Privacy Policy

Last Updated: 26 August, 2026

Introduction

Tether ("Tether," "we," "us," or "our") is a private family infrastructure application developed by 杭州景藏网络科技有限公司 (Hangzhou Jingzang Network Technology Co., Ltd.) ("Tether"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use the Tether mobile application (the "App"), our website, and any related services (collectively, the "Service").

By creating an account or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our practices, please do not use the Service.

We are committed to transparency and to the principles of privacy by design.

Contents

1. How We Collect and Use Your Personal Information

1.1 Information You Provide Directly

We collect information you provide when you create an account, set up your profile, or use features of the Service:

CategoryExamplesPurpose
Account InformationName, email address, phone number, password hash, date of birth, timezone, cityAccount creation, authentication, password recovery, age verification
Profile InformationDisplay name, avatar/photo, role label, notification preferences, pulse window settingsPersonalising your experience, family visibility
Family InformationFamily name, member relationships, invite codes, join requestsCreating and managing your family group
Stream EventsEvent titles, event details, photos/images, reactions, timestampsFamily communication and memory keeping
Daily Check-ins (Pulses)Mood rating (1-5), notes, photos, dateFamily presence signalling and daily connection
Emergency Alerts (SOS)Triggered by, contact information, alert status, timestampsEmergency family notification
Travel & Presence DataCountry codes, entry/exit dates, source (manual or stream event), visa records, tax residency profilesVisa expiry reminders, tax residency tracking, travel pattern awareness
Subscription InformationTether+ subscription status, trial status, purchase historyBilling, feature access, customer support

1.2 Information Collected Automatically

When you use the Service, we automatically collect certain technical information:

CategoryExamplesPurpose
Device InformationDevice model, operating system version, unique device identifiers, mobile network informationApp functionality, troubleshooting, security
Usage DataFeatures used, screens visited, actions taken, crash logs, performance dataImproving the Service, analytics, bug fixes
Push Notification TokensExpo push tokens, FCM tokensSending push notifications
Location DataCountry-level location only (derived from IP address or manual entry)Travel features, compliance with local laws
Authentication DataFirebase authentication tokens, session identifiersSecure sign-in, session management
Security LogsFailed login attempts, rate limit triggers, IP addressesFraud prevention, security monitoring

1.3 Information from Third Parties

We may recieve information about you from third parties:

SourceInformation ReceivedPurpose
Google Sign-InEmail address, name, profile photo (if authorised)Account creation and authentication
Sign in with AppleEmail address, nameAccount creation and authentication
RevenueCatSubscription status, purchase receipts, trial statusBilling and subscription management
Apple App Store / Google PlayPurchase validation, app installation dataPayment processing, app analytics
ExpoPush notification delivery statusNotification delivery optimisation
SendGridEmail delivery statusEmail delivery optimisation
AptabaseAnalytics identifiers, app usage events, crash logs, and performance dataProduct analytics and service improvement

1.4 How We Use Your Information

We use the collected information for the following purposes:

Core Service Provision
- Create and manage your account
- Enable family creation and member management
- Facilitate family communication through streams and pulses
- Provide emergency SOS alerts
- Provide travel history, visas, and tax residency status
- Deliver push notifications and reminders
- Deliver invite emails

Safety and Security
- Verify your identity and prevent fraud
- Enforce rate limits and prevent abuse
- Monitor for security incidents and unauthorised access
- Respond to emergency situations

Service Improvements
- Analyse usage patterns to improve features
- Fix bugs and optimise performance
- Develop new features based on user needs

Legal and Compliance
- Comply with legal obligations
- Respond to lawful requests from authorities
- Protect our rights and property
- Enforce our Terms of Use

Communications
- Send transactional emails (welcome, password reset, receipts)
- Provide customer support
- Send product updates and announcements (with your consent where required)

1.5 Legal Bases for Processing (GDPR/UK GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal bases:

- Contract Performance: Processing necessary to provide the Service you requested (account creation, family features, subscription billing).
- Legitimate Interests:
Processing for security, fraud prevention, analytics, and service improvement, where these interests are not overridden by your rights.
- Consent:
Processing for optional features, marketing communications, or where required by law. You may withdraw consent at any time.
- Legal Obligation:
Processing to comply with applicable laws, regulations, or legal processes.
- Vital Interests:
Processing to protect someone's life or physical safety (e.g., SOS emergency alerts).

