Skip to content
tape

Revision: 2026-08-13 · Last updated: 2026-08-13

Archived version. This is Privacy Policy revision 2026-08-13, last updated 2026-08-13. Read the current Privacy Policy.

Privacy Policy

Last updated: 2026-08-13

Tape captures your conversations and writes them up for you. The raw material — your audio and its transcript — stays on your device. This policy explains the limited information Tape ("Tape," "we," "us") does collect, what we do with it, and the choices you have.

We've tried to write this so it survives someone reading our code and watching our network traffic. Where the law needs precise wording, we've used it; the rest is in plain language.


The short version

  • Your audio and its transcript live on your device. They're stored on your device, protected by your device's encryption, and are never uploaded as part of normal use.
  • Transcription happens on your device. Speech becomes text using an on-device model. Your audio never leaves your device to be turned into text.
  • Summaries send conversation content off your device. They're created automatically after a capture for signed-in users whose account includes summaries; if you're signed out, no summary is generated. You choose the engine: Tape's managed summarizer (your transcript goes to Google's enterprise Gemini through the Tape server, then is discarded) or your own provider key (your transcript goes directly from your device to the Claude, Gemini, or OpenAI API you select, under your own provider account and never through Tape's servers). Either way it's sent only to write that summary, and Tape doesn't keep it.
  • If you connect Tape to Claude, Claude reads your tapes when you ask. Tape offers an optional, read-only connector for Claude. Install it, and when you ask Claude something that needs your tapes, Claude reads the ones it needs and sends that content to Anthropic to answer — only when you ask, never automatically, and never through Tape's servers. It's yours to add or remove in Claude.
  • If you connect Google Drive, Tape adds ordinary Google Docs to your Drive. New completed tapes are added automatically unless you turn that setting off; adding older tapes is a separate choice. The documents stay private until you share them or give another service Drive access. They travel directly between your device and Google and never through Tape's servers.
  • The account information we hold is small: your name and email from sign-in, encrypted sign-in and calendar authorization tokens, and usage metadata. Signed-in product analytics may be associated with your account ID and email so we can operate the beta and help when something goes wrong — never with your conversation content.

We don't claim "nothing ever leaves your device," because that wouldn't be true once summaries run, you connect Claude, or you connect Google Drive documents. Here is exactly what happens instead.


1. Who we are

Tape is provided by Tape, based in Israel. For privacy questions, or to exercise your rights, contact us at or@usetape.app.

For users in the European Economic Area (EEA), the United Kingdom, or Switzerland, Tape is the data controller for the personal data described here.


2. What stays on your device — always

The following never leaves your device to operate Tape, and we never receive it:

Stays on deviceWhere it lives
The audio you captureOn your device, protected by device encryption
The transcriptOn your device, protected by device encryption
Speaker labels, your edits, your notesOn your device, protected by device encryption

Turning speech into text runs entirely on your device. There is no "send us your audio" step. If you're signed out, or summaries aren't enabled for your account, no conversation content leaves your device through Tape.

One exception you control — backup. If you turn on backup (it's off by default), Tape uploads a copy of your library — your transcripts and kept audio — to your own Google Drive account, into a hidden app-only area, so you can get everything back on a new or replaced device. The backup goes to the Google account you choose and lives under your own storage; Tape's servers never receive or hold it. It is encrypted by Google at rest but is not end-to-end encrypted. You can turn backup off at any time, delete the backup from Tape's settings, or remove it yourself in Google Drive under "Manage apps".

Another exception you control — Google Docs. If you connect Google Drive for documents, Tape sends the title, date, duration, people, summary, notes, and transcript of a completed tape directly from your device to your own Google Drive as a native Google Doc. Audio and chats are not included. New completed tapes are added automatically unless you turn that setting off; adding tapes that were already complete is a separate choice. Tape updates only the document's marked "From Tape" section and pauses if that section was changed in Drive. Content you add after Tape's section is left untouched. The documents remain private until you share them or authorize another service to access them through Google Drive. Turning the feature off leaves existing documents in Drive. Tape's servers never receive or hold these documents.

Recording and consent

Tape is a tool you control — you decide when to capture a conversation. Where the law requires consent from other participants before a conversation is captured or transcribed, obtaining that consent is your responsibility (see the Terms of Service, Section 4). Any on-screen indicator Tape shows while capturing is a courtesy to the people around you, not a substitute for the consent the law requires.


3. Information we collect

Providing personal data is voluntary — there's no legal duty to provide it; without it, the signed-in features simply won't work.

