Legal

Privacy

What Tend measures about your Mac stays on your Mac. We collect the minimum we need to keep the app updated, run accounts and licenses, and email you when you've asked us to.

Last updated 11 October 2026 · Read the short version

Who we are

Tend is made by Mohamed Elsawy, an independent developer based in the United Arab Emirates (“we”, “us”). We decide how and why the personal data described here is used, which makes us its controller. When Tend's company is registered, we'll name it here. Contact us at support@tendmac.app.

What stays on your Mac

Battery readings, energy use per app, temperatures, fan speeds, disk scans, startup items and update lists are measured and kept on your Mac. They're never uploaded. Tend stores, in your Library folder:

  • a battery log for the Battery Coach (charge level, power source, charging state and battery temperature every few minutes), kept for 60 days;
  • per-app energy history, by the hour, kept for 30 days;
  • a daily battery health record (health, cycle count and capacity), kept until you delete it;
  • your settings.

Delete the history any time in Tend › Settings › Your data › Delete local history. If you use Pro or sign in, your license key, license token and sign-in session are kept in your Mac's keychain.

Tend contains no analytics, advertising or tracking code.

What the app sends to us

  • Update checks. About once a day, Tend asks tendmac.app whether a new version exists. The request includes the app's name and version.
  • Beta and sales status. Tend checks every few hours whether the public beta is still running. This request carries no identifiers.
  • License checks, if you use Pro: your license key and a device ID. The device ID is a one-way hash of your Mac's hardware identifier, so we never receive the identifier itself, but it is linked to your license, which makes it pseudonymous personal data rather than anonymous. We use it to enforce the 3-Mac limit.
  • Sign-in and your Macs, if you have an account: the details you sign in with (below), plus the device ID, your Mac's name (as set in System Settings) and its model identifier, so you can recognize and remove your Macs on your account page. We record when each Mac was added and last checked in.
  • Founding list sign-ups from the app: your email address.
  • Feedback you choose to send, such as an email to support, contains what you include. Tend's Send feedback and crash report buttons only open an email in your mail app, so you read it before anything is sent. If you switch on Include diagnostics, the email adds Tend's and macOS's versions and your Mac's model. A crash summary adds the same versions and technical details of where Tend crashed, without file paths, error messages or your name.

Like any internet request, these reach our servers with your IP address. See Security and abuse prevention.

Accounts

Accounts are optional. If you create one, we store:

  • your email address and whether it's verified;
  • your name, if you give it or your sign-in provider shares it;
  • if you use Sign in with Apple or Google, the account identifier that service gives us (with Apple, your email may be a private relay address);
  • your sign-in sessions: we keep only a one-way hash of each session token, when it was created and when it was last used;
  • the licenses and Macs linked to your account.

Email sign-in codes and sign-in requests expire after 10 minutes and are deleted within two days. Sessions expire 30 days after you last use them and at the latest 180 days after you signed in, or earlier when you sign out, sign out everywhere else, or remove the Mac they're on from your account page.

When you sign in on tendmac.app, api.tendmac.app sets one cookie, tend_session, that keeps you signed in. It's strictly necessary for the account page to work, so we don't ask for consent; it's not used for anything else. It lasts up to 30 days and is removed when you sign out. If you sign in with Apple or Google, a second strictly necessary cookie, tend_oauth_state, ties the sign-in to your browser. It lasts 10 minutes and is removed when the sign-in finishes.

The website

tendmac.app uses no analytics, advertising or tracking cookies, and loads no third-party scripts. Fonts are served from our own domain. We count a few things per day, such as downloads, sign-ups and purchases, as totals only: these counts contain no IP addresses, device IDs or other identifiers.

The founding list and email

If you join the founding list, we store your email address, where you signed up (the website or the app), when you joined and when you confirmed. We send one email asking you to confirm; you're only added once you click the link (double opt-in). If you don't confirm, we don't email you again unless you sign up again, and we delete your address 30 days after we sent the confirmation email. If the confirmation email can't be sent, we don't keep your address. If you join again with an address that's already confirmed, we send a short note saying so, at most once a day.

We use the list to send you one email when Tend launches, with your founding price. We won't email the list about anything else unless you agree to it first. The launch email has an unsubscribe link, and you can withdraw your consent at any time by emailing us. When you unsubscribe from our emails, we delete your founding-list entry. We delete the whole founding list 12 months after launch.

We also send emails you need: sign-in codes, the confirmation email, a welcome email when you create an account, your license details when you buy, and a reminder before a free trial ends. These don't need consent because you asked for them.

We send email through Brevo. To do that, Brevo holds your email address, which of our lists you're on (founding list, account holders or customers), and a few events: when you created an account, started a free trial (the plan and when the trial ends), bought (the plan) or cancelled (the plan and when it ends), so the right emails reach the right people. Brevo also records whether our emails are delivered, and may record whether they're opened and which links are clicked. We use that only to make sure emails arrive and to stop sending to addresses that bounce.

