tide
What is Tide Daily Tide Campuses Blog Opportunities FAQ
Log in Get the app
Legal · Privacy

Privacy Policy

Tide is a students-only, multi-campus social app. This explains what we collect, why, where it lives, who processes it, and the rights you have over it.

Effective date: August 3, 2026 · Applies to the Tide iOS app, the Tide Android app, and the web app at tidecampus.com.

Privacy Terms Safety Child Safety Contact

Tide is a students-only, multi-campus social app. Access is gated to verified .edu campuses: you sign in with your school email, and your campus feed, events, and class chats stay inside your own school. Matches and friendships can reach students at other campuses, which is deliberate and described in section 5. This policy explains what data Tide collects, why, where it is stored, who processes it, and the rights you have over it.

1. Who we are

Tide ("Tide," "we," "us") operates this app and the website at tidecampus.com. For any privacy question, deletion request, or concern, contact us at [email protected].

2. What we collect, why, and where it lives

We collect only what the app needs to work. Nothing is sold, and there is no third-party advertising or analytics SDK in Tide.

DataWhy we collect itWhere it's stored
.edu email addressTo sign you in with a one-time code (OTP) and to verify which campus you belong to. The code email is sent through our email delivery provider.Supabase Auth
Profile data, display name, handle, bio, major, interestsTo build your student profile and to power the daily match.Supabase Postgres
Avatar photoShown on your profile. Optional, you choose whether to upload one.Supabase Storage
Chat messagesTo deliver your direct messages, class group chats, and match chats.Supabase Postgres
Device push tokenTo send your daily-match reminder via Apple's push service (APNs) on iPhone or Google Firebase Cloud Messaging on Android. Collected only if you enable reminders; disabling reminders stops it.Supabase Postgres
Student ID photo, optionalOnly if you ask for the Verified badge. A person at Tide reviews it, then the photo is deleted and only the yes-or-no result is kept. Section 3 has the detail.Private Supabase Storage, then deleted
Match & compatibility-answer dataYour answers to compatibility questions and your daily match record, used to compute who you're matched with each day.Supabase Postgres
Usage eventsA short first-party log of what happens in the app, such as signing in, opening a chat, sending a message, creating a post, and revealing a match, so we can tell whether Tide is working. It records the event name and your account, not the contents of your messages or posts. This is first-party, there is no third-party analytics SDK.Supabase Postgres
Crash diagnosticsThe raw Apple MetricKit crash report gathered by the operating system and uploaded on the next launch after a crash, so we can fix bugs. This is first-party, there's no third-party crash-reporting SDK.Supabase Postgres

We do not collect: your contacts, your browsing activity, advertising identifiers, or any payment information. We do not track you in the background and we do not build a location history.

Location (Campus Deals only). Campus Deals is the one feature that uses your location, and only while you're using it. When you open the deals map, your device location is used to show what's near you. When you redeem a deal that requires you to be at the store, it's used once to check that you actually are. Your coordinates are not retained: they're used in the moment and then discarded, never written to your profile. The only thing kept alongside a redemption is a coarse distance result, a bucket such as "within 100 m", which is enough for a vendor to trust the redemption without us keeping any record of where you were. Location is optional, deals that don't require it work without it, and you can turn the permission off at any time in your device settings.

3. Student ID verification

Getting the Verified badge is optional. You can sign up, get your daily match, chat, make friends, and post without it. It unlocks a few extras: putting a photo on a post, redeeming a Campus Deal, where the local business wants to know the discount is going to a real student, and earning extra entries in a campus giveaway.

If you do want the badge, here is exactly what happens. Your phone reads the ID first and checks it looks like a student ID. Then the photo is uploaded to a private storage bucket that no other student can read. A person at Tide (today that is the founder) looks at it and decides yes or no. Once that decision is made, the photo is deleted. That deletion is automatic, not something anyone has to remember: an hourly job removes the photo of any request that has already been decided. What we keep afterwards is the outcome: a yes-or-no flag on your account, the date it was decided, a one-line note from the on-device check (something like "campus name found: yes"), and, if the answer was no, a short reason so you know what to fix. We do not keep your ID number, your photo, or anything else printed on the card.

The photo is never shown to other students, never used for matching, and never shared with advertisers or anyone outside Tide. If you change your mind before a decision is made, email us and we'll delete the upload.

