Revision: 2026-08-25-2 · Last updated: 2026-08-25
Privacy Policy
Tape captures your conversations and writes them up for you. Audio capture and transcription happen on your device by default. Optional features you enable can send or copy content to services you choose, as described below. This policy explains the limited information Tape ("Tape," "we," "us") collects, what we do with it, and the choices you have.
The short version
- Audio capture and transcription run on your device. Tape never sends audio to its own servers. If you enable Backup & Sync, a copy may be stored in your Google Drive.
- Summaries send transcript text off your device. For signed-in accounts that include summaries, a summary is generated after each capture. With Tape's managed summarizer, the transcript goes through the Tape server to Google Cloud. Readable content is used only to generate and deliver the summary; temporary encrypted copies follow the retention periods below. With your own provider key, it goes directly from your device to the Anthropic, Google, or OpenAI API you chose, under your own account, never through Tape's servers.
- Optional integrations you control: a read-only local connector for Claude Code and Codex (the assistant reads your tapes only when you ask it something that needs them), Google Docs in your own Google Drive, and Backup & Sync through your own Google Drive. None of these pass through Tape's servers.
- The account information we hold is small: your name and email from sign-in, authorization information, plan status, and usage metadata. Signed-in analytics may be linked to your account so we can operate the service and help you — never to your conversation content.
We don't claim "nothing ever leaves your device": summaries and the optional integrations above send content where you choose. The sections below explain those choices.
1. Who we are
Tape is operated by Or Git, a sole proprietor registered in Israel as an עוסק פטור. For privacy questions, or to exercise your rights, contact us at or@usetape.app.
For users in the European Economic Area (EEA), the United Kingdom, or Switzerland, Or Git is the data controller for the account and usage data described here. For conversation content you choose to send for a summary or to store in your own Google Drive, you decide what to send, and Tape processes it only on your instruction.
2. What Tape processes on your device by default
The following is created and processed on your device and is not sent to our own servers to operate Tape:
| Processed on device | Default location |
|---|---|
| The audio you capture | On your device, protected by your device's security settings |
| The transcript | On your device, same protection |
| Speaker labels, your edits, your notes | On your device, same protection |
Turning speech into text runs entirely on your device. If you're signed out, or summaries aren't enabled for your account, no conversation content leaves your device through Tape.
One exception you control — Backup & Sync. If you turn on Backup & Sync (it's off by default), Tape keeps a copy of your library in your own Google Drive account, in a hidden app-only area, and uses it to keep your Tape devices in sync. The copy includes your kept audio, transcripts, summaries, notes, chats, speaker information, and related event details. Deleting a tape removes it from your synced devices and Drive. The backup lives under your own Google storage; Tape's servers do not receive or hold it. It is encrypted by Google at rest but is not end-to-end encrypted. You can turn Backup & Sync off or delete the backup through Tape or Google Drive.
Another exception you control — Google Docs. If you connect Google Drive for documents, Tape sends a completed tape's title, transcript, summary, notes, participant details, and other tape metadata directly from your device to your own Google Drive as a Google Doc. Audio and chats are not included. New completed tapes are added automatically unless you turn that setting off. The documents remain private until you share them or authorize another service to access them. Turning the feature off leaves existing documents in Drive. Tape's servers do not receive or hold these documents.
Recording and consent
Tape is a tool you control — you decide when to capture a conversation. Where the law requires consent from other participants before a conversation is captured or transcribed, obtaining that consent is your responsibility (see the Terms of Service, Section 4). Any on-screen indicator Tape shows while capturing is a courtesy to the people around you, not a substitute for the consent the law requires.
3. Information we collect
Providing personal data is voluntary — there's no legal duty to provide it; without it, the signed-in features simply won't work.
Account information
When you sign in with Google or Apple, we receive your name (when available), email address, and the identifiers needed to keep you signed in. Google may also provide your profile image; Apple may provide a private relay address instead of your personal email. We never receive your Google or Apple password. Authorization tokens we hold are encrypted at rest; an Apple authorization is kept only so Tape can revoke it if you delete your account.
