Tiewell Privacy Policy

Your account · EU-hosted · never sold, never used to train models

Effective: July 2026 · Last updated: 20 September 2026

An account is required

Tiewell is built around your account. You sign in with Sign in with Apple, with Google, or with a one-time code emailed to you, and everything you keep in the app belongs to that account. There is no anonymous mode: the app's purpose is to keep one set of records in step across your iPhone and the Tiewell web app, and that needs an account to belong to.

If more than one person signs in on the same iPhone, each account sees only its own records.

What we store, and where

The records you create: the people you add (names, and any phone number, email address, LinkedIn handle, location, birthday or photo you choose to enter), the keywords and notes you write about them, how often you want to be in touch, the touches and activities you log with their dates and notes, and the groups, places and photos you attach.

These are kept in two places: on your iPhone, so the app works without a connection, and in your private account on our backend (Supabase, hosted in the European Union) so your other device can read them. Data travels over TLS, and database access rules mean only your own account can read your rows. Your content is never used to build a profile of you, never used to train AI models, and never sold or shared with advertisers.

When you sign out, your records stop being shown and stay cached on the device for your next sign-in. They are removed when you delete your account or delete the app.

What signing in tells us

MethodWhat we receive
Sign in with AppleThe email address Apple passes on — which may be Apple's private Hide My Email relay address — and a name if you choose to share one.
GoogleYour email address and basic profile (name and profile picture) from Google, used only to create and recognise your account. Tiewell asks for no access to Gmail, Google Drive or your Google Contacts.
Email codeThe email address you type, used to send the one-time code and to recognise your account.

Contacts and photos are on your terms

If you tap Import from Contacts, Tiewell reads your address book on the device only to show you a list to choose from. Nothing is read in the background, and only the people you tick are copied into the app. If you attach a photo to a person, group, place or activity, it is stored with that record and synced to your account like any other record. You can withdraw either permission at any time in iOS Settings, and the app keeps working without them.

Reminders stay on your device

The optional morning reminder is scheduled by iOS on your iPhone. We do not send push notifications and nothing about who is due to hear from you leaves the device to produce them.

Crash reports (diagnostics)

When the app hits an error, Tiewell sends a crash report to PostHog on EU-based servers so the problem can be found and fixed. A report contains the error type and message, the technical stack trace, the app version, your iOS version and which app update was running. It contains no names, notes, photos or anything else you enter, and it is not linked to your account or your email — it carries only a random identifier generated on the device.

Crash reports are not part of the analytics choice below, because an app that crashes without telling anyone cannot be repaired. Our legal basis is legitimate interest in keeping the app working (GDPR Article 6(1)(f)). You may object at any time using the contact address below. Crash reports are retained for up to 12 months.

Product analytics (opt-in, off unless you say yes)

If — and only if — you tap Allow analytics on the welcome screen, Tiewell sends product-usage events to PostHog on EU-based servers: which screens you open and which actions you take, such as "a person was added", "a touch was logged" or "the sign-in failed", together with counts like how many people are in your account.

These events carry no names, notes, photos, email addresses or any other content you enter — only the fact that an action happened. They are tied to a pseudonymous identifier derived from your account id (a one-way code, not your email), so we can see where people get stuck, for example how many sign-ins fail or how far into setup someone gets before stopping.

You can decline at first launch and turn it off at any time in Settings → Anonymous analytics, which stops all further collection. Analytics events are retained for up to 12 months and then deleted.

Tiewell Pro (purchases)

When offered, Pro is sold through Apple's in-app purchase system and we never see your payment details. To recognise a purchase across your devices we use RevenueCat, which receives an app-user identifier (your Tiewell account id), the purchase receipt Apple issues, and the device's country and app version. RevenueCat does not receive your name, email, or any content you enter. You can manage or cancel a subscription in Settings › Apple ID › Subscriptions on your iPhone, and restore purchases from the Pro screen in the app.

Inviting friends

If you share your invite code and a friend enters it, we record that your account referred theirs (two account ids and a date) so the reward can be applied. Neither of you sees the other's records, and this record is deleted with your account.

Deleting your data

Settings → Your account → Delete account & data permanently deletes the account itself along with every record and photo stored for it, on our servers and on the device — immediately, with no waiting period and without contacting us. Backups containing deleted data are cycled out within 30 days. Deleting the app alone removes the device copy but leaves the account, so use the in-app deletion if you want everything gone.

How long we keep data

Your records are kept until you delete them or delete your account. Crash reports and opt-in analytics events are kept for up to 12 months.

Who we share data with

Only the processors named here, each for the stated purpose: Supabase (EU) hosts your account and your records; Apple and Google handle the sign-in you choose and tell us only what is listed above; Apple processes purchases and RevenueCat validates them; PostHog (EU) receives crash reports and, if you allow it, analytics events. We do not sell data and we do not share it with advertisers.

Your rights (GDPR)

You can view, edit, export (Settings → Your data → Export a backup) and delete your content at any time inside the app, and delete your entire account as described above. If you are in the EU/EEA or the UK you have the right to access, rectify, erase, restrict and port your data, to object to processing carried out on the basis of legitimate interest, and to lodge a complaint with your local data-protection authority. To withdraw analytics consent, turn the switch off in Settings; to ask for previously collected events or crash reports to be deleted, contact us below.

Children

Tiewell is not directed at children under 13 and does not knowingly collect data from them.

Changes

If this policy changes we will update the date above and, where required, tell you in the app.

Contact

Questions or data requests: tiagobrbdias@gmail.com