Privacy

Your words stay quiet.

Tide is a daily-rhythm app for iOS. The thing it asks of you — small reflections, a dream, a mood, a few intentions — is the most private thing you’ll write all day. This page explains, in plain language, what Tide collects, what it doesn’t, and where your data actually lives.

Who’s behind Tide

Tide is built and operated by David Petrina, an independent developer based in Czechia. There is no company, no team, no server-side infrastructure under my control. The privacy contract below is what one person can honestly promise.

Contact: david@petrina.me.

What stays on your device, only

Everything you write and everything Tide writes about you. The names of your intentions, what you wrote at sundown, what you caught from the night, the mood you picked, the notes you sealed for your later self, the prose Tide keeps in your Almanac, your notification times, your accent colour — none of it reaches a server I control. It lives in Tide’s local database on your iPhone, iPad, or Apple Watch.

And in your own iCloud, if you let it. If you have iCloud signed in and keep the “iCloud” toggle on inside Tide’s Settings, the same content syncs to your private CloudKit database (iCloud.me.petrina.tide), which is part of your iCloud account. I cannot read it. Other Tide users cannot read it. It is private to your Apple ID. You can verify this in iOS Settings → your Apple ID → iCloud → Manage Storage → Tide.

A small copy for the widgets and the watch. So that a home-screen widget, a Control Center control, and your Apple Watch can show today’s tide without waking the whole app, Tide keeps a small summary — today’s count, your intention names and whether each is held — in a shared container on your own device. It never leaves the device, and it is removed when you uninstall Tide.

The permissions Tide asks for, and why

Tide asks for nothing at launch. Every permission below is requested only at the moment you reach for the feature that needs it, and every one of them can be refused without breaking the rest of the app.

Health. If you create a rest, bedtime, or steps intention, Tide asks to read those values from Apple Health so the tide can rise on its own when you sleep or walk. If you use the breath or the ebb, Tide asks to write those minutes back as Mindful Sessions. Health values are read on your device. From version 2.5.0 the reading itself is never stored— when Tide shows you “held · 7 h”, it is asking Health again, not repeating something it wrote down. On earlier versions the value behind an auto-held intention was saved with that day’s record and so reached your own private iCloud; updating to 2.5.0 removes the ones already there. Either way, no health value is ever sent to me, included in an analytics event, or attached to a crash report. You can revoke it at any time in iOS Settings → Health → Data Access & Devices → Tide.

Location.Only if you turn on “The sky” in Settings → Appearance, so that real weather can leave a quiet trace on the water. Tide requests approximatelocation only — reduced accuracy, roughly your area rather than your address — and uses it for one thing: asking Apple’s WeatherKit what the sky is doing near you. That request goes to Apple, under Apple’s privacy policy. Tide does not store your location, does not log it, does not sync it, and does not send it anywhere else. Leave the toggle off and Tide never asks.

Microphone and speech recognition. Only if you choose to speak a reflection instead of typing it. Tide listens while you are recording and uses Apple’s speech recognition to turn what you said into text in the editor. The recording is not kept, and the words end up exactly where a typed reflection would — on your device, and in your own iCloud if syncing is on.

Notifications. Only if you switch on one of the cairns. They are composed and scheduled on your device by iOS. There is no push server, so no notification you receive from Tide has passed through anything of mine.

Face ID or your passcode. Only if you turn on the app lock. iOS performs the check and tells Tide yes or no. Your biometric data is never available to Tide, and nothing about it is stored or transmitted.

What Tide collects from you, the user

Anonymous usage events.Tide uses Firebase Analytics to record a small set of events — first open, session start, screen view, which practice was started, that an intention was held, and tip-jar interactions. These are tied to a randomly generated Firebase instance ID, not to your name, your Apple ID, your email, or any identifier I choose. Tide does not link the IDFA (Apple’s advertising identifier), so the App Tracking Transparency prompt is never shown — because Tide does not track you.

What those events deliberately never contain. No text you have written, and no length or hash of it. No intention names, reflection bodies, dream notes, sealed notes, or gift messages. No health-derived value of any kind — not a sleep duration, not a step count, not a bedtime — and no event whose mere existence would reveal one. This is enforced in the app’s code, not merely promised here.

Crash and performance data. Firebase Crashlytics and Performance Monitoring collect diagnostics when Tide misbehaves: stack traces, device model, iOS version, app version, time of crash, and how long key operations took. They are not tied to your identity. They exist so I can fix things.

Tip-jar purchases. If you send an optional tip, Apple processes the payment through StoreKit. I never see your payment information — Apple shares only aggregate sales reports, with no identifying detail about who tipped.

When you share a tide with someone

Tide can be shared with one other person, and an intention can be held by the two of you together. This is the only case in which anything of yours is visible to another human being, it is entirely opt-in, and it is worth being precise about.

What they see.How many intentions you have held today and how many you have in total, the display name you chose for the share, and — for an intention you have explicitly agreed to hold together — that intention’s name and whether you have held your half today.

