Tendhus

Privacy

Last updated September 8, 2026 · Firehorse Studio LLC

Tendhus holds records about your home: repairs, receipts, and the people involved in them. This page says what we collect, why, who else touches it, and how to get it back or get rid of it. It is written to be read, not skimmed past.

What we collect

Your account. Name, email address, a hash of your password (never the password itself), and the timezone your browser reported, which is what decides when something counts as due today. A phone number too, if you add one: that one is optional, and it is shown to anyone you send a job to and to whoever lives in that home. Clearing it takes it off both.

What you put in. Homes, issues, expenses, reminders, lease details, and the photos, receipts, and documents you upload.

People you add. Contact details for tenants and vendors, entered by you. See “About tenants and vendors” below.

Notification subscriptions. If you turn on push, the endpoint your browser hands us so a notification can reach that device.

Server logs. Ordinary request logs (IP address, page, timestamp, browser) kept briefly for debugging and abuse handling.

What we do not collect

No analytics or advertising trackers, no third-party scripts that follow you, no location tracking, no bank or payment connections. The app has no advertising, and no part of it is funded by profiling you.

What we use it for

Running the app, and nothing else: showing your records, sending the notifications the app exists to send, by push and by email (a morning summary when something is due, and a message when somebody acts on one of your places), sending the transactional email you ask for (password reset, address confirmation, a tenant’s access link), and keeping the service secure.

We do not sell your data, share it with advertisers, or use it to train machine-learning models.

About tenants and vendors

When you add a tenant or a vendor, you are entering someone else’s personal information. You are responsible for having a legitimate basis to do that, and for what you send them from the app. We process that information on your behalf, as your service provider.

Tenants and vendors reach the app through a link, not an account. The link is the credential: anyone holding it can see that home’s issue history and act on it, so treat it like a key. Tenant links can be reset from the tenant’s page, which kills every session on the old link at once. Vendor job links expire after 14 days and are revoked when the job closes.

A tenant or vendor who wants their information corrected or removed can ask the property owner, who can do it in the app, or write to us at hello@tendhus.com and we will pass it on.

Who else touches it

We use these companies to run the service. Each one is bound to use the data only for that.

  • Vercel · Runs the application servers · Requests, server logs
  • Neon · Hosts the database · Every record you create
  • Cloudflare · DNS, network, and file storage (R2) · Uploaded photos, receipts, documents
  • Resend · Sends the app's email · Email addresses, message contents

Push notifications travel through the notification service belonging to your browser or phone (Apple, Google, or Mozilla). The message body is encrypted so only your device can read it, but those services do see that a message was sent to your device.

We will hand data to law enforcement only when legally compelled, and we will tell you unless we are barred from doing so.

Cookies

Two, both strictly necessary: one that keeps you signed in, and one that keeps a tenant signed in to their own page. No advertising or analytics cookies, so there is no consent banner to dismiss.

How long we keep it

Your records stay until you delete them or close your account. Closing your account deletes your homes, issues, expenses, reminders, tenancies, vendors, notification subscriptions, and the uploaded file bytes themselves. That deletion happens immediately in the app and cannot be undone.

Backups are the exception, and we would rather be plain about it than reassuring. We keep encrypted database backups so an accident or an outage cannot wipe out your records, and the most recent ones go back about two months. A backup taken before you deleted something still contains it until that backup ages out. Copies of uploaded files are kept alongside those backups for longer, because a database backup restored without its files would leave you looking at receipts that no longer exist.

Backups are never used to bring an account back after it is closed, and nobody reads them except to restore from a failure. Server logs are kept for a short window for debugging and security. If you need a deletion that reaches the backups too, write to us and we will do it by hand.

Getting your data out, or deleted

Every home has a tax export that produces a CSV, a PDF, and a zip of the original receipts, which is the app’s own export path and needs nobody’s permission. Account deletion is self-serve, under Account · Close this account.

Depending on where you live you may also have rights to access, correct, port, or object to our handling of your data. Write to hello@tendhus.com and we will answer within 30 days. We do not charge for this and will not treat you differently for asking.

Security

Traffic is encrypted in transit. Passwords are hashed. Uploaded files are private: they are never served from a public bucket, and every request for one is checked against who you are and what the file is attached to. No system is perfect, and we will not pretend otherwise; if a breach affects you we will tell you.

Where the data lives

On servers in the United States. If you use the app from elsewhere, your information is transferred and processed there.

Children

Tendhus is for adults taking care of a home. It is not directed at anyone under 18.

Changes

If this page changes in a way that matters, we will say so in the app before the change takes effect, not just move the date at the top.

Contact

Firehorse Studio LLC · hello@tendhus.com