Revision: 2026-08-21 · Last updated: 2026-08-21
Archived version. This is Privacy Policy revision 2026-08-21, last updated 2026-08-21. Read the current Privacy Policy.
Privacy Policy
Last updated: 2026-08-21
Tape captures your conversations and writes them up for you. Your audio and its transcript stay on your device. This policy explains the limited information Tape ("Tape," "we," "us") collects, what we do with it, and the choices you have.
The short version
- Your audio and transcripts live on your device. Transcription runs on your device with an on-device model; audio is never uploaded to us.
- Summaries send transcript text off your device. For signed-in accounts that include summaries, a summary is generated after each capture. With Tape's managed summarizer, the transcript goes through the Tape server to Google's enterprise Gemini and is discarded once the summary is written. With your own provider key, it goes directly from your device to the Anthropic, Google, or OpenAI API you chose, under your own account, never through Tape's servers.
- Optional integrations you control: a read-only local connector for Claude Code and Codex (the assistant reads your tapes only when you ask it something that needs them), Google Docs in your own Google Drive, and Backup & Sync through your own Google Drive. None of these pass through Tape's servers.
- The account information we hold is small: your name and email from sign-in, encrypted authorization tokens, plan status, and usage metadata. Signed-in analytics may be linked to your account so we can operate the service and help you — never to your conversation content.
We don't claim "nothing ever leaves your device": summaries and the optional integrations above send content where you choose. This policy describes exactly what happens.
1. Who we are
Tape is provided by Tape, based in Israel. For privacy questions, or to exercise your rights, contact us at or@usetape.app.
For users in the European Economic Area (EEA), the United Kingdom, or Switzerland, Tape is the data controller for the account and usage data described here. For conversation content you choose to send for a summary or to store in your own Google Drive, you decide what to send, and Tape processes it only on your instruction.
2. What stays on your device — always
The following stays on your device and is not sent to us to operate Tape:
| Stays on device | Where it lives |
|---|---|
| The audio you capture | On your device, protected by your device's encryption settings (data protection on iPhone, FileVault on Mac) |
| The transcript | On your device, same protection |
| Speaker labels, your edits, your notes | On your device, same protection |
Turning speech into text runs entirely on your device. If you're signed out, or summaries aren't enabled for your account, no conversation content leaves your device through Tape.
One exception you control — Backup & Sync. If you turn on Backup & Sync (it's off by default), Tape keeps a copy of your library in your own Google Drive account, in a hidden app-only area, and uses it to keep your Tape devices in sync: complete tapes and their transcripts, summaries, notes, speaker labels and people, the linked calendar event, chat, and kept audio travel between your devices through that Drive area, and a new or replaced device recovers the latest synced state from it. Deleting a tape on one device removes it from every synced device and from Drive. The backup lives under your own Google storage; Tape's servers do not receive or hold it. It is encrypted by Google at rest but is not end-to-end encrypted. You can turn Backup & Sync off on a device (the Drive copy stays for your other devices), delete the whole backup from Google Drive in Tape's settings, or remove it yourself in Google Drive under "Manage apps".
Another exception you control — Google Docs. If you connect Google Drive for documents, Tape sends the title, date, duration, people, summary, notes, and transcript of a completed tape directly from your device to your own Google Drive as a Google Doc. Audio and chats are not included. New completed tapes are added automatically unless you turn that setting off; adding older tapes is a separate choice. The documents remain private until you share them or authorize another service to access them through Google Drive. Turning the feature off leaves existing documents in Drive. Tape's servers do not receive or hold these documents.
Recording and consent
Tape is a tool you control — you decide when to capture a conversation. Where the law requires consent from other participants before a conversation is captured or transcribed, obtaining that consent is your responsibility (see the Terms of Service, Section 4). Any on-screen indicator Tape shows while capturing is a courtesy to the people around you, not a substitute for the consent the law requires.
3. Information we collect
Providing personal data is voluntary — there's no legal duty to provide it; without it, the signed-in features simply won't work.
Account information
When you sign in with Google or Apple, we receive your name (when available), email address, and the identifiers needed to keep you signed in. Google may also provide your profile image; Apple may provide a private relay address instead of your personal email. We never receive your Google or Apple password. Authorization tokens we hold are encrypted at rest; an Apple authorization is kept only so Tape can revoke it if you delete your account.
