We built Tether because we believe your contact information belongs to you — and so does your data. We don't sell your personal data as a source of revenue. We don't use it for advertising. We take care in overseeing how your data is accessed and what it is used for. Our philosophy: only collect and process what is necessary to operate and improve the Service, and treat your data the way we would want someone to treat ours.
Specific examples of how this philosophy is built into the product:
| Topic | Short Answer |
|---|---|
| Do we sell your data? | No |
| Do we use advertising networks? | No |
| Do we share data with third parties? | Only service providers necessary to operate the app (see Section 4.2) |
| Do we collect health data? | Only if you choose to fill in the optional allergy and dietary fields, for yourself or your contacts. Yours are never shared unless you choose to share them. |
| How do connection suggestions work? | If two people have each other's phone number saved, we may suggest they connect. A suggestion never connects you automatically. |
| Do we use product analytics? | Only with your explicit consent — PostHog events use a separate pseudonymous analytics ID and no contact data; see Section 4.2 |
| Do we strip EXIF/GPS from uploaded photos? | Yes — uploaded images are re-encoded to a normalized JPEG, which strips embedded EXIF/GPS metadata before storage (see Section 2.5) |
| Do we verify your phone number is a real mobile? | Yes — at signup we run a carrier lookup via Telnyx to confirm your number is a mobile line. Voice-over-IP, landline, and toll-free numbers are refused. The carrier name, line type, and country are stored to avoid re-paying for repeat lookups. See Section 2.9. |
| Do we detect compromised devices? | Yes — the app refuses to operate on jailbroken or rooted devices (see Section 3.8) |
| What happens when you change your phone or email? | A 24-hour revocation window with notifications to old phone, old email, and other devices (see Section 3.7) |
| Can you export your data? | Yes — vCard, CSV, or JSON via Settings |
| Can you delete your account? | Yes — Settings > Danger zone > Delete account |
Welcome to Tether ("we," "our," or "us"). Tether is a privacy-first professional contact management application that keeps your contact information current through live updates and synchronization across your devices.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (collectively, the "Service"). Please read this policy carefully. If you do not agree, please do not access the Service.
We reserve the right to make changes to this Privacy Policy at any time. We will alert you about material changes by updating the "Last Updated" date and, for significant changes, by providing prominent in-app notice, email notification, or both. Your continued use of the Service after the effective date of any revised Policy constitutes acceptance.
Account Information:
Contact Data: You may choose to store the following information about your contacts:
Event Data: When you create or participate in events:
Posts and Activity:
Privacy Circle Assignments:
Mailing and Address-Request Data:
Directory and Shared Circle Data:
Communication Preferences:
Device Information:
Usage Data: The product-analytics items below are collected only after you turn on analytics in Settings. Error and performance monitoring through Sentry is separate and privacy-filtered as described in Section 4.3.
Technical Data:
Contact Import Services: With your explicit permission, we may import contact data from:
Import lineage is preserved on each contact record (import source, batch ID, and fingerprint) for deduplication, undo, and audit purposes.
Selecting records for import only adds or updates contacts in Tether. It does not send an email, text, invitation, or other message to those contacts. If a possible match already exists in Tether, you review proposed changes before they are saved. A later group-message, contact-card, event, or address-request action is a separate user-directed step with its own recipient review.
When you authorize these integrations, we receive all contact information stored in those services, metadata about when contacts were created or last modified, and contact groupings and labels. We only request the minimum permissions necessary to provide our services. We do not access your emails, documents, or other data unrelated to contact management. Calendar access is a separate, optional feature with its own permission — see Section 2.10.
Google data. Tether's use of information received from Google APIs, including Google Contacts, adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google contact data only to import the contacts you choose into Tether. We do not sell it, use it for advertising, or let people read it except as needed for security, to comply with the law, or with your permission.