2. How We Share and Publicly Disclose Your Personal Information

2.1 Within Your Family Group

Tether is designed to share information within your chosen family group. When you join or create a family:

- Family members can see:
Your name, avatar, role label, pulse status, stream events you post, travel records, and SOS alerts you trigger.
- Family administrators can additionally see:
Join requests, member management options, and family settings.
- You control visibility:
You can toggle whether your travel data is visible to family members in your profile settings.

‍We do not share your personal information with other families or users outside your family group, except as described below.

2.2 Service Providers and Subprocessors

We engage trusted third-party companies to perform services on our behalf. These service providers are contractually obligated to protect your data and use it only as directed by us. Our current subprocessors include:

SubprocessorService ProvidedData SharedLocation
Google LLC (Google Cloud / Firebase)Authentication, database, cloud functions, analytics, storageAccount data, authentication tokens, usage data, photos, app contentUnited States, European Union, and other Google Cloud regions (excluding mainland China)
RevenueCatSubscription management and billingUser ID, subscription status, purchase receiptsUnited States
ExpoPush notification infrastructurePush tokens, device identifiersUnited States
Apple Inc.App Store distribution, payment processing, and Sign in with AppleApp installation data, authentication data, purchase validationGlobal
Google LLCGoogle Play distribution and Google Sign-InApp installation data, authentication dataGlobal
AptabaseAnalytics and crash reportingAggregated usage events, device identifiers, crash logs, performance dataEuropean Union

2.3 Legal Requirements and Protection

We may disclose your personal information if required to do so by law or in the good faith belief that such action is necessary to:

- Comply with a legal obligation, court order, or legal process served on us
- Protect and defend our rights or property
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of users or the public
- Protect against legal liabilityWe will notify you of legal requests where permitted by law and where we believe the request affects your rights.

2.4 Business Transfers

If we are involved in a merger, acquisition, asset sale, bankruptcy, or other business transition, your personal information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Service of any change in ownership or uses of your personal information.

2.5 With Your Consent

We may share your personal information with third parties when we have your explicit consent to do so.

2.6 Aggregated or De-identified Data

We may share aggregated, anonymised, or de-identified information that cannot reasonably be used to identify you for research, analytics, or business purposes. For example, we may publish statistics about total users or feature adoption without revealing individual identities.

3. Cookies, Identifiers, and Similar Technologies

3.1 Mobile Application Content

Tether is a mobile application and does not use browser cookies in the traditional sense. Instead, we use similar technologies, including mobile identifiers, local storage, and analytics SDKs.

3.2 Technologies We Use

TechnologyPurposeDuration
Aptabase AnalyticsUnderstanding app usage, crashes, and performanceSession-based and persistent
Local Storage / AsyncStorageStoring app preferences, cache, and offline dataUntil you clear app data or uninstall
Push Notification TokensDelivering push notifications to your deviceUntil you disable notifications or uninstall
Firebase Authentication TokensKeeping you signed in securely1 hour (access tokens) or until sign-out (refresh tokens)

3.3 Your Choices

You can control or reset these identifiers through your device settings:

- App Settings: You can disable notifications in the app settings or your device settings

Please note that disabling certain identifiers may affect app functionality, such as push notifications or personalised features.

4. Data Storage and Retention

4.1 Where We Store Your Data

Your personal information is stored on secure servers provided by Firebase. Data may be stored in data centres located in the United States, the European Union, or other regions where Google Cloud operates. Tether does not store your personal information in mainland China.

We use industry-standard encryption for data in transit and at rest.

4.2 How Long We Keep Your Data

We retain your personal information only for as long as necessary to provide the Service and fulfil the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

Data TypeRetention Period
Account and Profile DataAs long as your account is active, plus 30 days after account deletion for recovery purposes
Family and Stream DataAs long as the family exists and you are a member, or until you delete specific content
Pulse RecordsRetained as part of your family history until you delete them or delete your account
SOS Alert RecordsRetained for safety and legal compliance purposes, typically 2 years
Travel, Visa and Tax DataRetained while your account is active; deleted immediately upon account deletion
Subscription RecordsRetained as required by tax and accounting laws, typically 7 years
Security and Audit LogsRetained for 1 year for security monitoring and incident response
Push Notification TokensDeleted immediately when you disable notifications or delete your account

4.3 Account Deactivation and Deletion

Deactivate Function: Tether offers a deactivate feature that allows you to temporarily disable your account without permanently deleting your data. When you deactivate:

- Your profile becomes invisible to family members
- You stop receiving notifications
- Your data is retained for 30 days in case you wish to reactivate
- After 30 days, your data is permanently deleted unless legally required to retain it

Account Deletion: You can permanently delete your account at any time through the app settings. When you delete your account:

- We immediately begin the deletion process
- Personal data is removed from active systems within 30 days
- Data in backups is removed within 90 days
- Some information may be retained in anonymised form for analytics
- Legal holds may delay deletion if required by law

Family Creator Deletion: If you are a family creator, deleting your account will trigger the family deletion process, which includes a transfer protocol before you can delete your account.