What they never see.Your other intentions. Your reflections, dreams, moods, or sealed notes. Your Almanac. Anything from Health. Your streaks, your history, or any day but today. Tide sends the other person no signal about whether you followed through, and never notifies them that you didn’t.

How it travels.Through Apple’s CloudKit sharing, in a container separate from your private data, between your two iCloud accounts. It does not pass through any server of mine. Either of you can end the share at any time, from inside Tide or from iOS Settings, and the shared records are deleted when you do.

Gifting an intention. If you shape an intention for someone and send it, the link carries only the shape of it — a name, an icon, a colour, a cadence. It carries nothing about you, your history, or whether you kept it. Once they accept it, it is theirs, on their own tide, and you are told nothing further.

What Tide does not collect

  • The IDFA (Identifier for Advertisers). The Firebase IdentitySupport module isn’t linked. Apple’s advertising identifier stays inaccessible to Tide.
  • Your email address. Tide has no accounts and no sign-in.
  • The content of your intentions, reflections, dreams, moods, sealed notes, or Almanac. None of it is ever sent off-device to anything I run.
  • Your contacts, photos, or calendar.
  • Camera input. Tide never requests the camera.
  • Any health value reaching me, or any third party. Nothing from Health enters an analytics event, a crash report, or a shared tide. From version 2.5.0, nothing measured is stored by Tide at all.
  • Your precise location. Tide requests approximate location only, and only for weather, and only if you ask for it.
  • Anything from any third-party advertising network. There are no ad SDKs in Tide.

Who else can see what

Apple.Apple sees what Apple always sees for any iOS app: that you downloaded it, and your StoreKit purchases. Anything stored in your iCloud is governed by Apple, not by me. If you turn on “The sky”, your approximate location is sent to Apple’s WeatherKit to answer the weather request. Apple’s privacy policy applies to all of that.

Google (Firebase).The anonymous usage events and crash diagnostics described above flow to Google’s Firebase platform, which I use as my analytics and crash-reporting provider. Firebase data is governed by Google’s privacy policy. I have not enabled Google Analytics for Firebase audiences, ad personalisation, or any cross-app linking.

The person you share a tide with, and only to the extent set out above, and only for as long as either of you keeps the share open.

Nobody else. Tide ships no other third-party SDKs. There are no advertisers, no data brokers, no marketing automation, no profiling vendors. The full third-party list, end to end, is Apple plus Firebase.

Where the data is stored

Firebase data is processed on Google infrastructure, which may include servers in the United States and other regions. CloudKit data is stored by Apple in the region Apple determines for your Apple ID. On-device data stays on the device you’re holding.

If you are a resident of the European Union or the UK, the data transfer to Firebase is covered by Google’s standard contractual clauses. You have the rights granted under the GDPR — most usefully here, the right to deletion, which is achievable on your end without writing me a letter (see below).

How long Tide keeps things

On your device: for as long as you keep Tide installed. Uninstalling removes the local copy, the widget summary, and the watch copy.

In your iCloud:for as long as you keep Tide’s iCloud toggle on and the data present in your iCloud account. You can wipe it at any time through iOS Settings → your Apple ID → iCloud → Manage Storage → Tide → Delete Data.

In a shared tide: until either person ends the share, at which point the shared records are deleted. Your own copy of a shared intention stays with you, as yours.

In Firebase:Analytics events use Google’s default retention (currently up to 14 months for event data, with anonymous identifiers reset on a shorter cadence). Crashlytics retains crash reports up to 90 days.

Your rights and how to use them

Delete on-device data: uninstall Tide from your iPhone, iPad, or Apple Watch.

Delete iCloud data:iOS Settings → your Apple ID → iCloud → Manage Storage → Tide → Delete Data.

Stop syncing without deleting: inside Tide, Settings → Sync → iCloud → toggle off. Existing iCloud data stays until you delete it; future changes will not sync up.

Withdraw a permission:Health in iOS Settings → Health → Data Access & Devices → Tide. Location, microphone, speech recognition, and notifications in iOS Settings → Tide.

End a shared tide:inside Tide, or from iOS Settings → your Apple ID → iCloud → Shared.

Export your reflections: Settings → Sync → Export reflections offers Markdown and CSV. Your data is yours.

Ask me to delete Firebase data: because the analytics events are not linked to an identifier I control, I usually cannot find your specific records to delete. If you know the rough timing of your install and you’d like me to try, email david@petrina.me and I’ll do what I can.

Children

Tide carries a 4+ age rating in the App Store. It is not directed at children, and it does not knowingly collect personal information from anyone under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has used Tide and you’d like me to take action, write.

When this page changes

If I change what Tide collects or who it shares data with, I’ll update this page and bump the date at the bottom. For material changes I’ll also note it in the “What’s New” of the next App Store update, so the change isn’t hidden in a footnote.

Questions

If anything on this page is unclear, or if it doesn’t match what you observe in the app, write david@petrina.me. I’d rather rewrite a paragraph than leave a question hanging.

Effective 19 August 2026. Last reviewed 19 August 2026.