Our Privacy Philosophy: We built Tether because we believe your contact information belongs to you — and so does your data. We don't sell your personal data. We don't use it for advertising. We don't use advertising networks or ad-tech trackers. Your address book is encrypted at rest and in transit, and no human at Tether has routine access to it.
| Topic | Short Answer |
|---|---|
| Do we sell your data? | No |
| Do we use advertising networks? | No |
| Do we share data with third parties? | Only service providers necessary to operate the app (see Section 4.2) |
| How is phone number matching done? | Via salted SHA-256 hashing — raw numbers never compared |
| Are EXIF/GPS tags stripped from photos? | Yes, automatically |
| Can you export your data? | Yes — vCard, CSV, or JSON via Settings |
| Can you delete your account? | Yes — Settings > Account > Delete Account |
Welcome to Tether ("we," "our," or "us"). Tether is a privacy-first professional contact management application that automatically keeps your contact information current through live updates and intelligent synchronization across your devices.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (collectively, the "Service"). If you do not agree, please do not access the Service.
We reserve the right to make changes to this Privacy Policy at any time. We will alert you about material changes by updating the "Last Updated" date and, for significant changes, by providing prominent in-app notice or email notification.
Account Information: Phone number (required for SMS OTP authentication — Tether's sole sign-in method), name (first, last, optional middle, prefix, suffix), profile information (company, job title, department, handle/username, avatar photo), and account preferences (including accessibility settings).
Contact Data: Names, phone numbers (E.164 format), email addresses, physical addresses, social media profiles, website URLs, birthdays, anniversaries, notes, photos (EXIF metadata stripped), health information (allergies, medical conditions, emergency designations), custom fields, tags, labels, and referral codes.
Event Data: Event details (title, date, time, location), RSVP status, co-host assignments, guest lists, and per-RSVP snapshots (display name and email address captured at invite time).
Privacy Circle Assignments: Classification of contacts into sharing tiers (Community, Professional, Close), custom circle memberships, shared circle/directory memberships.
Directory and Shared Circle Data: Directory name, description, your membership status and role, information you choose to share with directory members.
Device Information: Device type, model, OS version, unique device identifiers (generated by SHA-256 hashing hardware IDs with your user ID), app version, language, region, and screen resolution.
Usage Data: Features used, actions performed, error logs and crash reports (via Sentry, PII auto-redacted), performance metrics, interaction patterns (aggregated and hashed, not linked to individual identities), and accessibility feature usage.
Technical Data: IP address (for security and approximate location), session duration, sync operation metadata, and network connection type.
With your explicit permission, we may import contact data from your device's native contacts, Google Contacts (via OAuth 2.0), Microsoft Contacts (via OAuth 2.0), and vCard/CSV files. We only request the minimum permissions necessary. We do not access your emails, calendars, documents, or other data unrelated to contact management.
If you enable biometric authentication (Face ID, Touch ID), we do not collect, store, or transmit your biometric data. Authentication is processed entirely on your device's secure enclave. We only receive a success/failure signal.
When you upload photos, we automatically strip all EXIF metadata (including GPS coordinates, camera info, and timestamps) prior to storage.
We collect approximate location data derived from your IP address for security and fraud prevention (city or region level, not GPS). No current core features require precise GPS location.
We do not use your contact data to train general-purpose AI models for sale or licensing to third parties.
We analyze aggregated, de-identified metrics for performance monitoring, feature usage understanding (hashed, anonymized), error tracking via Sentry (PII auto-redacted), and A/B testing.
We do not use your personal contact data for advertising targeting. We do not sell your data or share it for cross-context behavioral advertising.
Rate limiting, authenticated device session management, anomaly detection, and audit logs.
Sharing Tier Settings: When you connect with another user, you control what they see:
Default sharing for unassigned contacts: name, profile photo, handle, and mobile phone. Review and modify defaults in Settings > Privacy > Tier Defaults.
Data on Disconnect: When you block or remove a connection, all information received through that connection is automatically removed. Live data does not persist after disconnection.
Events and Co-hosts: Co-hosts can see only the display name and email address attached to each guest invitation (per-RSVP snapshot) — not any other information from your address book.
We share information with service providers who are contractually required to use your information only for specified services:
| Provider | Purpose |
|---|---|
| Supabase Inc. | Database, auth, file storage, real-time sync (AWS, US) |
| Sentry | Error tracking (PII auto-redacted) |
| RevenueCat | Subscription billing via App Store / Google Play |
| Telnyx | SMS OTP delivery |
| Resend | Transactional email (invitations, broadcasts) |
| Expo | Push notification delivery |
Sentry: Crash reports with PII auto-redacted. RevenueCat: Subscription lifecycle analytics.
We do not use Google Analytics, Facebook Pixel, or advertising-oriented analytics tools in the Tether mobile app.
We do not sell your personal data to advertisers. We do not share your data with advertising networks. We do not receive compensation for your data from any advertising partner. Tether generates revenue through subscription fees only.
If Tether is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will provide at least 30 days' notice before your information becomes subject to a materially different privacy policy.
We may disclose information if required by law or in response to valid requests by public authorities. When permitted, we will provide you with prompt notice of legal demands for your data.
We may disclose information to lawyers, auditors, bankers, and insurers subject to confidentiality obligations.
We may share aggregated, anonymized information that cannot identify you for business purposes including research and service improvement.
