Effective date: July 25, 2026 Last updated: July 25, 2026
Overview
Tandem Tiles ("the App") is an iPhone app for two people who share a private board. Each day, each partner may add one photo — a "tile" — to that shared board. Neither partner's photo for a given day is visible until both have added theirs; then the day reveals both at once.
The short version: the developer operates no servers, runs no analytics, serves no ads, and does no tracking. The App has no accounts, no login, and no password. Your photos and captions are stored in your own iCloud account using Apple's CloudKit, and are shared with the partner you invite using Apple's built-in sharing. The developer cannot see your photos, your captions, or your board.
What the App stores, and where
Your data goes to three places, all of them yours: your iCloud account, your device's app storage, and a temporary file on your device during upload. There is no fourth destination, and none of them is operated by the developer.
In your iCloud account (CloudKit)
The App uses the CloudKit container iCloud.com.timjones.tandemtiles. When you create a
board it is written to your private CloudKit database, in a custom zone, and then shared
with your partner using Apple's CKShare mechanism. When you accept an invitation instead,
the board lives in the other person's account and appears to you through Apple's shared
database.
The records the App writes contain:
- The board — a title, the creation date, and an identifier for each participant.
- Each tile entry — the day it belongs to (as a calendar date, e.g.
2026-07-25), an identifier for whichever partner added it, the date it was added, the photo itself, and an optional caption if you wrote one.
Each tile's internal record name is formed from the day and the identifier of the partner who added it, so those two values also appear in CloudKit record metadata.
This data is held in Apple's iCloud infrastructure under an Apple ID — yours if you created the board, your partner's if you joined theirs — subject to Apple's own privacy policy and security. The developer has no administrative console, no database access, and no ability to read it.
On your device
The App keeps the following locally, in standard app preferences:
- A reference to your current board: its record name, its iCloud zone, the identifier of the account that owns that zone (your partner's, if you joined their board), and which iCloud database it lives in.
- Your participant identifier (described below).
That is all that is stored in app preferences. If a photo cannot be uploaded — because you are offline or iCloud is unavailable — the App tells you so and keeps that photo in memory only, so you can retry. It is not written to app storage, and it is not sent anywhere until the upload succeeds.
Local data is removed when you delete the App.
Temporarily, during upload
Each photo is written to your device's temporary directory immediately before it is sent to iCloud, and deleted as soon as the upload finishes. If the App is force-quit or crashes mid-upload, that temporary copy can remain until iOS clears it.
Identifiers
The App identifies each partner with an opaque identifier supplied by Apple — the CloudKit user record name for your Apple ID within this app's container. It is specific to this app, is not your Apple ID, is not your email address, and cannot be used to identify you in any other app or service. If iCloud is unavailable, the App generates a random identifier on the device instead.
No advertising identifier is collected. The App does not use the App Tracking Transparency framework, because it does not track you.
Photos
Choosing your daily photo uses Apple's system photo picker. The picker runs outside the App, and the App receives only the single image you select. It does not read, browse, index, or scan your photo library.
The photo is uploaded as you selected it, in its original format and bytes. The App does not re-encode, resize, or strip anything from it. If the image file already carries embedded metadata — the date it was taken, camera information, or location, depending on your device settings and how the photo was created — that metadata travels with the photo into the shared board, where your partner can see it. If you would rather not share a photo's embedded location, remove it before selecting the photo, or use iOS's own option to share without location data.
Who your data is shared with
- Your partner. That is the entire purpose of the App. Whoever you invite to your board can see the photos and captions you add to it. Invitations are issued through Apple's standard sharing interface, and anyone holding a valid invitation can join the board — so share the invitation only with the person you intend.
- Apple. As the operator of iCloud and CloudKit, Apple stores and transmits this data. Apple's handling is governed by Apple's privacy policy.
- No one else. No advertisers, no data brokers, no analytics vendors, no third-party SDKs of any kind. The App contains no third-party libraries.
Apple does not permit the owner of a shared board to also join it as a participant, so a board cannot be shared with your own Apple ID.
What the App does not do
- No developer-operated servers, backends, or databases.
- No analytics, telemetry, crash-reporting, or attribution SDKs.
- No advertising and no ad identifiers.
- No tracking across apps or websites.
- No location, contacts, microphone, or camera access.
- No push notification service.
- No sale or sharing of personal information, under any definition, to anyone.
Your control over your data
- Delete a photo or a board from within the App, or from your iCloud storage settings.
- Stop sharing at any time through Apple's sharing controls; the board is a normal shared CloudKit record.
- Delete everything by deleting the App and removing its data from iCloud (Settings → your name → iCloud → Manage Account Storage).
Because the data lives in an iCloud account rather than on a developer server, deleting it there deletes it. The developer holds no separate copy to request the deletion of.
Children
The App is not directed at children and collects no personal information from anyone, including children. It has no chat, no public content, no discovery features, and no way to reach a stranger — a board is shared only with someone you personally invite.
Security
Data in transit and at rest is handled by Apple's iCloud and CloudKit infrastructure using Apple's encryption. The App uses only Apple-provided cryptography and contains no custom or non-exempt encryption.
Changes to this policy
If the App's data handling changes, this policy will be updated and the "Last updated" date above revised. Material changes will be reflected here before the corresponding App update is released.
Contact
Questions about this policy can be sent to tjones7306@gmail.com.
Tandem Tiles is an independent app. It is not affiliated with or endorsed by Apple Inc. iCloud, CloudKit and Apple are trademarks of Apple Inc.