Tether Tether
  • How It Works
  • Features
  • Privacy
  • Pricing
  • FAQ
Download App

Privacy Policy

Last Updated: June 24, 2026  ·  Effective Date: May 13, 2026

Contents

  • Our Privacy Philosophy
  • Summary of Key Points
  • 1. Introduction
  • 2. Information We Collect
  • 3. How We Use Your Information
  • 4. How We Share Your Information
  • 5. Data Security
  • 6. Data Retention
  • 7. Your Privacy Rights
  • 8. Children's Privacy
  • 9. Data About Non-Users
  • 10. Analytics, Tracking, and Mobile SDKs
  • 11. International Data Transfers
  • 12. Third-Party Links and Integrations
  • 13. Push Notifications and Communications
  • 14. Clipboard Access
  • 15. Job Applicants
  • 16. Updates to This Privacy Policy
  • 17. Contact Us
  • 18. Specific State and Country Disclosures
  • 19. Definitions

Our Privacy Philosophy

We built Tether because we believe your contact information belongs to you — and so does your data. We don't sell your personal data as a source of revenue. We don't use it for advertising. We take care in overseeing how your data is accessed and what it is used for. Our philosophy: only collect and process what is necessary to operate and improve the Service, and treat your data the way we would want someone to treat ours.

Specific examples of how this philosophy is built into the product:

  • Your address book is encrypted at rest and in transit; no human at Tether has routine access to it
  • Phone numbers are never exposed to other users — only salted SHA-256 hashes are compared for Autoconnect matching, and email addresses are matched in the same way
  • On sign-out, all local data is wiped from your device; no contact data survives a logout
  • We do not use advertising networks, behavioral-advertising trackers, or ad-tech identifiers in the Tether mobile app, and we do not place advertising cookies or tracking pixels on our website
  • We do not subscribe you to marketing lists when you sign up
  • We strip personally identifiable information from crash reports before they leave your device (see Section 4.2 — Sentry)
  • The one product-analytics SDK we use (PostHog) is gated on an opt-out you can toggle at any time, never sees contact data, and is enforced by an explicit allowlist of properties at the source-code level (see Section 4.2)
  • You can export all your data, and delete your account, at any time from within the app
  • Phone-number and email-address changes are wrapped in a 24-hour revocation window with a security notification fanned out to three independent channels (see Section 3.7)

Summary of Key Points

TopicShort Answer
Do we sell your data?No
Do we use advertising networks?No
Do we share data with third parties?Only service providers necessary to operate the app (see Section 4.2)
Do we collect health data?Only what you choose to enter for your contacts
How is phone number matching done?Via salted SHA-256 hashing — raw numbers never compared between users
How is email matching done?Via salted SHA-256 hashing (normalized) — raw emails never compared between users
Do we use product analytics?Yes — PostHog (events-only, no contact data, opt-out in Settings); see Section 4.2
Do we strip EXIF/GPS from uploaded photos?Yes — uploaded images are re-encoded to a normalized JPEG, which strips embedded EXIF/GPS metadata before storage (see Section 2.5)
Do we verify your phone number is a real mobile?Yes — at signup we run a carrier lookup via Telnyx to confirm your number is a mobile line. Voice-over-IP, landline, and toll-free numbers are refused. The carrier name, line type, and country are stored to avoid re-paying for repeat lookups. See Section 2.9.
Do we detect compromised devices?Yes — the app refuses to operate on jailbroken or rooted devices (see Section 3.8)
What happens when you change your phone or email?A 24-hour revocation window with notifications to old phone, old email, and other devices (see Section 3.7)
Can you export your data?Yes — vCard, CSV, or JSON via Settings
Can you delete your account?Yes — Settings > Account > Delete Account
Who is our EU/UK GDPR representative?See Section 7.2

1. Introduction

Welcome to Tether ("we," "our," or "us"). Tether is a privacy-first professional contact management application that automatically keeps your contact information current through live updates and intelligent synchronization across your devices.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (collectively, the "Service"). Please read this policy carefully. If you do not agree, please do not access the Service.

We reserve the right to make changes to this Privacy Policy at any time. We will alert you about material changes by updating the "Last Updated" date and, for significant changes, by providing prominent in-app notice, email notification, or both. Your continued use of the Service after the effective date of any revised Policy constitutes acceptance.


2. Information We Collect

2.1 Information You Provide to Us

Account Information:

  • Phone number (required for authentication via SMS OTP — Tether's primary sign-in method)
  • Email address (optional at signup; recommended for account recovery and required for the email-handshake discoverability; see Section 2.7)
  • Verified-identifier timestamps (phone_verified_at, email_verified_at) — see Section 2.7
  • Name (first, last, optional middle, prefix, suffix)
  • Profile information (company, job title, department, handle/username, pronouns, bio, avatar photo)
  • "Based-in" city and state (optional)
  • Account preferences and settings (including accessibility preferences such as dark mode, push-notification preferences, sharing-tier defaults, and analytics opt-out status)
  • Subscription tier and entitlement state (sourced from RevenueCat)
  • Account-lifecycle timestamps (locked_at, deleted_at, deletion-cooling-period status)
  • Pending-account-change records (see Section 3.7)

Contact Data: You may choose to store the following information about your contacts:

  • Basic: Names (including prefixes/suffixes), nicknames, pronouns, companies, departments, job titles
  • Bio: Free-form bio (up to ~2,000 characters)
  • Contact Details: Phone numbers (stored in E.164 international format), email addresses, physical addresses (street, city, state, postal code, country, optional Place ID and formatted address)
  • Social & Web: Social-media profiles across 15 platforms (including LinkedIn, X/Twitter, Instagram, Facebook, TikTok, Snapchat, GitHub, YouTube, WhatsApp, Telegram, Signal, Venmo, Pinterest, Cash App, and "other"), website URLs
  • Important Dates: Birthdays, anniversaries, graduations, and custom date fields (each may be flagged public or private)
  • Notes and Met-context: Free-form notes (up to ~5,000 characters), "how we met" (up to ~1,000 characters), met date, met location
  • Photos: Contact profile photos (EXIF metadata is automatically stripped on upload via JPEG re-encoding — see Section 2.5)
  • Health Information: Blood type, allergies (and a "no known allergies" flag), dietary preferences, medical conditions, medications, emergency notes, and a "doctor" contact link
  • Family and Children: Contact type (adult, child, company), child information (birth year, grade level, school name, parent links), shared_family_members (a list of additional family-member sketches with name, relationship, contact type, and an optional link to a Tether user); contact-to-contact family relationships
  • Custom Fields: User-defined label/value pairs typed as text, number, date, URL, phone, or email
  • Relationship Information: Tags, labels, and organizational data
  • Connection State: isLinked, linkedUserId, connectionStatus (active or stale)
  • Live Fields: A record of which fields on a linked contact came from the other user's live profile (see Section 3.1)
  • Live Location (Optional, User-Initiated Only): Latitude/longitude with timestamp, where the user has explicitly enabled location sharing for a particular connection; not used for any background tracking
  • Import Lineage: Import source, import-batch ID, import fingerprint
  • Referral Codes: Invitation referral codes used for attribution

Event Data: When you create or participate in events:

  • Event details (title, date, time, location, description)
  • Your RSVP status and attendance
  • Co-host assignments and guest lists
  • Per-RSVP snapshots: for each contact you invite to an event, we store a snapshot of their display name and email address on the RSVP record at invite time. This snapshot lets co-hosts see and contact the invitees you've added, and lets any host or co-host re-invite the same people to follow-up events. Only the name and email you attached to the invitation are captured — no phone numbers, addresses, notes, or other fields from your address book.

