This Privacy Policy explains how Tide (“Tide”, “the App”, “we”, “us”, or “our”) collects, uses, shares, and protects your information when you use the Tide mobile application and related services (collectively, the “Service”).
Tide is a group expense and shared-pot (“kitty”) tracking app. It helps groups of people record shared expenses, track contributions, and see who owes what when a trip or event settles up. Tide does not process, hold, transfer, or move any money. It is a bookkeeping tool only.
By downloading, accessing, or using Tide, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.
1. Who We Are (Data Controller)
Tide is published and operated by an individual developer based in the United Kingdom, not a company. For the purposes of the UK/EU General Data Protection Regulation (GDPR) and similar laws, the data controller responsible for your personal data is:
Sudwipto Kumar Mondal
13 Trendlewood Park
BS16 1TB, Bristol
United Kingdom
Contact: sudwiptokmondal@gmail.com
If you have any questions about this Privacy Policy or your data, contact us at the email address above.
2. Information We Collect
We collect only the information needed to run the Service. We group it into the categories below.
2.1 Information You Provide Directly
- Account information. When you create an account, we collect your email address, a display name, and (if you set one) a profile avatar image and an avatar color. Your password is handled by our authentication provider (see Section 4) and is never stored or seen by Tide in plain text.
- Payment handle (optional). You may add a payment handle — for example, a username for a third-party payment service. This is free-form text you choose to enter. It is shown to other members of your groups so they can settle up with you outside of Tide. Tide does not validate, use, or connect to any payment service, and does not collect card numbers, bank account numbers, or other financial account credentials.
- Group and expense content. When you use the Service, we store the content you create, including: trip/group names, currency selection, kitty targets, member roles, expenses (title, category, amount, notes, and how a cost is split), contributions, payouts, dues, transfers, and activity history.
- Receipt images (optional). If you attach a receipt to an expense, we store the image you select. Selecting an image requires your permission to access your device's photo library.
- Communications. If you contact us for support, we collect the information you choose to share with us.
2.2 Information Collected Automatically
- Basic technical data. To operate the app and keep your session secure, limited technical information (such as device and app version data used by our authentication and backend providers) may be processed. Tide does not include any third-party advertising or analytics/tracking SDKs, and does not build advertising profiles about you.
- Local storage. We use secure on-device storage to keep you signed in (for example, session tokens). This data stays on your device.
2.3 Information From Third-Party Sign-In
If you choose to sign in with Apple or Google (Single Sign-On), we receive basic account information from that provider — typically your name and email address — as permitted by that provider and your settings with them. We do not receive your password. Please review the privacy policies of Apple and Google for how they handle your data.
2.4 Information About Other People
When you invite people to a group or record an expense involving them, you may enter information about other individuals (such as their name). You are responsible for ensuring you have the right to share that information with us for this purpose.
2.5 Device Permissions
Tide may request the following permissions. You can grant or deny them, and change them later in your device settings:
- Photo library / Media access — only when you choose to attach a receipt image or set a profile picture.
- Clipboard — used to copy or paste group invite codes when you tap the relevant buttons.
We do not access the camera, contacts, precise location, microphone, or health data.
3. How We Use Your Information
We use your information for the following purposes:
- Provide the Service — create and manage your account; store and display your groups, expenses, contributions, and balances; sync your data across sessions.
- Authenticate and secure your account — sign you in, verify your email, enable password reset, and keep your session secure.
- Enable group features — let group members see shared expenses, roles, balances, and your chosen payment handle so they can settle up outside the app.
- Support — respond to your questions and troubleshoot issues.
- Legal and safety — comply with legal obligations, enforce our terms, prevent fraud and abuse, and protect the rights and safety of users.
- Improve the Service — diagnose problems and maintain reliability.
We do not sell your personal information, and we do not use your personal information for third-party advertising.
4. Legal Bases for Processing (EEA/UK Users)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR:
- Performance of a contract — to provide the Service you request (e.g., creating your account and storing your group data).
- Legitimate interests — to keep the Service secure, prevent abuse, and maintain and improve the app, provided these interests are not overridden by your rights.
- Consent — where required, for example when you grant access to your photo library or use optional features. You may withdraw consent at any time.
- Legal obligation — where we must process data to comply with the law.
5. How We Share Your Information
We share information only as described below. We do not sell your personal information.
5.1 With Other Users
Information you add to a group is visible to the other members of that group. This includes your display name, avatar, payment handle (if set), and the expenses, contributions, and balances you create or are part of.
5.2 With Service Providers (Sub-processors)
We use trusted third-party providers to operate the Service. They process data only on our behalf and under contract:
- Clerk — authentication and account management (handles sign-up, sign-in, email verification, password reset, and secure credentials).
- Convex — backend database and file storage (stores your app data and receipt images).
These providers may process and store data in the United States or other countries. We encourage you to review their privacy practices.
5.3 For Legal Reasons
We may disclose information if required to do so by law, or if we believe in good faith that disclosure is necessary to comply with a legal obligation, protect our rights or the safety of users, or investigate fraud or security issues.
5.4 Business Transfers
If Tide is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or use of your personal data.
6. International Data Transfers
Your information may be stored and processed in countries other than your own, including the United States, where our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for international transfers.
7. Data Retention
We keep your personal information for as long as your account is active or as needed to provide the Service. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where we are required to retain it to comply with legal obligations, resolve disputes, or enforce our agreements.
Note that content you contributed to a shared group (such as an expense you recorded) may remain visible to that group after your account is deleted, in a de-identified form, so the group's records stay accurate.
8. Your Rights and Choices
Depending on where you live, you may have some or all of the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or incomplete data.
- Deletion — ask us to delete your personal data (see Section 9).
- Portability — request your data in a portable format.
- Restriction / Objection — ask us to restrict or object to certain processing.
- Withdraw consent — withdraw consent where processing is based on it.
You can exercise many of these rights directly in the app (for example, edit your profile or delete your account). For other requests, contact sudwiptokmondal@gmail.com. We will respond within the timeframe required by applicable law. You will not be discriminated against for exercising your rights.
If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
For California Residents (CCPA/CPRA)
California residents have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share your personal information as those terms are defined under the CCPA/CPRA. To exercise your rights, contact sudwiptokmondal@gmail.com.
9. How to Delete Your Data
You can request deletion of your account and associated personal data at any time:
- In the app — open Settings, scroll to the bottom, and tap Delete account. After you confirm, your account is deleted and your personal data (email, display name, avatar, and payment handle) is removed or anonymized.
- By email — send a request to sudwiptokmondal@gmail.com from the email address associated with your account.
When you delete your account, expenses and contributions you added to a shared group remain in that group's records so the group's balances stay accurate, but they are no longer linked to your identity (they appear as an anonymized “Former member”). We complete deletion as described in Section 7, subject to legal retention requirements.
10. Data Security
We take reasonable technical and organizational measures to protect your information, including encryption in transit, secure authentication through our provider, and secure on-device storage of session tokens. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Children's Privacy
Tide is not intended for children under the age of 13 (or the minimum age required in your jurisdiction, such as 16 in parts of the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact sudwiptokmondal@gmail.com and we will delete it.
12. Third-Party Services
The Service integrates with third-party providers (Clerk, Convex) and sign-in providers (Apple, Google). This Privacy Policy does not cover the practices of those third parties. We encourage you to review their privacy policies:
- Clerk: clerk.com/legal/privacy
- Convex: convex.dev/legal/privacy
- Apple: apple.com/legal/privacy
- Google: policies.google.com/privacy
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice within the app. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:
Email: sudwiptokmondal@gmail.com