Tend privacy policy
Effective 29 July 2026
Who you are dealing with
Tend is built and run by Rui Luis, a solo founder — there is no support team behind this address, just one person. For questions, privacy requests, or anything a contact of yours wants to raise, write to ruimluis7@gmail.com.
Under GDPR terms: Tend is the controller for your account data — your email address, settings, and the record of what you spent credits on. For the people you put into Tend, you decide who goes in and why; Tend stores and processes them on your instructions, which makes it a processor for that data. If you use Tend purely for personal purposes, GDPR's household exemption may mean it does not apply to you at all. The legal bases relied on are performing the contract with you (running the service you signed up for) and legitimate interests (keeping it secure and working).
What Tend holds
Your account
- Your email address, used to sign in. Tend has no passwords — sign-in is a one-time link sent to that address.
- Your settings, your business profile if you fill one in, and the record of AI runs you have made — which feature, when, how many credits, and what it cost to serve. This is how the allowance is counted; it does not store the content of the run.
What you enter or import
- Contacts, notes, goals, reminders, tags, custom fields, important dates, and interaction history you type in.
- Files you upload — CSV or vCard contact exports, a LinkedIn data export, contact photos. Photos are stored at a long random URL that is not listed anywhere but is readable by anyone who has the link.
What you connect, with permission
Every connection below is optional, read-only, and disconnectable in Settings. Tend never sends mail, never posts, and never messages anyone on your behalf.
- Google — contacts and calendar (
contacts.readonly,calendar.readonly) to import people and log meetings onto their timelines. Gmail (gmail.readonly) is a separate opt-in you have to choose; without it Tend never sees your mail. Mail and events are read only for people already in your contacts, roughly 90 days back at first connect. - Microsoft — mail, calendar, and contacts, read-only (
Mail.Read,Calendars.Read,Contacts.Read), used the same way. - Any IMAP mailbox — if you connect one, the host, username, and password you enter are stored encrypted and used only to read mail from people you track.
- Todoist, if you connect it, to keep tasks and reminders in step.
- Access tokens and mailbox credentials are encrypted before they are stored. Disconnecting a channel in Settings deletes them.
The Chrome extension
The extension is selective by design. It never collects anything in the background, and it has no bulk path:
- Profile capture happens only when you click the ✚ Tend button on a LinkedIn profile. The visible text of that page and its URL are sent to Tend's server, which extracts the person's name, headline, title, company, and location. The raw page text is processed and not retained; the extracted fields are saved to your account.
- Conversation logging applies only to people already in your contacts. When you open a message thread with someone you track, the visible conversation is sent to Tend's server and new messages are logged to that contact's timeline. Conversations with anyone else are not stored. Nothing is read from threads you do not open on screen.
- The extension authenticates with a token you generate in Settings. Rotating or removing that token immediately revokes the extension's access.
If you sign up from the website
The email address — and the goal, if you write one — go to the founder's inbox and to the server log so the signup is not lost. They are used to get you set up and to reply to you. They are not added to a mailing list, and they are not shared or sold. The marketing pages run no analytics and no trackers; the only thing counted is which button a signup came from, as a number with no personal data attached.
Other people's data
This is the part worth reading twice. Most of what Tend holds is personal data about other people — your contacts' names, email addresses, job histories, and the content of messages and meetings you had with them. They did not sign up for Tend; you brought them in, exactly as you would in any address book or CRM.
- Their data is only ever visible to you. Tend is single-tenant per account: nothing is pooled, cross-referenced between users, or used to build any shared graph.
- Tend never enriches a contact from outside sources — no data brokers, no scraping, no lookups. Everything on a contact card came from you, from a file you uploaded, from a mailbox you connected, or from a page you clicked capture on.
- You are responsible for having a lawful reason to hold what you put in, and for honouring requests your contacts make to you. If one of your contacts writes to us directly, we cannot identify which account holds their data without your help — so we will ask you, and you can delete or export their record yourself from their contact page.
Google user data
Tend's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: Google data is used only to provide the features you connected it for, it is never sold, never used for advertising, and never used to train any AI model. No human reads it — not us, not anyone — except with your explicit permission, or where the law requires it. It reaches Anthropic's API only when you run an AI feature, as described below, and Anthropic does not train on it either.
AI processing
Tend's AI features — goal audits, suggestions, drafts, the daily brief, extraction from captured pages — send the relevant portion of your data to Anthropic's API for processing. Three things bound that:
- It runs when you ask — with two exceptions, named here rather than buried. The daily brief is prepared on a schedule for paid accounts so it is ready before your morning, and when new messages arrive on a channel you connected, replies from people on an active goal are read once to tell a yes from a no. Both obey the exclusions below. Everything else — audits, drafts, suggestions, Ask your network — happens on a click.
- Nothing trains a model. Anthropic does not train models on data submitted through its API, and Tend does not train anything of its own.
- You can exclude anything. Mark a contact or an interaction as excluded from AI, and every AI feature leaves it out — the exclusion is enforced where the data is fetched, not filtered afterwards.
What Tend never does
- Sell or rent your data, or show ads.
- Scrape, crawl, or bulk-collect anything — Tend only holds what you provide, import, connect, or capture with an explicit action.
- Message anyone on your behalf. Tend drafts; you send.
- Run trackers, analytics scripts, or advertising pixels on the marketing site.
Where it lives, and who else touches it
Data is stored and processed in the United States. These are the only companies that handle it, each for one job:
- Vercel — hosting, and storage for uploaded photos.
- Neon — the Postgres database (US East).
- Anthropic — the AI processing described above.
- Resend — delivering sign-in links and notification email.
If you are in the EU or UK, transfers to these providers rely on their standard contractual clauses. No one else receives your data — there is no advertising network, no analytics vendor, and no data broker in this list, and adding one would be a change to this page.
Keeping it, exporting it, deleting it
Your data is kept while your account exists — Tend does not expire or thin out old history, because the history is the product.
- Export — Settings → Export gives you every contact as CSV, or a full JSON backup with all timelines, reminders, custom fields, and important dates. No request needed, no waiting.
- Delete — Settings → Export & deletion removes your account and everything attached to it: contacts, timelines, goals, uploaded files, and connected-account credentials. It is immediate and permanent, with no soft-delete copy kept. Our database provider holds automatic backups for a short window for disaster recovery; deleted data ages out of those as they roll over.
- Server logs, which record request errors and signups, are kept by our hosting provider on their own short rolling schedule.
Your rights
Depending on where you live you have rights to access, correct, export, delete, and object to the processing of your personal data. Export and deletion you can do yourself, immediately, from Settings — that is deliberate. For anything else, email ruimluis7@gmail.com and you will get an answer within 30 days. If you are in the EU or UK and are not satisfied, you can complain to your national data protection authority.
Security
Data is transmitted over TLS and stored in managed infrastructure that encrypts it at rest. Connected-account tokens and mailbox passwords are separately encrypted before they are stored. Sign-in is by one-time link, so there is no password to steal. Extension tokens are stored hashed and can be rotated by you at any moment. No system is perfectly secure, and this one is run by one person — if something goes wrong that affects your data, you will be told promptly and plainly.
Children
Tend is for professional use and is not directed at anyone under 16.
Changes
If this policy changes materially, the effective date above changes with it and account holders are emailed. Substantive changes are not made quietly.
Back to Tend · Terms · Questions: ruimluis7@gmail.com