Privacy Policy
Tendra ("Tendra," "we," "us," or "our") is operated by Luemonora LLC. This Privacy Policy explains what information we collect, how we use and share it, and the choices you have. Tendra is a dating and community app for people affected by sexually transmitted infections (STIs) — our tagline is "Love without stigma."
By creating an account or using Tendra, you agree to this Privacy Policy. If you do not agree, do not use the app.
1. Who this applies to
Tendra is intended only for people 18 years of age or older. We do not knowingly collect information from anyone under 18.
2. Information we collect
2.1 Information you provide
- Account details: name/display name, email address, and birth year (used with your zodiac to display your age; the picker cannot select an age under 18, and you must certify you are 18+). We do not collect an exact date of birth.
- Profile information: gender, dating interests, photos (public profile photos and private album photos), bio/about text, lifestyle attributes (e.g. drinking, exercise, diet, pets), languages, interests, personality (Myers-Briggs) and zodiac, relationship and family preferences, and an optional avatar. You may also optionally add sensitive details to your profile — race/ethnicity, religion, and political views. These are voluntary; you can leave them blank or remove them at any time, and we never use them for advertising.
- Health-related information (special category / sensitive data): Tendra is a community for people affected by STIs. Information you choose to share — including your "community status," posts, comments, chatroom messages, and profile content — may reveal or imply health-related information. You provide this information voluntarily, and we process it only with your consent — where EEA/UK GDPR applies, your explicit consent (Article 9(2)(a)) — which you give by choosing to add it to your profile or posts. You can withdraw that consent at any time by editing or removing the information, using the app in avatar-only / anonymous mode, or deleting your account (Section 9); withdrawal does not affect processing that already happened. We never use your health-related information for advertising, and we share it only with the service providers in Section 8 acting on our instructions — except where we are legally required to disclose it (see Section 8).
- Messages and community content: direct (1:1) messages, community posts and comments, and chatroom messages.
- Support communications: messages you send us, including through the in-app "Tendra Team" chat.
2.2 Information collected automatically
- Location: approximate or precise GPS location (with your permission) to show nearby people and enable distance filters. You may instead set a manual city override.
- Device identifiers: a device identifier/fingerprint used for security, fraud prevention, and to enforce account bans (preventing banned users from evading bans by creating new accounts).
- Usage and diagnostic data: app activity, crash reports, and error logs.
- IP address: collected at sign-in, session refresh, and each photo upload — used for security, fraud and ban-evasion prevention, and, where legally required, for child-safety reporting (Section 8).
2.3 Purchases
When you buy a premium subscription, the purchase is processed by Apple App Store or Google Play — we do not receive your full payment card details. We receive and store purchase/receipt data (product, transaction ID, purchase and expiry dates) to validate and maintain your subscription.
3. How we use your information
- Create and operate your account and profile.
- Provide core features: discovery/matching, messaging, community feed and chatrooms.
- Process and validate subscriptions and premium features.
- Keep Tendra safe: moderate content, investigate reports, and enforce our Community Guidelines and Terms (including bans and ban-evasion prevention).
- Send service messages and push notifications (e.g. new matches, messages, likes).
- Diagnose crashes and improve the app.
- Comply with legal obligations and enforce our rights.
Legal bases (EEA/UK GDPR). Where GDPR applies, we rely on: performance of our contract with you (operating your account and the core features); your consent (marketing communications and — as explicit consent — the health-related information described in Section 2.1); our legitimate interests (safety, security, fraud and ban-evasion prevention, and service improvement); and legal obligation (e.g. accounting and responding to lawful requests). Where processing relies on consent, you can withdraw it at any time.
4. Content moderation and staff access
To keep Tendra safe, authorized Tendra staff may review content you submit — including profile information, photos (both public and private), and messages (both direct and chatroom) — when investigating reports, enforcing our Community Guidelines, providing support, or where required by law. Private photos and private messages are not visible to other users, but they are accessible to our moderation team for these purposes.
We also use automated moderation on uploaded images:
- SightEngine analyzes images and text for prohibited content (e.g. nudity, weapons, hateful or abusive language), and performs automated facial analysis to estimate whether a subject may be under 18 (age/minor detection).
- Microsoft PhotoDNA checks each image against known child-sexual-abuse-material (CSAM) hash databases using an irreversible mathematical hash of the image.
If we detect apparent CSAM, we are legally required to report it to the National Center for Missing & Exploited Children (NCMEC) CyberTipline (18 U.S.C. §2258A); see Section 8.
Biometric information — facial scan for age detection. The automated age/minor check above analyzes the geometry of faces in your uploaded photos to estimate age. In some states this facial-geometry analysis may be treated as biometric information (for example, under the Illinois Biometric Information Privacy Act), so we want to be explicit:
- What it is and why: an automated scan of facial features in your photo, performed solely to estimate whether a person may be under 18 and keep minors off Tendra.
- Who performs it: our moderation vendor, SightEngine, acting on our instructions.
- What we keep: the scan is transient. We do not store the facial-geometry data or any facial template — it is generated during the check and discarded immediately; we retain only the age determination (e.g. "likely adult"). We never sell, lease, trade, or otherwise profit from this data, and we do not disclose it except as required by law.
