SMS and OTP delivery logs (Telnyx), email delivery logs (Resend), error and performance events that reference your account identifier (Sentry), product-analytics events keyed to your account's opaque identifier (PostHog), and transient push-delivery receipts (Expo). These age out on each provider's own schedule. See Section 4.2 for the full subprocessor list.
Tether reserves the right (but is not currently obligated, and at this time has not implemented an automated mechanism) to send a re-engagement or deletion-warning notification to accounts that have shown no sign-in or sync activity for an extended period — a period we currently anticipate to be twelve (12) months or more. If we elect to send such a notification and the account holder does not respond within thirty (30) days of the notification, we may, at our discretion, delete the inactive account and its associated data subject to the retention exceptions in Section 6.2.
We will provide additional detail about any automated inactive-account-deletion procedure in this Section once such a procedure is implemented. Until then, this provision should be read as a reservation of right rather than a description of a current automated practice. If you wish to confirm the status of your account, or to be notified before any deletion, please contact [email protected].
Regardless of your location, you have the following rights:
Legal Bases for Processing:
| Processing Activity | Legal Basis |
|---|---|
| Authentication, sync, contact management | Contract performance (Article 6(1)(b)) |
| Fraud prevention, security, analytics | Legitimate interests (Article 6(1)(f)) |
| Marketing communications, optional features | Consent (Article 6(1)(a)) |
| Legal obligations compliance | Legal obligation (Article 6(1)(c)) |
Additional GDPR Rights:
Data Transfers: Your data may be transferred to and processed in countries outside the EEA/UK, including the United States. We ensure adequate safeguards through Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, and other legally approved transfer mechanisms.
EU Representative (Article 27 GDPR): [Designation in progress — contact [email protected] for all GDPR inquiries until a formal representative is confirmed]
UK Representative (Article 27 UK GDPR): [Designation in progress — contact [email protected] for all UK GDPR inquiries]
Categories of Personal Information We Collect:
California Privacy Rights:
Your Privacy Choices: You may exercise your privacy choices at tetherup.app/privacy-choices or by emailing [email protected].
Global Privacy Control (GPC): We recognize and honor the Global Privacy Control (GPC) signal to the extent required by California law and other applicable laws. If you use a browser or device that broadcasts a GPC signal when accessing tetherup.app, we will treat that signal as a valid opt-out of sale/sharing for cross-context behavioral advertising.
Do Not Sell or Share: We do not sell personal information to third parties. We do not share personal information for cross-context behavioral advertising. These practices will not change without providing you with at least 15 days' advance notice and the ability to opt out before they take effect.
Shine the Light: We do not share personal information with third parties for their direct marketing purposes. California residents with questions may contact [email protected].
Residents of the following states have privacy rights under applicable state law, which we honor to the extent required:
| State | Law | Rights |
|---|---|---|
| Texas | TDPSA | Access, correct, delete, portability, opt-out of sale/targeted advertising, appeal |
| Virginia | VCDPA | Access, correct, delete, portability, opt-out of sale/targeted advertising/certain profiling, appeal |
| Colorado | CPA | Access, correct, delete, portability, opt-out of sale/targeted advertising/certain profiling, appeal |
| Connecticut | CTDPA | Access, correct, delete, portability, opt-out of sale/targeted advertising, appeal |
| Montana | MCDPA | Access, correct, delete, portability, opt-out of sale, appeal |
| Utah | UCPA | Access, delete, portability, opt-out of sale/targeted advertising |
| Iowa | ICDPA | Access, delete, portability, opt-out of sale |
| Other enacted state laws | Various | Similar rights as required |
To exercise rights under any applicable state law, email [email protected]. We will verify your identity before fulfilling requests. We will respond within the timeframe required by applicable law. You may appeal our decision on a request by responding to our decision notice or emailing [email protected] with the subject line "Privacy Rights Appeal."
Brazilian residents have rights under the Lei Geral de Proteção de Dados (LGPD), including rights to confirmation, access, correction, anonymization, portability, deletion, information about sharing, and revocation of consent. We process your personal data as the controller for purposes described in this Policy. Legal bases include consent (optional features), contract performance (core services), legitimate interest (security and fraud prevention), and legal obligation. Contact [email protected] for LGPD inquiries.