Data About You from Others: Just as you may provide information about your contacts when you sync your device contacts, others may provide limited information about you when they do the same. For example, another Tether user may save your phone number in their address book, and that information may be used to suggest a mutual connection between you, subject to the connection-suggestion rules in Section 3.9.
Contact Import Authentication: When you authorize Google or Microsoft for contact import, we receive basic profile information to authenticate the connection, a provider-specific user identifier, and an account timestamp. These connections are used solely for contact import — they are not used for Tether authentication (Tether uses Phone OTP only).
If you enable biometric authentication (Face ID, Touch ID, fingerprint): we do not collect, store, or transmit your biometric data; authentication is processed entirely on your device using the secure enclave; we only receive a success/failure signal; your biometric templates never leave your device.
When you upload photos or images to the Service (including profile photos, contact photos, event photos, and life-update photos), the image is automatically re-encoded to a normalized JPEG before storage. This re-encoding strips embedded EXIF metadata — including GPS coordinates, camera make and model, device serial numbers, and timestamps — so that metadata is not retained on our servers or shared with other users.
Photos you upload may be visible to other users in accordance with your privacy-tier and circle settings. Note that metadata stripping happens at upload only; if you share an original image file outside Tether by other means, that copy may still contain its embedded metadata.
We collect precise location only if you turn on location sharing, which is off by default and currently available on iPhone. While it is on, the app shares your current location with the circles you have allowed to see it. Tether does not request the "Always" location permission and does not track your location in the background. You can turn sharing off at any time, which stops it.
We do not work out your location from your IP address. If you add a physical address to your profile or contacts, it is stored and shared according to your circle settings.
Each account in the Service has, at any point in time, zero or one "verified" status for the user's email address and zero or one "verified" status for the user's phone number. Verification is performed by sending a one-time code to the identifier and requiring the user to enter that code in the app.
We process verified-identifier status for the following purposes:
The dates your email and phone were verified are stored on your account record. Verification status does not result in publication of your email or phone to other users (see Section 3.1).
Being listed as someone's family member. If another Tether user lists you as a family member on their contact card and you are a Tether user, the people they share that card with may see that you are on Tether and may send you a connection request. As with all connection requests, this is governed by your connection-request settings, and you can decline any request. Your phone number and email address are never disclosed to those people through the other user's card.
Each time the app launches, it checks on your device whether the device has been jailbroken (iOS) or rooted (Android), and if so it refuses to run. The result is not stored on our servers or sent to our analytics provider. If a device is locked out, or the check cannot run, our error-monitoring provider receives only the reason and the platform so we can spot false alarms. See Section 3.8.
Early-access request form (tetherup.app/request-access). During our soft-launch period, anyone may submit a request for access by entering their name, mobile phone number, email address, and (optionally) where they heard about us. We also record the request's IP address and user-agent string for abuse prevention. Until an account is created, this information is stored in our access-request records with the request's review status. When you create an account using the same phone number, the request remains in our records as part of the eligibility audit trail. You may request deletion of an unfulfilled request at any time by emailing [email protected].
Phone-number carrier verification. Before sending a sign-in code to a new phone number, we ask Telnyx (see Section 4.2) whether it is a mobile number. We don't send codes to voice-over-IP, landline, or toll-free numbers, which are commonly used for automated sign-ups. We keep the result (carrier, line type, and country) under a hashed form of the number rather than your account, so we don't repeat the lookup. If you believe a mobile number was misclassified, email [email protected].
SMS delivery records. For up to 90 days, we retain a service-only dispatch record so retries cannot send duplicate codes and so we can confirm delivery. It contains a hashed form of the destination phone number, its allowed-country category, provider message/event identifiers, status and error codes, and timestamps. It does not contain the raw phone number, one-time code, or message body and is not linked to an account record.