Privacy Circle Assignments:

  • Your classification of contacts into sharing tiers (Community, Professional, Close)
  • Custom circle memberships
  • Shared circle/directory memberships

Directory and Shared Circle Data:

  • Directory name and description
  • Your membership status and role
  • Information you choose to share with directory members
  • Information other directory members choose to share with you

Communication Preferences:

  • Push notification settings
  • Email communication preferences
  • Feature opt-in/opt-out choices

2.2 Information Collected Automatically

Device Information:

  • Device type, model, and operating system version
  • Unique device identifiers: generated by combining device hardware identifiers with your user ID via SHA-256 hashing. This scoping ensures device identifiers cannot be used to cross-correlate data across users.
  • Push notification token: if you enable push notifications, we store the Expo push token issued to your device — a persistent per-device identifier — on our servers, keyed to your account, so we can deliver notifications to that device. The token is used only to route notifications. It is deleted when you sign out on that device, when the token goes unused (tokens inactive for 90 days are deactivated and hard-deleted after 180 days), and when you delete your account. See Sections 4.2, 6.1, 10.1, and 13.
  • App version and build number
  • Device language, region settings, screen resolution, and device capabilities

Usage Data:

  • Features you use within the app
  • Actions you perform (creating contacts, editing information, syncing data, joining directories, broadcasting contact cards, creating events, RSVPing)
  • Error logs and crash reports (collected via Sentry; personally identifiable information is automatically redacted before transmission — see Section 4.2)
  • Performance metrics (app launch time, sync duration, API response times)
  • Interaction patterns and feature adoption (aggregated and hashed; not linked to individual identities)
  • Accessibility feature usage (dark mode, Dynamic Type settings)

Technical Data:

  • IP address (used for security, fraud prevention, and approximate location — see Section 2.6)
  • Session duration and frequency
  • Sync operation metadata (timestamps, record counts, sync status)
  • Network connection type (WiFi, cellular)

2.3 Information from Third-Party Sources

Contact Import Services: With your explicit permission, we may import contact data from:

  • Your device's native contact database (iOS Contacts, Android Contacts) — labeled with import source device
  • Google Contacts (via OAuth 2.0 and Google People API) — labeled with import source google
  • Microsoft Contacts (via OAuth 2.0 and Microsoft Graph API) — labeled with import source microsoft
  • vCard (.vcf) files you upload — labeled with import source vcard
  • CSV files you upload (including spreadsheets used to seed an event guest list) — labeled with import source csv or event_spreadsheet
  • The guest list of a past event (where you re-invite or re-import names + emails captured at invite time) — labeled with import source past_event_invite
  • A QR-code / contact-card scan, where supported — labeled with import source scan
  • A user you connect with through a referral link — labeled with import source network
  • Manual entry within the app — labeled with import source manual

Import lineage is preserved on each contact record (import source, batch ID, and fingerprint) for deduplication, undo, and audit purposes.

When you authorize these integrations, we receive all contact information stored in those services, metadata about when contacts were created or last modified, and contact groupings and labels. We only request the minimum permissions necessary to provide our services. We do not access your emails, documents, or other data unrelated to contact management. Calendar access is a separate, optional feature with its own permission — see Section 2.10.

Data About You from Others: Just as you may provide information about your contacts when you sync your device contacts, others may provide limited information about you when they do the same. For example, another Tether user may save your phone number in their address book, and that information may be used to suggest a mutual connection between you, subject to the Autoconnect policies in Section 3.1.

Contact Import Authentication: When you authorize Google or Microsoft for contact import, we receive basic profile information to authenticate the connection, a provider-specific user identifier, and an account timestamp. These connections are used solely for contact import — they are not used for Tether authentication (Tether uses Phone OTP only).

2.4 Biometric Information

If you enable biometric authentication (Face ID, Touch ID, fingerprint): we do not collect, store, or transmit your biometric data; authentication is processed entirely on your device using the secure enclave; we only receive a success/failure signal; your biometric templates never leave your device.

2.5 Photo and Image Metadata

When you upload photos or images to the Service (including profile photos, contact photos, event photos, and life-update photos), the image is automatically re-encoded to a normalized JPEG before storage. This re-encoding strips embedded EXIF metadata — including GPS coordinates, camera make and model, device serial numbers, and timestamps — so that metadata is not retained on our servers or shared with other users.

Photos you upload may be visible to other users in accordance with your privacy-tier and circle settings. Note that metadata stripping happens at upload only; if you share an original image file outside Tether by other means, that copy may still contain its embedded metadata.

2.6 Location Data

We collect approximate location data derived from your IP address for security and fraud prevention purposes. This is imprecise location (city or region level) and is not GPS location. We do not collect precise GPS location from your device unless you explicitly turn on our optional location-sharing feature, which shares your current coordinates with the specific connections you choose. This sharing is foreground and user-initiated only: coordinates are sent while you have sharing active, and we do not track your location in the background. You can stop sharing at any time. If you choose to include a physical address in your profile or contacts, that address data is stored and subject to your privacy circle permissions.

2.7 Verified-Identifier Status (Email and Phone)

Each account in the Service has, at any point in time, zero or one "verified" status for the user's email address and zero or one "verified" status for the user's phone number. Verification is performed by sending a one-time code to the identifier and requiring the user to enter that code in the app.

We process verified-identifier status for the following purposes:

  • Account recovery. A verified email is the secondary channel by which you can recover access to your account if you lose access to your phone number.
  • Discovery handshake gating. Other users may discover and request to connect with you using your email address only when your email is verified. The same gate applies to your phone number.
  • Security-notification routing. Security notifications (including the 24-hour revocation notifications described in Section 3.7) are sent to your verified channels.

The timestamps email_verified_at and phone_verified_at are stored on your account record. Verification status does not result in publication of your email or phone to other users (Autoconnect and the discovery handshake operate on hashes, not raw identifiers — see Section 3.1).

Being listed as someone's family member. If another Tether user lists you as a family member on their contact card and you are a Tether user, the people they share that card with may see that you are on Tether and may send you a connection request. As with all connection requests, this is governed by your connection-request settings, and you can decline any request. Your phone number and email address are never disclosed to those people through the other user's card.

2.8 Device-Integrity Signals

Each time the app launches, it queries a device-integrity signal from the operating system and from the jail-monkey native module. The signal is a Boolean indicating whether the device is jailbroken (iOS) or rooted (Android). We do not store the signal server-side and we do not transmit the signal to our analytics or error-tracking providers; the signal is evaluated locally and, where positive, causes the app to render a lockout screen and refuse to operate. See Section 3.8 for how we use this signal and Section 2.10 of the Terms of Service for your obligations.

2.9 Pre-Account and Phone-Verification Data

Early-access request form (tetherup.app/request-access). During our soft-launch period, anyone may submit a request for access by entering their name, mobile phone number, email address, and (optionally) where they heard about us. We also record the request's IP address and user-agent string for abuse prevention. Until an account is created, this information is stored in our access_requests table with the request's review status (pending, approved, or denied). When you create an account using the same phone number, the request remains in our records as part of the eligibility audit trail. You may request deletion of an unfulfilled request at any time by emailing [email protected].

Phone-number carrier verification. Before sending an SMS one-time code to a new phone number, we run a carrier lookup via Telnyx (see Section 4.2) to confirm the number is served by a recognized mobile carrier. We refuse to send codes to voice-over-IP, landline, and toll-free numbers because those line types are the dominant vector for automated account-creation abuse. The carrier name, line type (e.g., mobile, voip, landline), country code, and validity flag returned by Telnyx are stored in our phone_intel table keyed by the SHA-256 hash of the phone number — once per number, lifetime — so we do not re-incur a paid lookup if you later change phones or sign back up. This data is not linked to your account record; it is keyed by phone-number hash so it survives account deletion (the carrier facts are about the line, not about you). If you believe a legitimate mobile number was misclassified, email [email protected] and we will manually allow it.