Australian users have rights under the Privacy Act 1988 and Australian Privacy Principles (APPs). We are committed to the APPs. We will not send unsolicited electronic messages except as permitted by the Spam Act 2003. Contact [email protected] for Australian privacy inquiries.
Canadian residents are served in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including Quebec's Law 25 (Act to modernize legislative provisions as regards the protection of personal information). Contact [email protected] for Canadian privacy inquiries.
You may designate an authorized agent to submit privacy rights requests on your behalf. We require: (a) written authorization signed by you or a valid power of attorney; and (b) identity verification directly with you (unless you have provided a power of attorney). We may deny requests from agents that do not submit required proof of authorization.
Tether is not intended for children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information directly from children under 13. Children are not Tether users — they may appear as contact entries managed by a parent or guardian, but they do not create accounts.
If you are a parent or guardian and believe your child has created a Tether account, contact [email protected]. If we learn that we have collected personal information from a child under 13 without parental consent verification, we will delete that information promptly.
Health information and other sensitive data about minor contacts (entered by a parent or guardian) are governed by our Health Information policies. Parents and guardians are solely responsible for the accuracy and lawfulness of any minor's data they enter.
When you use Tether, you may import, store, or share information about people who do not have Tether accounts ("non-users") — including contacts from your address book, event guests, and manually entered contacts.
You are responsible for ensuring: (a) you have a lawful basis for storing non-users' personal information in Tether; (b) you notify individuals whose information you store as required by applicable law; and (c) you respond to any requests from non-users seeking access to or deletion of their information that you have stored.
If a non-user contacts us to request information about or deletion of their data that you have stored, we may notify you and ask you to take appropriate action. Where required by law, we may take additional steps including restricting access to the relevant information.
As a mobile app, Tether uses software development kit (SDK) equivalents to what cookies do on websites. These SDKs collect technical data to help us operate and improve the Service. We use:
Sentry SDK (@sentry/react-native): Collects crash reports, error traces, and performance data. Our implementation is configured to redact PII before transmission. No contact data is transmitted to Sentry. Source maps and iOS dSYMs are uploaded for symbolication.
PostHog SDK (posthog-react-native): Captures product-analytics events with an enforced PII denylist (see Section 4.3 for the complete list of denylisted keys). Allowlisted user traits are limited to subscription tier, signup date, contact count, circle count, and cohort week. PostHog session replay is not enabled. Capture is gated on the in-app analytics opt-out, which when engaged converts all identify / capture calls to no-ops at the SDK boundary.
RevenueCat SDK (react-native-purchases): Processes subscription purchases and provides subscription lifecycle analytics. No contact data is shared. RevenueCat may collect purchase-related device data per their privacy policy.
Expo Push SDK (expo-notifications): Registers push notification tokens and delivers push notifications. Push tokens are not linked to your contact data.
jail-monkey (on-device only): Performs a local jailbreak/root check at app launch. The result is not transmitted off-device. See Section 3.8.
We do not embed advertising SDKs, social-media tracking SDKs, attribution SDKs (e.g., AppsFlyer, Branch, Adjust, Singular), or behavioral profiling SDKs in the Tether app. The app does not request or use Apple's IDFA, does not use Google Play's Advertising ID, and does not declare advertising as a data-use purpose in either App Store or Play Store privacy disclosures.
Most web browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature or setting. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. Accordingly, we do not currently respond to DNT browser signals in a standardized way. However, we honor the Global Privacy Control (GPC) signal as described in Section 7.3.
If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Policy.
For tetherup.app web properties, we use minimal, privacy-respecting analytics that do not build behavioral profiles and do not share data with advertising networks.
Tether is operated from the United States. Information we collect may be transferred to, processed, and stored in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from the laws of your country.
For EEA/UK users, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, and other approved transfer mechanisms. For other international users, we implement appropriate safeguards including contractual commitments and security measures. Contact [email protected] for information about specific safeguards applicable to your jurisdiction.
Tether integrates with: Google Contacts (Google People API); Microsoft Contacts (Microsoft Graph API); RevenueCat/Apple App Store/Google Play Store (payments); and social media platforms (when you choose to link social profiles).
We are not responsible for the privacy practices of third-party services. When you use these services, you are subject to their privacy policies. We recommend reviewing their policies before use. We only request the minimum necessary permissions and do not access data beyond what is required (e.g., we do not access your emails when connecting Google Contacts).
