Who this is from, and what it covers
In plain terms
This policy is about the Tend iPhone app and this site. Apple, MET Norway, and anywhere you send a file yourself have their own policies too.
This policy explains what happens to information when you use Tend, the iPhone app for people living with fibromyalgia. Tend is published by Off Script Foundry, Inc. (“we”, “us”), and in this policy “the app” means Tend and nothing else. Tend runs on iPhone today, and where this policy says your device it means the Apple device you have Tend installed on, so if Tend ever runs on another Apple device the same rules apply there.
This site is part of it. The public pages use PostHog to count limited, cookieless pageviews so we can understand which pages are useful. The site carries no advertising, does not record sessions or clicks, and does not use analytics cookies or browser storage. Our host also keeps ordinary server logs.
It does not cover Apple or MET Norway. The App Store, Apple Health, and the Face ID or passcode check your device performs are all Apple’s, and Apple’s privacy policy governs them. MET Norway’s handling of weather requests is covered by its published terms. It also does not cover what happens to a file after you export it from Tend and send it somewhere; section 12 covers that.
It sits alongside the Terms and Conditions, which cover what Tend is and is not.
What we collect
In plain terms
Tend syncs your record to your account. Beginning with Tend 1.0.1 build 8, the iOS app links six product actions to the account UUID in PostHog but excludes health details, email, name, location, and free text. The public site remains anonymous and cookieless.
Tend requires an account. You sign in with Apple or with Google, and we receive the account identifier and email address that provider gives us. If you use Sign in with Apple and choose Hide My Email, we only ever see the relay address Apple creates, never your own.
Your health record is stored on Tend’s server so that it reaches every device you sign in on, and so that losing a phone does not lose your days. That means we hold a copy of what you record: your symptoms, your pain map, medications, flares, notes, and the sleep, step and heart figures you choose to share from Apple Health.
We never sell it and never use it for advertising. We share it only with the service providers needed to store and sync it for you. It is stored with row-level access rules so that your rows are readable only by your account. The other app services are the limited PostHog analytics and optional weather requests described below.
Beginning with Tend 1.0.1 build 8, the app sends PostHog six product actions: analytics being enabled, an app open, first onboarding completion, a completed check-in, a paywall view, and—once purchases ship—a successful subscription start. It also sends the signed-in Tend account’s Supabase UUID as PostHog’s distinct ID. This creates one analytics profile for the account and associates those limited actions with it.
Earlier Tend builds sent the same limited actions under an app-installation identifier and did not identify the Tend account. When build 8 first identifies a signed-in account, PostHog may merge that installation’s earlier actions into the account profile.
PostHog does not receive your email, name, sign-in provider, check-in answers, symptom or sleep values, flare occurrence, notes, HealthKit data, location, or free text. The UUID is sent with no person properties. Automatic screen and interaction capture, session replay, surveys, feature-flag events, error capture, and IP-derived location are disabled. A code allowlist drops every unapproved event and property. Tend reads no advertising identifier and does not track you across apps or websites.
You can turn app analytics off under Privacy in Tend Settings; it is on by default. Turning it off stops future collection. It does not by itself erase analytics PostHog already retains. Contact us to request that deletion, or delete your Tend account as described in section 13.
The public website is separate from the app. When you visit a page, our analytics provider, PostHog, receives a pageview with the page path and time plus ordinary technical details such as browser type, operating system, device category and screen size. Query strings, URL fragments, campaign identifiers and referring pages are removed or disabled before the event is sent. Like any internet request, the request exposes an IP address and user agent to PostHog. In the cookieless mode enabled for this project, PostHog uses request data to calculate a privacy-preserving identifier on its servers for aggregate visitor counts. No PostHog identifier is stored in the visitor’s browser.
For the public website, PostHog is configured in permanent cookieless mode. It stores no PostHog identifier in cookies, local storage or session storage, and we do not create a profile or call its identify function. Session replay, click and form autocapture, heatmaps, surveys, feature flags, performance monitoring and error capture are all disabled. The site honors a browser’s Do Not Track setting. PostHog’s own handling of the limited event data is described in its privacy notice.
We use these website counts only to understand traffic and improve the public site. Website pageviews are not joined to the Tend account or the app’s PostHog profile, used for advertising, sold, or shared for cross-site tracking.
Where your information lives
In plain terms
Your health record lives in an encrypted database on your iPhone and is mirrored to your Tend account. Device settings and widget data stay on the device.
Everything you put into Tend is written to a database on your iPhone and mirrored to your Tend account. That includes your check-ins and every moment of a multi-moment day, the places you mark on the body map, your notes, flares and flare plans, medications and doses, labs, questions for your doctor, records of visits, reflections, experiment entries, and cycle dates if you choose to log them.
