Tether Tether
  • How it works
  • Guides
  • Pricing
  • Blog
Request access

Privacy Policy

Last Updated: September 14, 2026  ·  Effective Date: September 2, 2026

Contents

  • Our Privacy Philosophy
  • Summary of Key Points
  • 1. Introduction
  • 2. Information We Collect
  • 3. How We Use Your Information
  • 4. How We Share Your Information
  • 5. Data Security
  • 6. Data Retention
  • 7. Your Privacy Rights
  • 8. Children's Privacy
  • 9. Data About Non-Users
  • 10. Analytics, Tracking, and Mobile SDKs
  • 11. International Data Transfers
  • 12. Third-Party Links and Integrations
  • 13. Push Notifications and Communications
  • 14. Clipboard Access
  • 15. Job Applicants
  • 16. Updates to This Privacy Policy
  • 17. Contact Us
  • 18. Specific State and Country Disclosures
  • 19. Definitions

Our Privacy Philosophy

We built Tether because we believe your contact information belongs to you — and so does your data. We don't sell your personal data as a source of revenue. We don't use it for advertising. We take care in overseeing how your data is accessed and what it is used for. Our philosophy: only collect and process what is necessary to operate and improve the Service, and treat your data the way we would want someone to treat ours.

Specific examples of how this philosophy is built into the product:

  • Your address book is encrypted at rest and in transit; no human at Tether has routine access to it
  • Connection suggestions never show anyone your phone number or email address
  • When you sign out, Tether removes its data from that device before anyone else can sign in; copies you saved or shared outside Tether stay under your control
  • We do not use advertising networks, behavioral-advertising trackers, or ad-tech identifiers in the Tether mobile app, and we do not place advertising cookies or tracking pixels on our website
  • We do not subscribe you to marketing lists when you sign up
  • We strip personally identifiable information from crash reports before they leave your device (see Section 4.2 — Sentry)
  • Product analytics (PostHog) stays off unless you turn it on in Settings, and never receives your Tether account ID or contact data (see Section 4.3)
  • You can export all your data, and delete your account, at any time from within the app
  • Phone-number and email-address changes come with a 24-hour undo window and security notices (see Section 3.7)

Summary of Key Points

TopicShort Answer
Do we sell your data?No
Do we use advertising networks?No
Do we share data with third parties?Only service providers necessary to operate the app (see Section 4.2)
Do we collect health data?Only if you choose to fill in the optional allergy and dietary fields, for yourself or your contacts. Yours are never shared unless you choose to share them.
How do connection suggestions work?If two people have each other's phone number saved, we may suggest they connect. A suggestion never connects you automatically.
Do we use product analytics?Only with your explicit consent — PostHog events use a separate pseudonymous analytics ID and no contact data; see Section 4.2
Do we strip EXIF/GPS from uploaded photos?Yes — uploaded images are re-encoded to a normalized JPEG, which strips embedded EXIF/GPS metadata before storage (see Section 2.5)
Do we verify your phone number is a real mobile?Yes — at signup we run a carrier lookup via Telnyx to confirm your number is a mobile line. Voice-over-IP, landline, and toll-free numbers are refused. The carrier name, line type, and country are stored to avoid re-paying for repeat lookups. See Section 2.9.
Do we detect compromised devices?Yes — the app refuses to operate on jailbroken or rooted devices (see Section 3.8)
What happens when you change your phone or email?A 24-hour revocation window with notifications to old phone, old email, and other devices (see Section 3.7)
Can you export your data?Yes — vCard, CSV, or JSON via Settings
Can you delete your account?Yes — Settings > Danger zone > Delete account

1. Introduction

Welcome to Tether ("we," "our," or "us"). Tether is a privacy-first professional contact management application that keeps your contact information current through live updates and synchronization across your devices.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (collectively, the "Service"). Please read this policy carefully. If you do not agree, please do not access the Service.

We reserve the right to make changes to this Privacy Policy at any time. We will alert you about material changes by updating the "Last Updated" date and, for significant changes, by providing prominent in-app notice, email notification, or both. Your continued use of the Service after the effective date of any revised Policy constitutes acceptance.


2. Information We Collect

2.1 Information You Provide to Us

Account Information:

  • Phone number (required for authentication via SMS OTP — Tether's primary sign-in method)
  • Email address (optional; recommended for account recovery, and lets people who know your email find you; see Section 2.7)
  • When your phone number and email address were verified — see Section 2.7
  • Name (first, last, optional middle, prefix, suffix)
  • Profile information (company, job title, department, handle/username, pronouns, bio, avatar photo)
  • "Based-in" city and state (optional)
  • Account preferences and settings (including accessibility preferences such as dark mode, push-notification preferences, sharing-tier defaults, and analytics consent state)
  • Subscription tier and entitlement state (sourced from RevenueCat)
  • Account status dates (for example, when an account was locked or scheduled for deletion)
  • Your time zone and when you were last active
  • Pending-account-change records (see Section 3.7)

Contact Data: You may choose to store the following information about your contacts:

  • Basic: Names (including prefixes/suffixes), nicknames, pronouns, companies, departments, job titles
  • Bio: Free-form bio (up to ~2,000 characters)
  • Contact Details: Phone numbers (stored in E.164 international format), email addresses, physical addresses (street, city, state, postal code, country, optional Place ID and formatted address)
  • Social & Web: Social-media profiles across 15 platforms (including LinkedIn, X/Twitter, Instagram, Facebook, TikTok, Snapchat, GitHub, YouTube, WhatsApp, Telegram, Signal, Venmo, Pinterest, Cash App, and "other"), website URLs
  • Important Dates: Birthdays, anniversaries, graduations, and custom date fields (shared only with circles you allow to see that kind of date)
  • Notes and Met-context: Free-form notes (length limits depend on your current plan), "how we met" (up to 255 characters), met date, met location
  • Photos: Contact profile photos (EXIF metadata is automatically stripped on upload via JPEG re-encoding — see Section 2.5)
  • Health Information (optional): Allergies (and a "no known allergies" option) and dietary preferences, for yourself or your contacts. These are the only health-related fields Tether stores. See Section 4.1 for how your own health fields are shared.
  • Family and Children: Contact type (adult, child, company), child information (birth year, grade level, school name, parent links), a list of other family members (name, relationship, contact type, and an optional link to a Tether user); contact-to-contact family relationships
  • Custom Fields: User-defined label/value pairs typed as text, number, date, URL, phone, or email
  • Relationship Information: Tags, labels, and organizational data
  • Connection State: whether a contact is connected to a Tether user, and whether that connection is active
  • Live Fields: A record of which fields on a linked contact came from the other user's live profile (see Section 3.1)
  • Live Location (Optional, Off by Default): Latitude/longitude with timestamp, collected only while you have location sharing switched on. Sharing is a single account-wide switch — when it is on, your location is visible to the circles you have granted the location permission to, not to a per-connection selection. There is no continuous background location tracking: the app does not request the "Always" location permission and declares no background-location mode.
  • Import Lineage: Import source, import-batch ID, import fingerprint
  • Device Contact Identifiers: The identifier your phone assigns to an imported contact, so the same person isn't imported twice

Event Data: When you create or participate in events:

  • Event details (title, date, time, location, description)
  • Your RSVP status and attendance
  • Co-host assignments and guest lists
  • Per-RSVP snapshots: for each contact you invite to an event, we store a snapshot of their display name and email address on the RSVP record at invite time. This snapshot lets co-hosts see and contact the invitees you've added, and lets any host or co-host re-invite the same people to follow-up events. Only the name and email you attached to the invitation are captured — no phone numbers, addresses, notes, or other fields from your address book.

