# Tidy Privacy Policy

Last Updated: 23 April, 2026

This Privacy Policy and our [Terms of Service](/content/terms/index.html) together form one unified agreement governing your use of the Services. Please read both documents carefully.

## 1. About This Privacy Statement

This privacy statement explains how **POND AI, INC.** ("Tidy", "we", "us", "our") processes personal data in connection with the Tidy platform, website ( [https://withtidy.com](https://withtidy.com/)), iMessage-based interactions, and related AI agent automation services (collectively, the "Services"). Tidy is committed to safeguarding your privacy and processes personal data in accordance with applicable privacy laws, including the General Data Protection Regulation ("GDPR") where applicable. This statement gives you an overview of how we process personal data, for what purposes, and your rights as a data subject.

## 2. Who Is Responsible for Processing Your Personal Data?

Tidy is the data controller for personal data processed in connection with the Services. This means that we determine the purposes and means of the processing and are responsible for ensuring that your personal data is processed in compliance with applicable law.

Contact details:

POND AI, INC.

Address: 1111B S Governors Ave STE 34109 Dover, DE, 19904 US

E-mail: [privacy@withtidy.com](mailto:privacy@withtidy.com)

Registered in Delaware, File No. 10203186

## 3. Which Personal Data Do We Process and for Which Purposes?

### a. Account data and service administration

In connection with providing the Services, Tidy collects and processes personal data about users. To establish and administer user accounts and subscriptions, Tidy processes account and profile information, including name, email address, and login credentials. To process payments, billing and payment information is handled via third-party payment processors; Tidy does not store complete payment card numbers.

Tidy may also process aggregated and de-identified usage data for product analytics and service improvement. The legal basis for processing account and service data is performance of the contract between Tidy and you (GDPR Art. 6(1)(b)) and Tidy's legitimate interests in operating and improving its services (GDPR Art. 6(1)(f)).

### b. Agent Actions and credential storage

The core function of the Services is the execution of Agent Actions on your behalf.  Tidy processes the following categories of personal data:

- **Instructions and task data:** the content of requests you submit via the Tidy interface or iMessage, including any personal data contained in or referenced by those requests.
- **Authentication credentials for third-party services ("Credentials"):** where you choose to provide login credentials to enable Tidy to access and act within third-party services on your behalf. 
- **Agent action logs:** records of Agent Actions executed on your behalf, retained for troubleshooting, security, and audit purposes.
- **Third-party service data:** data accessed from third-party services in the course of executing Agent Actions, including but not limited to emails, calendar entries, messages, files, and form data.

### c. Third-party connected services and AI providers

When Tidy executes Agent Actions, data may be transmitted to the following categories of third parties:

- **Third-party applications and platforms:** such as email providers, messaging applications, social media platforms, scheduling tools, e-commerce platforms, and other services, as necessary to carry out your instructions.
- **Third-party AI model providers:** such as Anthropic, OpenAI, Fireworks AI, Amazon, Google, and Groq, whose models Tidy uses to interpret your instructions and generate Agent Actions.

### d. Suppliers and other business partners

Tidy processes personal data in connection with its agreements with suppliers and other business partners, including contact details and other information necessary to administer those relationships. The legal basis for such processing is Tidy's legitimate interest in managing supplier relationships (GDPR Art. 6(1)(f)).

### e. Google user data (Gmail and Google Calendar)

This section provides specific disclosures regarding personal data that Tidy accesses from Google services on your behalf, including:

**Scopes requested.** When you connect a Google account to Tidy, we request the following OAuth scopes:

- **userinfo.email** — to identify the Google account you connected.
- **calendar.events** — to read, create, update, and delete calendar events on your behalf.
- **gmail.modify** — to read your email and, where you enable those capabilities, to mark messages as read, apply labels, create drafts, and process unsubscribe requests on your behalf.

**How we use Google user data.** Google user data is used solely to provide Tidy's user-facing features:

- **Calendar:** to display your upcoming events in Tidy and to suggest events in response to your instructions.
- **Gmail:** to read emails when summarising or acting on them at your request.

## 4. Who Do We Share Your Personal Data With?

### a. Data processors

Your personal data may be made available to service providers that process data on our behalf. These include providers of cloud hosting, authentication, analytics, customer support tools, and payment processing.

### b. AI providers

Data processed by Tidy's AI functionality may be transmitted to third-party AI model providers. We select providers that maintain appropriate data protection standards.

### c. Third-party services

Data is shared with third-party services as necessary to execute your instructions.

### d. Other third parties

Tidy will not disclose your personal data to third parties beyond those necessary unless there is a lawful basis for such disclosure.

## 5. Automated Agent Actions and Limitation of Liability

The Services are designed to execute Agent Actions on your behalf, at your direction. You should be aware of the following:

- **Authorisation:** You represent that you have authority for actions you initiate and that such actions comply with applicable law.
- **Agency:** Tidy acts as your agent and is not responsible for the consequences of Agent Actions taken at your direction.

## 6. Your Rights

You have the following rights under applicable data protection law:

- **Access** – to know what personal data we process about you
- **Rectification** – to have inaccurate or incomplete data corrected
- **Erasure** – to request deletion of your personal data
- **Restriction** – to limit processing in certain circumstances
- **Portability** – to receive your personal data in a structured format
- **Objection** – to object to processing based on Tidy's legitimate interests
- **Withdraw consent** – to withdraw any consent you have given for specific processing activities

## 7. Cookies and Tracking Technologies

Tidy and its service providers may use cookies and similar tracking technologies on the Tidy website and platform to collect usage and browser information. The types of cookies we use include:

- **Essential cookies:** necessary for authentication, session management, and core platform functions.
- **Analytics cookies:** to help us understand how users interact with the Services.

You may manage cookie preferences through your browser settings.

## 8. How Long Do We Store Your Personal Data?

We retain personal data only for as long as necessary to fulfil the purposes described.

- **Account information:** retained for the duration of your account and for a reasonable period thereafter for legal, tax, and compliance purposes.
- **Credentials and agent action logs:** retained while your account is active and deleted within 30 days following account termination.

## 9. Measures to Safeguard Your Personal Data

We apply technical and organisational security measures, including encryption in transit and at rest, access controls, and secure cloud hosting, to protect personal data against unauthorised access, misuse, or disclosure.

## 10. International Data Transfers

The Services are hosted in the United States. If you are located in the European Economic Area, your personal data may be transferred to and processed in countries outside those jurisdictions that may not provide the same level of data protection.

## 11. Legal Bases for Processing (GDPR)

Where GDPR or equivalent legislation applies, our legal bases for processing personal data are:

- **Performance of a contract (Art. 6(1)(b))**
- **Legitimate interests (Art. 6(1)(f))**
- **Legal obligation (Art. 6(1)(c))**
- **Consent (Art. 6(1)(a))**

## 12. Children's Privacy

The Services are not directed at children under the age of 18. We do not knowingly collect personal data from children under 18. If you believe we have collected personal data from a child under 18, please contact us.

## 13. Changes to This Privacy Statement

We may update this privacy statement from time to time. The most current version will always be available at [withtidy.com/privacy](https://withtidy.com/privacy).
