Last Updated: 26 August, 2026
Tether ("Tether," "we," "us," or "our") is a private family infrastructure application developed by 杭州景藏网络科技有限公司 (Hangzhou Jingzang Network Technology Co., Ltd.) ("Tether"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use the Tether mobile application (the "App"), our website, and any related services (collectively, the "Service").
By creating an account or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our practices, please do not use the Service.
We are committed to transparency and to the principles of privacy by design.
We collect information you provide when you create an account, set up your profile, or use features of the Service:
| Category | Examples | Purpose |
|---|---|---|
| Account Information | Name, email address, phone number, password hash, date of birth, timezone, city | Account creation, authentication, password recovery, age verification |
| Profile Information | Display name, avatar/photo, role label, notification preferences, pulse window settings | Personalising your experience, family visibility |
| Family Information | Family name, member relationships, invite codes, join requests | Creating and managing your family group |
| Stream Events | Event titles, event details, photos/images, reactions, timestamps | Family communication and memory keeping |
| Daily Check-ins (Pulses) | Mood rating (1-5), notes, photos, date | Family presence signalling and daily connection |
| Emergency Alerts (SOS) | Triggered by, contact information, alert status, timestamps | Emergency family notification |
| Travel & Presence Data | Country codes, entry/exit dates, source (manual or stream event), visa records, tax residency profiles | Visa expiry reminders, tax residency tracking, travel pattern awareness |
| Subscription Information | Tether+ subscription status, trial status, purchase history | Billing, feature access, customer support |
When you use the Service, we automatically collect certain technical information:
| Category | Examples | Purpose |
|---|---|---|
| Device Information | Device model, operating system version, unique device identifiers, mobile network information | App functionality, troubleshooting, security |
| Usage Data | Features used, screens visited, actions taken, crash logs, performance data | Improving the Service, analytics, bug fixes |
| Push Notification Tokens | Expo push tokens, FCM tokens | Sending push notifications |
| Location Data | Country-level location only (derived from IP address or manual entry) | Travel features, compliance with local laws |
| Authentication Data | Firebase authentication tokens, session identifiers | Secure sign-in, session management |
| Security Logs | Failed login attempts, rate limit triggers, IP addresses | Fraud prevention, security monitoring |
We may recieve information about you from third parties:
| Source | Information Received | Purpose |
|---|---|---|
| Google Sign-In | Email address, name, profile photo (if authorised) | Account creation and authentication |
| Sign in with Apple | Email address, name | Account creation and authentication |
| RevenueCat | Subscription status, purchase receipts, trial status | Billing and subscription management |
| Apple App Store / Google Play | Purchase validation, app installation data | Payment processing, app analytics |
| Expo | Push notification delivery status | Notification delivery optimisation | SendGrid | Email delivery status | Email delivery optimisation |
| Aptabase | Analytics identifiers, app usage events, crash logs, and performance data | Product analytics and service improvement |
We use the collected information for the following purposes:
Core Service Provision
- Create and manage your account
- Enable family creation and member management
- Facilitate family communication through streams and pulses
- Provide emergency SOS alerts
- Provide travel history, visas, and tax residency status
- Deliver push notifications and reminders
- Deliver invite emails
Safety and Security
- Verify your identity and prevent fraud
- Enforce rate limits and prevent abuse
- Monitor for security incidents and unauthorised access
- Respond to emergency situations
Service Improvements
- Analyse usage patterns to improve features
- Fix bugs and optimise performance
- Develop new features based on user needs
Legal and Compliance
- Comply with legal obligations
- Respond to lawful requests from authorities
- Protect our rights and property
- Enforce our Terms of Use
Communications
- Send transactional emails (welcome, password reset, receipts)
- Provide customer support
- Send product updates and announcements (with your consent where required)
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal bases:
- Contract Performance: Processing necessary to provide the Service you requested (account creation, family features, subscription billing).
