Skip to main content

Privacy Policy

Last updated: June 20, 2026

This Privacy Policy describes how Tidal Work LLC (“Tidal,” “we,” “us,” or “our”) collects, uses, and protects information when you use tidal.work (the “Platform”). By using the Platform, you agree to the practices described in this policy.

1. Information We Collect

1.1 Information You Provide

When you create an account or contribute to the Platform, we may collect:

  • Email address (used for account authentication and account-related messages only)
  • Password (stored only as an encrypted hash; we never store plain-text passwords)
  • Your saved priorities/preferences, if you choose to set them — associated with your account so we can calculate your personalized score
  • The content of the contributions you choose to make — anonymous experiences, policy flags (and any note you add), verifications, and company suggestions

1.2 Information We Do NOT Collect

Tidal is designed to protect your identity. We specifically do not:

  • Collect your name, employer, or any identifying professional information
  • Log your IP address in connection with contributions
  • Store any link between your account and the anonymous experiences you share
  • Display your account or identity on any contribution
  • Sell, rent, or share your personal information with advertisers

1.3 Automatically Collected Information

We may collect limited technical data to maintain and improve the Platform, including browser type, pages visited, and error logs. This data is not linked to your account or contributions. While our application does not log IP addresses, our infrastructure providers (Supabase, Vercel) may collect standard server logs as described in their respective privacy policies.

2. How We Use Your Information

We use the information we collect to:

  • Operate and maintain your account
  • Send account-related emails (e.g., email verification, password reset)
  • Detect and prevent abuse, spam, or fraudulent activity
  • Improve the Platform and understand how it is used
  • Comply with legal obligations

We do not use your information for advertising, profiling, or sale to third parties.

3. Anonymity and Contributions

Tidal is designed so that your contributions cannot be traced back to you. How we handle each type of contribution:

  • Anonymous experiences: stored with no link to your account or identity. We do not record which account posted an experience, so we cannot connect an experience to you — including in response to legal process. To limit spam, we keep a separate daily count keyed to a one-way hash of your account; this counter holds only a number and cannot be used to identify which experiences you posted.
  • Policy flags, verifications, and contribution counts: disassociated from your account using one-way cryptographic hashing (HMAC-SHA256), with different salts per data type to prevent cross-referencing. These hashes are used only to prevent abuse and to power features like your contribution count, and cannot be reversed to reveal your identity.
  • Company suggestions: stored with no account link.
  • We never display your account email or identity on any public-facing page.

While we take significant technical measures to protect your anonymity, no system is perfectly secure. We recommend not including information that could identify you or another person in any contribution you make.

4. Cookies and Tracking

The Platform uses a limited number of cookies strictly necessary for operation:

  • Essential cookies: Supabase authentication session cookies are used to maintain your login state. These are required for the Platform to function and cannot be disabled.
  • No advertising or tracking cookies: We do not use cookies for advertising, retargeting, or behavioral tracking.
  • No third-party analytics cookies: We do not embed third-party analytics services that set their own cookies.

You can manage cookie settings through your browser. Disabling essential cookies may prevent you from logging in or using authenticated features of the Platform.

5. Data Retention

We retain different categories of data for different periods:

  • Account data: Retained while your account remains active.
  • After account deletion: Personal data (email, account credentials) is removed within 30 days of your deletion request.
  • Contributions: Anonymous experiences, policy flags, verifications, and company suggestions are retained indefinitely to maintain the integrity of the Platform. Anonymous experiences carry no link to your account, so they remain on the Platform and cannot be associated with or removed by reference to your account — even by us. Flags and contribution counts are one-way hashed and cannot be traced back to you.
  • Legal obligations: Data required to be retained by law, or necessary to resolve disputes, will be retained as long as legally required.

6. Your Rights

6.1 California / CCPA

As a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: You may request a copy of the personal information we hold about you
  • Right to Delete: You may request deletion of your personal information
  • Right to Opt-Out: We do not sell personal information, so there is nothing to opt out of
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

Do Not Sell My Personal Information: Tidal does not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. No sale of personal information occurs through the Platform.

To exercise these rights, contact us at: support@tidal.work

6.2 GDPR (European Economic Area)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR). Our legal bases for processing your personal data are:

  • Consent: Where you have provided explicit consent (e.g., creating an account)
  • Legitimate interest: Where processing is necessary for our legitimate interests (e.g., preventing abuse, improving the Platform), provided those interests are not overridden by your rights

Under the GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate personal data
  • Request deletion of your personal data
  • Port your data to another service
  • Restrict the processing of your personal data
  • Object to the processing of your personal data

To exercise any of these rights, contact us at support@tidal.work. International data transfers are conducted using Standard Contractual Clauses with Supabase in accordance with GDPR requirements.

6.3 Data Portability

You may request a copy of your personal data in a structured, machine-readable JSON format. To make a data portability request, email support@tidal.work. We will fulfill your request within 30 days.

7. Data Security

We use industry-standard security measures to protect your information, including:

  • Encrypted data storage via Supabase (our database provider)
  • HTTPS encryption for all data in transit
  • bcrypt password hashing
  • One-way cryptographic hashing (HMAC-SHA256) for contributor anonymity

However, no method of transmission over the internet is 100% secure.

Breach Notification: In the event of a data breach affecting your personal information, we will notify affected users within 72 hours via email. The notification will include: the nature of the breach, the categories of data involved, the likely consequences, and the steps we are taking to mitigate the breach. If a breach affects 500 or more California residents, we will also notify the California Attorney General as required by law.

8. Third-Party Services

We use the following third-party services to operate the Platform:

  • Supabase — database and authentication (supabase.com/privacy)
  • Vercel — hosting and content delivery (vercel.com/legal/privacy-policy)
  • Logo.dev — company logo display (no user data transmitted)
  • Greenhouse, Lever, Ashby — public job-board listings (company name used to look up open roles; no user data is shared)

These providers may collect standard server logs, including IP addresses, as part of their normal infrastructure operations. We are not responsible for the privacy practices of these third parties. We encourage you to review their respective privacy policies.

9. Law Enforcement Requests

Tidal will respond to requests for user data only when presented with valid legal process, including subpoenas, court orders, or warrants. When we receive such requests:

  • We will notify affected users of the request unless we are legally prohibited from doing so
  • We practice data minimization and will only disclose data specifically required by the legal process
  • We will publish a transparency report annually summarizing the number and types of law enforcement requests received

10. Children's Privacy

The Platform is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a minor, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users by email of material changes. Continued use of the Platform after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact:

Tidal Work LLC
Email: support@tidal.work
Website: tidal.work