If you enable Tether's calendar availability feature, the app reads your device calendar — using the calendar permission you grant your operating system — to determine when you are busy or free. We store only the start and end times of your busy periods on our servers; we do not receive or store event titles, locations, attendee lists, descriptions, notes, or any other content from your calendar entries. Calendar entries are read on your device, and only the resulting busy/free time ranges are transmitted to us. If you choose, the app can also add Tether events to your device calendar; this happens on your device. Busy/free ranges are deleted automatically 14 days after they end.
When you enable the calendar availability feature, your busy/free times are shared by default with the circles you create from Tether's standard templates — Close, Community, and Professional circles each include calendar availability in their default shared fields. You can change what any individual circle sees through that circle's Edit Permissions screen, stop sharing with a circle, or turn off calendar access entirely in the app's settings, at any time. Circles see time ranges only — never the underlying calendar entries. Turning the feature off deletes the busy-block data we have stored for you. We do not sell your calendar data, share it with third parties, or use it for advertising.
Tether does not use machine learning or artificial intelligence on your data, and we do not use personal data to train AI or large language models. We use fixed rules for:
We do not make solely automated decisions about you that have legal or similarly significant effects, except for security measures such as rate limiting or suspending an account for abuse. You can ask a person to review any such decision by contacting [email protected].
We do not use your personal contact data for advertising targeting. We do not sell your data or share it for cross-context behavioral advertising.
When you change the phone number or email address on your account, we keep a short-lived record of the change — the old and new identifier and when the undo window ends — so the change can be reversed. On a best-effort basis we send security notices to your previous phone number or email, your verified email, and your other signed-in devices, each with a link to undo the change within 24 hours.
Undoing a change restores the previous identifier, locks the account until you verify your identity, and signs out every device. A phone change also signs out every device; an email change signs out your other devices. If you are signed in with an email code, you must sign in with your phone before changing your email. We keep records of these changes and notices for security, and delete the change records at least 30 days after they are completed or undone.
We process this information to keep your account secure. These safeguards cannot be turned off, although replying STOP still stops all Tether SMS until you reply START.
At app launch, the Service runs an on-device jailbreak/root check. If the device is detected as compromised, the app renders a lockout screen and does not function. The result is not stored on Tether's servers and is not sent to our analytics provider. A security event naming the reason code is sent to our error-tracking provider when the device is locked out or the check cannot run, so that false-positive lockouts are detectable; see Section 2.8. We use this check to protect your account and the contact data stored on your device.
When two users each have the other's verified phone number saved, we may suggest that they connect. Someone who knows your name and your verified phone number or email address can also look you up to send you a connection request; they see only your name, photo, and handle. A suggestion never creates or accepts a connection: one person must send a request and the other must accept it. We can turn this feature off, and blocking someone or turning off connection requests prevents a connection.
With Other Tether Users (Sharing Tier Settings): When you connect with another Tether user, you control what they see through your sharing-tier settings. There are three tiers — Close, Community, and Professional — and each has a default set of fields that are shared. You can override the defaults on a per-circle basis from Settings > Privacy & sharing > What new people see. The default-shared fields for each tier, as currently configured in the app, are:
Health fields are never shared by default. The app asks for your consent before you add your own allergies or dietary preferences. Sharing them needs a separate consent: you can choose to share them with a particular circle only after agreeing to that consent in the app. You can withdraw either consent at any time in Settings. Withdrawing either one stops Tether sharing your health fields, but it does not delete health fields already on your profile; you can delete those yourself on your profile.
These defaults are set by the Service and may be revised in future releases, in which case this Section will be updated. You can review and change what each of your circles shares at any time in the app under Circles → circle settings.
Family members on your card. When "family members" is among the fields you share with a circle, the connections in that circle may see, for each family member you have linked: their name, your relationship to them, and contact type. For a family member who is not a Tether user, this may also include that person's primary phone number and email address as stored in your address book. For a family member who is a Tether user, their phone and email are never shared through your card — instead, your connection may see that the person is on Tether and may send them a connection request directly (subject to that person's own connection-request settings). Children's direct contact details (phone and email) are never shared through your card. Because this shares information about other people, you are responsible for having any consents required by law to do so (see our Terms of Service).