- Legitimate Interests: Processing for security, fraud prevention, analytics, and service improvement, where these interests are not overridden by your rights.
- Consent: Processing for optional features, marketing communications, or where required by law. You may withdraw consent at any time.
- Legal Obligation: Processing to comply with applicable laws, regulations, or legal processes.
- Vital Interests: Processing to protect someone's life or physical safety (e.g., SOS emergency alerts).
We engage trusted third-party companies to perform services on our behalf. These service providers are contractually obligated to protect your data and use it only as directed by us. Our current subprocessors include:
| Subprocessor | Service Provided | Data Shared | Location |
|---|---|---|---|
| Google LLC (Google Cloud / Firebase) | Authentication, database, cloud functions, analytics, storage | Account data, authentication tokens, usage data, photos, app content | United States, European Union, and other Google Cloud regions (excluding mainland China) |
| RevenueCat | Subscription management and billing | User ID, subscription status, purchase receipts | United States |
| Expo | Push notification infrastructure | Push tokens, device identifiers | United States |
| Apple Inc. | App Store distribution, payment processing, and Sign in with Apple | App installation data, authentication data, purchase validation | Global | Google LLC | Google Play distribution and Google Sign-In | App installation data, authentication data | Global |
| Aptabase | Analytics and crash reporting | Aggregated usage events, device identifiers, crash logs, performance data | European Union |
We may disclose your personal information if required to do so by law or in the good faith belief that such action is necessary to:
- Comply with a legal obligation, court order, or legal process served on us
- Protect and defend our rights or property
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of users or the public
- Protect against legal liabilityWe will notify you of legal requests where permitted by law and where we believe the request affects your rights.
If we are involved in a merger, acquisition, asset sale, bankruptcy, or other business transition, your personal information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Service of any change in ownership or uses of your personal information.
We may share your personal information with third parties when we have your explicit consent to do so.
We may share aggregated, anonymised, or de-identified information that cannot reasonably be used to identify you for research, analytics, or business purposes. For example, we may publish statistics about total users or feature adoption without revealing individual identities.
Tether is a mobile application and does not use browser cookies in the traditional sense. Instead, we use similar technologies, including mobile identifiers, local storage, and analytics SDKs.
| Technology | Purpose | Duration |
|---|---|---|
| Aptabase Analytics | Understanding app usage, crashes, and performance | Session-based and persistent |
| Local Storage / AsyncStorage | Storing app preferences, cache, and offline data | Until you clear app data or uninstall |
| Push Notification Tokens | Delivering push notifications to your device | Until you disable notifications or uninstall |
| Firebase Authentication Tokens | Keeping you signed in securely | 1 hour (access tokens) or until sign-out (refresh tokens) |
You can control or reset these identifiers through your device settings:
- App Settings: You can disable notifications in the app settings or your device settings
Please note that disabling certain identifiers may affect app functionality, such as push notifications or personalised features.
Your personal information is stored on secure servers provided by Firebase. Data may be stored in data centres located in the United States, the European Union, or other regions where Google Cloud operates. Tether does not store your personal information in mainland China.
We use industry-standard encryption for data in transit and at rest.
We retain your personal information only for as long as necessary to provide the Service and fulfil the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
| Data Type | Retention Period |
|---|---|
| Account and Profile Data | As long as your account is active, plus 30 days after account deletion for recovery purposes |
| Family and Stream Data | As long as the family exists and you are a member, or until you delete specific content |
| Pulse Records | Retained as part of your family history until you delete them or delete your account |
| SOS Alert Records | Retained for safety and legal compliance purposes, typically 2 years |
| Travel, Visa and Tax Data | Retained while your account is active; deleted immediately upon account deletion |
| Subscription Records | Retained as required by tax and accounting laws, typically 7 years |
| Security and Audit Logs | Retained for 1 year for security monitoring and incident response |
| Push Notification Tokens | Deleted immediately when you disable notifications or delete your account |
Deactivate Function: Tether offers a deactivate feature that allows you to temporarily disable your account without permanently deleting your data. When you deactivate:
- Your profile becomes invisible to family members
- You stop receiving notifications
- Your data is retained for 30 days in case you wish to reactivate
- After 30 days, your data is permanently deleted unless legally required to retain it
Account Deletion: You can permanently delete your account at any time through the app settings. When you delete your account:
- We immediately begin the deletion process
- Personal data is removed from active systems within 30 days
- Data in backups is removed within 90 days
- Some information may be retained in anonymised form for analytics
- Legal holds may delay deletion if required by law
Family Creator Deletion: If you are a family creator, deleting your account will trigger the family deletion process, which includes a transfer protocol before you can delete your account.