5. Your Personal Information Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

5.1 Universal Rights (All Users)

- Access: Request a copy of your personal information
- Correction:
Request correction of inaccurate or incomplete data
- Deletion:
Request deletion of your personal information
- Portability:
Request a copy of your data in a machine-readable format
- Withdraw Consent:
Withdraw consent for optional processing at any time
- Object:
Object to processing based on legitimate interests

5.2 California Residents (CCPA/CPRA)

If you are a California resident, you have the right to:

- Know:
Request disclosure of the categories and specific pieces of personal information we have collected, the sources, the purposes, and the third parties with whom we share it
- Delete:
Request deletion of your personal information, subject to certain exceptions
- Correct:
Request correction of inaccurate personal information
- Opt-Out:
Opt out of the sale or sharing of personal information for cross-context behavioural advertising (we do not sell your personal information)
- Limit:
Limit the use and disclosure of sensitive personal information (we do not use sensitive personal information for inferring characteristics)
- Non-Discrimination:
Not receive discriminatory treatment for exercising your rights

To exercise these rights, contact us at privacy@tetherfamily.com. We will verify your identity before processing requests.

5.3 European Economic Area, UK, and Switzerland (GDPR/UK GDPR)

If you are in the EEA, UK, or Switzerland, you have the right to:

- Access:
Obtain confirmation of whether we process your data and request a copy
- Rectification:
Request correction of inaccurate data
- Erasure:
Request deletion of your data ("right to be forgotten")
- Restriction:
Request restriction of processing in certain circumstances
- Data Portability:
Receive your data in a structured, commonly used format
- Object:
Object to processing based on legitimate interests or for direct marketing
- Withdraw Consent:
Withdraw consent at any time without affecting the lawfulness of prior processing
- Lodge a Complaint:
File a complaint with your local data protection authority

To exercise these rights, contact us at privacy@tetherfamily.com. We may need to verify your identity.

5.4 Virginia, Colorado, Connecticut, Utah, and Other US States

Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have similar rights to access, correct, delete, and opt out of certain processing. Please contact privacy@tetherfamily.com to exercise these rights.

5.5 Brazil (LGPD)

If you are in Brazil, you have the right to:

- Confirmation of the existence of processing
- Access to your data
- Correction of incomplete, inaccurate, or outdated data
- Anonymisation, blocking, or deletion of unnecessary or excessive data
- Portability of data to another service provider
- Deletion of data processed with your consent
- Information about entities with which data has been shared
- Information about the possibility of denying consent and its consequences
- Revocation of consent

Contact privacy@tetherfamily.com to exercise these rights.

5.6 Australia (Privacy Act 1988)

If you are in Australia, you have the right to:

- Access your personal information
- Request correction of your personal information
- Make a complaint about our handling of your personal information

Contact privacy@tetherfamily.com to exercise these rights. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).

5.7 How to Exercise Your Rights

To exercise any of these rights, please contact us at privacy@tetherfamily.com. We will respond to your request within 30 days, or as required by applicable law. We may need to verify your identity before processing your request.

6. Children's Privacy

6.1 Minimum Age Requirements

Tether is not intended for children under the following ages:

- 13 years old in the United States and most countries (171 countries total)
- 16 years old in Australia and Vietnam
- 16 years old in Brazil (A16 rating)
- 15 years old in the Republic of Korea

We do not knowingly collect personal information from children under the applicable minimum age. If you are under the minimum age in your jurisdiction, please do not use the Service or provide any personal information to us.

6.2 COPPA Compliance (United States)

The Children's Online Privacy Protection Act (COPPA) applies to children under 13. Tether does not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information as quickly as possible.

If you believe we might have any information from or about a child under 13, please contact us at safety@tetherfamily.com immediately.

6.3 Teen Users (13-17)

Users aged 13-17 (or the applicable age in their jurisdiction) may use Tether with parental consent where required by law. We encourage parents and guardians to monitor their teens’ use of the Service and to discuss online safety.

6.4 Family Accounts and Children

If a family includes a child under the minimum age, that child must not create their own account. Family data about a child may be managed by the family creator or administrator, but the child cannot independently use the Service.