That database is stored with iOS complete file protection, which means it is encrypted at rest and unreadable while your device is locked. It is not shared with any other app.
A small amount of ordinary app state is kept in the app’s own preferences on the same device: whether you have finished the introduction, your theme and accessibility choices, your reminder preferences, the date of your last Apple Health read, and whether the app lock is on. None of it is health data and none of it leaves the device.
If you use the Today home-screen widget, the app writes two facts — how today is reading, and whether you have recorded it — into a shared container on your own device so the widget can draw them. The channel runs one way, and the widget never opens your record.
If you connect weather, Tend also keeps a small operational cache in its protected cache directory. It contains the rounded 0.1-degree weather tile, forecast values, and cache timestamps—not your precise location or any health information. Disconnecting weather or using Delete everything removes this cache.
Where your record lives
In plain terms
Your record is kept on your device and on Tend's server. It is still excluded from iCloud Backup. Exporting is the portable copy you can hold yourself.
Your record is kept in two places: on this device, and on Tend’s server under your account. If you lose or erase this iPhone, signing in on a new one brings your days back.
Tend still marks its health-record database to be excluded from iCloud Backup. Apple never receives a copy, and your account is what restores the record instead.
You can delete it. “Delete everything” erases the record from this device and from our server and keeps your account; “Delete my account” does both and closes the account itself. Neither can be undone.
Exporting your data, described below, is the copy you keep yourself: a plain file that is readable without Tend.
Health information, and why it is held this way
In plain terms
Most of what Tend holds is sensitive health information. It is stored only to provide and sync your record, never for advertising, analytics, or model training.
Most of what Tend holds is health information about you: symptoms, pain, fatigue, sleep, mood, medications, and free text about your body and your life. In many places this is legally special category or sensitive personal information, and it is exactly the kind of information that does real harm when it escapes.
We keep it only to provide your record and sync it across your devices. It is never sold, rented, used for advertising or marketing, used to train a model, or sent to PostHog. Access is limited to operating and supporting Tend, and your database rows are protected by account-level access rules.
Apple Health
In plain terms
Optional and read-only. Tend never writes to Apple Health. Imported values become part of the Tend record synced to your account, but never go to PostHog.
If you choose to, Tend can read sleep analysis, step count, and resting heart rate. A separate Watch signal option can read heart-rate variability, sleeping heart rate, and heartbeat timing. These values sit beside what you tell the app; they never replace it.
It is off until you turn it on in Settings, it is read-only, and it is never required. Tend asks for no write permission at all, so it can never put anything into Apple Health. It does not read menstrual data from Health. If you turn on cycle tracking, the dates are the ones you enter yourself.
Anything read from Health is written into the same record as everything else and syncs to your Tend account. Raw heartbeat samples stay in HealthKit; Tend stores only the derived nightly Watch summary. None of this data goes to PostHog. If you decline, Tend uses what you tell it.
Weather and approximate location
In plain terms
Optional and foreground-only. Tend rounds a reduced-accuracy location to a 0.1-degree tile and sends it directly to MET Norway with the request IP. No health data goes with it.
The Weather & your body card is off until you tap Connect. Tend then asks iOS for reduced-accuracy, when-in-use location. It never asks for a temporary precise-location upgrade and does no background location work.
Before making a request, Tend rounds the location to one decimal degree—roughly a 5–11 km tile depending on latitude. It sends that rounded latitude and longitude directly to MET Norway over HTTPS. Like any direct internet request, MET Norway also receives the device’s IP address. The request contains no symptom, medication, note, HealthKit value, account identifier, advertising identifier, or other health-record data.
MET Norway returns local pressure, temperature, humidity, and forecast values. Its published terms state that request IP addresses and coordinates are recorded in service logs. Those logs are controlled by MET Norway, not Tend, and Tend cannot read or delete them. See MET Norway’s terms.
Tend checks only while the app is in use, normally no more than once every six hours, and follows MET Norway’s cache headers. The removable on-device weather cache is described above. Disconnect weather to clear it and stop future requests. Previously derived, non-reversible pressure-pattern readings remain in your local record unless you delete that record.
Voice notes
In plain terms
Speak a note and your phone turns it into text by itself. No recording is kept, and no audio is sent anywhere.
On days when typing is hard, Tend lets you speak a note instead.
Speech is turned into text by iOS on your device. The app requires on-device recognition, so there is no path in it that sends audio to a recognition server. No recording is saved: the audio exists only while you are speaking and is discarded as it is transcribed. If on-device recognition is not available on your device, the app offers a text field instead rather than quietly falling back to a network service.