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of your personal information
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal information
- Portability: Request a copy of your data in a machine-readable format
- Withdraw Consent: Withdraw consent for optional processing at any time
- Object: Object to processing based on legitimate interests
If you are a California resident, you have the right to:
- Know: Request disclosure of the categories and specific pieces of personal information we have collected, the sources, the purposes, and the third parties with whom we share it
- Delete: Request deletion of your personal information, subject to certain exceptions
- Correct: Request correction of inaccurate personal information
- Opt-Out: Opt out of the sale or sharing of personal information for cross-context behavioural advertising (we do not sell your personal information)
- Limit: Limit the use and disclosure of sensitive personal information (we do not use sensitive personal information for inferring characteristics)
- Non-Discrimination: Not receive discriminatory treatment for exercising your rights
To exercise these rights, contact us at privacy@tetherfamily.com. We will verify your identity before processing requests.
If you are in the EEA, UK, or Switzerland, you have the right to:
- Access: Obtain confirmation of whether we process your data and request a copy
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Request restriction of processing in certain circumstances
- Data Portability: Receive your data in a structured, commonly used format
- Object: Object to processing based on legitimate interests or for direct marketing
- Withdraw Consent: Withdraw consent at any time without affecting the lawfulness of prior processing
- Lodge a Complaint: File a complaint with your local data protection authority
To exercise these rights, contact us at privacy@tetherfamily.com. We may need to verify your identity.
Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have similar rights to access, correct, delete, and opt out of certain processing. Please contact privacy@tetherfamily.com to exercise these rights.
If you are in Brazil, you have the right to:
- Confirmation of the existence of processing
- Access to your data
- Correction of incomplete, inaccurate, or outdated data
- Anonymisation, blocking, or deletion of unnecessary or excessive data
- Portability of data to another service provider
- Deletion of data processed with your consent
- Information about entities with which data has been shared
- Information about the possibility of denying consent and its consequences
- Revocation of consent
Contact privacy@tetherfamily.com to exercise these rights.
If you are in Australia, you have the right to:
- Access your personal information
- Request correction of your personal information
- Make a complaint about our handling of your personal information
Contact privacy@tetherfamily.com to exercise these rights. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).
To exercise any of these rights, please contact us at privacy@tetherfamily.com. We will respond to your request within 30 days, or as required by applicable law. We may need to verify your identity before processing your request.
Tether is not intended for children under the following ages:
- 13 years old in the United States and most countries (171 countries total)
- 16 years old in Australia and Vietnam
- 16 years old in Brazil (A16 rating)
- 15 years old in the Republic of Korea
We do not knowingly collect personal information from children under the applicable minimum age. If you are under the minimum age in your jurisdiction, please do not use the Service or provide any personal information to us.
The Children's Online Privacy Protection Act (COPPA) applies to children under 13. Tether does not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information as quickly as possible.
If you believe we might have any information from or about a child under 13, please contact us at safety@tetherfamily.com immediately.
Users aged 13-17 (or the applicable age in their jurisdiction) may use Tether with parental consent where required by law. We encourage parents and guardians to monitor their teens’ use of the Service and to discuss online safety.
If a family includes a child under the minimum age, that child must not create their own account. Family data about a child may be managed by the family creator or administrator, but the child cannot independently use the Service.
