Privacy
TenTwo Privacy Policy
TenTwo exists to give you certainty in uncertain moments. That only works if you can trust us with what we hold. This policy is written to be read — plain English, no burying. Where law requires precise terms, we add them; where it doesn't, we speak like people.
DRAFT — pending legal review
This page is our plain-language statement of how the product actually behaves. The formal document prepared by counsel supersedes this wording on conflict.
The promises first
These are commitments, not summaries. They control how we interpret everything below.
- 1We never sell your data. Not your location, not your recordings, not your habits. No advertisers, no data brokers, ever.
- 2Your recordings belong to you. We store them; we don't own them, watch them, or mine them.
- 3No facial recognition, no biometric identification, and no AI content analysis is ever run on your session recordings. We certify arrangements, never persons.
- 4Access to your recordings happens two ways only: by your choice, or by valid legal process. There is no third way. If we receive a legal demand, we notify you unless the law forbids it.
- 5Absence means nothing. Not using TenTwo, or having no signal active, creates no record, no score, and no inference about you.
- 6Safety fails open. Emergency functions never require payment, and a lapsed subscription never blocks recording or emergency contact features.
What we collect
Account information: name, email, phone number, and — for agents — license and certification details you provide to us.
Location: only during an active session (a Protocol activation, a booking, a Witness Recording, or a walk you've chosen to share). We do not track your location in the background when nothing is active.
Recordings: video and audio you capture during sessions, encrypted in transit and at rest. Session media is hashed at upload so its integrity can be proven later.
Payment information: handled by our payment processors (Stripe; Apple and Google for in-app purchases). We never see or store full card numbers.
Device and usage basics: device type, app version, crash logs, and the minimum diagnostics needed to keep the service working.
Marketing website analytics (disclosure): our marketing website at ten-two.app currently loads a small analytics script called flock.js, injected by our hosting platform, that sends data to a third-party analytics service called Tinybird (api.tinybird.co). When you load a page on the marketing site, that script transmits: the full page URL you visited (including any query string), the referring URL, your browser's user-agent string, standard web performance measurements (page load and rendering timings), and a persistent identifier stored in your browser via cookies and localStorage that lets Tinybird recognize repeat visits from the same browser. This runs on the marketing website only. The TenTwo app itself — including the native App Store build — does not load this beacon and sends only the first-party telemetry already described in this policy, which carries no persistent identifier tied to you and never leaves our systems. We did not choose to add Tinybird and cannot currently remove it ourselves; we have asked our hosting platform for the ability to turn it off, and the moment they allow it we will remove both the beacon and this disclosure.
How we use it
To run the service you asked for: activating the Protocol, dispatching and verifying agents, storing your recordings, processing payments, notifying your chosen Trusted Eyes, and meeting our legal obligations. That's the list. We do not use your data to advertise to you, build profiles of you, or infer things about your life.
Who can see what
Your trusted eyes. The people you invite see that a mode has started and can follow it live — status, elapsed time, and sealed clips as they are recorded. They never see your location off-mode and never see your saved recordings.
Law enforcement. Only through lawful process, or when you hand over a link yourself. We publish what we receive and we tell you unless a court forbids it.
Service providers. The vendors who store files, process payments, and send messages for us. They act on our instructions only, and none of them may use your data for their own purposes.
Retention
Records you create stay until you delete them — nothing on your phone deletes itself today, and you can delete any record at any time. A shared recording link stops working 90 days after the stop, and a legal hold can require us to preserve a sealed record. Account data is kept while your account is active and deleted on request. Attested records you've exported are yours; deletion from our systems doesn't touch your copies.
Your rights
You can access, export, correct, or delete your data from inside the app or by emailing privacy@ten-two.app. We honor deletion requests within 30 days. Residents of states with privacy statutes (including California and Texas) have specific rights to know, delete, and correct — we extend those same rights to everyone, in every state, because it's simpler and it's right.
Recording laws
You are responsible for complying with your state's recording-consent laws. TenTwo displays in-app notices where recording is active, and marketplace sessions include disclosure to participants.
Minors
TenTwo accounts require users 18+. Teen Driver Setup operates under a parent's account with parental consent, and teen data receives every protection in this policy plus parental control over retention and Trusted Eyes.
Security
Encryption in transit and at rest, least-privilege access internally, integrity hashing on session media, and no employee access to recording content in the ordinary course of business. If a breach affects your data, we notify you promptly and plainly.
Changes
If we change this policy, we'll tell you in the app before the change takes effect — a real notice, not a silent edit. We will never change the six promises at the top except to strengthen them.
Read the full privacy policy prepared by counsel → privacy@ten-two.app