Privacy Policy
Effective date: September 2, 2026 · Last updated: September 2, 2026
TidalRun LLC ("we," "us," or "our") operates TidalRun and the website at tidalrun.com (together, the "Service"). This policy explains what personal information we collect, how we use it, who we share it with, and the choices available to you.
You can reach us at hello@tidalrun.com.
1. Information we collect
Information you give us
Account information. If you sign in to our application, we create an account for you. Sign-in is handled through Google, and when you authorize it Google provides us your name, email address, profile picture, and the identifier Google uses for your account. We keep those together with basic account records, such as when your account was created and when you last signed in. We do not receive your Google password, and we cannot see anything else in your Google account.
Contact and inquiry information. If you email us or submit a form on our website, we receive your name, email address, and whatever you include in your message.
Demo bookings. When you book a meeting with us, we collect your name, email address, and the details you provide about your institution — your role, roughly how many students you support, which student populations you focus on, and anything you tell us you'd like the meeting to cover. Scheduling is handled by Google Calendar's appointment scheduling, so this information is also stored in Google's systems and in the resulting calendar invitation.
Information collected automatically
Server and security logs. IP address, browser type, and request metadata, generated automatically when you connect to the Service and used by us and our infrastructure providers for security, abuse prevention, and diagnosing errors.
Usage data. We do not currently use any analytics service on this website. If we add one, it will be a service that operates without cookies, assigns no persistent identifier, and does not follow you across other websites, and we will update this policy before it goes live.
Information we do not collect
We do not collect payment card details. We do not buy personal information from data brokers, and we do not build advertising profiles.
Information our customers submit
If you use the Service as part of an organization, that organization may submit information about you, and content you provide may include information about other people. In those cases the organization decides what is collected and how it is used, and we process that information on its behalf under our agreement with it. Direct requests about that information to the organization, not to us — though we will assist them in responding.
Where an educational institution designates us as a school official with a legitimate educational interest under FERPA, we act under the institution's direct control with respect to education records, use them only for the purposes the institution authorizes, and do not re-disclose them except as the institution directs. The specific terms are set out in our written agreement with the institution.
This policy describes information we collect and control ourselves: from visitors to our website, and from people who contact us or book a meeting.
2. How we use information
We use personal information to:
- Provide, operate, secure, and maintain the Service
- Sign you in, keep you signed in, and give your account access to the features it is entitled to
- Respond to inquiries, bookings, and support requests
- Send you information about our products, features, and services, including follow-up messages after you contact us or book a meeting
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Comply with legal obligations
You can opt out of promotional messages at any time using the unsubscribe link in any such message, or by emailing us. We will still send transactional messages related to your bookings or support requests.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use it to serve targeted ads.
3. How we share information
We disclose personal information only in the circumstances below.
Service providers
We rely on a small number of vendors to operate the Service. Each processes information on our behalf, under contract, only for the purposes we specify, and is prohibited from using it for its own purposes. These fall into the following categories:
- Content delivery, DNS, and security providers
- Hosting and data storage providers
- Scheduling and meeting providers — currently Google Workspace, which handles demo bookings and the video meeting itself
- Analytics providers, if and when we use one
- Email delivery providers
Our providers are United States companies. Some of them, such as content delivery networks, operate global infrastructure, so information may be processed on servers outside the United States in the course of delivering the Service. We will identify our current providers on request.
Legal and safety
We may disclose information where we believe in good faith that disclosure is required by law, regulation, subpoena, or other legal process, or is necessary to protect our rights or the safety of any person.
Business transfers
If we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
4. Cookies and tracking
We do not use advertising, marketing, or cross-site tracking cookies, and we do not currently use analytics cookies of any kind.
The cookies we set are strictly necessary. If you sign in to our application, we use cookies to sign you in, to keep you signed in, and to protect the sign-in itself against misuse. They are not used for advertising or analytics and are not shared with other sites, and signing out ends your session. Our content delivery and security provider may also set security cookies, which distinguish human visitors from automated traffic and protect the Service against abuse.
Our booking tool is provided by Google. Its script and stylesheet load together with the page, so Google receives your IP address and browser information when you visit, whether or not you book. Opening the booking window loads the scheduler itself, which may set cookies governed by Google's privacy policy rather than ours.
Browsers allow you to block or delete cookies. Doing so will not affect your ability to read this site.
Do Not Track. We do not track users across third-party websites, so there is no cross-site tracking for a Do Not Track signal to disable.
5. How long we keep information
| Data | Retention |
|---|---|
| Account records | For as long as the account is open, then up to 12 months |
| Sign-in records | Up to 45 days from sign-in |
| Demo bookings and related correspondence | Up to 2 years from last contact |
| Inquiries and support correspondence | Up to 2 years from last contact |
| Server and security logs | Up to 90 days, or our hosting provider's own schedule where shorter |
These are the periods we work to. Some information sits with providers that run their own retention schedules, which we do not control — server logs held by our hosting provider, for example, or a calendar invitation in Google's systems. Where that is the case we delete what is ours to delete and the provider's schedule governs the rest.
We may retain limited records beyond these periods where necessary to comply with legal, tax, or accounting obligations, or to establish or defend legal claims.
6. Security
We use commercially reasonable technical and organizational safeguards, including encryption in transit, access controls, and multi-factor authentication on administrative accounts.
No system is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by applicable law.
7. Your rights and choices
Everyone. You may request access to, correction of, or deletion of the personal information we hold about you by emailing hello@tidalrun.com. You may opt out of non-essential email at any time using the unsubscribe link.
If you have an account, you can sign out at any time, and you can ask us to close the account and delete the information associated with it by emailing the same address. Closing an account ends your access to the application.
California residents. Under California law you may have the right to:
- Know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom we disclose it
- Request deletion of personal information we have collected from you
- Request correction of inaccurate personal information
- Not receive discriminatory treatment for exercising any of these rights
Because we do not sell personal information or share it for cross-context behavioral advertising, there is no opt-out for you to exercise.
To make a request, email hello@tidalrun.com with the subject line "Privacy Request." We will take reasonable steps to verify your identity before responding, and will respond within the period required by law. You may use an authorized agent, in which case we may ask for proof of authorization.
"Shine the Light." California Civil Code § 1798.83 allows California residents to request information about personal information disclosed to third parties for those third parties' own direct marketing purposes. We do not disclose personal information for that purpose.
8. Links to other sites
The Service may link to websites we do not operate. We are not responsible for their content or privacy practices, and this policy does not apply to them. Review the privacy policy of any site you visit through a link from ours.
9. Minors
The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us information, contact us and we will delete it.
10. Where information is processed
The Service is offered to users in the United States. Information is primarily stored and processed in the United States; where a provider's global infrastructure means it is processed elsewhere, as described in Section 3, it remains subject to this policy and to our agreements with that provider.
11. Changes to this policy
We may update this policy from time to time. We will post the revised version at this address and update the "Last updated" date above. If the changes are material, we will provide additional notice by email or through the Service before they take effect.
12. Contact
Questions about this policy, or requests about information we hold — email hello@tidalrun.com.