Terms acceptance record
When you accept our Terms of Service and Privacy Policy, the app records which version you accepted and when. If you sign in, that record (version and timestamp only) is stored with your account and deleted with it.
Plan record
Your account stores its plan or trial status, period dates, billing provider, and the provider identifiers needed to connect a purchase to your Tape account. These are billing references, not card details.
Calendar connection (only if you connect a calendar)
If you connect Google Calendar, our server stores your calendar authorization tokens (encrypted at rest), the calendar's email address, and your sync preferences. We use them only to fetch your upcoming events and return them to your device. We do not store your calendar events.
Usage and diagnostics
We collect metadata about how Tape performs: feature usage, timings, model and token metadata, success/failure and error codes, app/build/platform, device type and OS version, locale, network type, and random installation and session identifiers. Crash reports include stack frames and exception metadata. When you complete the onboarding questions, analytics also includes your fixed-choice answers (how you found Tape, what you do, how you expect to use it); there are no free-text answers.
When you're signed in, this metadata may be linked to your account ID and email so we can recognize participants, understand how individual users experience Tape, investigate problems, and provide support. We do not attach your name, audio, transcript, notes, or conversation content to analytics or diagnostics, and we do not enrich records with IP-based location.
Product analytics and a small set of operational and diagnostic signals (for example, whether an update succeeded, or a diagnostic breadcrumb stream we can enable when investigating a problem) are collected by default on released builds. There is no in-app opt-out yet; to ask us to exclude you, email or@usetape.app.
Support and bug reports (only if you send one)
When you send a bug report from the app, we receive what you chose to include: your description, any screenshots you attached, and the debug details shown to you before you submit (app version, OS, device model, session identifiers, model and storage state — never conversation content). The report is delivered to our support inbox and internal support tools so we can review and respond to it (see Section 6), and kept while we work on it. A screenshot shows whatever was on your screen — attach one only if you're comfortable sharing it.
Website analytics
Our website (usetape.app) uses PostHog (EU region) to understand how the site is used: pages visited, scrolling, clicks, load performance, errors, and a replay of the visit. This is anonymous — there is no sign-in on the site, we don't connect a visit to a person, we don't record IP-based location, and we strip referrer and campaign parameters. PostHog stores its state in local storage rather than advertising cookies, and replays are kept for a limited period. We honor the Global Privacy Control (GPC) and "Do Not Track" signals: if either is set, the site sends no analytics or replay. We don't use advertising cookies and we don't sell your data.
Windows availability waitlist
If you ask to hear when Tape is available for Windows, we collect the email address you submit, the language of the page, the version of the notice you agreed to, and the time you joined. We use this information only to send that Windows-availability notice, prevent abuse, and honor privacy requests. It is not connected to anonymous website analytics or a Tape account. We use Google reCAPTCHA to distinguish automated submissions; Google receives the browser and request signals needed to perform that check. We store the waitlist record in Google Cloud SQL and do not send the email address to PostHog or reCAPTCHA.
Summary content
When a summary is generated, your transcript text (with the event title and participant names from your connected calendar, and any notes you add) is sent to generate the summary and then discarded — see Section 5. Your name and email are not attached to it.
What we do not collect
- ❌ Your audio (it never reaches our servers)
- ❌ Your transcripts in our database (sent only to generate a summary, then dropped)
- ❌ Readable summaries in our database. While a summary job finishes, the database briefly holds job status and a result encrypted to a one-time key generated by your device. The running service has no private device key that can decrypt that stored result. The live row is deleted when your device collects it, and swept automatically within about 35 minutes either way. Cloud SQL keeps the seven most recent successful daily automated backups (normally about seven days, but potentially longer if successful backups stop), plus up to seven days of point-in-time recovery logs. Separately created backups follow their own lifecycle. Those layers may therefore retain the already device-sealed ciphertext for those periods
- ❌ Summary request or response bodies in our application logs or analytics. Our hosting platform separately records request metadata such as URL/path/query and user-agent; Tape's client sends summary content in the encrypted HTTPS body, not in those fields
4. How we use information
We use the information above to:
- Provide the service — keep you signed in, fetch your calendar events, generate your summaries, manage your plan, and deliver app updates.