Unassigned contacts. When a new connection is created and you have not yet assigned the connected user to a circle, a separate "Unassigned Defaults" setting determines what is shared until you make an assignment. The Unassigned Defaults are configured in Settings > Privacy & sharing > What new people see and are distinct from the Community tier defaults above.
Data on Disconnect: When you block or remove a connection, the details that person shared with you through Tether are removed from your device the next time the app syncs. Anything you saved about them yourself stays in your address book.
Events and Co-hosts: Co-hosts can see only the display name and email address you attached to each guest invitation (captured as a per-RSVP snapshot at invite time) — not any other information from your private address book. When a host or co-host reuses a past event's guest list for a future event, guests not already in the inviter's address book may be saved as new contacts from the snapshotted name and email, tagged with import source past_event_invite.
We share information with third-party service providers who perform services on our behalf. Our service providers may use your information only to provide their services to us, and they must protect it.
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase Inc. | Database, auth, file storage, real-time sync, edge functions (AWS, United States) | All user data stored in database |
| Cloudflare, Inc. | Website hosting, network and DNS services, bot protection (Turnstile) on web forms, CardDAV profile delivery, and R2 backup storage | Web request metadata, CardDAV profile delivery, encrypted logical-database archives, encrypted backup copies of Storage object bytes (including private photos), and minimal erasure receipts that record only the schema version and deletion time |
| GitHub, Inc. (GitHub Actions) | Planned database backups on a temporary GitHub-hosted runner; not enabled until our processor agreement covers it | When enabled, a database snapshot is processed briefly in plaintext while it streams from pg_dump into age encryption. The encrypted archive is stored in Cloudflare R2, and GitHub keeps only digest-only backup evidence, not database content. |
| Sentry | Pseudonymous error tracking and performance monitoring with egress filtering | Crash logs, error events, bounded device/app context, and generated operational correlation IDs; no direct Tether account ID, raw URL, request body, or raw contact data |
| PostHog | Consent-only product analytics (events only; no contact data; property filter enforced at the SDK boundary) | Event names, allowlisted traits (subscription tier, signup date, contact count, circle count, cohort week), a random pseudonymous analytics ID that is never the Tether account ID, app version, environment |
| RevenueCat | Subscription billing via App Store / Google Play and entitlement updates to our backend | Your opaque Tether account UUID, subscription status, purchase events, billing issue events |
| Telnyx | SMS OTP delivery; SMS notification to the prior number when phone changes; pre-signup carrier lookup (Number Lookup API) to confirm the number is a real mobile line (see Section 2.9) | Phone number, OTP body, security-notification body, carrier-lookup query (phone number only — result cached in our database) |
| Resend | Transactional email (event invitations, event reminders, RSVP notifications, circle invites, contact-card emails, mailing-address requests, phone-change and email-change security notifications, and similar) | Email addresses, sender/recipient metadata, and the content you choose to send |
| Expo | Push notification delivery and over-the-air app updates | Push tokens; generic notification envelopes containing an opaque owner-bound delivery nonce, request ID, type, and expiry, which do not contain contact/event names, authored text, entity identifiers, or security-action URLs; and basic device and app-version information for updates |
| Microsoft | Contact import from Outlook / Microsoft 365 via OAuth 2.0 + Microsoft Graph API — only when you choose to connect a Microsoft account | Your Microsoft sign-in (OAuth) and the Outlook contacts you import via the Contacts.Read scope: names, phone numbers, emails, addresses, and notes |
| jail-monkey (on-device) | Device-integrity check (jailbreak / root detection) | None to jail-monkey — the check runs locally. A lockout or a failed check emits a reason code to our error-tracking provider (Section 2.8) |
| Apple Inc. / Google LLC | App distribution, in-app purchase, push-notification transit; contact import (Apple Contacts / Google People API on connect); map tiles and address geocoding when you view or save a location | Per their respective developer terms and privacy policies; for contact import, the contacts you choose to import; for maps, approximate location/viewport coordinates |
| Google LLC | Web fonts on our website and in our emails; fetching a Google Sheets link you choose to import | IP address and browser information when fonts load; the sheet you import |
We use the following analytics and monitoring tools:
Sentry (Error & Performance Monitoring): Sentry receives crash reports, error events, and performance traces. We do not attach your account to them, and we filter out contact details, message content, and other personal information before they are sent. Governed by Sentry's Data Processing Agreement.
