Legal
Privacy Policy
1. Who we are
Tendi is operated by [LEGAL ENTITY] ("we"). For privacy questions contact hello@tendi.cc. [DATA PROTECTION OFFICER / EU REPRESENTATIVE if applicable.]
2. Our principle: least necessary data
Tendi is a monitoring and data-protection tool, so we are deliberately restrained. We do not capture passwords, we do not collect private content beyond what a policy explicitly enables, and we never secretly activate a webcam or microphone. Monitoring is intended to be transparent to the people affected.
3. Data we process
- Account data: username, email (required, for account recovery), hashed password, plan, and — if you enable it — a Google account identifier. Needed to operate the Service; this cannot be end-to-end encrypted.
- Device inventory: device name, label, group, operating system, online status, last-seen time.
- Screen content (live frames and log snapshots): images captured by the agent on devices you manage. This is your content. If you enable end-to-end encryption, this content is encrypted on your devices and only you can decrypt it — we and our infrastructure provider cannot read it.
- Control policies: blocked apps/sites/keywords and schedules you configure.
- Operational logs: security and audit events (who did what, when, on which device, result).
4. How we use data
To provide and secure the Service, operate your account, apply the policies you configure, prevent abuse and brute-force attacks, send transactional email (e.g. password reset), and meet legal obligations. We do not sell your data.
5. Role of the account owner (controller)
When you use Tendi to manage other people's devices (employees, children), you are the controller of that monitoring and are responsible for having a lawful basis, informing users, and honoring their rights. We act as a processor for that content on your behalf.
6. Where data is stored
On Cloudflare infrastructure (database and object storage), encrypted in transit via TLS. Cloudflare maintains its own security certifications (e.g. SOC 2, ISO 27001) for the underlying platform. Each account is fully isolated.
7. Retention
Log snapshots are retained for a limited window (default 30 days) and then deleted automatically. Account and device records are kept while your account is active. When you delete your account, we delete your data from our database and object storage.
8. Your rights
Depending on your location you may have rights to access, correct, delete, export or restrict processing of your personal data, and to object or withdraw consent. You can delete your account and data from the dashboard, or contact us. [GDPR/CCPA SPECIFICS, SUPERVISORY AUTHORITY.]
9. Security
We apply measures including TLS, salted password hashing (PBKDF2), signed sessions, rate-limiting and brute-force lockout, tenant isolation, optional end-to-end encryption of screen content, and audit logging. No method is perfectly secure.
10. International transfers & sub-processors
Data may be processed in regions operated by our infrastructure provider. [LIST SUB-PROCESSORS: Cloudflare (hosting), email provider, etc. + transfer safeguards such as SCCs.]
11. Children
Accounts are for adults. Monitoring a minor child in your guardianship is a supported, lawful use; you remain responsible for complying with applicable laws on children's data.
12. Changes
We may update this Policy; material changes will be notified. The "last updated" date reflects the current version.