7. International Data Transfers

7.1 Cross-Border Transfers

Tether is operated by 杭州景藏网络科技有限公司 (Hangzhou Jingzang Network Technology Co., Ltd.), a company registered in Hangzhou, China.

Your personal information is stored and processed on Google LLC’s Firebase servers located in the United States, the European Union, and other regions operated by Google Cloud Platform. Tether does not store your personal information in mainland China. When you use the Service, your personal information may be transferred to and processed in countries other than your own, which may have different data protection laws.

7.2 Safeguards for International Transfers

For transfers of personal data from the EEA, UK, or Switzerland to countries not deemed adequate by the European Commission or UK authorities, we rely on:

- Standard Contractual Clauses (SCCs): Approved by the European Commission for transfers to third countries
- Adequacy Decisions: Where the destination country has been deemed to provide adequate protection
- Your Explicit Consent: In limited circumstances, with your explicit consent

You may request a copy of the safeguards we use by contacting privacy@tetherfamily.com.

7.3 Brazil (LGPD)

For transfers of personal data from Brazil to other countries, we comply with the requirements of the LGPD, including ensuring an adequate level of protection or using standard contractual clauses.

7.4 Australia

For transfers of personal information from Australia to overseas recipients, we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles.

8. Data Security

8.1 Security Measures

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include:

- Encryption: Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 encryption
- Authentication: Secure user authentication via Firebase Authentication, Sign in with Apple, and Google Sign-In, using industry-standard OAuth 2.0 and token-based session management
- Access Controls: Role-based access control (RBAC) at the API layer and Firestore security rules
- Rate Limiting: Protection against brute force and abuse attacks
- Input Validation: Zod schema validation on all API inputs to prevent injection attacks
- Error Handling: Sanitised error messages that do not leak stack traces or internal details
- Firestore Security Rules: Strict access controls with default deny policies
- Secret Management: No hardcoded secrets; API keys and secrets are managed server-side. Client-side SDK keys are public by design and do not grant access to user data or backend systems

8.2 No Absolute Security

No method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. You are responsible for maintaining the confidentiality of your account credentials.

8.3 Incident Response

In the event of a data breach that affects your personal information, we will:

- Investigate and contain the breach
- Assess the risk to individuals
- Notify affected users and relevant authorities as required by law
- Take steps to prevent future breaches
- Document the incident and our response

9. Changes to This Policy

9.1 Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by:

- Posting the updated policy in the App and on our website
- Sending an email notification to the address associated with your account
- Providing a prominent notice within the App

9.2 Effective Date

The "Last Updated" date at the top of this Privacy Policy indicates when it was last revised. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

9.3 Review Cadence

We review this Privacy Policy at least every two weeks (fortnightly) to ensure it remains accurate and compliant with evolving legal requirements and our feature set.

10. Contact Us

10.1 Privacy Inquiries

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email: privacy@tetherfamily.com

10.2 Data Protection Officer

If you are in the European Economic Area, the UK, Switzerland, or Brazil, you may contact our Data Protection Officer at:

Email:
dpo@tetherfamily.com

10.3 General Support

For general customer support, technical issues, or account assistance, please contact:

Email: support@tetherfamily.com

10.4 Mailing Address

杭州景藏网络科技有限公司 (Hangzhou Jingzang Network Technology Co., Ltd.) Weiye Dexin AI Industrial Park, Puyan Street, Binjiang District, Hangzhou City, Zhejiang Province.

11. Other Important Information

11.1 Third-Party and Services

The Service may contain links to third-party websites, services, or applications (such as Google Sign-In, Sign in with Apple, Apple App Store, or Google Play). This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services before providing them with your personal information.

11.2 Do Not Track Signals

You can control analytics through the in-app Analytics toggle.

11.3 Marketing Communications

We may send you marketing communications about our products and services. You can opt out of receiving marketing emails by:

- Clicking the "unsubscribe" link in any marketing email
- Contacting us at privacy@tetherfamily.com
- Adjusting your notification settings in the App

Please note that even if you opt out of marketing communications, we may still send you transactional or service-related messages (e.g., password resets, purchase receipts, safety alerts).

11.4 Sensitive Personal Information

We do not intentionally collect sensitive personal information such as racial or ethnic origin, political opinions, religious beliefs, health data, genetic data, or biometric data for identification purposes. If you voluntarily provide such information in free-text fields (e.g., in notes or stream events), you do so at your own risk and should be aware that it may be visible to your family members.

11.5 Accessibility

If you have difficulty accessing this Privacy Policy due to a disability, please contact us at accessibility@tetherfamily.com, and we will provide the information in an alternative format.

