Legal
Privacy
Last updated · June 10, 2026
TIDES reads your body's signals and helps you see them clearly. We collect as little as possible, keep as much as we can on your device, and never sell your data, to anyone, ever. This page explains what we collect, why, and how you can export or delete it. Effective June 10, 2026.
Who we are
TIDES is operated by Tides Health, Inc. Contact privacy@trytides.com. TIDES is a wellness and self-tracking app. It is not a medical device, not a HIPAA-covered entity, and does not provide medical diagnosis, treatment, or advice.
What we collect
From Apple Health, if you grant permission: sleep (duration, stages, efficiency), heart signals (HRV, resting heart rate, workout heart rate), activity (steps, active energy, workouts), and body mass if you log it. TIDES reads only what you grant, and you can revoke access anytime in iOS Settings → Privacy & Security → Health → TIDES. With write permission, workouts and nutrition you log in TIDES can be saved back to Apple Health.
Things you tell us directly: meals (typed, spoken, or photographed), mood and felt-state check-ins, workouts, skin scans you choose to run, the protocol items you choose to track (supplements, peptides, medications, you decide what to log; we never ask for prescriptions), and your account email, or Apple's relay address if you use Sign in with Apple.
Collected automatically: subscription status (via RevenueCat), anonymized crash and performance data (via Sentry, never your name, email, or health data), and basic device info (iOS version, device model, app version) for debugging.
Photos: meals and face scans
Photos are the most sensitive thing the app touches, so the rules are strict. Meal photos and face scans are sent to our backend (Supabase, EU region), forwarded to an AI vision service for analysis, and deleted from our servers within 30 days, usually within minutes. Only the resulting readings are kept. Your Week-1 skin baseline photo stays on your device for honest before/after comparisons. You can delete photo history anytime in Profile → Data & privacy.
Cloud AI is a choice
Before anything you log is used for a cloud AI reading, TIDES shows you an explicit choice: use cloud AI, or keep everything on this device. You can change your answer anytime in Profile → Data & privacy. Prompts sent to AI providers are anonymized: never your name, email, or raw HealthKit records. Your data is never used to train anyone's AI models.
Third parties, the whole list
- Supabase (EU, Frankfurt), backend database and authentication. Everything you sync, encrypted at rest, scoped to you by row-level security.
- Our AI provider (reached only through our backend), powers Signal's coaching chat. Sees anonymized messages and a small signal-context snippet. Photo analysis and on-device routing are not live yet.
- RevenueCat, subscription state. Sees your Apple receipt and an anonymous app ID. No health data.
- Sentry, crash reporting. Stack traces and device info only.
- Open Food Facts / Nutritionix, food lookup for barcodes and natural-language meal parsing. Sees the food query, not your identity.
- Apple, App Store, HealthKit, Sign in with Apple, push notifications.
No advertising SDKs. No cross-app trackers. Nothing that sells or shares your data for advertising.
Where your data lives, and for how long
Recent history is cached on your phone so TIDES works offline. Your synced history lives encrypted (AES-256) on our EU servers for the life of your account, then is deleted within 30 days of account deletion. Photos: ≤30 days as above. Crash reports: 90 days. Everything in transit uses TLS 1.3.
Your rights
From Profile → Data & privacy you can export everything as JSON, delete specific logs, or delete your account, which permanently erases your local data, server records, and auth account (allow up to 30 days for backups to age out). EU/EEA residents have the full set of GDPR rights (access, rectification, erasure, portability, restriction, objection, withdrawal of consent). The in-app tools cover most of them, and privacy@trytides.com covers the rest. California residents have equivalent CCPA/CPRA rights; we do not sell or share personal information.
Children
TIDES is rated 17+ and not directed at anyone under 17. If you believe a minor has used TIDES, email us and we'll delete the account.
TIDES is not a medical service
Nothing in the app, not the Tide Score, not Signal, not the reports, diagnoses, treats, cures, or prevents any disease. TIDES is not FDA- or EMA-regulated, and is not a substitute for professional medical advice. Decisions you make based on TIDES are your own. In an emergency, call your local emergency number.
Security
TLS 1.3 in transit, AES-256 at rest, row-level security on every query, no privileged secrets in the iOS app, and your most sensitive on-device notes additionally encrypted on your phone. Found a vulnerability? Email security@trytides.com. We'll acknowledge within 72 hours.
International transfers & changes
Our backend lives in the EU; if you use TIDES elsewhere, your data is transferred to and stored there under Standard Contractual Clauses or your jurisdiction's equivalent. If this policy changes in a way that affects you, we'll tell you in the app before the change takes effect.
Contact
Privacy: privacy@trytides.com · Security: security@trytides.com · Support: support@trytides.com