2.10 Calendar Data

If you enable Tether's calendar availability feature, the app reads your device calendar — using the calendar permission you grant your operating system — to determine when you are busy or free. We store only the start and end times of your busy periods on our servers; we do not receive or store event titles, locations, attendee lists, descriptions, notes, or any other content from your calendar entries. Calendar entries are read on your device, and only the resulting busy/free time ranges are transmitted to us.

When you enable the calendar availability feature, your busy/free times are shared by default with the circles you create from Tether's standard templates — Close, Community, and Professional circles each include calendar availability in their default shared fields. You can change what any individual circle sees through that circle's Edit Permissions screen, stop sharing with a circle, or turn off calendar access entirely in the app's settings, at any time. Circles see time ranges only — never the underlying calendar entries. Turning the feature off deletes the busy-block data we have stored for you. We do not sell your calendar data, share it with third parties, or use it for advertising.


3. How We Use Your Information

3.1 Core Service Functionality

  • Account Management: Create and manage your account, authenticate your identity, and maintain session security
  • Contact Synchronization: Sync contact data across your devices using server-assigned sync versioning for conflict resolution
  • Live Updates: Automatically update contact information when your connections update their Tether profiles, in accordance with each user's privacy-tier settings and on a best-effort basis — see Section 10.9 of the Terms of Service for the disclaimer on reliance on live updates
  • Automatic Connections (Autoconnect) and Mutual-Contact Auto-Link: When two users each have the other's verified phone number (or, where supported, verified email) in their contact lists, we may automatically create — or, depending on per-account configuration, suggest — a connection. This matching is performed by comparing salted SHA-256 hashes of phone numbers and emails server-side. Raw phone numbers and email addresses are never compared between users, never stored alongside user identities for cross-reference, and never exposed to other users through this process. Only mutual matches trigger a connection. See also Section 3.9.
  • Event Management: Create, manage, and share events; send invitations via email; manage RSVPs; assign co-hosts; and capture per-RSVP snapshots of guest name and email at invite time for re-invitation to follow-up events
  • Life Updates: Optionally publish "life update" posts (e.g., birth announcements, milestones) to your circles, triggering push and email fan-out to subscribers
  • Communication Tracking: Track communication history with contacts, stored locally on your device and in your encrypted cloud backup (Tether+ only)
  • Duplicate Detection (Merge Intelligence): Identify and merge duplicate contacts using identity-gated additive scoring, fuzzy matching algorithms, alias-domain folding for emails, and salted SHA-256 hashing of phone numbers and emails for privacy-preserving comparison
  • Data Organization: Enable organizing contacts into privacy-tier circles, custom circles, and shared directories (institutional or social mode)
  • Contact Card Broadcast: Allow sharing updated contact information with selected circles via email (Resend)
  • CardDAV Export (Optional, User-Initiated): Generate a single-use .mobileconfig configuration profile that enables iOS to read your Tether contacts as a read-only address-book source. The token expires 30 minutes after issuance and is consumed atomically on first use; once consumed (or expired), the token cannot be reused. We do not push contacts to your device-native address book; CardDAV is a one-way read from Tether to your device.
  • Search and Filtering: Provide fast, accurate search across your contacts
  • Import and Export: Facilitate importing contacts from external services and exporting your data in vCard, CSV, or JSON formats

3.2 Machine Learning and Automated Processing

  • Duplicate Detection: We use identity-gated additive scoring models incorporating fuzzy name matching, email/phone normalization, and a machine learning component that learns from your accept/reject decisions on merge suggestions to improve future suggestions. This processing is performed on your data to serve you — we do not share learned patterns or your merge decisions with third parties.
  • Circle Auto-Suggestion: We analyze contact attribute signals (relationship indicators, corporate email domains, birthday presence, communication patterns) to suggest appropriate privacy circle placements. Suggestions are advisory only; you can accept, reject, or ignore them.
  • Spam and Fraud Detection: We use automated systems to detect patterns indicative of abuse, spam, or fraudulent activity.

We do not make solely automated decisions about you that have significant legal or similarly significant effects, except for security measures (such as rate limiting or account suspension for abuse), which you may appeal by contacting [email protected].

3.3 Service Improvement and Analytics

  • Performance Monitoring: Analyze app performance, identify bugs, and improve reliability using aggregated, de-identified metrics
  • Feature Usage: Understand which features are valuable to users using hashed, anonymized analytics — we cannot trace these analytics back to individual users
  • Error Tracking: Collect crash reports and error logs via Sentry (PII automatically redacted before transmission)
  • A/B Testing: Test new features and interface improvements with randomized user cohorts

We do not use your personal contact data for advertising targeting. We do not sell your data or share it for cross-context behavioral advertising.

3.4 Communications

  • Transactional SMS: OTP authentication codes and security alerts via Telnyx. Required for account functionality. By registering, you provide TCPA consent for these transactional messages.
  • Transactional Email: Critical service messages (sync status, event invitations, connection requests, contact card broadcasts) via Resend
  • Feature Updates: Notifications about new features or changes (with opt-out)
  • Account Support: Responses to support requests and feedback

3.5 Security and Fraud Prevention

  • Rate limiting authentication attempts and API calls
  • Managing authenticated device sessions with per-tier device limits (applied when your subscription tier changes)
  • Identifying unusual patterns that may indicate unauthorized access
  • Maintaining audit logs of data modifications for security and accountability

3.6 Legal and Compliance

  • Comply with applicable laws, regulations, legal processes, or governmental requests
  • Enforce our Terms of Service
  • Protect the rights, property, and safety of Tether, our users, and the public

3.7 Identity-Change Processing — Phone and Email Changes

When you change the phone number or email address associated with your account, we process additional categories of data for security purposes:

(a) Pending-change records. We create a short-lived "pending account change" record containing: the change type (phone or email), the prior identifier, the new identifier, an "expires at" timestamp 24 hours in the future, and a one-way hash (SHA-256) of a one-time revocation token. The raw token is not stored — only its hash — so a database snapshot cannot be used to forge a revocation link.

(b) Multi-channel notifications. We attempt to deliver security notifications on a fire-and-forget, best-effort basis. The set of channels depends on the change type:

For a phone-number change, we fan out to up to three channels: (i) SMS to the prior phone number (via Telnyx); (ii) email to your verified email address, if any (via Resend); and (iii) push notifications to any other devices currently signed in to your account (via Expo Push).

For an email-address change, we fan out to up to four channels: (i) email to your prior verified email address, if any (via Resend); (ii) email to the new email address (via Resend); (iii) SMS to your verified phone number, where applicable (via Telnyx); and (iv) push notifications to any other devices currently signed in to your account (via Expo Push).

Each notification contains a masked summary of the change and a single-use revocation link. We do not guarantee delivery of any individual notification. SMS notifications to the prior phone number depend on the availability of our SMS provider and on regulatory approvals (including, currently, Toll-Free Verification with the carriers); if the SMS provider is unavailable or unconfigured, the SMS leg silently fails while the other channels continue.

(c) Session revocation. A phone change triggers a global sign-out of all sessions across all devices (including the device on which you initiated the change), implemented by calling Supabase Auth's signOut(user_id, 'global'). An email change triggers a sign-out of all other devices but, by design, preserves the session on the device from which you initiated the change.

