Tilde
Privacy Policy
This Privacy Policy describes how Tilde collects, uses, discloses, retains, and protects information when you use the Tilde applications, website, and related services.
1. Scope
This policy explains how [LEGAL ENTITY NAME] (“Tilde,” “we,” “us,” or “our”) handles information through the Tilde apps, tildeapp.ai, and related services. It does not cover third-party websites or services that you reach independently.
Tilde is currently offered in English through United States app stores. If we materially change how covered information is handled, we will update the version and effective date and request renewed agreement in the app when appropriate.
2. What stays on your device
The downloaded AI model, ordinary model inference, readable chat history, memories, and the keys used to protect synced records are designed to remain on your trusted devices. Tilde does not upload ordinary conversations merely because you chat with the local model.
Local by default does not mean never networked. Information leaves your device when you choose an online capability, encrypted sync, account action, purchase, support request, or feedback submission. The sections below describe those boundaries.
3. Information we handle
Account and trusted-device information
When you create an account, we handle your email address, authentication state, account identifier, and the device registration and cryptographic metadata needed to recognize trusted devices and recover or sync your account. Authentication email is delivered by our email provider.
Encrypted cloud sync
If you use Cloud Sync, Tilde encrypts conversation records on a trusted device before uploading them. Our cloud stores ciphertext plus the routing, version, timestamp, and device metadata needed to synchronize it. The decryption keys remain with your trusted devices. No security system is perfect, and this architecture does not prevent someone with access to an unlocked trusted device from reading its local content.
Subscription and usage information
Apple or Google processes your payment credentials. Tilde and RevenueCat receive purchase and entitlement information such as product, trial or paid status, renewal state, billing period, expiration, and storefront-provided transaction identifiers. We also maintain the Search and Cloud Review counts needed to enforce allowances and show your next reset time.
Feedback and support
If you contact us or send feedback, we handle what you submit, your reply address if provided, and basic app, operating-system, device, model, and settings metadata. Tilde only attaches a conversation or response trace when the feedback interface tells you and you choose to include it. Feedback may be routed to our issue-management provider so we can investigate and respond.
Network and security information
Our hosting and security providers may process network information such as IP address, request time, app version, and integrity or attestation data when your device connects. We use this information to authenticate requests, prevent replay and abuse, diagnose outages, and protect the service.
4. User-requested cloud features
Online capabilities run only when you explicitly invoke them in Tilde. The app identifies the information needed for that request and sends it through Tilde’s service boundary.
- Web Search and current information: the focused query or structured request is sent through Tilde’s proxy to the applicable search or information provider. The provider does not receive your Tilde account identifier, device identifier, or full conversation from Tilde, although it necessarily receives the request content and Tilde’s server connection.
- Cloud Review: the selected request, Tilde’s local answer, and the minimum review context are sent to OpenAI to produce the independent review you asked for. This does not happen for ordinary local answers.
The results return to your device. We use metering records and content-free operational events to provide the feature, prevent abuse, and understand reliability; those records do not contain the text of your query, answer, or review.
5. Analytics and diagnostics
Content-free product analytics and diagnostics are enabled when you use Tilde. They help us answer questions such as which entry point opened a paywall, whether an operation succeeded, how much of a Plus allowance is used, and where the app encounters an error.
Before you sign in, PostHog assigns the installation a random, device-scoped identifier. If you sign in, Tilde identifies subsequent analytics with your Supabase account UUID and PostHog associates the earlier anonymous activity with that account journey. Tilde uses the same account UUID as RevenueCat’s App User ID so subscription access can follow your Tilde account across devices. Signing out resets PostHog to a new anonymous identifier.
The account UUID is used only as the external system’s identifier. We do not attach it as an ordinary event property or send your email address, name, chat text, memory content, search query, Cloud Review content, payment credentials, or store transaction identifier to PostHog. Tilde does not send your email address or name to RevenueCat. Automatic screen capture, session replay, and broad interaction autocapture are disabled.
Analytics and diagnostics are not optional within the current service. We disclose this collection in this Policy and in the applicable app-store privacy disclosures. You may stop this collection by discontinuing use of Tilde and uninstalling the app.
6. How we use and disclose information
We use covered information to:
- provide local AI, accounts, trusted devices, encrypted sync, and requested cloud features;
- authenticate users, protect the service, and prevent fraud or abuse;
- process and restore subscription entitlements and enforce usage allowances;
- send authentication and support email;
- measure reliability and product performance without collecting user content; and
- comply with law and enforce our Terms.
We disclose information to service providers only for those purposes. Current categories include Supabase for authentication and hosted data services; RevenueCat and Apple or Google for subscriptions; Resend for email; PostHog for product analytics and diagnostics; OpenAI for user-requested Cloud Reviews; Brave, Bright Data, Open-Meteo, and ESPN for user-requested web or current-information results; and Linear for feedback and support issue handling. Providers process information under their own terms and our applicable agreements.
We may also disclose information when required by law, to protect users or the service, or as part of a corporate transaction subject to appropriate protections. We do not sell personal information or share it for cross-context behavioral advertising, and Tilde does not serve targeted advertising.
7. Retention and security
Local content remains on your device until you remove it, remove the app, or use an applicable deletion control. Account, encrypted sync, entitlement, usage, legal-acceptance, support, and security records are kept for as long as needed to provide the service, maintain accurate billing and allowances, comply with law, resolve disputes, and prevent abuse. Backup and audit copies may persist for a limited period after deletion.
We use encryption in transit, device-side encryption for synced conversation content, access controls, request attestation where supported, and limited service credentials. No method of storage or transmission can guarantee absolute security.
8. Your choices and rights
- Use Tilde without an account for supported local features.
- Choose whether to create an account and use encrypted Cloud Sync.
- Invoke Web Search or Cloud Review only when you want that request sent to the cloud.
- Manage or cancel a subscription through Apple or Google.
- Request access, correction, or deletion by emailing hello@tildeapp.ai.
Draft release dependency: the final policy will link the in-app and web account-deletion controls required for launch. Deleting a Tilde account does not itself cancel a store subscription; the deletion flow will direct you to the applicable store’s subscription-management controls.
Depending on where you live and applicable law, you may have additional rights to know, access, correct, delete, or limit the use of personal information and to appeal a denied request. We will verify requests as appropriate and will not discriminate against you for exercising a legal right. Because Tilde does not sell personal information or share it for cross-context behavioral advertising, there is no sale or advertising share to opt out of.
9. Children
Tilde is not directed to children under [MINIMUM AGE], and we do not knowingly collect personal information from children below that age. If you believe a child provided personal information contrary to this policy, contact us so we can investigate and take appropriate action.
10. Changes and contact
We may update this policy as Tilde changes. We will post the revised policy, update its version and effective date, and provide additional notice or request renewed agreement when required.
Questions or privacy requests can be sent tohello@tildeapp.ai or mailed to:
[LEGAL ENTITY NAME]
[BUSINESS MAILING ADDRESS]