PostHog (Product Analytics — Events Only): PostHog stays off unless you turn on analytics in Settings > Privacy & sharing > Who can reach you, and leaving it off never reduces what the app can do. When on, it receives filtered in-app events — never contact details, messages, notes, or addresses — tied to a random analytics ID that is not your Tether account ID. Session replay and automatic capture are off. If you turn analytics off, future collection stops; events already sent are handled under PostHog's retention settings. We use PostHog's U.S. cloud under its Data Processing Agreement.
RevenueCat (Subscription Analytics): RevenueCat receives your opaque Tether account UUID, purchase events, and subscription status updates necessary to process transactions, restore access, and provide subscription analytics (conversion rates, churn, subscription lifecycle events). We do not send your address book to RevenueCat. We retain the subscription projection needed to apply plan limits and support purchase issues.
Cloudflare Web Analytics (Web Properties): Our tetherup.app web properties use Cloudflare's privacy-respecting RUM analytics, which does not use cookies and does not build behavioral user profiles. No data from the mobile app passes through Cloudflare Web Analytics.
We do not use Google Analytics, Facebook Pixel, TikTok Pixel, Meta Audience Network, or any advertising-oriented analytics or attribution SDK in the Tether mobile app. We do not place advertising cookies or tracking pixels on our website. We do not use Apple's App Tracking Transparency-gated identifiers (IDFA) and the app declares "No, app does not use advertising ID" on Google Play.
We do not sell your personal data to advertisers. We do not share your personal data with advertising networks for behavioral targeting. We do not receive compensation for your data from any advertising partner. Tether generates revenue through subscription fees only.
If Tether is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of company assets, your information may be transferred as part of the transaction. We will provide at least 30 days' notice before your information becomes subject to a materially different privacy policy.
We may disclose your information if required by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, national security or law enforcement requests). We may also disclose when we believe in good faith that disclosure is necessary to comply with applicable law, enforce our Terms, protect against fraud or security risks, or protect the rights or safety of Tether, our users, or the public.
When permitted by applicable law and not prohibited by the legal demand itself, we will: provide you with prompt notice of any legal demand for your data; review requests for legal sufficiency; and, where appropriate, challenge overbroad or improper requests.
We may disclose personal information to professional advisors (lawyers, auditors, bankers, insurers) where necessary in the course of professional services they render to us, subject to confidentiality obligations.
We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you, for business purposes including research, service improvement, and industry reporting.
We may share your information for any other purpose with your explicit, informed consent.
We use industry-standard safeguards designed to protect your information, including:
Sessions. We do not impose a fixed session lifetime or inactivity timeout. A session continues unless you sign out, revoke the device or session, delete your account, or it is invalidated for a security or account-administration reason.
We review and update these measures as the Service and the threats it faces change.