The microphone and speech recognition permissions are requested the first time you use this feature, and never otherwise.
Reminders and notifications
In plain terms
Reminders are set by your phone, for your phone. No server sends you anything.
Any reminder Tend gives you is a local notification scheduled by the app on your own device. Nothing is sent from a server, no push token is registered, and no notification identifier is transmitted anywhere.
After you have saved a few check-ins, Tend quietly asks iOS for the gentlest kind of notification permission. No prompt appears, and reminders arrive softly in Notification Center rather than as banners. Full banners are only ever requested when you ask for them in Settings. If you decline, or switch them off later in iOS Settings, the app carries on without them and does not nag.
The app lock, Face ID and Touch ID
In plain terms
The lock is your phone's, not ours. Tend only ever learns that the check passed. Your device passcode always works, so it cannot shut you out of your own record.
You can ask Tend to require Face ID, Touch ID or your device passcode before it opens. This is off unless you turn it on, and you can turn it off again at any time.
It is handled entirely by iOS through the LocalAuthentication framework. Tend receives one thing back: whether the check succeeded. It never receives your face, your fingerprint or your passcode, and it stores no biometric data of any kind. Nothing about the lock is sent anywhere.
The lock always accepts your device passcode as a fallback, so it can never lock you out of your own health record. While it is on, Tend hides its contents in the iOS app switcher and the home-screen widget redacts itself.
Permissions the app asks for
In plain terms
Five, all optional, each asked when you reach the feature that needs it. Refuse every one and the rest of the app still works.
Tend asks for these, and only these:
- Apple Health, read-only, when you tap to connect it in Settings. Four data types, described above.
- Microphone and speech recognition, the first time you speak a note instead of typing it.
- Notifications, for the reminders you set yourself. Tend also makes one silent request after a few check-ins, described in section 09, which shows no prompt.
- Face ID or Touch ID, only if you turn the app lock on.
- Approximate location, only after you tap Connect on the weather card. It is used as described in the weather section.
The app asks for no camera or photo access, contacts, calendars, or Bluetooth. Every permission above is optional, is never asked up front, and is never asked for a second time if you decline. The app works when you say no to all of them.
When information leaves your device
In plain terms
Your health record syncs to your Tend account. Exports go where you choose. Analytics never receives the record, and weather requests carry no health data.
Your health record is sent to Tend’s Supabase database so it can sync across devices signed in to your account. That transfer is the app’s core service. PostHog receives only the limited product actions described in section 02 and never receives the record. The separate weather request also contains no part of the record.
Export my data. Settings writes your record to a JSON file and a CSV file and hands them to the standard iOS share sheet. You choose the destination: a message, a mail app, Files, another app, your own computer.
The doctor’s letter. Tend can compose a printable PDF summary of what you have logged and share it the same way, so you can bring something real to an appointment.
Once a file leaves through the share sheet it is in the hands of whatever service or person you sent it to, under their terms, and out of our reach. It never passes through us on the way.
One related thing worth naming: the crisis resources screen opens your phone or messages app with a number already filled in. Placing the call or sending the text is your action, handled by your device and your carrier. Tend does not place it, does not record it, and does not know whether you did.
Taking your data, and erasing it
In plain terms
Export gives you the Tend record as JSON and CSV. Delete everything erases that record but keeps the account and analytics. Delete my account also requests PostHog deletion.
Export. “Export my data” in Settings gives you your complete record as a JSON file and a day-per-row CSV file, immediately, free, and in a form other software can read.
Delete everything.In Settings, this erases your record from this device and Tend’s server, and removes the operational weather cache. It asks you to confirm, and there is no undo. It keeps your Tend account and does not delete its PostHog analytics profile or already-retained events. New permitted app events remain linked to the same account unless you disable analytics.
Delete my account. This erases the same Tend record, asks PostHog to delete the profile and events associated with the account UUID, and closes the Supabase account. The server performs these steps in that order; if a required deletion step fails, the account remains open so the deletion can be tried again.
Deleting the app.Removing Tend from your iPhone removes its local database and preferences. The server copy remains available to your account until you use Tend’s delete controls. Any file you exported yourself remains yours to manage.
Edit and correct. Every entry in Tend can be changed or removed by you, at any time, in the app.
How long anything is kept
In plain terms
Your Tend record is kept until you delete it. Account-linked iOS analytics remains under PostHog retention until it is deleted; disabling analytics stops future collection only. Website pageviews remain anonymous.
Your record stays on your device and in your Tend account until you delete it. The server copy is retained so your other signed-in devices can restore and sync the record.