Posts and Activity:

  • Life updates you post, including their text and photos
  • Communication-log entries you record about your contacts

Privacy Circle Assignments:

  • Your classification of contacts into sharing tiers (Community, Professional, Close)
  • Custom circle memberships
  • Shared circle/directory memberships

Mailing and Address-Request Data:

  • Mailing-household choices, address-scoped keep-separate decisions, custom envelope names, and the date and address fingerprint of a confirmation
  • For an address request you choose to send: the circle and people covered, delivery contact and email address, the address shown at send time, your optional note, delivery and reminder status, and the recipient's confirmation or proposed update
  • Public response and unsubscribe links are random capabilities stored only in hashed form

Directory and Shared Circle Data:

  • Directory name and description
  • Your membership status and role
  • Information you choose to share with directory members
  • Information other directory members choose to share with you

Communication Preferences:

  • Push notification settings
  • Email communication preferences
  • Feature opt-in/opt-out choices

2.2 Information Collected Automatically

Device Information:

  • Device type, model, and operating system version
  • Unique device identifiers: generated by combining a random per-installation identifier stored on your device — never a hardware identifier — with your user ID. The result is scoped to your account and is not used to correlate you across other apps or services.
  • Push notification token: if you enable push notifications, we store the Expo push token issued to your device — a persistent per-device identifier — on our servers, keyed to your account, so we can deliver notifications to that device. The token is used only to route notifications. We delete it when you sign out, and tokens are also removed when unused (inactive after 90 days and hard-deleted after 180 days) and when you delete your account. See Sections 4.2, 6.1, 10.1, and 13.
  • App version and build number
  • Device language, region settings, screen resolution, and device capabilities

Usage Data: The product-analytics items below are collected only after you turn on analytics in Settings. Error and performance monitoring through Sentry is separate and privacy-filtered as described in Section 4.3.

  • Features you use within the app
  • Actions you perform (creating contacts, editing information, syncing data, joining directories, emailing contact cards, creating events, RSVPing)
  • Error logs and crash reports (collected via Sentry; personally identifiable information is automatically redacted before transmission — see Section 4.2)
  • Performance metrics (app launch time, sync duration, API response times)
  • Interaction patterns and feature adoption associated with a random, memory-only pseudonymous analytics identifier that is never your Tether account ID
  • Accessibility feature usage (dark mode, Dynamic Type settings)

Technical Data:

  • IP address (used for security, rate limiting, and abuse prevention; we do not work out your location from it)
  • Invitation links: when someone opens a Tether invitation, event, circle, or contact-card link, we record which link was opened and when, along with hashed network and browser details used to count link opens and prevent abuse. Those details are removed after 30 days, and unused link records are deleted after 24 months.
  • Session duration and frequency
  • Sync operation metadata (timestamps, record counts, sync status)
  • Network connection type (WiFi, cellular)

2.3 Information from Third-Party Sources

Contact Import Services: With your explicit permission, we may import contact data from:

  • Your device's native contact database (iOS Contacts, Android Contacts)
  • Google Contacts (via OAuth 2.0 and Google People API)
  • Microsoft Contacts (via OAuth 2.0 and Microsoft Graph API)
  • vCard (.vcf) files you upload
  • CSV files you upload (including spreadsheets used to seed an event guest list)
  • A Google Sheets link you choose to import
  • The guest list of a past event (where you re-invite or re-import names + emails captured at invite time)
  • A QR-code / contact-card scan, where supported
  • A user you connect with through a referral link
  • Manual entry within the app

Import lineage is preserved on each contact record (import source, batch ID, and fingerprint) for deduplication, undo, and audit purposes.

Selecting records for import only adds or updates contacts in Tether. It does not send an email, text, invitation, or other message to those contacts. If a possible match already exists in Tether, you review proposed changes before they are saved. A later group-message, contact-card, event, or address-request action is a separate user-directed step with its own recipient review.

When you authorize these integrations, we receive all contact information stored in those services, metadata about when contacts were created or last modified, and contact groupings and labels. We only request the minimum permissions necessary to provide our services. We do not access your emails, documents, or other data unrelated to contact management. Calendar access is a separate, optional feature with its own permission — see Section 2.10.

Google data. Tether's use of information received from Google APIs, including Google Contacts, adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google contact data only to import the contacts you choose into Tether. We do not sell it, use it for advertising, or let people read it except as needed for security, to comply with the law, or with your permission.

Data About You from Others: Just as you may provide information about your contacts when you sync your device contacts, others may provide limited information about you when they do the same. For example, another Tether user may save your phone number in their address book, and that information may be used to suggest a mutual connection between you, subject to the connection-suggestion rules in Section 3.9.

Contact Import Authentication: When you authorize Google or Microsoft for contact import, we receive basic profile information to authenticate the connection, a provider-specific user identifier, and an account timestamp. These connections are used solely for contact import — they are not used for Tether authentication (Tether uses Phone OTP only).

2.4 Biometric Information

If you enable biometric authentication (Face ID, Touch ID, fingerprint): we do not collect, store, or transmit your biometric data; authentication is processed entirely on your device using the secure enclave; we only receive a success/failure signal; your biometric templates never leave your device.

2.5 Photo and Image Metadata

When you upload photos or images to the Service (including profile photos, contact photos, event photos, and life-update photos), the image is automatically re-encoded to a normalized JPEG before storage. This re-encoding strips embedded EXIF metadata — including GPS coordinates, camera make and model, device serial numbers, and timestamps — so that metadata is not retained on our servers or shared with other users.

Photos you upload may be visible to other users in accordance with your privacy-tier and circle settings. Note that metadata stripping happens at upload only; if you share an original image file outside Tether by other means, that copy may still contain its embedded metadata.

2.6 Location Data

We collect precise location only if you turn on location sharing, which is off by default and currently available on iPhone. While it is on, the app shares your current location with the circles you have allowed to see it. Tether does not request the "Always" location permission and does not track your location in the background. You can turn sharing off at any time, which stops it.

We do not work out your location from your IP address. If you add a physical address to your profile or contacts, it is stored and shared according to your circle settings.

2.7 Verified-Identifier Status (Email and Phone)

Each account in the Service has, at any point in time, zero or one "verified" status for the user's email address and zero or one "verified" status for the user's phone number. Verification is performed by sending a one-time code to the identifier and requiring the user to enter that code in the app.

We process verified-identifier status for the following purposes:

  • Account recovery. A verified email is the secondary channel by which you can recover access to your account if you lose access to your phone number.
  • Discovery handshake gating. Other users may discover and request to connect with you using your email address only when your email is verified. The same gate applies to your phone number.
  • Security-notification routing. Security notifications (including the 24-hour revocation notifications described in Section 3.7) are sent to your verified channels.

