Privacy Policy
Your folks live in your iCloud, not ours.
Tendlet (the "app", "we") is built by Q10 Labs, Belgium. This policy explains what data the app and public website handle and what we do — and don't — do with it.
The short version: your household care data lives on your device and, when iCloud is available, in your private iCloud database. Household profile and journal photos may sync through that private iCloud database. The current release has no subscription or in-app purchase. Plant scans pass through Tendlet's proxy to Pl@ntNet without proxy image retention. Only if you explicitly consent to accuracy feedback does Tendlet store a resized review photo and your answer in public iCloud for 90 days, then delete it during the next daily cleanup, normally within 24 hours.
What we don't do
- No in-app analytics SDK. The iOS app does not integrate Mixpanel, Amplitude, Google Analytics, Firebase Analytics, or a similar analytics SDK. Consented Plant Identifier answers are reviewed only to measure and improve identification accuracy. Apple MetricKit performance diagnostics require separate per-device consent.
- No advertising. No ads. No advertising identifier collected.
- No tracking. Tendlet does not track you across apps or websites.
- Limited service use. Tendlet contacts Apple CloudKit, contacts WeatherKit only after you configure local weather, and contacts Pl@ntNet through a Q10 Labs Cloudflare Worker only when you use Plant Identifier. The separate private diagnostics service receives optional performance reports only after you enable sharing.
- No purchases. The current release offers no subscription or in-app purchase and Q10 Labs does not receive payment details.
- No account sign-up. Tendlet doesn't ask for an email address, phone number, or social login.
Public website analytics
The public Tendlet website uses Vercel Web Analytics for aggregate traffic statistics. It records page views and limited technical context such as the page path, referrer, approximate region, browser, operating system, and device type.
- It does not receive names, photos, routines, health records, meal plans, or any other data stored in the Tendlet app.
- Vercel Web Analytics does not use third-party cookies. Vercel states that its page-view data is anonymous and not tied to an individual or IP address, and that its temporary visitor hash is discarded after 24 hours.
- We use these aggregate statistics only to understand which public pages are useful and whether the website is working as expected.
Vercel describes the collected data and retention model in its Web Analytics privacy and compliance documentation.
Public beta
The current Tendlet iOS beta is distributed through Apple TestFlight.
Data Tendlet stores on your device
When you use Tendlet, the app stores the following locally on your device:
- The names, species, breed, and optional birthday of the folks (pets, plants) you add
- Optional photos you attach to journal entries or folks
- Care routines, completions, and timestamps
- Medication, weight, symptom, and document records (pets)
- Family member names (display-only, used to label "watered by Alex")
- Your selected country, palette, density, and other UI preferences
- Vet contact information you add manually
- If you enable local weather, a rounded, coarse plant-area coordinate
The coarse plant-area coordinate is device-only, can be removed in the app, and is not included in household data or CloudKit. When an iCloud account is available, Tendlet automatically syncs the remaining household data through the user's private CloudKit database so it can be restored and kept current across that user's Apple devices. Folk profile, symptom, journal, and plant-progress photos and veterinary attachments are household data and may sync through that private database.
iCloud sync (CloudKit)
When an iCloud account is available, Tendlet uses Apple's CloudKit automatically to:
- Store your data in your personal iCloud account (your private database)
- Sync that data between your own devices
- If you later invite a family member from You → Family share, share the household record with that person so their device can read and write the same data
We do not review this private or shared household data. CloudKit operates between your device and Apple's servers using your iCloud credentials.
To delete this data, sign in to iCloud → Manage Storage → Tendlet on any device and clear the app's iCloud data.
Purchases
The current release has no paid tier, subscription, or in-app purchase. Tendlet does not contact StoreKit for products or entitlement status in this release, and Q10 Labs does not receive payment details.
Plant identification and optional accuracy feedback
When you choose a plant photo, Tendlet re-encodes and resizes it before sending it through a Q10 Labs Cloudflare Worker to the Pl@ntNet recognition API.
- The proxy protects the Pl@ntNet API key and does not retain the scan image or identification response.
- To enforce the five-scan daily limit, the app sends a one-way pseudonymous account or app-install hash. The proxy keeps a second hash and the current UTC-day count until shortly after the next daily reset. When an iCloud user identifier is available, the hash lets the limit apply across that user's devices; otherwise it is based on a random app-install identifier. The proxy cannot recover the source identifier from the hash, and the counter is not used for analytics or tracking.
- Pl@ntNet states that submitted images are kept only in volatile memory during identification and are not stored in its image database. See Pl@ntNet's current terms.
- The result contains one likely common/scientific name, a confidence score, and provider version information.
After a result, Tendlet asks whether the species was correct. Sharing the answer is optional and requires explicit consent. If you agree, Tendlet stores the following in its public CloudKit database so Q10 Labs can review identification quality:
- A metadata-free JPEG limited to 1024 pixels on its longest edge
- The prediction, confidence score, yes/no answer, and optional corrected plant name
- App/provider versions, locale, consent version, and submission/expiry dates
- The pseudonymous CloudKit creator identifier assigned to the active iCloud account
Review records are not used for advertising or tracking, and app users are not given access to other people's submissions. A daily Q10 Labs Cloudflare Worker cleanup deletes expired public-CloudKit review records after 90 days, normally within 24 hours of expiry. You can revoke consent or delete submissions created by your current iCloud account from You → About → Privacy. Identification still works without iCloud, but feedback cannot be uploaded.