In the event of a security breach involving your personal information, we will:
We keep a record of every security breach involving personal information, including our assessment of whether notice was required, for as long as the law requires.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
| Data Category | Retention Period |
|---|---|
| Contact data | While account is active; until contact is deleted |
| Account information | While account is active |
| Sync transactions | 24 hours |
| Change logs (audit) | 90 days |
| Soft-deleted contacts | 60 days, then permanently deleted by a daily maintenance job. A contact you merged into another contact is kept for as long as that surviving contact exists, so the merge stays reversible; it is hard-deleted on a later run of the same job once the surviving contact is itself deleted. |
| Event RSVP records | Retained with the event; deleted with account |
| Push tokens | Deleted when you sign out or your session ends; deactivated after 90 days unused and deleted after 180 days; deleted with your account |
| Error/crash logs (Sentry) | Kept under our error-monitoring provider's retention settings, with personal information filtered out |
| Product-analytics events (PostHog) | Collected only if you turn on analytics; kept under PostHog's retention settings |
| CRM communication logs | While account is active |
| Contact-card download payloads | 30 days after the final eligible scheduled delivery (no more than approximately 60 days from creation) |
| Contact-card email records | Recipient email, name, and unsubscribe details are removed after 13 months; the remaining record, which keeps only a hashed address, is deleted after 24 months |
| Address-request response links | 30 days |
| Unresolved address-update proposals | 60 days, then the submitted address is deleted |
| Address-request delivery records | Recipient email and name are removed after 13 months; the remaining request ledger is deleted after 24 months. Applied or rejected submitted-address payloads are cleared immediately. |
| Health-field consents | Kept as a record of your choice for as long as the law requires |
| Pending account-change records (phone / email / sign-in notice) | Live records: up to 24 hours (revocation window). Terminal records (committed or revoked): purged by the daily maintenance job, no fewer than 30 days after the terminal event. |
| Undo links for phone and email changes | Deleted with the related change record |
| Account-lockout records | While account is locked; preserved in audit log after recovery for security and forensics purposes |
| Transactional records | 7 years (tax and accounting purposes) |
| Lifetime inventory receipt | Minimal durable purchase-count record; account association removed on account deletion (see Section 6.2) |
When you request account deletion (Settings > Danger zone > Delete account):
You can also ask us to delete your account by emailing [email protected] from the email address on your account (we will verify the request). Deleting your account does not cancel an App Store or Google Play subscription; cancel it in your app store's subscription settings.
Immediate Actions:
After 30-Day Cooling Period:
Data We Retain After Deletion:
Most data is permanently erased at the end of the 30-day cooling period. A limited set of records is deliberately retained for the lawful purposes below. Where a record is kept, it is de-identified wherever de-identification still serves the purpose:
Third-Party Processor Residuals. Data already transmitted to our subprocessors before you deleted your account is deleted according to each subprocessor's own retention schedule, which we do not directly control. As part of account cleanup we request deletion of the subscription-processor customer record associated with your account (RevenueCat), and keep retrying until the provider confirms that it is absent. Acceptance of a deletion request alone is not confirmation of completed deletion. We record the residual-cleanup status for each processor. Residuals may include: SMS and OTP delivery logs (Telnyx), email delivery logs (Resend), pseudonymous error/performance events that carry no direct Tether account identifier but may retain operational correlation IDs (Sentry), consented product-analytics events keyed to a pseudonymous identifier that Tether does not map to your account (PostHog), and generic push-delivery receipts sent through Expo. These age out on each provider's own schedule. See Section 4.2 for the full subprocessor list.
We may delete an account that has had no sign-in or sync activity for 12 months or more, after giving at least 30 days' notice. Deletion follows Section 6.2. To keep your account, simply sign in before the date in the notice.
Regardless of your location, you have the following rights:
Categories of Personal Information We Collect:
California Privacy Rights:
Your Privacy Choices: Email [email protected] to exercise any of these rights.
Global Privacy Control (GPC): Tether does not sell or share personal information for cross-context behavioral advertising, so there is nothing for a GPC signal to opt you out of. If that ever changes we will honor the signal and say so here before the change takes effect.
Do Not Sell or Share: We do not sell personal information to third parties. We do not share personal information for cross-context behavioral advertising. These practices will not change without providing you with at least 15 days' advance notice and the ability to opt out before they take effect.