The dates your email and phone were verified are stored on your account record. Verification status does not result in publication of your email or phone to other users (see Section 3.1).

Being listed as someone's family member. If another Tether user lists you as a family member on their contact card and you are a Tether user, the people they share that card with may see that you are on Tether and may send you a connection request. As with all connection requests, this is governed by your connection-request settings, and you can decline any request. Your phone number and email address are never disclosed to those people through the other user's card.

2.8 Device-Integrity Signals

Each time the app launches, it checks on your device whether the device has been jailbroken (iOS) or rooted (Android), and if so it refuses to run. The result is not stored on our servers or sent to our analytics provider. If a device is locked out, or the check cannot run, our error-monitoring provider receives only the reason and the platform so we can spot false alarms. See Section 3.8.

2.9 Pre-Account and Phone-Verification Data

Early-access request form (tetherup.app/request-access). During our soft-launch period, anyone may submit a request for access by entering their name, mobile phone number, email address, and (optionally) where they heard about us. We also record the request's IP address and user-agent string for abuse prevention. Until an account is created, this information is stored in our access-request records with the request's review status. When you create an account using the same phone number, the request remains in our records as part of the eligibility audit trail. You may request deletion of an unfulfilled request at any time by emailing [email protected].

Phone-number carrier verification. Before sending a sign-in code to a new phone number, we ask Telnyx (see Section 4.2) whether it is a mobile number. We don't send codes to voice-over-IP, landline, or toll-free numbers, which are commonly used for automated sign-ups. We keep the result (carrier, line type, and country) under a hashed form of the number rather than your account, so we don't repeat the lookup. If you believe a mobile number was misclassified, email [email protected].

SMS delivery records. For up to 90 days, we retain a service-only dispatch record so retries cannot send duplicate codes and so we can confirm delivery. It contains a hashed form of the destination phone number, its allowed-country category, provider message/event identifiers, status and error codes, and timestamps. It does not contain the raw phone number, one-time code, or message body and is not linked to an account record.

2.10 Calendar Data

If you enable Tether's calendar availability feature, the app reads your device calendar — using the calendar permission you grant your operating system — to determine when you are busy or free. We store only the start and end times of your busy periods on our servers; we do not receive or store event titles, locations, attendee lists, descriptions, notes, or any other content from your calendar entries. Calendar entries are read on your device, and only the resulting busy/free time ranges are transmitted to us. If you choose, the app can also add Tether events to your device calendar; this happens on your device. Busy/free ranges are deleted automatically 14 days after they end.

When you enable the calendar availability feature, your busy/free times are shared by default with the circles you create from Tether's standard templates — Close, Community, and Professional circles each include calendar availability in their default shared fields. You can change what any individual circle sees through that circle's Edit Permissions screen, stop sharing with a circle, or turn off calendar access entirely in the app's settings, at any time. Circles see time ranges only — never the underlying calendar entries. Turning the feature off deletes the busy-block data we have stored for you. We do not sell your calendar data, share it with third parties, or use it for advertising.


3. How We Use Your Information

3.1 Core Service Functionality

  • Account Management: Create and manage your account, authenticate your identity, and maintain session security
  • Contact Synchronization: Sync contact data across your devices using server-assigned sync versioning for conflict resolution
  • Live Updates: Automatically update contact information when your connections update their Tether profiles, in accordance with each user's privacy-tier settings and on a best-effort basis — see Section 10.9 of the Terms of Service for the disclaimer on reliance on live updates
  • Mutual-Contact Suggestions: When two users each have the other's verified phone number in their contact lists, we may suggest that they connect. The process never automatically creates or accepts a connection. A user must send a request and the other user must accept it. See also Section 3.9.
  • Event Management: Create, manage, and share events; send invitations via email; manage RSVPs; assign co-hosts; and capture per-RSVP snapshots of guest name and email at invite time for re-invitation to follow-up events
  • Life Updates: Optionally publish "life update" posts (e.g., birth announcements, milestones) to your circles, which sends a push notification to people in those circles
  • Communication Tracking: Track communication history with contacts, stored on your device and synced to your account. Available on all tiers; Tether+ allows longer notes
  • Duplicate Detection: Suggest possible duplicate contacts using fixed scoring rules that compare names, phone numbers, and email addresses (see Section 3.2)
  • Data Organization: Enable organizing contacts into privacy-tier circles, custom circles, and shared directories (institutional or social mode)
  • Group Communication: Open your device's email or Messages composer with destinations from a circle or people you selected, after showing the exact recipients and channel disclosure
  • Contact Card Email: Allow sharing updated contact information with chosen people or the eligible group in a circle via separate transactional emails (Resend), after recipient, sender, message, and field review
  • Mailing Tools: Plan household or individual mailing rows, preserve envelope names and keep-separate choices, and export the format you choose
  • Address Requests: At your direction, ask non-users in a private circle to confirm or add a mailing address, apply an unchanged response to your contact record, or hold it for your review if the record changed in the meantime
  • CardDAV Export (Optional, Tether+): You can install a configuration profile that lets your iPhone or Mac read your Tether contacts as a read-only address book. The download link works once and expires after 30 minutes. The installed profile keeps a sign-in credential until you remove it, turn off CardDAV in Tether, or delete your account. Tether never writes to your device's address book.
  • Search and Filtering: Provide fast, accurate search across your contacts
  • Import and Export: Facilitate importing contacts from external services and exporting your data in vCard, CSV, or JSON formats

3.2 Automated Suggestions

Tether does not use machine learning or artificial intelligence on your data, and we do not use personal data to train AI or large language models. We use fixed rules for:

  • Duplicate Detection: On your device, the app compares names, phone numbers, and email addresses using fixed scoring rules to suggest possible duplicates. If you dismiss a suggestion, we remember that pair so it is not suggested again.
  • Circle Suggestions: Fixed rules look at contact details — such as a shared family name, a saved birthday, or a work email address — to suggest a circle. We count how often you accept or decline each kind of suggestion and show that kind more or less often accordingly. Suggestions are advisory; nothing changes until you act.
  • Spam and Fraud Prevention: Automated rules such as rate limits and carrier checks help detect abuse.

We do not make solely automated decisions about you that have legal or similarly significant effects, except for security measures such as rate limiting or suspending an account for abuse. You can ask a person to review any such decision by contacting [email protected].

3.3 Service Improvement and Analytics

  • Performance Monitoring: Analyze app performance, identify bugs, and improve reliability using pseudonymous, privacy-filtered Sentry events
  • Feature Usage: With your explicit consent, understand which features are valuable using a separate pseudonymous analytics identifier that is never your Tether account ID
  • Error Tracking: Collect crash reports and error logs via Sentry after removing account identity, raw URLs, request bodies, authored identifiers, and recognized PII before transmission

We do not use your personal contact data for advertising targeting. We do not sell your data or share it for cross-context behavioral advertising.