Account information

When you sign in with Google or Apple, we receive your name (when available), email address, and the identifiers needed to keep you signed in. Google may also provide your profile image. Apple may provide a private relay address instead of your personal email. Our server completes the provider exchange and gives the app a Tape session; third-party refresh tokens are never exposed to the app. Apple authorization tokens are encrypted at rest and kept only so Tape can revoke that authorization if you delete your account. Google authorization tokens retained by Tape are also encrypted at rest.

Terms acceptance record

When you accept our Terms of Service and Privacy Policy (the notice shown when you first set up Tape), the app records which version you accepted and when. If you sign in, that record (version number and timestamp only — no device details, no IP address) is stored with your account, and is deleted with your account.

Plan record

Your account stores its plan or trial status, period dates, billing provider, and the provider identifiers needed to connect a purchase to your Tape account. These are billing references, not card details.

Calendar connection (only if you connect a calendar)

If you connect Google Calendar, our server stores your calendar OAuth tokens, encrypted at rest (AES-256-GCM), along with the calendar's email address and your sync preferences (which sub-calendars are enabled). We use these tokens only to fetch your upcoming events and return them to your device. We do not store your calendar events — they're proxied to your device and not retained on our servers.

Usage and diagnostics

We collect metadata about how Tape performs so we can keep it working: event counts, feature usage, timings, model names, token counts, success/failure, and error codes. For signed-in product analytics, we associate this metadata with your account ID and email so we can recognize beta participants, understand how individual users experience Tape, investigate problems, and provide support. Your email is stored on your PostHog person profile; it is not copied into ordinary analytics events or diagnostic logs. We do not attach your name, audio, transcript, notes, or conversation content.

  • Product analytics (which features get used) is collected by default on released builds to help us keep Tape working and improve it. It is metadata only — it never carries your conversation content. We don't currently offer an in-app opt-out; to ask us to exclude you, email or@usetape.app.
  • A small set of operational signals (for example, whether an auto-update succeeded) is reported by default, the same posture as crash reporting, so we can tell whether the app is healthy.

Support and bug reports (only if you send one)

When you send a bug report from the app, we receive what you chose to include: the category and description you wrote, any screenshots you attached, and the debug details the form shows you before you submit (app version, OS, device model, session identifiers, and the app's model and storage state — never your conversation content). The report is delivered by email to our support inbox (see Amazon SES in Section 6) and kept there while we work on the issue. A screenshot shows whatever was on your screen — attach one only if you're comfortable sharing what it shows.

Website cookies and analytics

Our website (usetape.app) uses PostHog (EU region) to understand how the site is actually used, so we can make it clearer. On the website we collect which pages are visited, how far down the page people scroll, what they click, how quickly the page loads, and any errors it hits. PostHog also builds a replay of the visit: a reconstruction of the page and how it was used (scrolling, mouse movement, clicks) that we can play back later.

This covers the website only, and it stays anonymous. There is no sign-in on the site, we never connect a visit to a person, and your IP address is dropped as it arrives. The site has no forms or text fields, so there is nothing you type for us to collect, and anything typed into a field added later is hidden before it leaves your browser. PostHog stores its state in your browser's local storage, not advertising cookies. Replays of a visit are kept for 30 days, then deleted.

We honor the Global Privacy Control (GPC) and "Do Not Track" signals your browser sends. If either is set, we collect nothing at all for your visit, replay included. We don't use cookies for advertising, and we don't sell your data. This is separate from the in-app product analytics described above.

Summary content (when a summary is generated)

When a summary is generated, your transcript text (plus the event title and participant names, which may come from your connected calendar, and any notes you add to steer it) is sent in transit to generate the summary, then discarded — to the Tape server (which holds it briefly in a delivery queue while the summary job runs) and on to Google's Gemini on the managed engine, or directly to Anthropic, Google's Gemini API, or OpenAI on a bring-your-own-key engine. Your name and email are not attached to the content sent to the AI engine. See Section 5.

What we do not collect

  • ❌ Your audio (it never reaches our servers at all)
  • ❌ Your transcripts (sent only to generate a summary you requested, then dropped)
  • ❌ Your generated summaries (returned to you, never archived on our servers)
  • ❌ Conversation content of any kind in our logs or analytics

4. How we use information

We use the information above to:

  • Provide the service — keep you signed in, fetch your calendar events, generate your summaries, and deliver app updates.
  • Keep Tape reliable and safe — diagnose errors, measure performance, prevent abuse, and enforce per-user limits on the cloud summary feature.
  • Improve the product, using metadata and product analytics.
  • Communicate with you — service and security notices are part of using Tape; any product news or marketing is opt-in, and you can unsubscribe at any time.
  • Comply with law and enforce our Terms of Service.