Payments

Purchases are handled by Paddle (Paddle.com Market Ltd), our reseller and merchant of record, under Paddle's privacy policy. Paddle is responsible for the payment and tax data it collects. Checkout runs on Paddle's system, embedded in a page on api.tendmac.app.

From Paddle we receive what we need to issue and manage your license: your email address, Paddle's customer and subscription IDs, your plan, its status and its renewal dates. If Paddle's notification doesn't include your email, we look it up with Paddle. If you don't have a Tend account with that email, we create a basic one so your purchase can follow you when you sign in. We never see your card details.

Emailing us

Mail to support@tendmac.app is forwarded by Cloudflare Email Routing to our inbox, which is hosted by Google (Gmail). We keep support conversations only as long as we need them to help you, and delete them within two years.

Security and abuse prevention

Our website and servers run on Cloudflare, which processes IP addresses to deliver pages and protect them from attacks. Our server uses IP addresses and email addresses briefly to limit how often sign-in codes, sign-ups and license requests can be sent; these limits aren't stored with your account. Cloudflare may keep request logs, including IP addresses, for a short time for security and debugging.

Where data protection laws such as the GDPR or UK GDPR apply, we rely on these legal bases:

PurposeDataLegal basisHow long we keep it
Your account and sign-inEmail, name, sign-in identifiers, sessionsContract: providing the account you asked forUntil you delete your account; sessions 30 days after last use, 180 days at most
Licenses and your MacsLicense key, plan and status, Paddle IDs, device IDs, Mac names and modelsContractLicenses for as long as billing and tax rules require; Macs until you remove them. If you delete your account, licenses are kept unlinked from you; their Macs keep their device IDs (so the 3-Mac limit still holds) but not their names or models
Founding list and the launch emailEmail, sign-up source and datesConsent, which you can withdraw at any timeUntil you unsubscribe or ask us to delete it, and no longer than 12 months after launch
Emails you need (codes, license details, trial reminders)Email, name, planContractAs long as you have an account
SupportWhat you send usLegitimate interests: helping youAs long as needed, at most two years
Security and abuse preventionIP addresses, request detailsLegitimate interests: keeping Tend safe and availableBriefly; Cloudflare's short log retention
Daily totalsCounts only, no personal dataNot personal dataIndefinitely

Who helps us run Tend

We share personal data only with the services that help us run Tend, and only what each needs. We don't sell personal data or share it for advertising.

ServiceWhat it does for usWhere
Cloudflare, Inc.Hosts the website, the license and account server and its database; routes support emailUnited States and Cloudflare's global network
Paddle.com Market LtdCheckout, payments, tax, invoices and subscription billing, as merchant of record and a separate controllerUnited Kingdom
Brevo (Sendinblue SAS)Sends our emails and stores our email contactsEuropean Union (France)
AppleSign in with Apple, only if you choose itUnited States and Ireland
GoogleSign in with Google, only if you choose it; Gmail hosts our support inboxUnited States

Apple and Google also handle your sign-in under their own privacy policies, as they do whenever you use your Apple Account or Google Account. We may also disclose data if the law requires it.

International transfers

We're based outside the European Economic Area and the UK, and some of the services above process data in other countries, including the United States. Where personal data from the EEA or UK goes to a country without an adequacy decision, the service uses recognized safeguards, such as the European Commission's Standard Contractual Clauses or the EU-US Data Privacy Framework. Ask us for details.

Your rights

Depending on where you live, you can ask us to:

  • tell you what we hold about you and give you a copy, including in a portable format;
  • correct it;
  • delete it (you can delete your account yourself on your account page);
  • restrict or object to how we use it;
  • stop emailing you, by withdrawing consent at any time. Withdrawing doesn't affect what we did before.

Email support@tendmac.app. We'll respond within one month, and may ask you to confirm the request comes from your email address.

You also have the right to complain to a data protection authority, for example the authority in the EU country where you live or work, or the Information Commissioner's Office in the UK. We'd appreciate the chance to put things right first.

Deleting your account

When you delete your account, we delete your account record, your sign-in links and sessions, your founding-list entry and your contact at Brevo straight away. If we can't reach Brevo, nothing is deleted and you can try again, so your contact is never left behind. Your licenses stay in our records for billing and tax, unlinked from your account. The Macs registered to them keep only their device IDs, so the 3-Mac limit still holds; their names and models are erased. To remove the device IDs too, remove the Macs on your account page before you delete it, or email us and we'll do it. Paddle keeps its own purchase records under its policy.

If you only ever signed in with Apple or Google using an address they don't host (for example a work address on an Apple ID), we haven't confirmed the address is yours, so deleting the account doesn't touch what belongs to that address: its founding-list entry and its contact at Brevo. Sign in once with an email code first, or email us, to have those deleted too.

Children

Tend isn't directed at children under 16, and we don't knowingly collect their data. If you think a child has given us personal data, email us and we'll delete it.

How we protect data

Everything travels over HTTPS. We store sign-in session tokens only as one-way hashes, sign licenses so they can't be forged, keep server access limited to us, and collect as little as we can in the first place.

Changes

If we change this policy, we'll update the date above. For significant changes we'll tell you in the app or by email before they take effect.