3.4 Communications

  • Transactional SMS: OTP authentication codes and security alerts via Telnyx. Required for phone-based authentication and related account-security functionality. You provide SMS consent only by selecting the unchecked consent box shown with the program disclosures when you enter or change your phone number.
  • Transactional Email: Critical service messages (including account security notices and sign-in codes) via Resend
  • User-Directed Email: Event invitations, contact-card emails, and mailing-address requests that a Tether user affirmatively asks us to deliver after reviewing recipients and content. Contact-card and address-request recipients receive purpose-specific opt-out links; those preferences are separate from one another and from event and critical service messages. Address requests skip people already on Tether and never send automatic reminders.
  • Marketing: We do not currently send marketing email or SMS. If we start, we will ask for any consent the law requires and include an unsubscribe option in every message.
  • Account Support: Responses to support requests and feedback

3.5 Security and Fraud Prevention

  • Rate limiting authentication attempts and API calls
  • Managing authenticated device sessions so you can inspect and revoke access
  • Identifying unusual patterns that may indicate unauthorized access
  • Maintaining audit logs of data modifications for security and accountability

3.6 Legal and Compliance

  • Comply with applicable laws, regulations, legal processes, or governmental requests
  • Enforce our Terms of Service
  • Protect the rights, property, and safety of Tether, our users, and the public

3.7 Phone and Email Changes

When you change the phone number or email address on your account, we keep a short-lived record of the change — the old and new identifier and when the undo window ends — so the change can be reversed. On a best-effort basis we send security notices to your previous phone number or email, your verified email, and your other signed-in devices, each with a link to undo the change within 24 hours.

Undoing a change restores the previous identifier, locks the account until you verify your identity, and signs out every device. A phone change also signs out every device; an email change signs out your other devices. If you are signed in with an email code, you must sign in with your phone before changing your email. We keep records of these changes and notices for security, and delete the change records at least 30 days after they are completed or undone.

We process this information to keep your account secure. These safeguards cannot be turned off, although replying STOP still stops all Tether SMS until you reply START.

3.8 Device-Integrity Checks

At app launch, the Service runs an on-device jailbreak/root check. If the device is detected as compromised, the app renders a lockout screen and does not function. The result is not stored on Tether's servers and is not sent to our analytics provider. A security event naming the reason code is sent to our error-tracking provider when the device is locked out or the check cannot run, so that false-positive lockouts are detectable; see Section 2.8. We use this check to protect your account and the contact data stored on your device.

3.9 Connection Suggestions

When two users each have the other's verified phone number saved, we may suggest that they connect. Someone who knows your name and your verified phone number or email address can also look you up to send you a connection request; they see only your name, photo, and handle. A suggestion never creates or accepts a connection: one person must send a request and the other must accept it. We can turn this feature off, and blocking someone or turning off connection requests prevents a connection.


4. How We Share Your Information

4.1 Information Sharing You Control

With Other Tether Users (Sharing Tier Settings): When you connect with another Tether user, you control what they see through your sharing-tier settings. There are three tiers — Close, Community, and Professional — and each has a default set of fields that are shared. You can override the defaults on a per-circle basis from Settings > Privacy & sharing > What new people see. The default-shared fields for each tier, as currently configured in the app, are:

  • Close (family and inner circle): name, avatar, handle, nickname, bio, pronouns, company, job title, department, home and work phone, personal and work email, home and work address, social profiles (LinkedIn, Instagram, X/Twitter, Facebook, TikTok, YouTube, GitHub, Pinterest, WhatsApp, Snapchat, Telegram, Venmo), personal and work websites, birthday, anniversary, custom dates, family members, calendar availability (busy/free times, when the calendar feature is enabled), and live location (when enabled).
  • Community (friends and acquaintances): name, avatar, handle, nickname, bio, pronouns, company, job title, department, personal email, social profiles (LinkedIn, Instagram, X/Twitter, Facebook, TikTok, YouTube, GitHub, Pinterest, WhatsApp, Snapchat, Telegram, Venmo), personal website, birthday, and calendar availability (busy/free times, when the calendar feature is enabled). Note: your mobile number is always shared with every connection at every tier — it is part of the always-on identity floor (name, photo, handle, nickname, mobile) and cannot be withheld. Other phone numbers and postal addresses are NOT shared by default; you can opt in to share those on a per-circle basis.
  • Professional (work contacts): name, avatar, handle, nickname, bio, company, job title, department, work phone, work email, work address, LinkedIn, GitHub, work website, and calendar availability (busy/free times, when the calendar feature is enabled).

Health fields are never shared by default. The app asks for your consent before you add your own allergies or dietary preferences. Sharing them needs a separate consent: you can choose to share them with a particular circle only after agreeing to that consent in the app. You can withdraw either consent at any time in Settings. Withdrawing either one stops Tether sharing your health fields, but it does not delete health fields already on your profile; you can delete those yourself on your profile.

These defaults are set by the Service and may be revised in future releases, in which case this Section will be updated. You can review and change what each of your circles shares at any time in the app under Circles → circle settings.

Family members on your card. When "family members" is among the fields you share with a circle, the connections in that circle may see, for each family member you have linked: their name, your relationship to them, and contact type. For a family member who is not a Tether user, this may also include that person's primary phone number and email address as stored in your address book. For a family member who is a Tether user, their phone and email are never shared through your card — instead, your connection may see that the person is on Tether and may send them a connection request directly (subject to that person's own connection-request settings). Children's direct contact details (phone and email) are never shared through your card. Because this shares information about other people, you are responsible for having any consents required by law to do so (see our Terms of Service).

Unassigned contacts. When a new connection is created and you have not yet assigned the connected user to a circle, a separate "Unassigned Defaults" setting determines what is shared until you make an assignment. The Unassigned Defaults are configured in Settings > Privacy & sharing > What new people see and are distinct from the Community tier defaults above.

Data on Disconnect: When you block or remove a connection, the details that person shared with you through Tether are removed from your device the next time the app syncs. Anything you saved about them yourself stays in your address book.

Events and Co-hosts: Co-hosts can see only the display name and email address you attached to each guest invitation (captured as a per-RSVP snapshot at invite time) — not any other information from your private address book. When a host or co-host reuses a past event's guest list for a future event, guests not already in the inviter's address book may be saved as new contacts from the snapshotted name and email, tagged with import source past_event_invite.

4.2 Service Providers

We share information with third-party service providers who perform services on our behalf. Our service providers may use your information only to provide their services to us, and they must protect it.