We process this data on these legal bases (GDPR): performance of a contract (providing the service you signed up for, including summaries), legitimate interests (reliability, security, and product improvement through metadata and analytics, balanced against your rights), consent (where you opt in to marketing email), and legal obligation where applicable.


5. Summary providers and the Claude connector

Summaries are created automatically after a capture for signed-in users whose account includes summaries. Tape's managed summarizer is a paid feature, enabled for your account rather than toggled per capture; or you can add your own provider key and summarize directly from your device. If you're signed out, no summary is generated. You choose the engine — and that choice decides where your transcript goes.

Tape's managed summarizer (the default). Your transcript text (plus the event title and participant names, which may come from your connected calendar, and any notes you add to steer it) is sent over an encrypted HTTPS connection to the Tape server, which forwards it to Google's enterprise Gemini (Vertex AI) to write the summary, then discards it. Google does not use it to train its models (a commitment of the enterprise tier), and, under an abuse-monitoring exception Google granted for Tape, Google does not log or retain the transcript or the summary, even for abuse monitoring. The Tape server keeps nothing about the summary beyond a per-day usage counter (numbers only, no content).

Emailing your summaries to yourself (optional). In Settings you can turn on "Email summaries to me." While it's on, each completed managed summary is sent to the email address on your account, delivered by our email provider Amazon SES. The email contains the summary text and is sent only to your own address — never to anyone else. This applies to the managed summarizer only; summaries made with your own provider key never reach our servers, so they are never emailed. It's off by default, and you can turn it off at any time.

Your own provider key (bring your own key). You can add an API key for Anthropic (Claude), Google (Gemini API), or OpenAI and choose a model from that provider. The same content is sent directly from your device only to the provider you selected, under your own provider account. It never passes through Tape's servers. Each key is stored in a separate slot in your device's Keychain and is sent only to its provider, never to Tape. Usage and billing are governed by your own agreement with that provider.

The commercial Anthropic and OpenAI APIs do not use API inputs or outputs to train their models by default. Google's paid Gemini API does not use prompts or responses to improve its products. These providers may keep limited content or safety records for abuse monitoring, legal compliance, or according to retention controls on your account; their current terms and settings control that handling. Tape requests no provider-side file, search, or explicit caching feature, and asks OpenAI not to store the response as application state (store: false).

The Claude connector (optional). Tape offers a local connector that lets Claude read your on-device tapes. It is read-only — it can browse and search your conversations, transcripts, summaries, and people, and it never changes or deletes anything. You install it into Claude yourself, and you can remove it there at any time. When you ask Claude something that uses it, Claude reads the tapes that request needs and sends that content to Anthropic to answer — only when you ask, per request, and only what the request touches. This path runs directly between your device and Claude: Tape's servers are not involved, and we never see what's read. Because Claude does the reading under your own Claude account, that content is handled under your agreement with Anthropic, the same as the bring-your-own-key path above. Nothing is shared automatically.


6. How we share information — and our subprocessors

We don't sell your personal data, and we don't share it for advertising. We share information only with the service providers ("subprocessors") that make Tape work, each under contract and only for the purpose described:

