Privacy

Last updated: 16 September 2026

The short version

Tending helps organisations remember, understand and share the relationships they hold. That can include personal data about people who do not themselves use Tending, so we treat the organisation's relationship data differently from ordinary account and billing data. We do not sell personal data or run advertising tracking.

Who is responsible for the data?

For the people, relationships, notes and connected-source information an organisation records in Tending, that client organisation is normally the data controller and decides why the information is being used. Tending acts as its processor and handles that data on its instructions. We are separately a controller for data we need to run our own service, such as user accounts, billing, security and support records.

Organisations using Tending are responsible for identifying an appropriate lawful basis for the personal data they record. The product includes fields for source, lawful basis, consent status where relevant, and supporting notes. A data processing agreement covering client data is available from hello@tending.network.

What we store

  • Your account — name, email address and sign-in information needed to provide access to Tending.
  • Your organisation's relationship data — connections, contact details, moments, spaces, relationship stories, stewardship, observations, quality signals and provenance information your team creates or confirms.
  • Connected-source context — if you deliberately connect services such as Google Calendar, Gmail, Slack or ClickUp, Tending may temporarily import relevant event/message context to suggest moments or connections. Suggestions remain private to the user whose source produced them until they are deliberately kept as normal organisation data. Disconnecting a source removes its imported context events.
  • Email capture — where an organisation uses a Tending capture address, the incoming email is processed to create or suggest a moment.
  • Billing — payment card details are handled by Stripe; Tending stores the identifiers needed to manage the subscription rather than card details themselves.

Where data is held and processed

  • Neon — the primary Postgres database is hosted in AWS eu-west-2 (London, United Kingdom).
  • Vercel — application hosting and request processing. Requests and operational data may be processed on Vercel infrastructure as required to deliver the service.
  • Resend — transactional email and supported email-capture flows.
  • Stripe — subscription and payment processing.
  • OpenRouter and eligible model providers — language-model processing for AI features. Tending requires OpenRouter routes marked Zero Data Retention and disallows providers marked as collecting request data. The selected underlying provider still receives the request transiently to produce its response.
  • ElevenLabs and OpenAI — voice transcription where the corresponding transcription route is used. Audio is processed to produce text; Tending does not keep the source audio after transcription.

Our subprocessor schedule records the services we use, their role and relevant data-location information. Connected services such as Google, Slack and ClickUp are also governed by the account and permissions you choose when connecting them.

AI processing

Some Tending features use language models to understand moment text, identify already-confirmed connections, synthesise a living relationship story and, where enabled by an organisation admin, suggest relationship-quality signals. AI-suggested observations are labelled as inferred rather than treated as facts.

AI relationship observations can be switched off at organisation level. When switched off, Tending does not send moment text to an AI model for quality inference. Other AI features needed for a chosen workflow may still process data as described here.

Retention and deletion

Relationship records are kept while the organisation chooses to keep them. Connected-source context is designed to be temporary and is removed when its source is disconnected. At present, permanent deletion of a whole organisation is handled by a verified email request rather than a self-service button. The deletion process and any agreed return/deletion arrangements are also documented in the data processing agreement.

Cookies and analytics

Tending uses the session information needed to keep you signed in. We do not use advertising cookies or fingerprinting, and we do not sell usage or relationship data to advertisers.

Your rights

Depending on the data and context, UK data protection law may give you rights including access, rectification, erasure, restriction, portability and objection. If your request concerns relationship data recorded by one of our client organisations, that organisation is normally best placed to respond as controller. You can also contact us at hello@tending.network.

Changes

If this policy changes in a way that materially affects how signed-in users' data is handled, we will update the date above and communicate the change through an appropriate service channel.