ProviderPurposeData Shared
Supabase Inc.Database, auth, file storage, real-time sync, edge functions (AWS, United States)All user data stored in database
Cloudflare, Inc.Website hosting, network and DNS services, bot protection (Turnstile) on web forms, CardDAV profile delivery, and R2 backup storageWeb request metadata, CardDAV profile delivery, encrypted logical-database archives, encrypted backup copies of Storage object bytes (including private photos), and minimal erasure receipts that record only the schema version and deletion time
GitHub, Inc. (GitHub Actions)Planned database backups on a temporary GitHub-hosted runner; not enabled until our processor agreement covers itWhen enabled, a database snapshot is processed briefly in plaintext while it streams from pg_dump into age encryption. The encrypted archive is stored in Cloudflare R2, and GitHub keeps only digest-only backup evidence, not database content.
SentryPseudonymous error tracking and performance monitoring with egress filteringCrash logs, error events, bounded device/app context, and generated operational correlation IDs; no direct Tether account ID, raw URL, request body, or raw contact data
PostHogConsent-only product analytics (events only; no contact data; property filter enforced at the SDK boundary)Event names, allowlisted traits (subscription tier, signup date, contact count, circle count, cohort week), a random pseudonymous analytics ID that is never the Tether account ID, app version, environment
RevenueCatSubscription billing via App Store / Google Play and entitlement updates to our backendYour opaque Tether account UUID, subscription status, purchase events, billing issue events
TelnyxSMS OTP delivery; SMS notification to the prior number when phone changes; pre-signup carrier lookup (Number Lookup API) to confirm the number is a real mobile line (see Section 2.9)Phone number, OTP body, security-notification body, carrier-lookup query (phone number only — result cached in our database)
ResendTransactional email (event invitations, event reminders, RSVP notifications, circle invites, contact-card emails, mailing-address requests, phone-change and email-change security notifications, and similar)Email addresses, sender/recipient metadata, and the content you choose to send
ExpoPush notification delivery and over-the-air app updatesPush tokens; generic notification envelopes containing an opaque owner-bound delivery nonce, request ID, type, and expiry, which do not contain contact/event names, authored text, entity identifiers, or security-action URLs; and basic device and app-version information for updates
MicrosoftContact import from Outlook / Microsoft 365 via OAuth 2.0 + Microsoft Graph API — only when you choose to connect a Microsoft accountYour Microsoft sign-in (OAuth) and the Outlook contacts you import via the Contacts.Read scope: names, phone numbers, emails, addresses, and notes
jail-monkey (on-device)Device-integrity check (jailbreak / root detection)None to jail-monkey — the check runs locally. A lockout or a failed check emits a reason code to our error-tracking provider (Section 2.8)
Apple Inc. / Google LLCApp distribution, in-app purchase, push-notification transit; contact import (Apple Contacts / Google People API on connect); map tiles and address geocoding when you view or save a locationPer their respective developer terms and privacy policies; for contact import, the contacts you choose to import; for maps, approximate location/viewport coordinates
Google LLCWeb fonts on our website and in our emails; fetching a Google Sheets link you choose to importIP address and browser information when fonts load; the sheet you import

4.3 Analytics and Monitoring Technologies

We use the following analytics and monitoring tools:

Sentry (Error & Performance Monitoring): Sentry receives crash reports, error events, and performance traces. We do not attach your account to them, and we filter out contact details, message content, and other personal information before they are sent. Governed by Sentry's Data Processing Agreement.

PostHog (Product Analytics — Events Only): PostHog stays off unless you turn on analytics in Settings > Privacy & sharing > Who can reach you, and leaving it off never reduces what the app can do. When on, it receives filtered in-app events — never contact details, messages, notes, or addresses — tied to a random analytics ID that is not your Tether account ID. Session replay and automatic capture are off. If you turn analytics off, future collection stops; events already sent are handled under PostHog's retention settings. We use PostHog's U.S. cloud under its Data Processing Agreement.

RevenueCat (Subscription Analytics): RevenueCat receives your opaque Tether account UUID, purchase events, and subscription status updates necessary to process transactions, restore access, and provide subscription analytics (conversion rates, churn, subscription lifecycle events). We do not send your address book to RevenueCat. We retain the subscription projection needed to apply plan limits and support purchase issues.

Cloudflare Web Analytics (Web Properties): Our tetherup.app web properties use Cloudflare's privacy-respecting RUM analytics, which does not use cookies and does not build behavioral user profiles. No data from the mobile app passes through Cloudflare Web Analytics.

We do not use Google Analytics, Facebook Pixel, TikTok Pixel, Meta Audience Network, or any advertising-oriented analytics or attribution SDK in the Tether mobile app. We do not place advertising cookies or tracking pixels on our website. We do not use Apple's App Tracking Transparency-gated identifiers (IDFA) and the app declares "No, app does not use advertising ID" on Google Play.

4.4 Advertising

We do not sell your personal data to advertisers. We do not share your personal data with advertising networks for behavioral targeting. We do not receive compensation for your data from any advertising partner. Tether generates revenue through subscription fees only.

4.5 Business Transfers

If Tether is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of company assets, your information may be transferred as part of the transaction. We will provide at least 30 days' notice before your information becomes subject to a materially different privacy policy.

4.6 Legal Requirements

We may disclose your information if required by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, national security or law enforcement requests). We may also disclose when we believe in good faith that disclosure is necessary to comply with applicable law, enforce our Terms, protect against fraud or security risks, or protect the rights or safety of Tether, our users, or the public.

When permitted by applicable law and not prohibited by the legal demand itself, we will: provide you with prompt notice of any legal demand for your data; review requests for legal sufficiency; and, where appropriate, challenge overbroad or improper requests.

4.7 Professional Advisors

We may disclose personal information to professional advisors (lawyers, auditors, bankers, insurers) where necessary in the course of professional services they render to us, subject to confidentiality obligations.

4.8 Aggregated and De-identified Data

We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you, for business purposes including research, service improvement, and industry reporting.

4.9 With Your Consent

We may share your information for any other purpose with your explicit, informed consent.


5. Data Security

5.1 Security Measures

We use industry-standard safeguards designed to protect your information, including:

  • encryption of data in transit and at rest, including the data Tether stores on your device;
  • sign-in with one-time codes instead of passwords, with limits on repeated attempts;
  • access controls that keep each account's data separate, and limited internal access to user data;
  • security notices and a 24-hour undo window when your phone number or email changes (Section 3.7);
  • removing Tether's data from a device when you sign out;
  • refusing to run on jailbroken or rooted devices (Section 3.8); and
  • monitoring, backups, and incident-response procedures.

Sessions. We do not impose a fixed session lifetime or inactivity timeout. A session continues unless you sign out, revoke the device or session, delete your account, or it is invalidated for a security or account-administration reason.

We review and update these measures as the Service and the threats it faces change.

5.2 Security Breach Notification

In the event of a security breach involving your personal information, we will:

  • Investigate and confirm the scope of the breach as promptly as possible
  • Notify affected users without undue delay and, where required by law notify the appropriate authorities
  • Provide breach notification via email and/or in-app notification describing the nature of the breach, categories of data involved, and steps we are taking
  • Cooperate with applicable regulatory authorities

We keep a record of every security breach involving personal information, including our assessment of whether notice was required, for as long as the law requires.

5.3 Limitations

No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.


