Version 1.5 · In force and last updated: 16 August 2026
1. Data controller and contact
Tandem is an iOS application that helps the members of the same household organise and share out domestic tasks.
Data controller: Jonathan Darmouni, 49 rue Saint-Louis, 93250 Villemomble, France.
Privacy contact and exercise of rights: jonathan.darmouni@gmail.com.
The application does not appoint a data protection officer. Should this change, their contact details would be added here.
2. Scope and summary
- Tandem does not ask for an account, an email address or a password.
- The data needed to share a household is synchronised with Convex, including the photo of the home and the members' profile photos. Display preferences, reminder settings and onboarding state remain on the iPhone.
- Tandem includes no advertising and no advertising tracking: the application never asks for iOS tracking permission and does not access the advertising identifier (IDFA). No data is used to track you from one application or website to another.
- Tandem does, however, use an audience measurement tool, Google Analytics for Firebase, limited to anonymous usage statistics (see the "Audience measurement" section).
- We do not sell or rent personal data.
- A household's invitation link is confidential: a person who obtains it can request to join that household.
This policy applies to the Tandem mobile application. It does not apply to the services of Apple, Convex, RevenueCat or Google when those companies process your data for their own purposes; their respective policies then apply.
3. Data processed and purposes
| Purpose | Data concerned | Legal basis | Mandatory nature |
|---|---|---|---|
| Create, display and synchronise a shared household | Technical identifiers of the household and members, household name, members' first name or nickname, avatar colour, household administrator status, rooms, tasks, task-related preferences, completion or scheduling events, technical dates and invitation code | Performance of the contract to provide Tandem | Necessary for the shared features; without them, synchronisation cannot work |
| Display the photo of the home and the profile photos to household members | Image file and its storage identifier | Your consent: adding a photo is a voluntary action, never requested by the application | Optional; the application works fully without any photo |
| Ensure the integrity and security of synchronisation | Technical identifiers, invitation code, timestamps and data needed to diagnose an incident | Legitimate interest in securing and maintaining the service | Necessary for synchronisation to work |
| Detect abandoned households in order not to keep unnecessary data | Date of the household's last activity (lastSeenAt), recorded by the server on each synchronisation | Legitimate interest in limiting data retention (minimisation principle) | Automatic; cannot be disabled without ceasing to use synchronisation |
| Manage premium purchases and their restoration | Pseudonymous identifier assigned by RevenueCat, product chosen, status and any expiry date of the premium entitlement | Performance of the purchase contract | Necessary only if a premium offering is purchased or restored |
| Transcribe a dictated task | Audio stream during dictation and transcribed text | Your consent, given through the iOS microphone and speech recognition permissions | Optional; keyboard entry remains available |
| Display reminders on the device | Preferences and reminder content stored locally | Your consent, given through the iOS notifications permission | Optional |
| Measure use of the application in order to improve it | Installation identifier assigned by Firebase, name of the screens and actions triggered (opening, onboarding step completed, task created or completed, purchase started or completed, invitation shared), device model, iOS version, application version, language and approximate country inferred from the IP address | Legitimate interest in understanding the real use of the application in order to fix and improve it | Automatic; cannot be disabled from the application |
Free-text fields — in particular household, room and task names — are entered by users. Do not enter sensitive data or information about third parties that is not necessary for organising the household.
Local data
The indicator designating the member associated with this device, the themes and display preferences, the reminder settings and the onboarding state are stored only on the iPhone and are never transmitted.
Photos, on the other hand, are kept on the device and transmitted (see below).
Synchronised data
When a shared household is used, Convex receives the information necessary for this synchronisation: data about the household, the members, the rooms, the tasks and their recent history. Events are returned to the application within a technical window of 120 days; this read limit does not, on its own, constitute a server-side deletion period.