Tether is operated by 杭州景藏网络科技有限公司 (Hangzhou Jingzang Network Technology Co., Ltd.), a company registered in Hangzhou, China.
Your personal information is stored and processed on Google LLC’s Firebase servers located in the United States, the European Union, and other regions operated by Google Cloud Platform. Tether does not store your personal information in mainland China. When you use the Service, your personal information may be transferred to and processed in countries other than your own, which may have different data protection laws.
For transfers of personal data from the EEA, UK, or Switzerland to countries not deemed adequate by the European Commission or UK authorities, we rely on:
- Standard Contractual Clauses (SCCs): Approved by the European Commission for transfers to third countries
- Adequacy Decisions: Where the destination country has been deemed to provide adequate protection
- Your Explicit Consent: In limited circumstances, with your explicit consent
You may request a copy of the safeguards we use by contacting privacy@tetherfamily.com.
For transfers of personal data from Brazil to other countries, we comply with the requirements of the LGPD, including ensuring an adequate level of protection or using standard contractual clauses.
For transfers of personal information from Australia to overseas recipients, we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles.
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption: Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 encryption
- Authentication: Secure user authentication via Firebase Authentication, Sign in with Apple, and Google Sign-In, using industry-standard OAuth 2.0 and token-based session management
- Access Controls: Role-based access control (RBAC) at the API layer and Firestore security rules
- Rate Limiting: Protection against brute force and abuse attacks
- Input Validation: Zod schema validation on all API inputs to prevent injection attacks
- Error Handling: Sanitised error messages that do not leak stack traces or internal details
- Firestore Security Rules: Strict access controls with default deny policies
- Secret Management: No hardcoded secrets; API keys and secrets are managed server-side. Client-side SDK keys are public by design and do not grant access to user data or backend systems
No method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. You are responsible for maintaining the confidentiality of your account credentials.
In the event of a data breach that affects your personal information, we will:
- Investigate and contain the breach
- Assess the risk to individuals
- Notify affected users and relevant authorities as required by law
- Take steps to prevent future breaches
- Document the incident and our response
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by:
- Posting the updated policy in the App and on our website
- Sending an email notification to the address associated with your account
- Providing a prominent notice within the App
The "Last Updated" date at the top of this Privacy Policy indicates when it was last revised. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
We review this Privacy Policy at least every two weeks (fortnightly) to ensure it remains accurate and compliant with evolving legal requirements and our feature set.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: privacy@tetherfamily.com
If you are in the European Economic Area, the UK, Switzerland, or Brazil, you may contact our Data Protection Officer at:
Email: dpo@tetherfamily.com
For general customer support, technical issues, or account assistance, please contact:
Email: support@tetherfamily.com
杭州景藏网络科技有限公司 (Hangzhou Jingzang Network Technology Co., Ltd.) Weiye Dexin AI Industrial Park, Puyan Street, Binjiang District, Hangzhou City, Zhejiang Province.
The Service may contain links to third-party websites, services, or applications (such as Google Sign-In, Sign in with Apple, Apple App Store, or Google Play). This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services before providing them with your personal information.
You can control analytics through the in-app Analytics toggle.
We may send you marketing communications about our products and services. You can opt out of receiving marketing emails by:
- Clicking the "unsubscribe" link in any marketing email
- Contacting us at privacy@tetherfamily.com
- Adjusting your notification settings in the App
Please note that even if you opt out of marketing communications, we may still send you transactional or service-related messages (e.g., password resets, purchase receipts, safety alerts).
We do not intentionally collect sensitive personal information such as racial or ethnic origin, political opinions, religious beliefs, health data, genetic data, or biometric data for identification purposes. If you voluntarily provide such information in free-text fields (e.g., in notes or stream events), you do so at your own risk and should be aware that it may be visible to your family members.
If you have difficulty accessing this Privacy Policy due to a disability, please contact us at accessibility@tetherfamily.com, and we will provide the information in an alternative format.