6. Data Retention

6.1 Active Account Data Retention Schedule

Data CategoryRetention Period
Contact dataWhile account is active; until contact is deleted
Account informationWhile account is active
Sync transactions24 hours
Change logs (audit)90 days
Soft-deleted contacts60 days, then permanently deleted by a daily maintenance job. A contact you merged into another contact is kept for as long as that surviving contact exists, so the merge stays reversible; it is hard-deleted on a later run of the same job once the surviving contact is itself deleted.
Event RSVP recordsRetained with the event; deleted with account
Push tokensDeleted when you sign out or your session ends; deactivated after 90 days unused and deleted after 180 days; deleted with your account
Error/crash logs (Sentry)Kept under our error-monitoring provider's retention settings, with personal information filtered out
Product-analytics events (PostHog)Collected only if you turn on analytics; kept under PostHog's retention settings
CRM communication logsWhile account is active
Contact-card download payloads30 days after the final eligible scheduled delivery (no more than approximately 60 days from creation)
Contact-card email recordsRecipient email, name, and unsubscribe details are removed after 13 months; the remaining record, which keeps only a hashed address, is deleted after 24 months
Address-request response links30 days
Unresolved address-update proposals60 days, then the submitted address is deleted
Address-request delivery recordsRecipient email and name are removed after 13 months; the remaining request ledger is deleted after 24 months. Applied or rejected submitted-address payloads are cleared immediately.
Health-field consentsKept as a record of your choice for as long as the law requires
Pending account-change records (phone / email / sign-in notice)Live records: up to 24 hours (revocation window). Terminal records (committed or revoked): purged by the daily maintenance job, no fewer than 30 days after the terminal event.
Undo links for phone and email changesDeleted with the related change record
Account-lockout recordsWhile account is locked; preserved in audit log after recovery for security and forensics purposes
Transactional records7 years (tax and accounting purposes)
Lifetime inventory receiptMinimal durable purchase-count record; account association removed on account deletion (see Section 6.2)

6.2 Account Deletion

When you request account deletion (Settings > Danger zone > Delete account):

You can also ask us to delete your account by emailing [email protected] from the email address on your account (we will verify the request). Deleting your account does not cancel an App Store or Google Play subscription; cancel it in your app store's subscription settings.

Immediate Actions:

  • Your account enters a 30-day cooling-off period. Your phone number, email, and handle are released right away, so you can cancel from the banner in the app only on a device that is still signed in. If you have signed out, email [email protected] within the 30 days; we can restore your account unless another account has since taken your number or email
  • Your profile becomes inaccessible to other users
  • You are logged out of all devices
  • Tether's data is erased from the device you used
  • Your directory memberships are terminated
  • Your upcoming events are cancelled and your guests notified, your seats at other people's events are released, and your pending connection requests are withdrawn
  • Personal data about you held on other people's records, which no account link can reach, is erased immediately and permanently: any pending website access request in your name, directory invitations addressed to your email, your guest entries on other people's events (the entry is removed, so the host's guest list no longer shows you and your seat is released), referral attribution identifying your verified email, and your details inside administrative audit records
  • Cancelling within the 30 days restores your account, your profile and your phone, email and handle. It does not restore the items in the two points above — cancelled events, released seats, withdrawn requests and the invitations and records erased on other people's data are not recoverable

After 30-Day Cooling Period:

  • All contact data permanently deleted from our servers by automated cleanup
  • Your account information permanently deleted
  • All sub-entity data (phones, emails, addresses, social profiles) cascade-deleted
  • Shared directory contributions anonymized or removed
  • Third-party import connections revoked
  • CardDAV tokens invalidated

Data We Retain After Deletion:

Most data is permanently erased at the end of the 30-day cooling period. A limited set of records is deliberately retained for the lawful purposes below. Where a record is kept, it is de-identified wherever de-identification still serves the purpose:

  • Onboarding-trial claim. While your account exists, a service-only record keyed by its immutable account UUID prevents that account from claiming the onboarding trial twice. Separately, to enforce the one-trial-per-phone rule while allowing genuinely reassigned numbers to become eligible again, we keep a coded form of the verified phone number for 12 months after a trial claim. This receipt contains no raw phone number or account UUID and is not available to app users.
  • Lifetime purchase count. To keep the limited Founders Lifetime sales count accurate, we retain a minimal record of each completed production store purchase for as long as the Lifetime offering and its purchase history are maintained. It contains a coded transaction identifier, store, purchase time, refund state, and observation time. Your account association is removed when the account is permanently deleted. We do not keep your name, phone, email, raw transaction identifier, or contact data in this record. Deletion, transfer, refund, or revocation does not reopen a sold place. The coded identifier can still be matched against a known store transaction; it is not anonymous data.
  • Carrier-verification cache. The carrier facts about your phone line (carrier name, line type, country) stored in our carrier-lookup cache are keyed by phone-number hash, not your account, and survive deletion because they describe the line, not you (see Section 2.9).
  • Anonymized health-consent record. If you gave a health-field consent (to add your health fields or to share them), the record that you agreed on a given device — including the consent version and timestamp — is retained as a legal audit trail with your user ID removed, so it cannot be used to re-identify you.
  • Deletion audit log. A pseudonymous record (your account's internal identifier, deletion timestamp, per-table row counts, and per-processor cleanup status) is retained to demonstrate that erasure occurred. No name, email, or phone is kept.
  • Handle hold. If you released a username/handle, a hold on that handle is retained for approximately six months to prevent immediate impersonation; the identifier of the releasing account is removed.
  • Export audit record. If you exported your data, a pseudonymous record of the export (event counts and timestamp, with email, IP address, and user-agent removed) is retained.
  • Backups. Encrypted backup copies are overwritten on the normal rotation and are automatically deleted within 90 days. Backups are not used to restore a deleted account.
  • Legal and tax records. Transactional records required for tax and accounting are retained for the period required by law; records related to a legal dispute or investigation are retained for the duration of that matter.
  • Aggregated, de-identified data. Statistics that no longer identify you may be retained indefinitely. This does not include the content of your contacts, notes, photos, or health fields.

Third-Party Processor Residuals. Data already transmitted to our subprocessors before you deleted your account is deleted according to each subprocessor's own retention schedule, which we do not directly control. As part of account cleanup we request deletion of the subscription-processor customer record associated with your account (RevenueCat), and keep retrying until the provider confirms that it is absent. Acceptance of a deletion request alone is not confirmation of completed deletion. We record the residual-cleanup status for each processor. Residuals may include: SMS and OTP delivery logs (Telnyx), email delivery logs (Resend), pseudonymous error/performance events that carry no direct Tether account identifier but may retain operational correlation IDs (Sentry), consented product-analytics events keyed to a pseudonymous identifier that Tether does not map to your account (PostHog), and generic push-delivery receipts sent through Expo. These age out on each provider's own schedule. See Section 4.2 for the full subprocessor list.

6.3 Inactive Accounts

We may delete an account that has had no sign-in or sync activity for 12 months or more, after giving at least 30 days' notice. Deletion follows Section 6.2. To keep your account, simply sign in before the date in the notice.


7. Your Privacy Rights

7.1 Rights Available to All Users

Regardless of your location, you have the following rights:

  • Access & Portability: Access your contact data at any time through the app. Export all contacts in standard formats (vCard .vcf, CSV, JSON) via Settings > Your data > Download everything. Request a copy of all personal information we hold at [email protected].
  • Correction: Edit your profile and contact data directly in the app. Contact [email protected] for corrections you cannot make yourself.
  • Deletion: Delete individual contacts or your entire account through app settings. Request deletion at [email protected].
  • Analytics Choice: Product analytics is disabled by default. Turn it on or off at any time in Settings > Privacy & sharing > Who can reach you without losing app functionality.
  • Opt-Out of Communications: Disable push notifications in device settings. Opt out of non-essential emails via the unsubscribe link. Reply STOP to opt out of all Tether SMS, including authentication codes and security alerts; phone-code sign-in will remain unavailable until you reply START, while a previously verified recovery email remains available for account recovery.