ProviderRoleWhat it receives
Google Cloud — Vertex AI / GeminiGenerates summaries on the managed engineTranscript text in transit only, when a summary is generated; not logged or retained (Tape holds Google's abuse-monitoring exception), never used for training
Amazon SES (AWS)Sends your summary emails (only if you turn on "Email summaries to me") and delivers bug reports you submitThe summary's text and your own email address, to deliver the message to your inbox; or, when you send a bug report, the report you wrote (with any screenshots you attached) to reach our support inbox. SES relays the message and does not retain a readable copy of it (message archiving is not enabled)
Google Calendar APIFetches your eventsCalendar queries; events return to your device and are not stored by us
Google Sign-InAuthenticationIdentity verification (ID-token exchange); your name, email
Sign in with AppleAuthenticationIdentity verification and authorization exchange/revocation; your name and email (or an Apple private relay address)
Google Cloud (Cloud Run and Cloud SQL)Server and database hostingCloud Run processes your requests in transit. Cloud SQL stores the limited account and authentication identifiers described above; encrypted Google and Apple authorization tokens; terms-acceptance, plan, and usage-counter records; and desktop sign-in handoff metadata
Google Cloud TasksQueues a summary request so it completes reliably even if your connection drops mid-wayThe same request that goes to Vertex AI (transcript text, title, participant names, any steering notes), held inside the queued job only while it runs; deleted with the job when it completes or fails
Firebase Hosting (Google Cloud)Website, API gateway, and app-update deliveryStandard web request data (e.g., IP) for the website, the gateway in front of our API server, and macOS update downloads
PostHogProduct analytics & diagnostics (EU region)In the app: signed-in account ID and email, release cohort, and metadata such as counts, timings, model, and error codes; never your name or conversation content. Email is a person-profile property, not part of ordinary analytics events or diagnostic logs. On the website: anonymous page-use detail — scrolling, clicks, performance, errors, and a replay of the visit (see "Website cookies and analytics")
CloudflareDomain name service (DNS)DNS lookups for our domain (e.g., the resolving IP address)
PolarMerchant of record and hosted checkout for web and Mac subscriptionsTape sends an account identifier and receives subscription and purchase status. Polar's hosted checkout separately collects the contact, billing, tax, and payment information required to complete the purchase. Tape never receives your full card details.
Apple App StoreApp distribution and iPhone subscriptionsApple handles your Apple payment account and payment information. Tape receives signed transaction and subscription status needed to activate Pro, never your full payment details.

If you use your own provider key or the Claude connector: the bring-your-own-key summary engine sends your content directly to Anthropic, Google, or OpenAI under the provider account you selected. The Claude connector sends content directly to Anthropic under your Claude account. On those paths the selected company is your processor, not Tape's subprocessor — Tape's servers aren't involved — and your data is handled under your agreement with that company. The subprocessors above apply to Tape's managed services.

If you turn on backup: your backup travels directly from your device to your own Google Drive account (Section 2). Google Drive is your storage provider on that path, not Tape's subprocessor — Tape's servers never receive the backup. What Tape's servers do keep is a small restore record: an opaque identifier for the backup's Drive workspace, the immutable Google account identifier it is pinned to, and when that pointer last updated — never the Google email address, device details, or backup contents.

If you connect Google Drive for documents: the approved completed-tape fields travel directly from your device to native Google Docs in your own Drive (Section 2). Google Drive is your storage provider on that path, not Tape's subprocessor. Tape's servers receive no document contents, document IDs, folder IDs, or Google account details for this capability. If you later let an AI service access those documents through Google Drive, that access is between you, Google, and the service you chose, under your agreements with them.

We may also disclose information if required by law, to protect rights and safety, or as part of a business transfer (merger or acquisition), in which case we'll honor the commitments in this policy.

A current list of subprocessors is maintained here; we'll update it as it changes.

Google API Services User Data Policy (Limited Use)

Tape's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve Tape's user-facing features. We never use it for advertising, and we never sell it or transfer it to data brokers.

Because a summary can include the linked event's title and participant names drawn from your connected Google Calendar, that calendar-derived data may be sent (in transit, alongside your transcript, only when a summary is generated) to the AI provider that writes the summary: Google's enterprise Gemini on Vertex AI, or the Anthropic, Gemini, or OpenAI API you choose on a bring-your-own-key engine. The provider's API data terms described in Section 5 apply, and Tape does not use it to train any model.


7. Data retention

  • Audio, transcripts, notes: kept on your device under your control; we never hold them. Delete them in the app, or by removing the app and its data.
  • Transcript sent for a summary: held only inside the queued summary request while the job runs (minutes at most, including any delivery retries) and discarded with the job once the summary is generated. Never written to our database, and (under Google's abuse-monitoring exception for Tape) not logged or retained by Google's Vertex AI either.
  • Content sent with your own provider key: sent from your device to Anthropic, Google's Gemini API, or OpenAI when a summary is generated. Tape's servers aren't involved and we keep nothing; the selected provider handles it under your agreement.
  • Content read through the Claude connector: sent from your device to Anthropic when you ask Claude, to answer that request. Tape's servers aren't involved and we keep nothing; Anthropic handles it under your agreement with them.
  • Account, sign-in grants, calendar connection, plan, and usage records: kept while your account is active. When you delete your account, they are removed immediately — your account record, encrypted Apple authorization grants, calendar connection and its encrypted tokens, plan record, and usage counters all cascade-delete together — except where we must retain limited records to meet legal obligations. Tape attempts to revoke an Apple authorization before removing its encrypted grant.
  • Desktop sign-in handoffs: valid for 10 minutes and contain only a hashed flow identifier, PKCE challenge, nonce, status, timestamps, and the linked user ID after a successful browser sign-in. They never contain a Tape bearer, Apple token, or conversation content. A handoff is deleted as soon as the app consumes it. Expired handoffs, including abandoned ones after their 10-minute lifetime, are deleted when a later desktop sign-in begins; linked handoffs are also deleted with the account.
  • Usage counters and diagnostics: metadata only (no conversation content). We keep them only as long as useful to operate and improve the service; analytics held by PostHog is retained under its EU-region retention settings. The email and release cohort on a PostHog person profile are removed when the Tape account is deleted.
  • Server logs: metadata only, captured by our hosting provider (Google Cloud) and retained under its operational log-retention settings.