Terms acceptance record
When you accept our Terms of Service and Privacy Policy, the app records the onboarding notice version and when you accepted it. If you sign in, that record (version and timestamp only) is stored with your account and deleted with it. Later revisions of the documents are identified by their dates and revision labels; prior revisions are preserved in the public archives linked above.
Plan record
Your account stores its plan or trial status, period dates, billing provider, and the provider identifiers needed to connect a purchase to your Tape account. These are billing references, not card details.
Calendar connection (only if you connect a calendar)
If you connect Google Calendar, our server stores your calendar authorization tokens (encrypted at rest), the calendar's email address, and your sync preferences. We use them only to fetch your upcoming events and return them to your device. We do not store your calendar events.
Usage and diagnostics
We collect metadata about product use, performance, and errors, including feature and model usage, app and device information, and random installation and session identifiers. Crash reports include technical diagnostic information. Fixed-choice onboarding answers may also be included; onboarding analytics contains no free-text answers.
When you're signed in, this metadata may be linked to your account ID and email so we can recognize participants, understand how individual users experience Tape, investigate problems, and provide support. We do not attach your name, audio, transcript, notes, or conversation content to analytics or diagnostics, and we do not enrich records with IP-based location.
Product analytics and limited operational diagnostics are collected by default on released builds. There is no in-app opt-out yet; to ask us to exclude you, email or@usetape.app.
Support and bug reports (only if you send one)
When you send a bug report from the app, we receive the description, attachments, and technical diagnostic information shown to you before submission — never conversation content unless you include it yourself in an attachment or description. The report goes to our support tools and is kept while we work on it. Attach only material you're comfortable sharing.
Website analytics
Our website (usetape.app) uses PostHog (EU region) to understand how the site is used: page interactions, performance, errors, and a replay of the visit. This data is pseudonymous rather than anonymous and includes browser and session identifiers. We don't intentionally connect a visit to a named person or Tape account. We honor the Global Privacy Control (GPC) and "Do Not Track" signals: if either is set, the site sends no analytics or replay. We don't use advertising cookies and we don't sell your data.
Windows availability waitlist
If you ask to hear when Tape is available for Windows, we collect the email address you submit and a record of your request. We use it only to send that Windows-availability notice, prevent abuse, and honor privacy requests. It is not connected to website analytics or a Tape account. Google reCAPTCHA receives browser and request signals needed to detect automated submissions, but not the email address you submit.
Summary content
When a summary is generated, your transcript text (with the event title and participant names from your connected calendar, and any notes you add) is sent to the provider you selected. With Tape's managed summarizer, readable content is discarded after processing; temporary encrypted request and result copies may remain for the limited periods described in Sections 5 and 7. Your name and email are not included in the summary content sent to the model.
What we do not collect
- ❌ Your audio (it never reaches our servers)
- ❌ Your transcripts in our database (sent only to generate a summary, then dropped)
- ❌ Readable summaries in our database. A completed managed summary may remain encrypted specifically for your device for approximately 35 minutes while you collect it. Encrypted database backups may retain that ciphertext for the periods described in Section 7
- ❌ Summary request or response bodies in our application logs or analytics. Service providers may retain standard request metadata under their operational settings
4. How we use information
We use the information above to:
- Provide the service — keep you signed in, fetch your calendar events, generate your summaries, manage your plan, and deliver app updates.
- Keep Tape reliable and safe — diagnose errors, measure performance, prevent abuse, and enforce per-user limits on cloud features.
- Improve the product, using metadata and product analytics.
- Communicate with you — service and security notices are part of using Tape; any product news or marketing is opt-in, and you can unsubscribe at any time.
- Comply with law and enforce our Terms of Service.
Our legal bases (GDPR) are performance of a contract (providing the service you signed up for), legitimate interests (reliability, security, and product improvement, balanced against your rights), consent (where you opt in, e.g. marketing email), and legal obligation where applicable.