Shine the Light: We do not share personal information with third parties for their direct marketing purposes. California residents with questions may contact [email protected].
Depending on where you live, state privacy laws — including those of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia — may give you the right to:
Sensitive data. We process sensitive data — such as precise location if you turn on location sharing, or health fields if you choose to add them — only with your consent, and you can withdraw that consent in the app at any time.
Requests and appeals. Email [email protected]. We will verify your identity and respond within the time your state's law requires. If we deny your request, you can appeal by replying to our decision or emailing [email protected] with the subject "Privacy Rights Appeal." If we deny your appeal, you may contact your state's Attorney General.
Tether is not currently offered in Quebec. For users elsewhere in Canada, we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.
You may designate an authorized agent to submit privacy rights requests on your behalf. We require: (a) written authorization signed by you or a valid power of attorney; and (b) identity verification directly with you (unless you have provided a power of attorney). We may deny requests from agents that do not submit required proof of authorization.
Tether is for adults 18 and older, and we do not knowingly allow anyone under 18 to create an account. If we learn that someone under 18 has an account, we will delete it. If you believe a minor has an account, contact [email protected].
Parents and guardians may store information about their own children as contacts — for example, in a school directory. That information is managed by the parent or guardian, is not used to contact the child, and is covered by the rest of this Policy.
When you use Tether, you may import, store, or share information about people who do not have Tether accounts ("non-users") — including contacts from your address book, event guests, and manually entered contacts.
You are responsible for having a lawful basis for storing other people's information in Tether and for giving any notice the law requires.
If someone whose information is stored in Tether contacts us about it, we will respond to them directly as the law requires and will not tell the user who stored it who made the request. We may ask that user to help, and we may restrict or delete the information where the law requires.
As a mobile app, Tether uses software development kit (SDK) equivalents to what cookies do on websites. These SDKs collect technical data to help us operate and improve the Service. We use:
Sentry SDK (@sentry/react-native): Collects crash reports, error traces, and performance data. We do not attach your account, and personal information is filtered out before transmission.
PostHog SDK (posthog-react-native): Not started until you turn on analytics. It uses a random ID that is never your Tether account ID, does not record your screen or capture taps automatically, and stops when you turn analytics off.
RevenueCat SDK (react-native-purchases): Processes subscription purchases and provides subscription lifecycle analytics. No contact data is shared. RevenueCat may collect purchase-related device data per their privacy policy.
Expo Push SDK (expo-notifications): Registers push tokens for your devices. Notification text on your lock screen is generic; details load inside the app.
jail-monkey (on-device only): Performs a local jailbreak/root check at app launch. The result is not stored on our servers; a lockout or a failed check sends only the reason and platform to our error-monitoring provider (see Section 2.8).
We do not embed advertising SDKs, social-media tracking SDKs, attribution SDKs (e.g., AppsFlyer, Branch, Adjust, Singular), or behavioral profiling SDKs in the Tether app. The app does not request or use Apple's IDFA, does not use Google Play's Advertising ID, and does not declare advertising as a data-use purpose in either App Store or Play Store privacy disclosures.
Most web browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature or setting. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. Accordingly, we do not currently respond to DNT browser signals in a standardized way. Because we do not sell or share personal information, there is nothing for a Global Privacy Control (GPC) signal to opt you out of (see Section 7.2).
If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Policy.
For tetherup.app web properties, we use minimal, privacy-respecting analytics that do not build behavioral profiles and do not share data with advertising networks.
Tether is operated from the United States, and your information is stored and processed in the United States by us and the service providers listed in Section 4.2. If you use Tether from outside the United States, your information will be transferred to and processed in the United States.
Tether integrates with: Google Contacts (Google People API); Microsoft Contacts (Microsoft Graph API); RevenueCat/Apple App Store/Google Play Store (payments); and social media platforms (when you choose to link social profiles).