Account-linked iOS product events, the UUID profile, and cookieless website pageviews remain under PostHog’s service retention settings until Tend requests deletion. Disabling analytics stops future collection but does not automatically erase already-retained analytics. You can delete account-linked analytics by deleting your Tend account, or contact us to request deletion without closing the account. Disconnecting weather or choosing Delete everything removes Tend’s operational cache. MET Norway separately records the rounded coordinates and request IP in service logs under its published terms; it does not give Tend access to those logs or promise Tend a user-specific deletion control.
Because the public site creates no account, cookie, or stable person profile, we cannot connect a pageview to a named visitor or locate one visitor’s pageview for individual deletion.
Children
In plain terms
Tend is made for adults managing their own health. It is not directed to children and does not knowingly collect a child's information.
Tend is intended for adults managing their own health. It is not directed at, designed for, or marketed to children, and it does not knowingly handle information from anyone under 13, or under the minimum age of digital consent where you live if that age is higher.
Tend does not ask for age. If a child has used the app, the account holder can use “Delete everything” or contact us to erase the record. A visit to the public site may produce the same limited cookieless pageview described in section 02, but we do not knowingly use it to identify a child.
Your rights over your information
In plain terms
You can export, correct, and delete your Tend record in the app. You can also contact us about your account or limited analytics.
Depending on where you live, you may have rights under the EU General Data Protection Regulation, the UK GDPR, the California Consumer Privacy Act, or a similar law. They cover knowing what is held, getting a copy, correcting it, deleting it, limiting its use, and not being treated worse for asking.
Tend stores your health record under your account and uses PostHog for limited product analytics linked by the account UUID. This is what exercising those rights looks like in practice:
- Access and portability. Section 13 describes “Export my data”: the whole record, in machine-readable JSON and CSV, at once, at no cost. The in-app export does not include PostHog analytics. Contact us about access to account or analytics information; the account UUID lets us locate the PostHog profile.
- Correction. Every entry is editable by you in the app.
- Deletion and erasure. Section 13 describes “Delete everything”, which removes the device and server copies but keeps the account and its retained analytics. “Delete my account” also requests deletion of the associated PostHog profile and events. You can contact us for help deleting either the account or its analytics. Disconnecting weather clears its on-device operational cache and stops future requests, but we cannot identify or delete MET Norway’s service logs.
- Sale, sharing and targeted advertising.We do not sell personal information or share it for targeted advertising, and we have never done so. There is no advertising in the app or on the site. The site also honors your browser’s Do Not Track setting.
- Restriction, objection and limiting sensitive information.Keep weather disconnected to prevent its network requests. Turn off “Share app activity” in Tend Settings to stop future iOS analytics; this does not erase prior events. For the website, enable Do Not Track in your browser or contact us to object to limited analytics processing.
- Automated decision-making and profiling. None takes place. The patterns the app shows you are calculated on your own device from your own entries. They describe your data back to you. They decide nothing about you.
If you want to raise something anyway, or you think any of this is wrong, write to daniel@offscriptfoundry.com and a person will read it. If you are in the European Economic Area or the United Kingdom, you also have the right to complain to your local data protection authority.
Security
In plain terms
Your record is encrypted on your phone and protected by account rules on Tend's server. PostHog receives the account UUID and limited actions, never the health record.
The record is stored with iOS complete file protection: encrypted at rest and unreadable while the device is locked. The optional app lock, described in section 10, adds Face ID, Touch ID or your passcode in front of the app itself.
Tend uses signed account sessions and row-level access rules so one account cannot read another account’s record. PostHog is isolated behind a narrow analytics API and receives the Supabase account UUID, the six allowed actions, and limited SDK context—but no email, name, health-record values, notes, location, or free text. Server-only keys used to delete Supabase and PostHog data are never shipped in the app.
The controls that matter most are the ones you already hold: keep a passcode on your iPhone, keep iOS up to date, and keep the device backed up. No system is perfect.
Changes to this policy
In plain terms
Changes are posted here with a new date. If a future version sends another kind of data off your phone or adds another outside service, we will say so here before it does.
If this policy changes, the updated version is posted on this page with a new date at the top. That date is the policy’s version marker.
If a change is significant, and in particular if a future version of the app sends another kind of data off your device or adds an outside service, we will name the change here.
Contact
In plain terms
Write to us and a person reads it.
Questions about this policy, about the app, or about something that could be gentler: daniel@offscriptfoundry.com.
Tend is published by Off Script Foundry, Inc., 1248 W 700 S, Pleasant Grove, UT 84062, USA.