8. How we keep your data secure

  • On-device data is stored on your device and protected by your device's encryption (iOS Data Protection / macOS FileVault).
  • Google and Apple authorization tokens are encrypted at rest (AES-256-GCM); refresh tokens never leave our server.
  • All network traffic uses encrypted HTTPS connections.
  • Sessions are short-lived and revocable, and our backend never exposes third-party refresh tokens to the app.
  • Our logs and analytics carry no conversation content — and this is enforced in code (see Section 13).

No method of storage or transmission is 100% secure, but we work to protect your information and to limit how much we hold in the first place. If a security incident affects your personal data, we'll notify you and the relevant authorities as required by law.


9. Your privacy rights

Depending on where you live, you have some or all of the following rights over your personal data. Because your conversations live on your device, you already control most of your content directly — the rights below apply to the limited account data we hold.

Everyone

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and associated data (see Section 10).
  • Withdraw consent where we rely on it (for example, marketing email).
  • Ask us to exclude you from product analytics by emailing or@usetape.app (there's no in-app toggle yet); on the website, we honor Global Privacy Control (GPC) and "Do Not Track" signals automatically.
  • Opt out of marketing email at any time via the unsubscribe link or by emailing us; you'll still get essential service and security notices.

EEA / UK / Switzerland (GDPR)

In addition to the above: the right to restrict or object to processing, the right to data portability, the right not to be subject to decisions based solely on automated processing with legal effects, and the right to lodge a complaint with your local supervisory authority.

California (CCPA/CPRA)

The right to know what we collect and how it's used, to delete, to correct, and to opt out of sale or sharing — we do not sell or share your personal data, and we do not use sensitive personal data for purposes requiring an opt-out. We will not discriminate against you for exercising these rights.

Israel (Privacy Protection Law)

The right to review the personal data we hold about you, to request its correction or deletion, and to contact us with concerns.

To exercise any right, email or@usetape.app. We'll verify your request and respond within the period required by applicable law. You may use an authorized agent where the law allows.


10. Deleting your account and data

  • Your conversations: delete individual tapes in the app, or remove the app and its on-device data, at any time.
  • Your account: you can delete your account and the server-side data tied to it. Deletion cascades — your account record, encrypted sign-in grants, calendar connection (and its encrypted tokens), and usage counters are removed. If you used Sign in with Apple, Tape first attempts to revoke that authorization. If Apple's revocation credential is no longer available, deletion still proceeds and Tape directs you to remove its authorization manually in your Apple Account settings.

11. International data transfers

We're based in Israel. Our primary server and database run in Google Cloud's me-west1 region in Israel. Our providers (Google, Anthropic, OpenAI, Apple, Amazon Web Services, Cloudflare, and PostHog) may also process data in the United States, the European Union, and other regions. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and providers' adequacy mechanisms. We've chosen our analytics region (PostHog EU) to keep diagnostic metadata in-region where practical.


12. Children

Tape is not directed to children. You must be at least 16 years old (or the minimum age of digital consent in your country) to use Tape. We don't knowingly collect personal data from children under that age; if you believe a child has provided us data, contact or@usetape.app and we'll delete it.


13. How we keep these promises true

Several promises above aren't just policy — they're enforced in our code and checked on every build: the server has no field that could store your conversation content, our logs and analytics can't carry it, and only the summary path can send content off your device. You can verify the basics yourself, too — transcription runs on-device, and the only conversation content that ever leaves is what's sent to generate a summary.


14. Changes to this policy

We may update this policy as Tape evolves. When we make a material change, we'll update the "Last updated" date and, where appropriate, notify you in the app or by email. Significant new uses of your data will be introduced with clear notice and, where required, your consent.


15. Contact us

Questions, requests, or concerns:

Tape or@usetape.app Israel

Windows waitlist

Leave your email and we’ll tell you when Tape is ready for Windows.

We’ll use your email only for this update. Privacy Policy