5. Summary providers and the local connector
Summaries are generated automatically after a capture for signed-in accounts that include summaries. You choose the engine — and that choice decides where your transcript goes. If you're signed out, no summary is generated.
Tape's managed summarizer (the default). Your transcript text, notes, event title, and participant names included in the request are sent through Tape's cloud service to Google Cloud. The content is handled in readable form only while generating and delivering the summary. It is not written to our database, application logs, or analytics. Under the enterprise terms we use, Google is not permitted to use it to train its models.
Tape may retain an encrypted copy of the request temporarily to complete and retry it. It is normally deleted after processing and active retries (about an hour), but in exceptional cases may remain for up to 31 days. A completed result may remain encrypted specifically for your device for approximately 35 minutes; encrypted backups follow the retention period in Section 7. We keep content-free usage and status records.
Emailing your summaries to yourself (optional). If you turn on "Email summaries to me," each completed managed summary is emailed to the address on your account through Amazon SES. It goes only to your own address. It's off by default.
Your own provider key (bring your own key). You can add an API key for Anthropic (Claude), Google (Gemini API), or OpenAI. The same content is then sent directly from your device to the provider you selected, under your own account with that provider; it does not pass through Tape's servers, and your key is stored on your device and sent only to its provider. Your agreement with the provider you choose governs how it handles that content.
The local connector for coding assistants (optional). Tape offers a local, read-only connector for Claude Code (Anthropic) and Codex (OpenAI). You register it in that tool yourself and can remove it there at any time. When you ask the assistant something that uses it, it reads the tapes that request needs and sends that content to its provider — Anthropic or OpenAI — to answer, only per request and only what the request touches. Tape's servers are not involved, and that content is handled under your agreement with the provider. Nothing is shared automatically.
6. How we share information
We don't sell your personal data, and we don't share it for advertising. We share information only with service providers and other recipients that make Tape work, for the purposes described:
| Provider or service category | Role | What it receives |
|---|---|---|
| Google Cloud | Provides cloud infrastructure and managed summary processing | The account, plan, authorization, usage, and waitlist information described above; readable summary content only while generating and delivering a managed summary; temporary encrypted request and result copies for the periods in Section 7. Summary content is not used for training under the enterprise terms we use |
| Amazon SES (AWS) | Sends your summary emails (if you turn them on) and delivers bug reports you submit | The message content and your own email address, or the bug report content and support address, as needed to deliver the email |
| Google Calendar API | Fetches your events | Calendar queries; events return to your device and are not stored by us |
| Google Sign-In | Authentication | Identity verification; your name and email |
| Sign in with Apple | Authentication | Identity verification; your name and email (or an Apple private relay address) |
| Google reCAPTCHA Enterprise | Distinguishes automated Windows-waitlist submissions | Browser and request signals needed for the abuse assessment; never the email address submitted to the waitlist |
| PostHog | Product analytics and diagnostics (EU region) | In the app: your account ID and email when signed in, installation and session identifiers, app/device metadata, feature, error, diagnostic, and crash metadata — never conversation content. On the website: pseudonymous page-use data, browser and session identifiers, and visit replays |
| Support and internal collaboration services | Helps us organize support requests and operational alerts | The support report and contact details you choose to send; internal operational metadata |
| Polar | Merchant of record and hosted checkout for web and Mac subscriptions | An account identifier from Tape, and subscription/purchase status back. Polar's checkout separately collects the contact, billing, tax, and payment details needed to complete the purchase; Tape never receives your full card details |
| Apple App Store | App distribution and iPhone subscriptions | Apple handles your payment account; Tape receives signed transaction and subscription status needed to activate Plus, never your payment details |
If you use your own provider key or the local connector: your content goes directly to Anthropic, Google, or OpenAI under your own account with that company. On those paths the provider is your processor, not Tape's subprocessor, and your data is handled under your agreement with it.
If you turn on Backup & Sync: your backup travels directly from your device to your own Google Drive account (Section 2); Google is your storage provider on that path, not Tape's subprocessor. Tape's servers keep only the backup and Google-account identifiers needed to locate and manage it, plus its last-update time — never the backup contents or Google email address.