- Keep Tape reliable and safe — diagnose errors, measure performance, prevent abuse, and enforce per-user limits on cloud features.
- Improve the product, using metadata and product analytics.
- Communicate with you — service and security notices are part of using Tape; any product news or marketing is opt-in, and you can unsubscribe at any time.
- Comply with law and enforce our Terms of Service.
Our legal bases (GDPR) are performance of a contract (providing the service you signed up for), legitimate interests (reliability, security, and product improvement, balanced against your rights), consent (where you opt in, e.g. marketing email), and legal obligation where applicable.
5. Summary providers and the local connector
Summaries are generated automatically after a capture for signed-in accounts that include summaries. You choose the engine — and that choice decides where your transcript goes. If you're signed out, no summary is generated.
Tape's managed summarizer (the default). Your transcript text (with the event title, participant names, and any steering notes) is sent over an encrypted connection to the Tape server, which forwards it to Google's enterprise Gemini (Vertex AI) to write the summary and then discards it. Under the enterprise terms we use, Google is not permitted to use it to train its models, and it is not retained for other purposes. Tape's public server encrypts each queued request with a fresh one-time key before Google Cloud Tasks receives it; Google Cloud KMS wraps that one-time key, and a separate private worker decrypts the request only while processing it. The service necessarily handles readable text in memory while it forwards the request to Gemini, but does not write that text or Gemini's readable response to our database, application logs, or analytics. The database keeps content-free usage and job-status records plus the short-lived device-sealed result described above.
Emailing your summaries to yourself (optional). If you turn on "Email summaries to me," each completed managed summary is emailed to the address on your account through Amazon SES. It goes only to your own address. It's off by default.
Your own provider key (bring your own key). You can add an API key for Anthropic (Claude), Google (Gemini API), or OpenAI. The same content is then sent directly from your device to the provider you selected, under your own account with that provider; it does not pass through Tape's servers, and your key is stored on your device and sent only to its provider. These providers' current commercial API terms state that API inputs and outputs are not used to train their models. Those terms are theirs to change — your agreement with the provider you choose governs what happens to that content.
The local connector for coding assistants (optional). Tape offers a local, read-only connector for Claude Code (Anthropic) and Codex (OpenAI). You register it in that tool yourself and can remove it there at any time. When you ask the assistant something that uses it, it reads the tapes that request needs and sends that content to its provider — Anthropic or OpenAI — to answer, only per request and only what the request touches. Tape's servers are not involved, and that content is handled under your agreement with the provider. Nothing is shared automatically.
6. How we share information — and our subprocessors
We don't sell your personal data, and we don't share it for advertising. We share information only with the service providers ("subprocessors") that make Tape work, each under contract and only for the purpose described:
| Provider or service category | Role | What it receives |
|---|---|---|
| Google Cloud — Vertex AI / Gemini | Generates summaries on the managed engine | Transcript text in transit when a summary is generated; not retained or used for training under the enterprise terms we use |
| Google Cloud Tasks | Queues a summary request so it completes reliably | An encrypted task envelope; normally deleted after successful delivery or the configured active retries (about an hour), but a paused or unavailable queue can retain the ciphertext up to Google's 31-day task limit. It does not receive readable transcript or summary text |
| Google Cloud KMS | Wraps the one-time encryption key for a queued summary | A random per-task data-encryption key and integrity metadata — not the transcript or summary |
| Amazon SES (AWS) | Sends your summary emails (if you turn them on) and delivers bug reports you submit | The message content and your own email address, or the bug report content and support address, as needed to deliver the email |
| Google Calendar API | Fetches your events | Calendar queries; events return to your device and are not stored by us |
| Google Sign-In | Authentication | Identity verification; your name and email |
| Sign in with Apple | Authentication | Identity verification and authorization exchange/revocation; your name and email (or an Apple private relay address) |
| Google Cloud (Cloud Run and Cloud SQL) | Server and database hosting | Cloud Run processes your requests; Cloud SQL stores the account, plan, encrypted-token, usage, and Windows-waitlist records described above |
| Google reCAPTCHA Enterprise | Distinguishes automated Windows-waitlist submissions | The browser and request signals needed for the abuse assessment and an opaque token; never the email address submitted to the waitlist |