- Retention and destruction: because no facial-geometry data is stored, any transient biometric data is destroyed immediately upon completing the age check — and in no case retained beyond the earlier of the purpose being satisfied or three years after your last interaction with Tendra.
- Consent: before your first photo is scanned, we ask for your consent to this facial analysis. If you do not consent, you can use Tendra in avatar-only mode without uploading photos.
- Withdrawing consent: you can withdraw your consent at any time in Settings → Privacy → Photo age check. Withdrawal takes effect immediately and stops any future scan; because nothing biometric is stored, there is no retained data to delete. After withdrawing you remain avatar-only for new photos (photos already added are unaffected) until you turn the setting back on.
5. How your information is stored and protected
- Photos are stored with our cloud storage provider, Backblaze B2. Public profile photos are served via standard content-delivery URLs. Private album photos are stored in a separate storage bucket, under separate access credentials, and are served only via time-limited links that expire after about one hour. If credentials for our public photo storage were compromised, private album photos would remain protected by a separate credential set.
- Access to a user's private album is granted only through an in-app request that the owner controls.
- We use technical and organizational measures to protect your information. However, no method of transmission or storage is completely secure, and photos and messages are not end-to-end encrypted — they are stored on our systems and, as described in Section 4, are accessible to authorized staff for safety and support.
6. Advertising and tracking
Tendra does not show ads. We do not use advertising networks, we do not use your advertising identifier (iOS IDFA / Android Advertising ID), and we do not track you across other apps or websites for advertising. We do not sell or share your personal information for cross-context behavioral advertising.
7. Marketing communications
We send marketing messages (offers, feature announcements) by email or push notification only if you opt in — the marketing checkbox at signup is unticked by default, and we record when you give consent. You can withdraw at any time in Settings → Marketing & offers (turn off email or push individually, or use "Unsubscribe from all marketing"), and every marketing email we send will include an unsubscribe link. Opting out of marketing does not affect service messages we must send to operate Tendra (e.g. sign-in links, purchase confirmations, safety notices). Non-essential push notification categories (likes & matches, messages, community) can be controlled separately in Settings → Notifications.
8. Third parties we share information with
We do not sell your personal information, and we do not share it for advertising. We share information only with the service providers that process it on our behalf:
| Provider | Purpose | Data involved |
|---|---|---|
| DigitalOcean | Cloud infrastructure — hosts our application servers and database | All account data stored in our database (profile, activity, messages) |
| Apple App Store / Google Play | In-app purchases & receipt validation | Purchase/receipt data |
| Apple / Google | Sign-in (OAuth) | Authentication identifiers, email |
| Backblaze B2 | Photo storage | Profile and private photos |
| SightEngine | Automated image/text moderation & age/minor detection | Uploaded images and text |
| Microsoft (PhotoDNA) | Known-CSAM hash matching | Irreversible image hash only (not the image) |
| OneSignal | Push notifications | Push token, device info |
| Brevo (Sendinblue) | Transactional email (e.g. magic sign-in links) | Email address |
| Sentry | Crash and error reporting | Diagnostic/crash data, device info |
| Firebase (Google) | App infrastructure | Device/app identifiers |
We may also disclose information to comply with law, enforce our Terms, or protect the rights, safety, and property of Tendra, our users, or others; and in connection with a merger, acquisition, or sale of assets. In particular, if we detect apparent child sexual abuse material, we are legally required to report it — including the image and related account information (such as email, display name, profile/bio content, and IP addresses) — to the National Center for Missing & Exploited Children (NCMEC) under 18 U.S.C. §2258A.
9. Data retention and deletion
We retain your information for as long as your account is active or as needed to provide the service. You can delete your account at any time in Settings → Delete Account. When you delete your account, we permanently delete your account, profile, and messages, and photos are fully removed from our cloud storage within 24 hours. We may retain limited information where required for legal, security, fraud-prevention (including ban-evasion records), or accounting purposes.
Typical retention periods:
- Account, profile, photos, messages, community content: kept while your account is active; deleted when you delete your account (photos removed from cloud storage within 24 hours).
- Magic sign-in links: expire after 15 minutes.
- Purchase/subscription records: kept while your subscription is active, then as required for tax, accounting, and dispute purposes.
- Moderation, enforcement, and ban-evasion records (including device identifiers of banned accounts): kept as long as necessary to keep bans effective and Tendra safe.
- Crash and diagnostic data: retained by our crash-reporting provider for approximately 90 days.
- Server logs: retained for a limited period and routinely rotated.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. Residents of the EEA/UK (GDPR) and California (CCPA/CPRA) have specific rights, including the right not to be discriminated against for exercising them. To exercise any right, contact us at privacy@tendra.date. Many actions (profile edits, account deletion) can be done directly in the app.
11. International transfers
Your information may be processed in countries other than where you live, including the United States. Where required, we use appropriate safeguards for such transfers.
12. Children
Tendra is for adults 18+. We do not knowingly collect data from minors. If you believe a minor has provided us information, contact childsafety@luemonora.com and we will delete it.
13. Changes to this policy
We may update this Privacy Policy. We will post the updated version with a new "Last updated" date and, where appropriate, notify you in the app.
14. Contact us
Luemonora LLC
Privacy: privacy@tendra.date
Support: support@tendra.date
7901 4th St N #17350
St. Petersburg, FL 33702, USA