This Privacy Policy is written in English. If we provide translations, the English version will prevail in case of any conflict or inconsistency.
Categories of Personal Information Collected: We collect identifiers (name, email, phone), commercial information (subscription history), internet activity (app usage), geolocation (country-level), professional information (visa status), and inferences (family relationships).
Business or Commercial Purpose for Collection: Providing the Service, security, analytics, legal compliance, and customer support.
Categories of Third Parties with Whom We Share: Service providers (Firebase, RevenueCat, Expo), app stores (Apple, Google), and legal authorities when required.
Sale of Personal Information: We do not sell your personal information.
Sharing for Cross-Context Behavioural Advertising: We do not share personal information for cross-context behavioural advertising.
Virginia residents have the right to:
- Confirm whether we process their personal data
- Access their personal data
- Correct inaccuracies
- Delete personal data
- Obtain a copy of personal data in a portable format
- Opt out of targeted advertising, sale of personal data, or profilingTo exercise these rights, contact privacy@tetherfamily.com.
Colorado residents have similar rights to access, correct, delete, and opt out of targeted advertising or sale. Contact privacy@tetherfamily.com to exercise these rights.
Connecticut residents have similar rights to access, correct, delete, and opt out of targeted advertising or sale. Contact privacy@tetherfamily.com to exercise these rights.
Utah residents have similar rights to access, delete, and opt out of targeted advertising or sale. Contact privacy@tetherfamily.com to exercise these rights.
Data Controller: 杭州景藏网络科技有限公司 (Hangzhou Jingzang Network Technology Co., Ltd.) is the data controller for your personal information.
Legal Bases: See Section 1.5 for legal bases under GDPR.
International Transfers: Although Tether is operated by a company registered in China, your personal information is stored and processed on Google LLC’s Firebase servers located in the United States, the European Union, and other regions. Tether does not store your personal information in mainland China. For transfers from the EEA to countries not deemed adequate by the European Commission, we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms.
Data Protection Authority: You have the right to lodge a complaint with your local data protection authority.
Data Controller: 杭州景藏网络科技有限公司 (Hangzhou Jingzang Network Technology Co., Ltd.) is the data controller for your personal information under UK GDPR.
International Transfers: Although Tether is operated by a company registered in China, your personal information is stored and processed on Google LLC’s Firebase servers located in the United States, the European Union, and other regions. Tether does not store your personal information in mainland China. For users in the United Kingdom: transfers of your personal data from the UK to the United States are conducted under the UK International Data Transfer Agreement (IDTA) or the Addendum to the EU Standard Contractual Clauses, as applicable. For users in the European Economic Area: transfers of your personal data from the EEA to the United States are conducted under the European Commission's Standard Contractual Clauses.
Data Controller: 杭州景藏网络科技有限公司 (Hangzhou Jingzang Network Technology Co., Ltd.) is the data controller for your personal information.
International Transfers: Although Tether is operated by a company registered in China, your personal information is stored and processed on Google LLC’s Firebase servers located in the United States, the European Union, and other regions. Tether does not store your personal information in mainland China.
Data Protection Officer: Contact dpo@tetherfamily.com for LGPD inquiries.
International Transfers: Although Tether is operated by a company registered in China, your personal information is stored and processed on Google LLC’s Firebase servers located in the United States, the European Union, and other regions. Tether does not store your personal information in mainland China.
National Data Protection Authority (ANPD): You may file complaints with the ANPD.
Privacy Officer: Contact privacy@tetherfamily.com for Privacy Act inquiries.
International Transfers: Although Tether is operated by a company registered in China, your personal information is stored and processed on Google LLC’s Firebase servers located in the United States, the European Union, and other regions. Tether does not store your personal information in mainland China.
OAIC: You may contact the Office of the Australian Information Commissioner if unsatisfied with our response.
The service is not available in mainland China and is not directed at residents of mainland China.