(d) Revocation processing. If the revocation link is clicked within 24 hours, we (i) revert the change, (ii) lock the account by setting accounts.locked_at, and (iii) broadcast a Realtime force_logout event followed by a deferred global sign-out, in that order, so subscribed clients receive the broadcast before their sessions are terminated.

(e) Cleanup. Terminal pending-change records (those that have committed or been revoked) are purged by the daily maintenance job, no fewer than 30 days after the terminal event. Live (in-window) records are preserved until terminal.

(f) Audit. Each pending change, notification attempt, and revocation event is logged for security audit purposes. Audit logs are retained per the schedule in Section 6.1.

(g) Source-of-authentication gate for email changes. If you are signed in via an email-only OTP session, the Service refuses to allow you to change your email until you sign in via phone OTP. This gate exists to defeat attackers who have compromised your email but not your phone.

We process this data on the legal bases of contract performance and legitimate interest in the security of the Service. You cannot opt out of the 24-hour revocation window, multi-channel notification fan-out, or session-revocation behaviors; these are core security features of the Service.

3.8 Device-Integrity Checks

At app launch, the Service evaluates device-integrity signals (jailbreak/root detection) via the jail-monkey native module. If the device is detected as compromised, the app renders a lockout screen and does not function. The Boolean result of the check is not transmitted off-device, is not stored on Tether's servers, and is not sent to our analytics or error-tracking providers. We process this signal on the legal basis of legitimate interest in the security of the Service and the protection of contact data stored on the device.

We may, in the future, add additional integrity signals (e.g., emulator detection, debug-build detection, OS-version freshness checks). Such additions will be reflected in an update to this Section.

3.9 Mutual Contact Auto-Link (Server-Side)

We operate a server-side process called "mutual contact auto-link," which periodically scans for cases in which two users have each other's verified phone numbers (or, where supported, verified emails) saved in their address books, using salted SHA-256 hashes for the comparison. When a mutual match is found and the relevant configuration toggle is set to auto, the Service automatically creates a connection between the two users, subject to each user's default tier setting. When the toggle is set to suggest, the Service queues a suggestion for the user to confirm. When the toggle is set to off, no auto-link is performed.

You can adjust your participation in auto-link in Settings > Privacy > Connections, and you can remove any individual connection that was created via this process at any time.


4. How We Share Your Information

4.1 Information Sharing You Control

With Other Tether Users (Sharing Tier Settings): When you connect with another Tether user, you control what they see through your sharing-tier settings. There are three tiers — Close, Community, and Professional — and each has a default set of fields that are shared. You can override the defaults on a per-circle basis from Settings > Privacy > Tier Defaults. The default-shared fields for each tier, as currently configured in the app, are:

  • Close (family and inner circle): name, avatar, handle, nickname, bio, pronouns, company, job title, department, home and work phone, personal and work email, home and work address, the full social-profile set (LinkedIn, Instagram, X/Twitter, Facebook, TikTok, YouTube, GitHub, Pinterest, WhatsApp, Snapchat, Telegram, Venmo), personal and work websites, birthday, anniversary, custom dates, child info, family members, granular health fields (allergies, dietary preferences), calendar availability (busy/free times, when the calendar feature is enabled), and live location (when enabled).
  • Community (friends and acquaintances): name, avatar, handle, nickname, bio, pronouns, company, job title, department, personal email, the full social-profile set (LinkedIn, Instagram, X/Twitter, Facebook, TikTok, YouTube, GitHub, Pinterest, WhatsApp, Snapchat, Telegram, Venmo), personal website, birthday, and calendar availability (busy/free times, when the calendar feature is enabled). Note: phone numbers and addresses are NOT shared by default at the Community tier; you can opt in to share them on a per-circle basis.
  • Professional (work contacts): name, avatar, handle, nickname, bio, company, job title, department, work phone, work email, work address, LinkedIn, GitHub, work website, and calendar availability (busy/free times, when the calendar feature is enabled).

The defaults are encoded in apps/mobile/src/constants/circleTypeDefaults.ts; they may be revised in future releases of the Service, in which case this Section will be updated.

Family members on your card. When "family members" is among the fields you share with a circle, the connections in that circle may see, for each family member you have linked: their name, your relationship to them, and contact type. For a family member who is not a Tether user, this may also include that person's primary phone number and email address as stored in your address book. For a family member who is a Tether user, their phone and email are never shared through your card — instead, your connection may see that the person is on Tether and may send them a connection request directly (subject to that person's own connection-request settings). Children's direct contact details (phone and email) are never shared through your card. Because this shares information about other people, you are responsible for having any consents required by law to do so (see our Terms of Service).

Unassigned contacts. When a new connection is created and you have not yet assigned the connected user to a circle, a separate "Unassigned Defaults" setting determines what is shared until you make an assignment. The Unassigned Defaults are configured in Settings > Privacy > Tier Defaults and are distinct from the Community tier defaults above.

Data on Disconnect: When you block or remove a connection, all information received through that connection is automatically removed from your device. Live data is treated as "on loan" and does not persist after disconnection.

Events and Co-hosts: Co-hosts can see only the display name and email address you attached to each guest invitation (captured as a per-RSVP snapshot at invite time) — not any other information from your private address book. When a host or co-host reuses a past event's guest list for a future event, guests not already in the inviter's address book may be saved as new contacts from the snapshotted name and email, tagged with import source past_event_invite.

4.2 Service Providers

We share information with third-party service providers who perform services on our behalf. All service providers are contractually required to use your information only for specified services, implement appropriate security measures, comply with applicable data protection laws, and not sell or share your information with third parties.

ProviderPurposeData Shared
Supabase Inc.Database, auth, file storage, real-time sync, edge functions (AWS, United States)All user data stored in database
Cloudflare, Inc.Edge network, DNS, web/landing pages, CardDAV reverse-proxy, and serverless workers (e.g., the RevenueCat webhook relay)HTTP request metadata, web analytics beacons, CardDAV-profile delivery
SentryError tracking and performance monitoring (PII auto-redacted before transmission)Crash logs, error events (no raw contact data)
PostHogProduct analytics (events-only, opt-out in Settings; no contact data; PII denylist enforced at the SDK boundary)Event names, allowlisted user traits (subscription tier, signup date, contact count, circle count, cohort week), Supabase user ID as distinct_id, app version, environment
RevenueCatSubscription billing via App Store / Google Play, webhook fan-out to our backendSubscription status, purchase events, billing issue events
TelnyxSMS OTP delivery; SMS notification to the prior number when phone changes; pre-signup carrier lookup (Number Lookup API) to confirm the number is a real mobile line (see Section 2.9)Phone number, OTP body, security-notification body, carrier-lookup query (phone number only — response cached locally)
ResendTransactional email (event invitations, event reminders, RSVP notifications, circle invites, contact-card broadcasts, vCard email exports, phone-change and email-change security notifications, and similar)Email addresses, sender/recipient metadata, and the content you choose to send
ExpoPush notification delivery (Expo Notifications service)Push tokens, notification payloads
MicrosoftContact import from Outlook / Microsoft 365 via OAuth 2.0 + Microsoft Graph API — only when you choose to connect a Microsoft accountYour Microsoft sign-in (OAuth) and the Outlook contacts you import via the Contacts.Read scope: names, phone numbers, emails, addresses, and notes
jail-monkey (on-device)Device-integrity check (jailbreak / root detection)None — the check runs locally and the result is not transmitted off-device
Apple Inc. / Google LLCApp distribution, in-app purchase, push-notification transit; contact import (Apple Contacts / Google People API on connect); map tiles and address geocoding when you view or save a locationPer their respective developer terms and privacy policies; for contact import, the contacts you choose to import; for maps, approximate location/viewport coordinates

4.3 Analytics and Monitoring Technologies

We use the following analytics and monitoring tools:

Sentry (Error & Performance Monitoring): Sentry receives crash reports, error events, and performance traces. Our Sentry configuration automatically redacts PII (names, phone numbers, email addresses, contact data) before transmission. No personally identifiable contact data is transmitted. Governed by Sentry's Data Processing Agreement.

