Privacy
Effective 4 September 2026 (media relay paragraph added) · applies to the Tern beta on iPhone, Android, Mac and Windows
Tern is built so that there is as little as possible to have a privacy policy about. This page says exactly what exists, where, and what we can and cannot see.
What we never collect
- No account. There is no sign-up, no phone number, no email. Your identity is a cryptographic key generated on your device.
- No message content. Messages, photos, videos, voice notes, calls, statuses, polls and call history are end-to-end encrypted (MLS / DTLS-SRTP). Our server relays sealed bytes it cannot decrypt. This is architecture, not policy — there is no code path that could read your content.
- No contact upload. Inviting from your contacts happens on your phone; your address book never leaves it.
- No analytics or tracking. The apps and this website contain no third-party SDKs, trackers, ad IDs, or crash reporters, and fetch nothing from third-party hosts.
- The AI stays home. Summaries, reply suggestions, search and transcription run on your device. Your words are never sent to any AI service.
What our relay necessarily sees
Any messaging service needs a server to pass sealed envelopes between devices. Ours sees, and only while operating:
- Connection metadata — your IP address and when your device connects, like any server you reach on the internet. Not logged beyond standard short-lived operational logs.
- Encrypted traffic shape — sizes and timing of sealed envelopes, and one deliberate visible bit that marks "this envelope is a call ring" so locked phones can be woken. Never the content, sender name, or room name.
- Call media relay — group and video calls pass through a media server (an SFU) that forwards each participant's frames to the others. Every frame is encrypted on your phone before it is sent, under a key that exists only on the phones in the room, so the server sees encrypted frames, who is in which call, and when — never the sound or picture. It keeps no recordings; there is no code path that could.
- Push tokens — the Apple/device token needed to wake your phone, kept until your device unregisters. iPhone push notifications themselves are content-free ("You have new messages"); Android previews are generated on your own phone.
Where your data lives
On your devices. Your history syncs between the phones and computers in your rooms, encrypted, and can be removed by deleting the app. We hold no copy to delete, subpoena, or breach. If you install the on-device AI model, it downloads once from our file server (a model file, nothing about you goes up).
Beta distribution
iPhone builds are delivered through Apple TestFlight, which shares install and crash statistics with us under Apple's privacy terms. Android builds are downloaded directly from this site with no store in between.
Reporting and safety
You can report a message or block a person from within the app. A report you choose to send goes to the room's admin (a person in your room — not to us; we could not read it anyway).
Children
Tern is not directed at children under 13, and the beta is invite-based.
Changes and contact
If this page changes, the date above changes with it. Questions, or anything you'd like deleted that we actually hold (a push token, an email you sent us): smaan@aimadds.com.