7.2 California Users — CCPA/CPRA

Categories of Personal Information We Collect:

  • Identifiers (name, phone number, email, device ID)
  • Commercial information (subscription tier, purchase history)
  • Internet/electronic activity (usage data, error logs, sync metadata)
  • Professional/employment information (job title, company)
  • User-generated content (contacts, notes, photos)
  • Sensitive Personal Information (SPI): precise geolocation (if you turn on location sharing) and health information (if you add it). We do not collect biometric data.

California Privacy Rights:

  • Right to Know: Disclosure of personal information collected, used, shared, or sold
  • Right to Delete: Deletion of personal information (subject to legal exceptions)
  • Right to Correct: Correction of inaccurate personal information
  • Right to Opt-Out of Sale/Sharing: We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
  • Sensitive Personal Information: We use sensitive personal information only as needed to provide the Service you ask for, so there is no additional use to limit. Questions: [email protected].
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

Your Privacy Choices: Email [email protected] to exercise any of these rights.

Global Privacy Control (GPC): Tether does not sell or share personal information for cross-context behavioral advertising, so there is nothing for a GPC signal to opt you out of. If that ever changes we will honor the signal and say so here before the change takes effect.

Do Not Sell or Share: We do not sell personal information to third parties. We do not share personal information for cross-context behavioral advertising. These practices will not change without providing you with at least 15 days' advance notice and the ability to opt out before they take effect.

Shine the Light: We do not share personal information with third parties for their direct marketing purposes. California residents with questions may contact [email protected].

7.3 U.S. State Privacy Rights

Depending on where you live, state privacy laws — including those of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia — may give you the right to:

  • confirm whether we process your personal data and access it;
  • correct it;
  • delete it;
  • get a portable copy;
  • opt out of the sale of personal data, targeted advertising, and profiling that produces significant effects — Tether does none of these;
  • get a list of the categories of third parties (or, where your state requires, the specific third parties) we disclose personal data to; Section 4.2 lists our service providers; and
  • appeal our decision on your request.

Sensitive data. We process sensitive data — such as precise location if you turn on location sharing, or health fields if you choose to add them — only with your consent, and you can withdraw that consent in the app at any time.

Requests and appeals. Email [email protected]. We will verify your identity and respond within the time your state's law requires. If we deny your request, you can appeal by replying to our decision or emailing [email protected] with the subject "Privacy Rights Appeal." If we deny your appeal, you may contact your state's Attorney General.

7.4 Canadian Users

Tether is not currently offered in Quebec. For users elsewhere in Canada, we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.

  • Privacy Officer: Our Privacy Officer can be reached at [email protected] or Tether, LLC, 5900 Balcones Dr Ste 100, Austin, TX 78731, USA.
  • Where your information is stored: Your information is stored and processed in the United States by Tether and the service providers listed in Section 4.2, and may be accessible to courts, law enforcement, and national-security authorities there. You can ask our Privacy Officer about our policies for service providers outside Canada.
  • Complaints: If you are not satisfied with our response, you can contact the Office of the Privacy Commissioner of Canada or your provincial privacy commissioner.

7.5 Authorized Agents

You may designate an authorized agent to submit privacy rights requests on your behalf. We require: (a) written authorization signed by you or a valid power of attorney; and (b) identity verification directly with you (unless you have provided a power of attorney). We may deny requests from agents that do not submit required proof of authorization.


8. Children's Privacy

Tether is for adults 18 and older, and we do not knowingly allow anyone under 18 to create an account. If we learn that someone under 18 has an account, we will delete it. If you believe a minor has an account, contact [email protected].

Parents and guardians may store information about their own children as contacts — for example, in a school directory. That information is managed by the parent or guardian, is not used to contact the child, and is covered by the rest of this Policy.


9. Data About Non-Users

When you use Tether, you may import, store, or share information about people who do not have Tether accounts ("non-users") — including contacts from your address book, event guests, and manually entered contacts.

9.1 How We Handle Non-User Data

  • Phone numbers and email addresses of non-users may be stored in your encrypted Tether address book
  • To suggest connections, we match the phone numbers saved in users' address books. If someone you invited to a circle or event later joins Tether with the same verified phone number or email address, we connect that invitation to their new account. We do not use your contacts to build profiles of people who are not on Tether
  • Non-user contact data is subject to the same security protections as all other Service data
  • A Tether user may deliberately select a non-user and ask us to email that user's contact card. The card itself is the primary content; a secondary Tether invitation may be included. We do not use non-user contact data to send unrelated marketing communications.
  • Before a contact-card email is sent, we skip addresses that belong to an existing Tether account, have bounced or complained, have opted out, or would reach someone who has blocked the sender. The sender sees only totals and is never told that someone blocked them.
  • Every contact-card email includes a link to opt that email address out of future contact-card emails, plus standards-based one-click unsubscribe headers. This contact-card preference does not opt the address out of event email or critical service and security communications.
  • A Tether user may ask selected non-users in a private circle to confirm or add a mailing address. We skip people already on Tether, send a private email to each reviewed delivery target, limit and space requests, and permit at most one manual reminder after seven days. The response page offers an optional Tether invitation only after the address response is submitted.
  • An address response is applied automatically only if every covered contact still has the same address fingerprint that was shown when the request was sent. Otherwise the response is held for the address-book owner to review and does not overwrite their records.
  • Address-request email has its own opt-out. Opting out of address requests does not opt the address out of contact-card, event, or critical service and security messages.
  • Non-user address-book data is deleted when you delete the associated contact or close your account. Separate contact-card and address-request delivery records follow the purpose-specific retention schedules in Section 6.1.

9.2 Requests About Non-User Data

You are responsible for having a lawful basis for storing other people's information in Tether and for giving any notice the law requires.

If someone whose information is stored in Tether contacts us about it, we will respond to them directly as the law requires and will not tell the user who stored it who made the request. We may ask that user to help, and we may restrict or delete the information where the law requires.


10. Analytics, Tracking, and Mobile SDKs

10.1 Mobile Analytics SDKs

As a mobile app, Tether uses software development kit (SDK) equivalents to what cookies do on websites. These SDKs collect technical data to help us operate and improve the Service. We use:

Sentry SDK (@sentry/react-native): Collects crash reports, error traces, and performance data. We do not attach your account, and personal information is filtered out before transmission.

PostHog SDK (posthog-react-native): Not started until you turn on analytics. It uses a random ID that is never your Tether account ID, does not record your screen or capture taps automatically, and stops when you turn analytics off.

RevenueCat SDK (react-native-purchases): Processes subscription purchases and provides subscription lifecycle analytics. No contact data is shared. RevenueCat may collect purchase-related device data per their privacy policy.

Expo Push SDK (expo-notifications): Registers push tokens for your devices. Notification text on your lock screen is generic; details load inside the app.

jail-monkey (on-device only): Performs a local jailbreak/root check at app launch. The result is not stored on our servers; a lockout or a failed check sends only the reason and platform to our error-monitoring provider (see Section 2.8).

We do not embed advertising SDKs, social-media tracking SDKs, attribution SDKs (e.g., AppsFlyer, Branch, Adjust, Singular), or behavioral profiling SDKs in the Tether app. The app does not request or use Apple's IDFA, does not use Google Play's Advertising ID, and does not declare advertising as a data-use purpose in either App Store or Play Store privacy disclosures.