PostHog (Product Analytics — Events Only): PostHog receives product-analytics events (for example, when a user views the paywall, completes onboarding, or imports contacts). Our PostHog integration enforces a PII denylist at the source-code level: properties whose keys are email, phone, phoneNumber, phone_number, firstName, lastName, fullName, displayName, middleName, contactName, contact_name, address, street, city, postalCode, zip, avatarUrl, password, token, accessToken, refreshToken, secret, message, notes, or note are dropped before send, and only primitive values (strings, numbers, booleans) are transmitted. Identification uses your Supabase user ID as a stable opaque distinct_id together with a small allowlist of traits: subscription tier (free / tether_plus / lifetime / unknown), signup date, contact count, circle count, and cohort week (ISO YYYY-WW). PostHog session replay is not enabled and we do not capture screen contents. PostHog event capture is gated on a privacyStore.settings.analyticsOptedOut toggle in the app — when you opt out, all identify and capture calls become no-ops at the SDK boundary and the SDK's own opt-out machinery is also engaged. Default hosting region is PostHog's U.S. cloud (us.posthog.com); the integration is governed by PostHog's Data Processing Agreement.

RevenueCat (Subscription Analytics): RevenueCat receives purchase events and subscription status updates necessary to process transactions and provide subscription analytics (conversion rates, churn, subscription lifecycle events). No contact data is shared with RevenueCat beyond what is necessary to process transactions.

Cloudflare Web Analytics (Web Properties): Our tetherup.app web properties use Cloudflare's privacy-respecting RUM analytics, which does not use cookies and does not build behavioral user profiles. No data from the mobile app passes through Cloudflare Web Analytics.

We do not use Google Analytics, Facebook Pixel, TikTok Pixel, Meta Audience Network, or any advertising-oriented analytics or attribution SDK in the Tether mobile app. We do not place advertising cookies or tracking pixels on our website. We do not use Apple's App Tracking Transparency-gated identifiers (IDFA) and the app declares "No, app does not use advertising ID" on Google Play.

4.4 Advertising

We do not sell your personal data to advertisers. We do not share your personal data with advertising networks for behavioral targeting. We do not receive compensation for your data from any advertising partner. Tether generates revenue through subscription fees only.

4.5 Business Transfers

If Tether is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of company assets, your information may be transferred as part of the transaction. We will provide at least 30 days' notice before your information becomes subject to a materially different privacy policy.

4.6 Legal Requirements

We may disclose your information if required by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, national security or law enforcement requests). We may also disclose when we believe in good faith that disclosure is necessary to comply with applicable law, enforce our Terms, protect against fraud or security risks, or protect the rights or safety of Tether, our users, or the public.

When permitted by applicable law and not prohibited by the legal demand itself, we will: provide you with prompt notice of any legal demand for your data; review requests for legal sufficiency; and, where appropriate, challenge overbroad or improper requests.

4.7 Professional Advisors

We may disclose personal information to professional advisors (lawyers, auditors, bankers, insurers) where necessary in the course of professional services they render to us, subject to confidentiality obligations.

4.8 Aggregated and De-identified Data

We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you, for business purposes including research, service improvement, and industry reporting.

4.9 With Your Consent

We may share your information for any other purpose with your explicit, informed consent.


5. Data Security

5.1 Security Measures

Encryption:

  • All data in transit encrypted using TLS (TLS 1.2+ as negotiated by your operating system and our hosting providers; TLS 1.3 where supported by both endpoints)
  • TLS certificate validation is performed against the operating-system trust store; the current build does not implement custom SSL/TLS certificate or public-key pinning (we are evaluating adding pinning in a future release; this Section will be updated if and when it is implemented)
  • Contact data encrypted at rest using AES-256 (provided by our hosting infrastructure)
  • Phone numbers and emails hashed using salted SHA-256 (with email normalization including alias-domain folding and case-insensitive local-part comparison) for duplicate detection and Autoconnect — raw values never compared between users
  • Device identifiers use SHA-256 hashing combining hardware IDs with user IDs to prevent cross-account data leakage

Authentication Security:

  • Phone OTP via SMS is Tether's primary sign-in method; no passwords are used
  • Email OTP is also supported as a sign-in method (via the supabase.auth.signInWithOtp flow and the email-verify-otp edge function), and is the recovery path if you lose access to your phone number
  • Sessions signed in via email OTP are blocked from changing the email address on file — to change the email address, the user must first re-authenticate via phone OTP (see Section 3.7(g))
  • Biometric authentication, where enabled, is processed locally on your device's secure enclave
  • JWT session tokens stored in iOS Keychain / Android Keystore
  • Access token expiry: 1 hour; refresh token expiry: 90 days
  • Rate limiting on authentication attempts (currently 3 OTP sends per hour per phone number for SMS; 3 sends per hour per user for email; subject to change without notice)
  • Signed-in devices are tracked per account and are individually revocable; when your subscription tier changes we trim your signed-in devices to that tier's device limit (Free: 1; Tether+: 2). We do not block additional sign-ins at login.

Access Controls:

  • Row-level security (RLS) policies ensuring users can only access their own data
  • All database operations through SECURITY DEFINER RPCs — clients cannot read or write tables directly
  • Role-based access control (RBAC) for internal systems

Cross-User Isolation (Wipe-on-Logout): On sign-out, we execute a three-step wipe of all locally stored user data from your device, including all application state, service caches, and encrypted storage keys. This ensures no contact data survives a logout and eliminates any possibility of a subsequent user on the same device accessing prior user data.

Operational Security:

  • Automated security scanning in our CI pipeline (static analysis and dependency review) and periodic internal security reviews
  • Automated vulnerability scanning
  • Secure secrets management (1Password vault and Supabase Vault for production secrets; legacy credentials rotated to scoped tokens; service-role keys not embedded in mobile builds)
  • Network isolation and firewall protection
  • Automated backups with point-in-time recovery
  • Incident response procedures
  • Device-integrity gate. At app launch, the Service checks whether the device is jailbroken (iOS) or rooted (Android) via the jail-monkey native module; if so, the app renders a lockout screen and refuses to operate. See Section 3.8.
  • Phone- and email-change revocation window. Identity changes are wrapped in a 24-hour revocation window with notifications to three independent channels and global (phone-change) or other-device (email-change) session sign-out. See Section 3.7.
  • Source-of-authentication gate for email changes. Email-OTP sessions cannot change the email address on file; the user must sign in via phone-OTP first. See Section 3.7(g).
  • Revocation-token hashing. Revocation tokens are stored as SHA-256 hashes; a database snapshot cannot be used to forge a revocation link.

5.2 Security Breach Notification

In the event of a security breach involving your personal information, we will:

  • Investigate and confirm the scope of the breach as promptly as possible
  • Notify affected users without undue delay and, where required by law (including within 72 hours under GDPR), notify the applicable supervisory authority
  • Provide breach notification via email and/or in-app notification describing the nature of the breach, categories of data involved, and steps we are taking
  • Cooperate with applicable regulatory authorities

If we determine that a breach does not require notification under applicable law, we will retain records of our assessment.

5.3 Limitations

No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.