11.6 Language

This Privacy Policy is written in English. If we provide translations, the English version will prevail in case of any conflict or inconsistency.

12. Jurisdiction-Specific Addenda

12.1 California Privacy

Categories of Personal Information Collected: We collect identifiers (name, email, phone), commercial information (subscription history), internet activity (app usage), geolocation (country-level), professional information (visa status), and inferences (family relationships).

Business or Commercial Purpose for Collection: Providing the Service, security, analytics, legal compliance, and customer support.

Categories of Third Parties with Whom We Share: Service providers (Firebase, RevenueCat, Expo), app stores (Apple, Google), and legal authorities when required.

Sale of Personal Information: We do not sell your personal information.

Sharing for Cross-Context Behavioural Advertising: We do not share personal information for cross-context behavioural advertising.

12.2 Virginia Consumer Data Protection Act Notice

Virginia residents have the right to:

- Confirm whether we process their personal data
- Access their personal data
- Correct inaccuracies
- Delete personal data
- Obtain a copy of personal data in a portable format
- Opt out of targeted advertising, sale of personal data, or profilingTo exercise these rights, contact privacy@tetherfamily.com.

12.3 Colorado Privacy Act Notice

Colorado residents have similar rights to access, correct, delete, and opt out of targeted advertising or sale. Contact privacy@tetherfamily.com to exercise these rights.

12.4 Connecticut Data Privacy Act Notice

Connecticut residents have similar rights to access, correct, delete, and opt out of targeted advertising or sale. Contact privacy@tetherfamily.com to exercise these rights.

12.5 Utah Consumer Privacy Act Notice

Utah residents have similar rights to access, delete, and opt out of targeted advertising or sale. Contact privacy@tetherfamily.com to exercise these rights.

12.6 European Economic Area (EEA) Notice

Data Controller: 杭州景藏网络科技有限公司 (Hangzhou Jingzang Network Technology Co., Ltd.) is the data controller for your personal information.

Legal Bases: See Section 1.5 for legal bases under GDPR.

International Transfers: Although Tether is operated by a company registered in China, your personal information is stored and processed on Google LLC’s Firebase servers located in the United States, the European Union, and other regions. Tether does not store your personal information in mainland China. For transfers from the EEA to countries not deemed adequate by the European Commission, we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms.

Data Protection Authority: You have the right to lodge a complaint with your local data protection authority.

12.7 United Kingdom Notice

Data Controller: 杭州景藏网络科技有限公司 (Hangzhou Jingzang Network Technology Co., Ltd.) is the data controller for your personal information under UK GDPR.

International Transfers: Although Tether is operated by a company registered in China, your personal information is stored and processed on Google LLC’s Firebase servers located in the United States, the European Union, and other regions. Tether does not store your personal information in mainland China. For users in the United Kingdom: transfers of your personal data from the UK to the United States are conducted under the UK International Data Transfer Agreement (IDTA) or the Addendum to the EU Standard Contractual Clauses, as applicable. For users in the European Economic Area: transfers of your personal data from the EEA to the United States are conducted under the European Commission's Standard Contractual Clauses.

12.8 Switzerland Notice

Data Controller: 杭州景藏网络科技有限公司 (Hangzhou Jingzang Network Technology Co., Ltd.) is the data controller for your personal information.

International Transfers: Although Tether is operated by a company registered in China, your personal information is stored and processed on Google LLC’s Firebase servers located in the United States, the European Union, and other regions. Tether does not store your personal information in mainland China.

12.9 Brazil Notice

Data Protection Officer: Contact dpo@tetherfamily.com for LGPD inquiries.

International Transfers: Although Tether is operated by a company registered in China, your personal information is stored and processed on Google LLC’s Firebase servers located in the United States, the European Union, and other regions. Tether does not store your personal information in mainland China.

National Data Protection Authority (ANPD): You may file complaints with the ANPD.

12.10 Australia Notice

Privacy Officer: Contact privacy@tetherfamily.com for Privacy Act inquiries.

International Transfers: Although Tether is operated by a company registered in China, your personal information is stored and processed on Google LLC’s Firebase servers located in the United States, the European Union, and other regions. Tether does not store your personal information in mainland China.

OAIC: You may contact the Office of the Australian Information Commissioner if unsatisfied with our response.

12.11 China Notice

The service is not available in mainland China and is not directed at residents of mainland China.

App Screen Cta Image

Your family already misses you. Let them know you're okay.

Download now! Subscription starts at $8.99/m.

Google Play ButtonApp Store Button