We are not responsible for the privacy practices of third-party services. When you use these services, you are subject to their privacy policies. We recommend reviewing their policies before use. We only request the minimum necessary permissions and do not access data beyond what is required (e.g., we do not access your emails when connecting Google Contacts).
Transactional/Service Messages:
Marketing Messages: We do not currently send marketing email or SMS. If we start, we will ask for any consent the law requires and include an unsubscribe option in every message.
Push Notifications (Can Opt Out):
By selecting the unchecked SMS consent box when you provide or change your phone number, you expressly consent to receive SMS messages from Tether via Telnyx, including OTPs and security alerts required for phone-based authentication and related Service functionality. Message and data rates may apply. Message frequency varies by activity.
Full SMS terms: tetherup.app/sms
Tether does not read your clipboard. The app writes to your clipboard only when you tap a copy button, and only the value you chose. Nothing you copy is sent to our servers.
When you apply for a position at Tether through our website or via email, we collect information you provide in connection with your job application, including contact information, professional credentials, employment history, educational background, and other information typically included in a résumé or CV. We use this information to facilitate our recruitment activities and process employment applications, monitor recruitment statistics, and respond to your application. We do not use job applicant data for purposes unrelated to recruitment. Applicant data is retained for the duration of the recruitment process and for a reasonable period thereafter to comply with legal obligations or respond to inquiries. Contact [email protected] for questions about your applicant data.
We may update this Privacy Policy from time to time. We will post updates in the app and on our website, update the "Last Updated" date, and for material changes, provide prominent notice via in-app notification, email, and/or push notification. Your continued use after the effective date constitutes acceptance. We will ask for your consent before using information we already hold in a materially different way. If you do not agree, discontinue use and delete your account. We maintain a version history of this Privacy Policy; contact [email protected] for previous versions.
| Purpose | Contact |
|---|---|
| General privacy inquiries | [email protected] |
| Rights requests (access, deletion, correction) | [email protected] |
| Privacy appeals | [email protected] (Subject: Privacy Rights Appeal) |
| General support | [email protected] |
| Postal | Tether, LLC, 5900 Balcones Dr Ste 100, Austin, TX 78731, USA |
| In-App | Settings > Help & Support |
We aim to respond to all privacy inquiries within 30 days (or as required by applicable law for rights requests).
We do not sell "covered information" as defined by Nevada law.
We do not sell personal data. We do not process personal data for targeted advertising. Your rights under the TDPSA (access, correct, delete, portability, appeal) are honored as described in Section 7.3.
Because we do not sell or share personal information, and use sensitive personal information only as needed to provide the Service, we do not offer "Do Not Sell or Share" or "Limit the Use of My Sensitive Personal Information" links. You can make any privacy request at [email protected].
See Section 7.4.
Personal Information: Information that identifies, relates to, describes, or could reasonably be linked with you or your household.
Processing: Any operation performed on personal information, including collection, use, storage, disclosure, and deletion.
Service: The Tether mobile application and all related services.
User / You: The person using Tether or the entity on whose behalf the person is using Tether.
Device: Any electronic device capable of running the Tether application.
Contact: A person whose information you store in Tether.
Non-User: A person whose information you have stored in Tether but who does not have a Tether account.
Privacy Circle / Sharing Tier: One of three type categories (Community, Professional, Close) controlling what information you share.
Shared Directory/Circle: A collaborative space where multiple Tether users share contact information based on common affiliation.
Sensitive Personal Information (SPI): Personal information including health data, precise geolocation, biometric data, financial account information, racial or ethnic origin, religious beliefs, and other categories defined under CCPA/CPRA and similar laws.
Mutual-Contact Discovery: A suggestion, based on the phone numbers saved in two users' address books, that they may know each other. It never creates or accepts a connection; one user must send a request and the other must accept it.
EXIF Metadata: Exchangeable Image File Format data embedded in digital photos, which may include GPS coordinates, camera model, and timestamps.