6. Data Retention

6.1 Active Account Data Retention Schedule

Data CategoryRetention Period
Contact dataWhile account is active; until contact is deleted
Account informationWhile account is active
Sync history90 days
Change logs (audit)90 days
Soft-deleted contacts60 days, then auto-hard-deleted (daily maintenance job, 09:31 UTC). A contact you merged into another contact is kept for as long as that surviving contact exists, so the merge stays reversible; it is hard-deleted on a later run of the same job once the surviving contact is itself deleted.
Dead-letter queue (failed sync ops)30 days, then auto-purged
Abandoned sync transactionsCleaned daily (2:00 AM UTC)
Event RSVP recordsPer subscription tier retention period; deleted with account
Push tokensUntil device access revoked or account deleted
Error/crash logs (Sentry)90 days (PII redacted)
Product-analytics events (PostHog)Per PostHog Cloud retention (currently 7 years for events; subject to PostHog's then-current retention settings) — opt-out at any time
CRM communication logsWhile account is active
Health sharing consentsRetained as immutable audit records per legal requirements
Pending account-change records (phone / email / sign-in notice)Live records: up to 24 hours (revocation window). Terminal records (committed or revoked): purged by the daily maintenance job, no fewer than 30 days after the terminal event.
Revocation-link tokensStored only as SHA-256 hashes; deleted when the parent pending-change record is purged.
Account-lockout recordsWhile account is locked; preserved in audit log after recovery for security and forensics purposes
Transactional records7 years (tax and accounting purposes)

6.2 Account Deletion

When you request account deletion (Settings > Account > Delete Account):

Immediate Actions:

  • Your account enters a 30-day cooling-off period; you may cancel the deletion request during this time
  • Your profile becomes inaccessible to other users
  • You are logged out of all devices
  • All local data is immediately wiped from the requesting device
  • Your directory memberships are terminated

After 30-Day Cooling Period:

  • All contact data permanently hard-deleted from servers via automated cleanup (execute_pending_deletions)
  • Your account information permanently deleted
  • All sub-entity data (phones, emails, addresses, social profiles) cascade-deleted
  • Shared directory contributions anonymized or removed
  • Third-party import connections revoked
  • CardDAV tokens invalidated

Data We Retain After Deletion:

Most data is permanently erased at the end of the 30-day cooling period. A limited set of records is deliberately retained for the lawful purposes below. Where a record is kept, it is de-identified wherever de-identification still serves the purpose:

  • Anti-abuse phone hash. A salted SHA-256 hash of your phone number is retained to prevent the same number from repeatedly claiming a free trial by re-signing up. The hash cannot be reversed to recover your number.
  • Carrier-verification cache. The carrier facts about your phone line (carrier name, line type, country) stored in our carrier-lookup cache are keyed by phone-number hash, not your account, and survive deletion because they describe the line, not you (see Section 2.9).
  • Anonymized health-consent record. If you accepted a health-data waiver, the record that a waiver was accepted on a given device — including the waiver version, timestamp, and a hash of the waiver text — is retained as a legal audit trail with your user ID removed, so it cannot be used to re-identify you.
  • Deletion audit log. A pseudonymous record (your account's internal identifier, deletion timestamp, per-table row counts, and per-processor cleanup status) is retained to demonstrate that erasure occurred. No name, email, or phone is kept.
  • Handle hold. If you released a username/handle, a hold on that handle is retained for approximately six months to prevent immediate impersonation; the identifier of the releasing account is removed.
  • Export audit record. If you exported your data, a pseudonymous record of the export (event counts and timestamp, with email, IP address, and user-agent removed) is retained.
  • Backups. Encrypted backup copies are overwritten on the normal rotation and are automatically deleted within 90 days. Backups are not used to restore a deleted account.
  • Legal and tax records. Transactional records required for tax and accounting are retained for the period required by law; records related to a legal dispute or investigation are retained for the duration of that matter.
  • Aggregated, de-identified data. Statistics that no longer identify you may be retained indefinitely. This does not include the content of your contacts, notes, photos, or health fields.

Third-Party Processor Residuals. Data already transmitted to our subprocessors before you deleted your account is deleted according to each subprocessor's own retention schedule, which we do not directly control. On deletion we delete the subscription-processor customer record associated with your account (RevenueCat), and we record the residual-cleanup status for each processor. Residuals may include: SMS and OTP delivery logs (Telnyx), email delivery logs (Resend), error and performance events that reference your account identifier (Sentry), product-analytics events keyed to your account's opaque identifier (PostHog), and transient push-delivery receipts (Expo). These age out on each provider's own schedule. See Section 4.2 for the full subprocessor list.

6.3 Inactive Accounts

Tether reserves the right (but is not currently obligated, and at this time has not implemented an automated mechanism) to send a re-engagement or deletion-warning notification to accounts that have shown no sign-in or sync activity for an extended period — a period we currently anticipate to be twelve (12) months or more. If we elect to send such a notification and the account holder does not respond within thirty (30) days of the notification, we may, at our discretion, delete the inactive account and its associated data subject to the retention exceptions in Section 6.2.

We will provide additional detail about any automated inactive-account-deletion procedure in this Section once such a procedure is implemented. Until then, this provision should be read as a reservation of right rather than a description of a current automated practice. If you wish to confirm the status of your account, or to be notified before any deletion, please contact [email protected].


7. Your Privacy Rights

7.1 Rights Available to All Users

Regardless of your location, you have the following rights:

  • Access & Portability: Access your contact data at any time through the app. Export all contacts in standard formats (vCard .vcf, CSV, JSON) via Settings > Data & Privacy > Export Data. Request a copy of all personal information we hold at [email protected].
  • Correction: Edit your profile and contact data directly in the app. Contact [email protected] for corrections you cannot make yourself.
  • Deletion: Delete individual contacts or your entire account through app settings. Request immediate deletion at [email protected].
  • Opt-Out of Communications: Disable push notifications in device settings. Opt out of non-essential emails via the unsubscribe link. You cannot opt out of critical transactional messages (authentication codes, security alerts).

7.2 EEA/UK Users — GDPR and UK GDPR

Legal Bases for Processing:

Processing ActivityLegal Basis
Authentication, sync, contact managementContract performance (Article 6(1)(b))
Fraud prevention, security, analyticsLegitimate interests (Article 6(1)(f))
Marketing communications, optional featuresConsent (Article 6(1)(a))
Legal obligations complianceLegal obligation (Article 6(1)(c))

Additional GDPR Rights:

  • Right to Restriction: Limit how we process your data
  • Right to Object: Object to processing based on legitimate interests (including profiling)
  • Right to Withdraw Consent: Withdraw at any time (does not affect lawfulness of prior processing)
  • Right Not to Be Subject to Solely Automated Decisions: Where we make decisions solely through automated means with significant effects on you, you may request human review
  • Right to Lodge a Complaint: File a complaint with your local supervisory authority

Data Transfers: Your data may be transferred to and processed in countries outside the EEA/UK, including the United States. We ensure adequate safeguards through Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, and other legally approved transfer mechanisms.