| Firebase Hosting (Google Cloud) | Website, API gateway, and app-update delivery | Encrypted-in-transit web/API requests, including managed-summary request bodies while proxying them to Cloud Run, plus standard request metadata such as IP address |
| PostHog | Product analytics and diagnostics (EU region) | In the app: your account ID and email when signed in, installation and session identifiers, app/device metadata, feature, error, diagnostic, and crash metadata — never conversation content. On the website: anonymous page-use data and visit replays |
| Support and internal collaboration services | Helps us organize support requests and operational alerts | The support report and contact details you choose to send; internal operational metadata |
| Cloudflare | Domain name service (DNS) | DNS lookups for our domain |
| Polar | Merchant of record and hosted checkout for web and Mac subscriptions | An account identifier from Tape, and subscription/purchase status back. Polar's checkout separately collects the contact, billing, tax, and payment details needed to complete the purchase; Tape never receives your full card details |
| Apple App Store | App distribution and iPhone subscriptions | Apple handles your payment account; Tape receives signed transaction and subscription status needed to activate Plus, never your payment details |
If you use your own provider key or the local connector: your content goes directly to Anthropic, Google, or OpenAI under your own account with that company. On those paths the provider is your processor, not Tape's subprocessor, and your data is handled under your agreement with it.
If you turn on Backup & Sync: your backup travels directly from your device to your own Google Drive account (Section 2); Google is your storage provider on that path, not Tape's subprocessor. Tape's servers keep only a small restore record — an opaque identifier for the backup's Drive workspace, the Google account identifier it is pinned to, and when that pointer last updated — never the Google email address or backup contents.
If you connect Google Drive for documents: the completed-tape fields travel directly from your device to Google Docs in your own Drive (Section 2). Tape's servers receive no document contents or identifiers. If you later let an AI service access those documents through Google Drive, that is between you, Google, and the service you chose.
We may also disclose information if required by law, to protect rights and safety, or as part of a business transfer (merger or acquisition), in which case we'll honor the commitments in this policy.
Google API Services User Data Policy (Limited Use)
Tape's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve Tape's user-facing features. We never use it for advertising, and we never sell it or transfer it to data brokers.
Because a summary can include the linked event's title and participant names from your connected Google Calendar, that calendar-derived data may be sent, together with your transcript and only when a summary is generated, to the AI provider that writes the summary (Section 5). Tape does not use it to train any model.
7. Data retention
- Audio: kept on your device under your control; we never hold it.
- Transcript and notes sent for a managed summary: encrypted while queued, handled in readable memory only while the summary runs, and then discarded; never written to our database, application logs, or analytics. The encrypted queued task is normally deleted within about an hour; Google's provider ceiling is 31 days if a queue is paused or unavailable.
- Summary-job result: the readable result exists in worker memory long enough to return or email it. The live database keeps only device-sealed ciphertext until pickup or the roughly 35-minute expiry. Cloud SQL keeps the seven most recent successful daily automated backups (normally about seven days, but potentially longer if successful backups stop), plus up to seven days of point-in-time recovery logs. Separately created backups follow their own lifecycle; those layers can retain the already device-sealed ciphertext for those periods.
- Content sent with your own provider key or read through the local connector: goes from your device to the provider you chose; Tape's servers aren't involved and we keep nothing.
- Account, sign-in grants, calendar connection, plan, and usage records: kept while your account is active and removed when you delete your account, except where we must retain limited records to meet legal obligations. Short-lived sign-in records are deleted when used or expired.
- Windows waitlist: kept until we send the Windows-availability notice or you ask us to delete it; deleted within 30 days after the notice is sent.
- Usage counters and diagnostics: metadata only. Analytics events and website replays are retained for a limited period, typically under a year, in PostHog's EU region; diagnostic logs under the service's operational retention. When you delete your account we remove your name, email, and account labels from the analytics profile; a de-identified profile keyed to a random identifier may remain in aggregate counts.
- Billing-provider notification records: a small number of provider notifications are kept without your account details, for accounting and fraud-prevention purposes, for as long as tax law requires.
- Server logs: application-emitted fields are metadata only. Hosting request logs also contain URL/path/query and user-agent metadata, retained under the provider's operational settings.