Transactional/Service Messages (Cannot Opt Out):
Marketing/Promotional Messages (Can Opt Out):
Push Notifications (Can Opt Out):
By providing your phone number and creating an account, you expressly consent to receive SMS messages from Tether via Telnyx, including OTPs and security alerts required for Service functionality. Message and data rates may apply. Message frequency varies by activity.
Full SMS terms: tetherup.app/sms
Tether does not read the contents of your clipboard. The app only writes to your clipboard, and only when you explicitly tap or long-press a "copy" affordance in the user interface — it copies just the value you chose. Clipboard writes are local to your device and do not transmit any data to Tether's servers. Current write surfaces include:
MemberContactCard and CustomFieldRow long-press handlers);When you apply for a position at Tether through our website or via email, we collect information you provide in connection with your job application, including contact information, professional credentials, employment history, educational background, and other information typically included in a résumé or CV. We use this information to facilitate our recruitment activities and process employment applications, monitor recruitment statistics, and respond to your application. We do not use job applicant data for purposes unrelated to recruitment. Applicant data is retained for the duration of the recruitment process and for a reasonable period thereafter to comply with legal obligations or respond to inquiries. Contact [email protected] for questions about your applicant data.
We may update this Privacy Policy from time to time. We will post updates in the app and on our website, update the "Last Updated" date, and for material changes, provide prominent notice via in-app notification, email, and/or push notification. Your continued use after the effective date constitutes acceptance. If you do not agree, discontinue use and delete your account. We maintain a version history of this Privacy Policy; contact [email protected] for previous versions.
| Purpose | Contact |
|---|---|
| General privacy inquiries | [email protected] |
| Rights requests (access, deletion, correction) | [email protected] |
| Privacy appeals | [email protected] (Subject: Privacy Rights Appeal) |
| General support | [email protected] |
| Phone | +1 (214) 286-5678 |
| Postal | Tether, LLC, [Address to be provided] |
| In-App | Settings > Help & Support > Contact Us |
We aim to respond to all privacy inquiries within 30 days (or as required by applicable law for rights requests).
We do not sell "covered information" as defined by Nevada law.
We do not sell personal data. We do not process personal data for targeted advertising. Your rights under the TDPSA (access, correct, delete, portability, appeal) are honored as described in Section 7.4.
Do Not Sell or Share Link: tetherup.app/privacy-choices
Sensitive Personal Information Opt-Out Link: tetherup.app/privacy-choices
Metrics (prior 12 months): [To be populated annually per CPRA requirements]
See Section 7.5. Our appointed Data Protection Officer (DPO) contact: [email protected].
See Section 7.6. Nothing in this Policy restricts, excludes, or modifies any rights under the Privacy Act 1988 that cannot be excluded by agreement.
See Section 7.7. Our Privacy Officer contact: [email protected].
Personal Information: Information that identifies, relates to, describes, or could reasonably be linked with you or your household.
Processing: Any operation performed on personal information, including collection, use, storage, disclosure, and deletion.
Service: The Tether mobile application and all related services.
User / You: The person using Tether or the entity on whose behalf the person is using Tether.
Device: Any electronic device capable of running the Tether application.
Contact: A person whose information you store in Tether.
Non-User: A person whose information you have stored in Tether but who does not have a Tether account.
Privacy Circle / Sharing Tier: One of three type categories (Community, Professional, Close) controlling what information you share.
Shared Directory/Circle: A collaborative space where multiple Tether users share contact information based on common affiliation.
Sensitive Personal Information (SPI): Personal information including health data, precise geolocation, biometric data, financial account information, racial or ethnic origin, religious beliefs, and other categories defined under CCPA/CPRA and similar laws.
Autoconnect: The automatic creation of a mutual connection between two users whose verified phone numbers appear in each other's contact lists, using salted SHA-256 hashing.
EXIF Metadata: Exchangeable Image File Format data embedded in digital photos, which may include GPS coordinates, camera model, and timestamps.
SCALAR_SYNC_FIELDS: Contact fields owned by the data subject (the person the contact represents) that sync unconditionally — the data owner's value always wins.
SYNC_PREFER_LOCAL_FIELDS: Contact fields owned by the contact owner (you) that sync for backup but where your non-empty local value always takes precedence.
This Privacy Policy is effective as of May 13, 2026 and was last updated on June 24, 2026.