4. Who processes your data

Tide uses infrastructure providers to run the app. None of them are given your data for their own purposes:

  • Supabase, hosts our database, file storage, and authentication. Your profile, posts, chats, matches, push token, and crash diagnostics are stored here.
  • Apple (APNs), Apple's Push Notification service delivers notifications to iPhones. Apple receives only the payload needed to deliver the notification.
  • Google Firebase (FCM), does the same job for Android phones. Every Android notification from Tide goes through it, and Google receives only what's needed to deliver the notification.
  • Cloudflare, hosts tidecampus.com and the web app and sits in front of our traffic. Like any web host, it processes the network requests your browser makes, including your IP address.
  • Resend, our email delivery provider. It sends the email Tide sends you, such as your sign-in code and waitlist mail, so it handles your email address and the contents of that message.
  • OpenStreetMap, supplies the map tiles behind Campus Deals on the web app and on Android. When the map draws, your device requests those tiles directly from OpenStreetMap's servers, so they see your IP address and which part of the map you're looking at. We send them nothing else, and the map only loads if you open Campus Deals.
  • Apple Maps, draws the Campus Deals map on iPhone instead of OpenStreetMap. Same shape: your device talks to Apple to draw the map, and only when you open Campus Deals.
  • Google Fonts, serves the typefaces this site and the web app use. Your browser fetches them from Google on page load, so Google sees your IP address.

We do not sell your data, we do not share it for advertising, and we use no third-party advertising or analytics SDK.

5. How we protect your data

  • What your account can reach. Row Level Security on the backend decides what every request is allowed to touch, so you can only read and write the data your own account is part of. You can't pull another student's private data, and you can't read a chat you're not in. Campus feeds, events, and class group chats are scoped to your own school.
  • Meeting people at other campuses. Matches and friendships are the deliberate exception, because a nearby school is still a place you can meet people. Your daily match can be a student at another campus, and anyone can send you a friend request with your 5-digit code. The Only my campus can add me toggle where you add friends limits who can add you by code. It does not limit your daily match, which can still be someone at another school.
  • Session security. Your sign-in session is stored securely on your device (the Keychain on iOS).
  • Encryption in transit. All traffic between the app and the backend uses HTTPS.

6. Data retention & your rights

  • Sign out at any time from the Profile tab.
  • Disable reminders at any time; this stops collection and use of your push token.
  • Request deletion of your account and associated data by emailing [email protected]. We'll delete your profile, posts, chats, match data, push token, and crash diagnostics, subject to any legal retention we're required to keep.
  • Access / correction. You can edit your profile (name, bio, major, interests, avatar) in-app at any time, and you may request a copy of your data via the contact email.

We retain your data for as long as your account is active. Crash diagnostics are retained only as long as needed to investigate and fix the underlying issue.

7. Students & age

Tide is gated to verified .edu campus email holders and is intended for college/university students. It is not directed at children under 13. If you believe a child has provided us data, contact us and we'll remove it.

8. Browser extension (Tide Campus for Chrome)

Tide Campus is an optional Chrome extension. It is a read-only companion to the web app: it cannot post, comment, vote, or send messages, and it never signs you in.

  • How it gets access. A script that runs only on tidecampus.com/app pages reads the session you already created by signing in there, and hands the extension your access token, its expiry, and your user id. Your refresh token is deliberately never stored by the extension.
  • What it keeps on your device. In your browser's local extension storage: that access token, a cached copy of up to 20 recent chat rows (including the one-line preview of the most recent message), two bookkeeping timestamps, a "last seen" marker used to count unread chats, your on/off choice for the 8pm reminder, and the id of the Tide window it opened. None of it is uploaded, and nothing is written to Chrome's sync storage.
  • Where data travels. The extension makes read-only HTTPS requests to Tide's own backend (hosted on Supabase, see section 4) to fetch your daily match, your chats, and your campus feed. It sends data nowhere else: no ad networks, no data brokers, no third-party analytics.
  • Notifications. At most one local notification a day, at 8pm your time, when the daily drop goes live. It is generated on your own device, no push service is involved, and you can switch it off in the extension's popup.
  • Clearing it. Signing out of Tide on tidecampus.com in that browser clears the cached chats. Removing the extension deletes everything it stored. An install left unused clears its cached chats once the stored session is more than seven days past expiry.

9. Changes to this policy

We may update this policy as Tide evolves. Material changes will be reflected in the effective date above and, where appropriate, surfaced in-app.

10. Contact

Privacy questions or requests:

✉️ [email protected]
← Back to tidecampus.com
tide

Your whole campus, finally social. Made for students, verified with .edu, never sold to anyone.

tidecampus.com
Product
Features Daily Tide The app Download
Legal
Privacy Terms Safety Child Safety Contact
© 2026 Tide. Built for students, by students.
Made with 🌊 on campus