Optional performance diagnostics
Share performance diagnostics is off by default and applies only to this app installation. Enable it under You → About → Privacy. It is unavailable in builds without the private diagnostics service configured. Apple's MetricKit supplies periodic performance summaries and some crash or hang diagnostics; delivery is not immediate or guaranteed.
With consent, Tendlet sends allowlisted numeric speed, CPU/GPU activity, memory, disk-write, animation-hitch, crash and hang measurements; measurement dates; app and operating-system versions; device model; and code binary UUIDs and relative offsets used to find code locations. Payload versions are preserved across app upgrades. Reports never contain household content, family names, care records, emails, iCloud account IDs, photos, invite URLs, absolute memory addresses, exception messages, or file paths. No advertising or hardware identifier is requested.
A separate Q10 Labs Cloudflare Worker and private D1 database receive reports. The service assigns a random installation ID and separate upload/deletion credentials, stored only in this device's Keychain; the server stores credential hashes. It processes a daily hash of the connecting IP address for abuse quotas, clears the enrollment copy immediately, and retains the quota hash for up to two days under normal daily cleanup. It does not store the raw address in the diagnostics database. Cloudflare may independently process network information to operate and secure its infrastructure.
- Reports beginning before consent are discarded. Each report is at most 256 KiB, and the backup-excluded local queue is limited to 2 MiB. Reports expire locally after seven days and are removed when Tendlet next processes the queue.
- Active server reports expire after 30 days and are removed by daily cleanup. Deleted or expired reports may remain in D1 Time Travel backups for up to 30 additional days; backups are excluded from normal developer reporting.
- Turning sharing off, or choosing Delete this device’s performance reports, stops collection, cancels uploads, clears queued reports, and requests authenticated deletion. Offline deletion retries when Tendlet reconnects. The status shows pending deletion; only the deletion credential is retained locally until acknowledged.
- Installation credentials and consent metadata remain active while reports are being received. After 90 days without an accepted report, the server revokes the installation, including enrollments that never uploaded a report. Sharing then requires a new explicit opt-in in the app.
- Random installation IDs and hashed deletion/revocation metadata remain for 90 days after deletion or inactivity revocation to prevent late uploads or restores from recreating deleted reports. This metadata contains no report content. Backups must be reconciled with revocations before restored data can be used.
Diagnostics are used only to improve reliability and performance, are not linked to your iCloud account, and are never used for advertising or tracking across apps. Uninstalling cannot send a deletion request; use the in-app control first if you want deletion before normal expiry. Q10 Labs cannot identify a report from your name or email.
Weather (WeatherKit)
Local weather is off until you tap the Today weather surface, read Tendlet's explainer, and choose to continue. If permission is still needed, iOS then asks for it. Tendlet captures an approximate location once, rounds it to a coarse plant-area coordinate, and stores that coordinate only on your device. It does not follow your location on each refresh.
- WeatherKit requests use the saved coarse plant area to fetch current conditions and a bounded next-24-hour forecast. Apple receives that query — Q10 Labs does not.
- Apple's WeatherKit privacy practices are documented at developer.apple.com/weatherkit/data-source-attribution.
- The rounded coordinate is not part of your household, care history, or CloudKit data. You can update or remove it by tapping the weather surface in Tendlet.
- You can revoke location access at any time in iOS Settings → Tendlet → Location. The app continues to work and labels any saved weather it can no longer refresh.
- Weather checks are advisory. Frost, freeze, heat, and forecast-rain cards never change a task or care record.
- Weather data may be inaccurate. Tendlet presents it as context for care and asks you to check actual conditions.
- If you explicitly confirm that current rain met a plant's full watering need, Tendlet saves a rainfall-specific watering record and can complete a matching water task. That care record and its non-coordinate rain-event provenance sync like other household care history; the coordinate does not.
Service providers
Tendlet uses Apple (CloudKit, WeatherKit, and silent push), Cloudflare (the plant-identification proxy, review-record cleanup, and optional performance diagnostics), Pl@ntNet (plant identification), and Vercel (public website hosting and aggregate website analytics) only for the functions described above. Q10 Labs does not authorize these providers to use Tendlet data for advertising or cross-service tracking. Where a provider processes Tendlet data on our behalf, its service terms must provide privacy protection consistent with this policy and applicable law. Apple may also process service data independently under Apple's privacy policy and your Apple Account settings.
Push notifications
Tendlet schedules local notifications on your device for routine reminders. These are scheduled by UNUserNotificationCenter and never sent through our servers or any third-party push provider. We do not see when they fire or whether you acted on them.
Apple's silent-push (used by CloudKit to notify your device of remote changes) is the only push channel that touches Apple's servers, and it carries no payload we control.
Children
Tendlet is a general-audience care app and is not directed to children. We do not knowingly seek personal information from children. Plant review feedback is optional, clearly disclosed, and can be deleted from the app.
Your rights
Your private household data lives in your iCloud account:
- Access / export household data → use iOS's standard iCloud tools
- Delete household data → uninstall the app and clear its iCloud data from iCloud → Manage Storage → Tendlet
- Delete plant review feedback → You → About → Privacy → Delete my plant review submissions
- Revoke future feedback consent → You → About → Privacy → Revoke
EU residents have additional rights under GDPR. If you have a question, contact us at the address below.
Changes to this policy
If we ever change this policy (e.g. to add a feature that requires new data handling), we'll update the "Last updated" date at the top. Significant changes will also be summarised in the app's "What's new" notes for that version.
Contact
Q10 Labs
Handboogstraat 6/31
8500 Kortrijk
Belgium
+32 456 79 37 37
support@tendlet.app