EU Representative (Article 27 GDPR): [Designation in progress — contact [email protected] for all GDPR inquiries until a formal representative is confirmed]

UK Representative (Article 27 UK GDPR): [Designation in progress — contact [email protected] for all UK GDPR inquiries]

7.3 California Users — CCPA/CPRA

Categories of Personal Information We Collect:

  • Identifiers (name, phone number, email, device ID)
  • Commercial information (subscription tier, purchase history)
  • Internet/electronic activity (usage data, error logs, sync metadata)
  • Geolocation data (approximate — derived from IP address)
  • Professional/employment information (job title, company)
  • User-generated content (contacts, notes, photos)
  • Sensitive Personal Information (SPI): precise geolocation (if enabled), health information (if stored), biometric data (local device only)

California Privacy Rights:

  • Right to Know: Disclosure of personal information collected, used, shared, or sold
  • Right to Delete: Deletion of personal information (subject to legal exceptions)
  • Right to Correct: Correction of inaccurate personal information
  • Right to Opt-Out of Sale/Sharing: We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
  • Right to Limit Use of Sensitive Personal Information: You may direct us to limit our use and disclosure of your SPI to uses necessary to provide the Service. To exercise this right, email [email protected] or use the "Limit Use of My Sensitive Information" link at tetherup.app/privacy-choices.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

Your Privacy Choices: You may exercise your privacy choices at tetherup.app/privacy-choices or by emailing [email protected].

Global Privacy Control (GPC): We recognize and honor the Global Privacy Control (GPC) signal to the extent required by California law and other applicable laws. If you use a browser or device that broadcasts a GPC signal when accessing tetherup.app, we will treat that signal as a valid opt-out of sale/sharing for cross-context behavioral advertising.

Do Not Sell or Share: We do not sell personal information to third parties. We do not share personal information for cross-context behavioral advertising. These practices will not change without providing you with at least 15 days' advance notice and the ability to opt out before they take effect.

Shine the Light: We do not share personal information with third parties for their direct marketing purposes. California residents with questions may contact [email protected].

7.4 U.S. State Privacy Rights

Residents of the following states have privacy rights under applicable state law, which we honor to the extent required:

StateLawRights
TexasTDPSAAccess, correct, delete, portability, opt-out of sale/targeted advertising, appeal
VirginiaVCDPAAccess, correct, delete, portability, opt-out of sale/targeted advertising/certain profiling, appeal
ColoradoCPAAccess, correct, delete, portability, opt-out of sale/targeted advertising/certain profiling, appeal
ConnecticutCTDPAAccess, correct, delete, portability, opt-out of sale/targeted advertising, appeal
MontanaMCDPAAccess, correct, delete, portability, opt-out of sale, appeal
UtahUCPAAccess, delete, portability, opt-out of sale/targeted advertising
IowaICDPAAccess, delete, portability, opt-out of sale
Other enacted state lawsVariousSimilar rights as required

To exercise rights under any applicable state law, email [email protected]. We will verify your identity before fulfilling requests. We will respond within the timeframe required by applicable law. You may appeal our decision on a request by responding to our decision notice or emailing [email protected] with the subject line "Privacy Rights Appeal."

7.5 Brazilian Users — LGPD

Brazilian residents have rights under the Lei Geral de Proteção de Dados (LGPD), including rights to confirmation, access, correction, anonymization, portability, deletion, information about sharing, and revocation of consent. We process your personal data as the controller for purposes described in this Policy. Legal bases include consent (optional features), contract performance (core services), legitimate interest (security and fraud prevention), and legal obligation. Contact [email protected] for LGPD inquiries.

7.6 Australian Users — Privacy Act

Australian users have rights under the Privacy Act 1988 and Australian Privacy Principles (APPs). We are committed to the APPs. We will not send unsolicited electronic messages except as permitted by the Spam Act 2003. Contact [email protected] for Australian privacy inquiries.

7.7 Canadian Users — PIPEDA and Law 25

Canadian residents are served in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including Quebec's Law 25 (Act to modernize legislative provisions as regards the protection of personal information). Contact [email protected] for Canadian privacy inquiries.

7.8 Authorized Agents

You may designate an authorized agent to submit privacy rights requests on your behalf. We require: (a) written authorization signed by you or a valid power of attorney; and (b) identity verification directly with you (unless you have provided a power of attorney). We may deny requests from agents that do not submit required proof of authorization.


8. Children's Privacy

Tether is not intended for children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information directly from children under 13. Children are not Tether users — they may appear as contact entries managed by a parent or guardian, but they do not create accounts.

If you are a parent or guardian and believe your child has created a Tether account, contact [email protected]. If we learn that we have collected personal information from a child under 13 without parental consent verification, we will delete that information promptly.

Health information and other sensitive data about minor contacts (entered by a parent or guardian) are governed by our Health Information policies. Parents and guardians are solely responsible for the accuracy and lawfulness of any minor's data they enter.


9. Data About Non-Users

When you use Tether, you may import, store, or share information about people who do not have Tether accounts ("non-users") — including contacts from your address book, event guests, and manually entered contacts.

9.1 How We Handle Non-User Data

  • Phone numbers and email addresses of non-users may be stored in your encrypted Tether address book
  • We may hash phone numbers and email addresses using salted SHA-256 to identify potential connections if those individuals later create Tether accounts
  • Non-user contact data is subject to the same security protections as all other Service data
  • We do not use non-user contact data to send marketing communications to those individuals
  • Non-user contact data is deleted when you delete the associated contact or close your account

9.2 Your Responsibility for Non-User Data

You are responsible for ensuring: (a) you have a lawful basis for storing non-users' personal information in Tether; (b) you notify individuals whose information you store as required by applicable law; and (c) you respond to any requests from non-users seeking access to or deletion of their information that you have stored.

If a non-user contacts us to request information about or deletion of their data that you have stored, we may notify you and ask you to take appropriate action. Where required by law, we may take additional steps including restricting access to the relevant information.


10. Analytics, Tracking, and Mobile SDKs

10.1 Mobile Analytics SDKs

As a mobile app, Tether uses software development kit (SDK) equivalents to what cookies do on websites. These SDKs collect technical data to help us operate and improve the Service. We use:

Sentry SDK (@sentry/react-native): Collects crash reports, error traces, and performance data. Our implementation is configured to redact PII before transmission. No contact data is transmitted to Sentry. Source maps and iOS dSYMs are uploaded for symbolication.

PostHog SDK (posthog-react-native): Captures product-analytics events with an enforced PII denylist (see Section 4.3 for the complete list of denylisted keys). Allowlisted user traits are limited to subscription tier, signup date, contact count, circle count, and cohort week. PostHog session replay is not enabled. Capture is gated on the in-app analytics opt-out, which when engaged converts all identify / capture calls to no-ops at the SDK boundary.

RevenueCat SDK (react-native-purchases): Processes subscription purchases and provides subscription lifecycle analytics. No contact data is shared. RevenueCat may collect purchase-related device data per their privacy policy.

Expo Push SDK (expo-notifications): Registers push notification tokens and delivers push notifications. Push tokens are not linked to your contact data.

jail-monkey (on-device only): Performs a local jailbreak/root check at app launch. The result is not transmitted off-device. See Section 3.8.

We do not embed advertising SDKs, social-media tracking SDKs, attribution SDKs (e.g., AppsFlyer, Branch, Adjust, Singular), or behavioral profiling SDKs in the Tether app. The app does not request or use Apple's IDFA, does not use Google Play's Advertising ID, and does not declare advertising as a data-use purpose in either App Store or Play Store privacy disclosures.

10.2 Do Not Track (DNT)

Most web browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature or setting. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. Accordingly, we do not currently respond to DNT browser signals in a standardized way. However, we honor the Global Privacy Control (GPC) signal as described in Section 7.3.

If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Policy.

10.3 Web Analytics

For tetherup.app web properties, we use minimal, privacy-respecting analytics that do not build behavioral profiles and do not share data with advertising networks.


11. International Data Transfers

Tether is operated from the United States. Information we collect may be transferred to, processed, and stored in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from the laws of your country.