Encryption:
Authentication Security:
Access Controls:
Cross-User Isolation: On sign-out, we execute a five-step wipe of all locally stored user data, ensuring no contact data survives a logout.
In the event of a security breach, we will investigate promptly, notify affected users without undue delay (within 72 hours under GDPR where required), and cooperate with regulatory authorities.
No method of transmission or storage is 100% secure. While we use commercially acceptable means, we cannot guarantee absolute security.
| Data Category | Retention Period |
|---|---|
| Contact data | While account is active |
| Sync history | 90 days |
| Change logs (audit) | 1 year |
| Soft-deleted contacts | 30 days, then auto-hard-deleted (daily, 3:00 AM UTC) |
| Error/crash logs (Sentry) | 90 days (PII redacted) |
| Transactional records | 7 years (tax/accounting) |
When you request account deletion (Settings > Account > Delete Account):
Immediate Actions:
After 30-Day Cooling Period:
Exceptions: Transactional records (7 years), legal dispute records, aggregated analytics, backup copies (deleted within 90 days).
Accounts inactive for 12 months may receive notification. If no response within 30 days, we may delete the account and data.
Legal Bases for Processing:
Additional GDPR Rights: Right to restriction, right to object, right to withdraw consent, right not to be subject to solely automated decisions, right to lodge a complaint.
Data Transfers: We ensure adequate safeguards through Standard Contractual Clauses (SCCs) and adequacy decisions.
EU/UK Representatives: Designation in progress — contact [email protected].
California Privacy Rights:
Global Privacy Control (GPC): We recognize and honor the GPC signal to the extent required by California law.
Do Not Sell or Share: We do not sell personal information or share it for cross-context behavioral advertising.
Your privacy choices: [email protected] or tetherup.app/privacy-choices.
Residents of the following states have privacy rights which we honor:
Email [email protected] to exercise rights. You may appeal our decision by emailing with the subject line "Privacy Rights Appeal."
Brazilian residents have rights under the LGPD including confirmation, access, correction, anonymization, portability, deletion, and revocation of consent. Contact [email protected].
We are committed to the Australian Privacy Principles (APPs). Contact [email protected].
Canadian residents are served in accordance with PIPEDA and Quebec's Law 25. Contact [email protected].
You may designate an authorized agent to submit privacy requests on your behalf with written authorization and identity verification.
Tether is not intended for children under 13. We do not knowingly collect personal information directly from children under 13. Children are not Tether users — they may appear as contact entries managed by a parent or guardian, but they do not create accounts.
If you believe a child under 13 has created an account, contact [email protected].
When you use Tether, you may store information about people who do not have Tether accounts ("non-users").
You are responsible for ensuring you have a lawful basis for storing non-users' personal information.
We do not embed advertising SDKs, social media tracking SDKs, or behavioral profiling SDKs.
We do not currently respond to DNT browser signals in a standardized way. However, we honor the Global Privacy Control (GPC) signal as described in Section 7.3.
For tetherup.app web properties, we use minimal, privacy-respecting analytics that do not build behavioral profiles.
Tether is operated from the United States. For EEA/UK users, we rely on Standard Contractual Clauses (SCCs) and adequacy decisions. For other international users, we implement appropriate safeguards including contractual commitments and security measures.
Tether integrates with Google Contacts (Google People API), Microsoft Contacts (Microsoft Graph API), RevenueCat/Apple App Store/Google Play Store (payments), and social media platforms. We are not responsible for the privacy practices of third-party services.
Transactional (Cannot Opt Out): Authentication codes (SMS OTPs via Telnyx), security alerts, sync status, critical service updates.
Marketing (Can Opt Out): Feature announcements, product updates, surveys.
Push Notifications (Can Opt Out): Contact updates, birthday reminders, directory activity, event invitations, connection notifications.
By providing your phone number, you expressly consent to receive SMS from Tether via Telnyx. Message and data rates may apply.
Full SMS terms: tetherup.app/sms
Push: Device Settings > Notifications >
Tether, or configure in app settings.
Email: Click "Unsubscribe" in marketing
emails.
SMS: Text STOP to opt out of promotional SMS.
When you install Tether after visiting a referral invite page, the app may check your device clipboard for a referral code. This is used solely for attribution. Your device's OS will prompt you before clipboard access. No other clipboard data is read or stored.
When you apply for a position at Tether, we collect information you provide (contact information, professional credentials, employment history). We use this information solely for recruitment. Applicant data is retained for the duration of recruitment and a reasonable period thereafter. Contact [email protected] for questions about your applicant data.
We may update this Privacy Policy from time to time. We will post updates in the app and on our website, update the "Last Updated" date, and for material changes, provide prominent notice via in-app notification, email, and/or push notification. We maintain a version history; contact [email protected] for previous versions.
We aim to respond to all privacy inquiries within 30 days (or as required by applicable law).
We do not sell "covered information" as defined by Nevada law.
We do not sell personal data or process it for targeted advertising.
Do Not Sell or Share Link:
tetherup.app/privacy-choices
Sensitive Personal Information Opt-Out:
tetherup.app/privacy-choices
DPO contact: [email protected].
Nothing in this Policy restricts, excludes, or modifies any rights under the Privacy Act 1988 that cannot be excluded by agreement.
Privacy Officer: [email protected].
This Privacy Policy is effective as of April 15, 2026 and was last updated on April 15, 2026.