8. How we keep your data secure
- On-device data is protected by your device's encryption.
- Authorization tokens we hold are encrypted at rest and are never exposed to the app.
- All network traffic uses encrypted connections; sessions are short-lived and revocable.
- Queued summary requests are envelope-encrypted with a fresh per-task key; the public API and private worker have separate identities and split encrypt/decrypt permissions.
- Among runtime identities only the private worker has decrypt permission. The standing production cloud Owner retains direct administrative queue-read and key-decrypt authority.
- Gemini implicit caching is disabled for our project, and prediction request/response content logging is not enabled.
- Our application logs and analytics omit summary request and response bodies; these limits are enforced in code and checked automatically before we ship. Platform request logs retain the request metadata described above.
No method of storage or transmission is 100% secure, but we work to protect your information and to limit how much we hold in the first place. If a security incident affects your personal data, we'll notify you and the relevant authorities as required by law.
9. Your privacy rights
Depending on where you live, you have some or all of the following rights over your personal data. Because your conversations live on your device, you already control most of your content directly — the rights below apply to the limited account data we hold.
Everyone
- Access a copy of the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and associated data (see Section 10).
- Withdraw consent where we rely on it (for example, marketing email).
- Ask us to exclude you from product analytics by emailing or@usetape.app; on the website, we honor Global Privacy Control (GPC) and "Do Not Track" automatically.
- Opt out of marketing email at any time; you'll still get essential service and security notices.
EEA / UK / Switzerland (GDPR)
In addition to the above: the right to restrict or object to processing, the right to data portability, the right not to be subject to decisions based solely on automated processing with legal effects, and the right to lodge a complaint with your local supervisory authority.
California (CCPA/CPRA)
The right to know what we collect and how it's used, to delete, to correct, and to opt out of sale or sharing — we do not sell or share your personal data, and we do not use sensitive personal data for purposes requiring an opt-out. We will not discriminate against you for exercising these rights.
Israel (Privacy Protection Law)
The right to review the personal data we hold about you, to request its correction or deletion, and to contact us with concerns.
To exercise any right, email or@usetape.app. We'll verify your request and respond within the period required by applicable law. You may use an authorized agent where the law allows.
10. Deleting your account and data
- Your conversations: delete individual tapes in the app, or remove the app and its on-device data, at any time.
- Your account: you can delete your account and the server-side data tied to it. Deletion cascades — your account record, encrypted sign-in grants, calendar connection (and its encrypted tokens), plan record, and usage counters are removed. If you used Sign in with Apple, Tape first attempts to revoke that authorization; if it can't, deletion still proceeds and Tape directs you to remove the authorization in your Apple Account settings.
- Your backup and subscription: if Backup & Sync was ever set up, account deletion also removes the Drive backup (using the restore record described in Section 6, so it works even from a device that was disconnected) and then revokes Tape's Drive authorization. Google Docs created by Tape stay in your Drive. A Plus subscription bought through Polar is cancelled as part of deletion; a subscription bought through the App Store is managed by Apple, and you cancel it in your Apple Account settings — deleting your Tape account does not cancel it.
11. International data transfers
We're based in Israel. Our server and database run in Google Cloud's Israel region. Summary requests are queued in the EU and processed by Google's global Gemini endpoints, which may route to other regions; summary emails are sent from the EU. Our other providers (Anthropic, OpenAI, Apple, Cloudflare, Polar, and PostHog) may process data in the United States, the European Union, and other regions. Israel benefits from a European Commission adequacy decision, so transfers from the EEA to Tape do not require additional safeguards; where a provider processes data outside the EEA we rely on its Standard Contractual Clauses or an equivalent mechanism.
12. Children
Tape is not directed to children. You must be at least 16 years old (or the minimum age of digital consent in your country) to use Tape. We don't knowingly collect personal data from children under that age; if you believe a child has provided us data, contact or@usetape.app and we'll delete it.
13. Changes to this policy
We may update this policy as Tape evolves. When we make a material change, we'll update the "Last updated" date and, where appropriate, notify you in the app or by email. Significant new uses of your data will be introduced with clear notice and, where required, your consent.
14. Contact us
Questions, requests, or concerns:
Tape or@usetape.app