Photos
If you add a photo of the home or a profile photo, the image file is transmitted to Convex and stored in its file service, so that the other household members can see it. Each photo is automatically reduced by the application before any upload (600 points maximum, JPEG format); the original image from your photo library is never transmitted. A household may include at most one photo of the home and one profile photo per member.
Adding a photo is optional and does not condition any feature: without a photo, Tandem displays the initial of the first name on a coloured background. You can remove a photo at any time from the application; the previous file is then deleted from the storage service.
Photographs of third parties. Only add a photo of another person — including a child of the household — if you are entitled to do so and after having informed them. If the person concerned is a minor, it is for you, as the holder of parental authority, to decide whether this transmission is appropriate. If in doubt, prefer the coloured avatar.
Voice dictation
Tandem requests the necessary iOS permissions before starting dictation. Where on-device speech recognition is available, Tandem requires it. If it is not, the processing may be carried out by Apple in accordance with its own rules. The transcribed text is used to pre-fill a task; Tandem does not keep the audio recording.
Purchases and notifications
Payments are carried out by Apple via the App Store. Tandem neither receives nor stores bank details. RevenueCat helps Tandem verify the lifetime purchase as well as monthly subscriptions, renewals, cancellations and expiries. Convex receives these changes via an authenticated webhook in order to update the shared household.
Reminders are currently local notifications: Tandem does not send push notifications from its own server.
Audience measurement
Tandem uses Google Analytics for Firebase in order to measure the real use of the application. The aim is to know which steps are completed or abandoned — for example how many people finish onboarding — and to fix what gets in the way.
What is transmitted to Google: an installation identifier assigned by Firebase (distinct from Apple's advertising identifier, and reset if you delete and then reinstall the application), the name of the actions triggered in the application, and usual technical information — device model, iOS version, application version, language, and approximate country inferred from the IP address.
What is not transmitted: none of the content you enter. Household, room, task and member names, as well as photos, are never sent to Google. Events carry only fixed labels and, where applicable, aggregated numerical values (number of points of a task, band of the number of tasks for the day).
This is not advertising tracking. Tandem does not access Apple's advertising identifier (IDFA), never displays the iOS tracking permission screen, and does not cross-reference these measurements with any other application or website. Google Analytics advertising features are not used.
4. Sharing within your household
Tandem is designed to make a shared organisation visible to the members of the same household. When you create or join a household, the other members of that household can see the synchronised information relating to it: members' names or nicknames, the photo of the home and the profile photos where they exist, rooms, tasks, task-related preferences, recent history and allocation information.
Only add to the household people with whom you wish to share this information. A household's data is not intended to be visible to the members of another household.
5. Recipients, providers and transfers
Only the people and providers necessary for the service may access the data concerned:
- Convex, Inc., for hosting and synchronisation. The deployment used by the application is configured in the
eu-west-1(Ireland) region: household data is therefore hosted in the European Union. - RevenueCat, Inc., for managing the subscription, the lifetime purchase and premium entitlements. RevenueCat acts only as a processor, on our documented instructions alone.
- Apple Inc., an independent controller for App Store payments and, where it is involved, speech recognition. Its processing is covered by its own privacy policy.
- Google Ireland Limited and Google LLC, for audience measurement via Google Analytics for Firebase, as a processor under the Firebase data processing terms. No household data, no entered content and no photo is transmitted to them.
We may also disclose data where the law requires it or in order to establish, exercise or defend rights in legal proceedings.
International transfers
Household data is hosted in the European Union (Ireland). As Convex, Inc. and RevenueCat, Inc. are companies established in the United States, some ancillary processing — technical support, service administration — may involve access from that country.
The audience measurement data is an exception: Google Analytics for Firebase processes it on infrastructure located in part in the United States. It contains no entered content, no photo and no household data.
These transfers are governed by the standard contractual clauses adopted by the European Commission (Decision 2021/914), included in those providers' data processing agreements, to which the Publisher is subject as a result of using their services. A copy of the applicable safeguards may be obtained on request at the contact address above.