10.2 Do Not Track (DNT)

Most web browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature or setting. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. Accordingly, we do not currently respond to DNT browser signals in a standardized way. Because we do not sell or share personal information, there is nothing for a Global Privacy Control (GPC) signal to opt you out of (see Section 7.2).

If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Policy.

10.3 Web Analytics

For tetherup.app web properties, we use minimal, privacy-respecting analytics that do not build behavioral profiles and do not share data with advertising networks.


11. International Data Transfers

Tether is operated from the United States, and your information is stored and processed in the United States by us and the service providers listed in Section 4.2. If you use Tether from outside the United States, your information will be transferred to and processed in the United States.


12. Third-Party Links and Integrations

12.1 Third-Party Services

Tether integrates with: Google Contacts (Google People API); Microsoft Contacts (Microsoft Graph API); RevenueCat/Apple App Store/Google Play Store (payments); and social media platforms (when you choose to link social profiles).

12.2 Third-Party Privacy Practices

We are not responsible for the privacy practices of third-party services. When you use these services, you are subject to their privacy policies. We recommend reviewing their policies before use. We only request the minimum necessary permissions and do not access data beyond what is required (e.g., we do not access your emails when connecting Google Contacts).


13. Push Notifications and Communications

13.1 Types of Communications

Transactional/Service Messages:

  • Authentication codes (SMS OTPs via Telnyx and email OTPs via Resend — required for account access)
  • Security alerts (for example, when a new device signs in to your account)
  • Phone-number-change security notifications — sent to the prior phone number (SMS), the verified email address (email), and any other signed-in devices (push), each containing a 24-hour revocation link (see Section 3.7)
  • Email-address-change security notifications — sent to the prior verified email address (email), the new email address (email), the verified phone number (where applicable, SMS), and any other signed-in devices (push), each containing a 24-hour revocation link (see Section 3.7)
  • Critical service updates (maintenance, outages, security patches)

Marketing Messages: We do not currently send marketing email or SMS. If we start, we will ask for any consent the law requires and include an unsubscribe option in every message.

Push Notifications (Can Opt Out):

  • Contact information updates
  • Birthday and important date reminders
  • Directory activity
  • Event invitations and RSVP reminders

13.2 SMS Consent and TCPA Compliance

By selecting the unchecked SMS consent box when you provide or change your phone number, you expressly consent to receive SMS messages from Tether via Telnyx, including OTPs and security alerts required for phone-based authentication and related Service functionality. Message and data rates may apply. Message frequency varies by activity.

  • Opt out of SMS: Reply STOP to any message. Tether sends only transactional SMS, so STOP stops every message we send — including the one-time passcodes used to sign you in.
  • Help: Reply HELP or contact [email protected]
  • Note: If you cancel all SMS from us, you may lose access to certain features (including account authentication)
  • We will not share or sell mobile information or SMS opt-in data to third parties for promotional or marketing purposes. We also do not rent SMS-program data or disclose it for an unaffiliated third party's independent use

Full SMS terms: tetherup.app/sms

13.3 Managing Communications

  • Push Notifications: Disable via device settings (Settings > Notifications > Tether) or configure specific types in app settings
  • Email: Use the unsubscribe link in contact-card and event emails, or manage notifications in app settings
  • SMS: Text STOP to stop all Tether SMS, including authentication codes and security alerts. Text START to opt back in

14. Clipboard Access

Tether does not read your clipboard. The app writes to your clipboard only when you tap a copy button, and only the value you chose. Nothing you copy is sent to our servers.


15. Job Applicants

When you apply for a position at Tether through our website or via email, we collect information you provide in connection with your job application, including contact information, professional credentials, employment history, educational background, and other information typically included in a résumé or CV. We use this information to facilitate our recruitment activities and process employment applications, monitor recruitment statistics, and respond to your application. We do not use job applicant data for purposes unrelated to recruitment. Applicant data is retained for the duration of the recruitment process and for a reasonable period thereafter to comply with legal obligations or respond to inquiries. Contact [email protected] for questions about your applicant data.


16. Updates to This Privacy Policy

We may update this Privacy Policy from time to time. We will post updates in the app and on our website, update the "Last Updated" date, and for material changes, provide prominent notice via in-app notification, email, and/or push notification. Your continued use after the effective date constitutes acceptance. We will ask for your consent before using information we already hold in a materially different way. If you do not agree, discontinue use and delete your account. We maintain a version history of this Privacy Policy; contact [email protected] for previous versions.


17. Contact Us

PurposeContact
General privacy inquiries[email protected]
Rights requests (access, deletion, correction)[email protected]
Privacy appeals[email protected] (Subject: Privacy Rights Appeal)
General support[email protected]
PostalTether, LLC, 5900 Balcones Dr Ste 100, Austin, TX 78731, USA
In-AppSettings > Help & Support

We aim to respond to all privacy inquiries within 30 days (or as required by applicable law for rights requests).


18. Specific State and Country Disclosures

18.1 Nevada (NRS 603A)

We do not sell "covered information" as defined by Nevada law.

18.2 Texas (TDPSA)

We do not sell personal data. We do not process personal data for targeted advertising. Your rights under the TDPSA (access, correct, delete, portability, appeal) are honored as described in Section 7.3.

18.3 California — Additional Disclosures

Because we do not sell or share personal information, and use sensitive personal information only as needed to provide the Service, we do not offer "Do Not Sell or Share" or "Limit the Use of My Sensitive Personal Information" links. You can make any privacy request at [email protected].

18.4 Canada (PIPEDA)

See Section 7.4.


19. Definitions

Personal Information: Information that identifies, relates to, describes, or could reasonably be linked with you or your household.

Processing: Any operation performed on personal information, including collection, use, storage, disclosure, and deletion.

Service: The Tether mobile application and all related services.

User / You: The person using Tether or the entity on whose behalf the person is using Tether.

Device: Any electronic device capable of running the Tether application.

Contact: A person whose information you store in Tether.

Non-User: A person whose information you have stored in Tether but who does not have a Tether account.

Privacy Circle / Sharing Tier: One of three type categories (Community, Professional, Close) controlling what information you share.

Shared Directory/Circle: A collaborative space where multiple Tether users share contact information based on common affiliation.

Sensitive Personal Information (SPI): Personal information including health data, precise geolocation, biometric data, financial account information, racial or ethnic origin, religious beliefs, and other categories defined under CCPA/CPRA and similar laws.

Mutual-Contact Discovery: A suggestion, based on the phone numbers saved in two users' address books, that they may know each other. It never creates or accepts a connection; one user must send a request and the other must accept it.

EXIF Metadata: Exchangeable Image File Format data embedded in digital photos, which may include GPS coordinates, camera model, and timestamps.


Tether Tether

Stay reachable to the people who matter.

Product

  • How it works
  • Guides
  • Pricing
  • Blog
  • Request access

Company

  • About
  • FAQ
  • Your data
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • SMS Terms
  • Community Guidelines
  • Privacy Inquiries
  • Billing Support
© 2026 Tether, LLC All rights reserved.