For EEA/UK users, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, and other approved transfer mechanisms. For other international users, we implement appropriate safeguards including contractual commitments and security measures. Contact [email protected] for information about specific safeguards applicable to your jurisdiction.


12. Third-Party Links and Integrations

12.1 Third-Party Services

Tether integrates with: Google Contacts (Google People API); Microsoft Contacts (Microsoft Graph API); RevenueCat/Apple App Store/Google Play Store (payments); and social media platforms (when you choose to link social profiles).

12.2 Third-Party Privacy Practices

We are not responsible for the privacy practices of third-party services. When you use these services, you are subject to their privacy policies. We recommend reviewing their policies before use. We only request the minimum necessary permissions and do not access data beyond what is required (e.g., we do not access your emails when connecting Google Contacts).


13. Push Notifications and Communications

13.1 Types of Communications

Transactional/Service Messages (Cannot Opt Out):

  • Authentication codes (SMS OTPs via Telnyx and email OTPs via Resend — required for account access)
  • Security alerts (unusual login activity, session changes, new-device logins)
  • Phone-number-change security notifications — sent to the prior phone number (SMS), the verified email address (email), and any other signed-in devices (push), each containing a 24-hour revocation link (see Section 3.7)
  • Email-address-change security notifications — sent to the prior verified email address (email), the new email address (email), the verified phone number (where applicable, SMS), and any other signed-in devices (push), each containing a 24-hour revocation link (see Section 3.7)
  • Account-lockout notifications — sent when your account is locked following a revocation event or other security trigger (see Section 3.7 and Terms of Service Sections 2.8–2.11)
  • Sync status and critical account status notifications
  • Critical service updates (maintenance, outages, security patches)

Marketing/Promotional Messages (Can Opt Out):

  • Feature announcements and product updates
  • User surveys and feedback requests

Push Notifications (Can Opt Out):

  • Contact information updates
  • Birthday and important date reminders
  • Directory activity
  • Event invitations and RSVP reminders
  • Automatic connection notifications

13.2 SMS Consent and TCPA Compliance

By providing your phone number and creating an account, you expressly consent to receive SMS messages from Tether via Telnyx, including OTPs and security alerts required for Service functionality. Message and data rates may apply. Message frequency varies by activity.

  • Opt out of non-transactional SMS: Reply STOP to any message
  • Help: Reply HELP or contact [email protected]
  • Note: If you cancel all SMS from us, you may lose access to certain features (including account authentication)
  • We do not share, sell, or rent data collected through our SMS program to third parties for independent purposes

Full SMS terms: tetherup.app/sms

13.3 Managing Communications

  • Push Notifications: Disable via device settings (Settings > Notifications > Tether) or configure specific types in app settings
  • Email: Click "Unsubscribe" in marketing emails or manage in app settings
  • SMS: Text STOP to opt out of promotional SMS; authentication codes cannot be disabled

14. Clipboard Access

Tether does not read the contents of your clipboard. The app only writes to your clipboard, and only when you explicitly tap or long-press a "copy" affordance in the user interface — it copies just the value you chose. Clipboard writes are local to your device and do not transmit any data to Tether's servers. Current write surfaces include:

  • Copying a contact's phone number, email, or other field value from a contact card (including the MemberContactCard and CustomFieldRow long-press handlers);
  • Copying an event share link from the event-created confirmation sheet;
  • Copying a shared-circle invite code from circle settings;
  • Copying your account profile values from the profile screen;
  • Copying the SHA-256 integrity hash from the GDPR data-export screen.

15. Job Applicants

When you apply for a position at Tether through our website or via email, we collect information you provide in connection with your job application, including contact information, professional credentials, employment history, educational background, and other information typically included in a résumé or CV. We use this information to facilitate our recruitment activities and process employment applications, monitor recruitment statistics, and respond to your application. We do not use job applicant data for purposes unrelated to recruitment. Applicant data is retained for the duration of the recruitment process and for a reasonable period thereafter to comply with legal obligations or respond to inquiries. Contact [email protected] for questions about your applicant data.


16. Updates to This Privacy Policy

We may update this Privacy Policy from time to time. We will post updates in the app and on our website, update the "Last Updated" date, and for material changes, provide prominent notice via in-app notification, email, and/or push notification. Your continued use after the effective date constitutes acceptance. If you do not agree, discontinue use and delete your account. We maintain a version history of this Privacy Policy; contact [email protected] for previous versions.


17. Contact Us

PurposeContact
General privacy inquiries[email protected]
Rights requests (access, deletion, correction)[email protected]
Privacy appeals[email protected] (Subject: Privacy Rights Appeal)
General support[email protected]
Phone+1 (214) 286-5678
PostalTether, LLC, [Address to be provided]
In-AppSettings > Help & Support > Contact Us

We aim to respond to all privacy inquiries within 30 days (or as required by applicable law for rights requests).


18. Specific State and Country Disclosures

18.1 Nevada (NRS 603A)

We do not sell "covered information" as defined by Nevada law.

18.2 Texas (TDPSA)

We do not sell personal data. We do not process personal data for targeted advertising. Your rights under the TDPSA (access, correct, delete, portability, appeal) are honored as described in Section 7.4.

18.3 California — Additional Disclosures

Do Not Sell or Share Link: tetherup.app/privacy-choices

Sensitive Personal Information Opt-Out Link: tetherup.app/privacy-choices

Metrics (prior 12 months): [To be populated annually per CPRA requirements]

18.4 Brazil (LGPD)

See Section 7.5. Our appointed Data Protection Officer (DPO) contact: [email protected].

18.5 Australia

See Section 7.6. Nothing in this Policy restricts, excludes, or modifies any rights under the Privacy Act 1988 that cannot be excluded by agreement.

18.6 Canada (PIPEDA / Law 25)

See Section 7.7. Our Privacy Officer contact: [email protected].


19. Definitions

Personal Information: Information that identifies, relates to, describes, or could reasonably be linked with you or your household.

Processing: Any operation performed on personal information, including collection, use, storage, disclosure, and deletion.

Service: The Tether mobile application and all related services.

User / You: The person using Tether or the entity on whose behalf the person is using Tether.

Device: Any electronic device capable of running the Tether application.

Contact: A person whose information you store in Tether.

Non-User: A person whose information you have stored in Tether but who does not have a Tether account.

Privacy Circle / Sharing Tier: One of three type categories (Community, Professional, Close) controlling what information you share.

Shared Directory/Circle: A collaborative space where multiple Tether users share contact information based on common affiliation.

Sensitive Personal Information (SPI): Personal information including health data, precise geolocation, biometric data, financial account information, racial or ethnic origin, religious beliefs, and other categories defined under CCPA/CPRA and similar laws.

Autoconnect: The automatic creation of a mutual connection between two users whose verified phone numbers appear in each other's contact lists, using salted SHA-256 hashing.

EXIF Metadata: Exchangeable Image File Format data embedded in digital photos, which may include GPS coordinates, camera model, and timestamps.

SCALAR_SYNC_FIELDS: Contact fields owned by the data subject (the person the contact represents) that sync unconditionally — the data owner's value always wins.

SYNC_PREFER_LOCAL_FIELDS: Contact fields owned by the contact owner (you) that sync for backup but where your non-empty local value always takes precedence.


This Privacy Policy is effective as of May 13, 2026 and was last updated on June 24, 2026.

Tether Tether

The privacy-first contact manager that keeps your network current. Built for professionals who value both connection and control.

Product

  • Features
  • Pricing
  • FAQ
  • What's New

Company

  • About
  • Blog
  • Press Kit
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Privacy Inquiries
  • Billing Support
© 2026 Tether, LLC All rights reserved.