6. Retention periods
| Data | Period / criterion |
|---|---|
| Local data | Until deleted in the application or until uninstallation. Any iOS backup created by the user remains subject to their own Apple settings. |
| Synchronised household data | As long as the household is active, then until the erasure request is processed or the household is deleted. |
| Task history (events) | 180 days. Beyond that, these records are no longer necessary — the application never displays more than 12 weeks of them. |
| Household with no activity at all | 365 days. After this period without any synchronisation whatsoever, the household and all of its data (including photos) are deleted. This deliberately long period takes account of the absence of an account: no prior warning is technically possible. |
| Purchase data accessible to Tandem | For the time necessary to manage premium entitlements, their restoration and proof of the transactions, subject to applicable legal obligations. |
| Requests relating to rights | For the time necessary to process them and to evidence the response. |
| Audience measurement data | Kept by Google for the period configured in the Firebase console, capped at 14 months for data attached to an installation identifier. Aggregated statistics, which do not allow you to be identified, may be kept beyond that. |
Erasure at your request. Independently of the periods above, an erasure request is carried out manually: the household concerned, its members, rooms, tasks, history and photo files are permanently deleted from the service. This deletion is irreversible and cannot be undone.
It does not affect the data remaining on the household members' iPhones: that data disappears by deleting the application from each device, which remains in each person's hands.
Deletion from the application. An administrator of the household can delete it themselves, without writing to us: Settings → Sensitive area → "Delete household". To avoid any accidental deletion, the application asks you to retype the household name before proceeding, and reminds you how many other members will lose access to its data.
The creator of the household is its administrator and can appoint other administrators. If you are not an administrator of the household and wish your data to be erased from it, write to us at the address given below: we will process your request. Note that a household is by nature shared — the erasure of common data concerns all of its members, and we may need to inform the other members before proceeding.
7. Your rights
Subject to the conditions laid down by the GDPR, you may request access, rectification, erasure, restriction, portability or, where the processing is based on legitimate interest, object to it. You may withdraw the microphone, speech recognition or notification permissions at any time in the iOS settings; this withdrawal does not affect processing already carried out.
Write to jonathan.darmouni@gmail.com. As Tandem does not use accounts, state the household name and, if possible, the invitation code or the household identifier. We may request only the elements reasonably necessary to verify your membership of the household and to protect the other members.
We will reply within the applicable statutory period, in principle one month from receipt of the request. Access, portability and erasure of a household's data can be carried out immediately once your membership has been verified. You may lodge a complaint with the CNIL.
8. Minors
Tandem is intended to be used by adults within a household and offers no independent sign-up for children.
The application neither collects nor processes anyone's age, date of birth or minor status. It does not distinguish household members according to their age: a member is a first name, a colour, and possibly a photo. This absence of distinction is deliberate — it avoids creating a category of data relating to minors for information that the application has no use for.
An adult may add a child of the household as a member, in the same way as any other person. It is then for them to have the necessary authority, to inform the child of this processing in appropriate language, and in particular to decide whether or not they wish to add a photograph (see "Photographs of third parties", section 3).
The application is not intended for children under 15 acting alone. If you believe that a minor is using Tandem without the agreement of their legal representatives, write to us: we will delete the data concerned.
9. Security
Communications with the synchronisation service use HTTPS. There is no authentication by email or password: access to synchronised data relies on the confidentiality of the household's technical identifier, and the invitation code allows a person to join that household. Do not publish an invitation link, and request erasure of the household if this link or the household identifier has been shared by mistake. No system guarantees absolute security.
10. Automated decisions, cookies and changes
The allocation and workload-balance calculations serve as an aid to organisation; they do not produce automated decisions having a legal effect or a similarly significant effect on you.
Tandem is a native application and does not place cookies. If a Tandem website is created later, its cookie policy will have to be published separately.
We may modify this policy to reflect a change in the service or in regulations. The new version will state its effective date and its version number. In the event of a substantial change, we will inform users by an appropriate means.