If you connect Google Drive for documents: the completed-tape fields travel directly from your device to Google Docs in your own Drive (Section 2). Tape's servers receive no document contents or identifiers. If you later let an AI service access those documents through Google Drive, that is between you, Google, and the service you chose.
We may also disclose information if required by law, to protect rights and safety, or as part of a business transfer (merger or acquisition), in which case we'll honor the commitments in this policy.
Google API Services User Data Policy (Limited Use)
Tape's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve Tape's user-facing features. We never use it for advertising, and we never sell it or transfer it to data brokers.
Because a summary can include the linked event's title and participant names from your connected Google Calendar, that calendar-derived data may be sent, together with your transcript and only when a summary is generated, to the AI provider that writes the summary (Section 5). Tape does not use it to train any model.
7. Data retention
- Audio: kept on your device under your control; we never hold it.
- Transcript and notes sent for a managed summary: kept temporarily in encrypted form, handled in readable form only while the summary is generated and delivered, and then discarded. They are never written to our database, application logs, or analytics. The encrypted request is normally deleted within about an hour, but in exceptional cases may remain for up to 31 days.
- Completed managed summary: the readable result is handled long enough to return or email it. Our database keeps only a copy encrypted specifically for your device until pickup or the approximately 35-minute expiry. Operational backups normally retain that ciphertext for about seven days; exceptional recovery copies are deleted when no longer needed.
- Content sent with your own provider key or read through the local connector: goes from your device to the provider you chose; Tape's servers aren't involved and we keep nothing.
- Account, sign-in grants, calendar connection, plan, and usage records: kept while your account is active and removed when you delete your account, except where we must retain limited records to meet legal obligations. Short-lived sign-in records are deleted when used or expired.
- Windows waitlist: kept until we send the Windows-availability notice or you ask us to delete it; deleted within 30 days after the notice is sent.
- Usage counters and diagnostics: metadata only. Analytics events and website replays are retained for a limited period, typically under a year, in PostHog's EU region; diagnostic logs under the service's operational retention. When you delete your account we remove direct account labels; de-identified analytics may remain in aggregate records.
- Billing records: limited records may be kept for accounting and fraud prevention for as long as tax law requires.
- Server logs: application logs contain metadata only. Hosting providers retain standard request metadata under their operational settings.
8. How we keep your data secure
- On-device data is protected by your device's security settings.
- Authorization data we hold is encrypted at rest, and network traffic uses encrypted connections.
- Access to personal data is restricted to authorized services and administrators.
- Managed summary requests are encrypted while temporarily retained, and summary content is excluded from our application logs and analytics.
No method of storage or transmission is 100% secure, but we work to protect your information and to limit how much we hold in the first place. If a security incident affects your personal data, we'll notify you and the relevant authorities as required by law.
9. Your privacy rights
Depending on where you live, you have some or all of the following rights over your personal data. You directly control content kept on your device or in your Google Drive; the rights below apply to the limited account data we hold.
Everyone
- Access a copy of the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and associated data (see Section 10).
- Withdraw consent where we rely on it (for example, marketing email).
- Ask us to exclude you from product analytics by emailing or@usetape.app; on the website, we honor Global Privacy Control (GPC) and "Do Not Track" automatically.
- Opt out of marketing email at any time; you'll still get essential service and security notices.
EEA / UK / Switzerland (GDPR)
In addition to the above: the right to restrict or object to processing, the right to data portability, the right not to be subject to decisions based solely on automated processing with legal effects, and the right to lodge a complaint with your local supervisory authority.
California (CCPA/CPRA)
The right to know what we collect and how it's used, to delete, to correct, and to opt out of sale or sharing — we do not sell or share your personal data, and we do not use sensitive personal data for purposes requiring an opt-out. We will not discriminate against you for exercising these rights.
Israel (Privacy Protection Law)
The right to review the personal data we hold about you, to request its correction or deletion, and to contact us with concerns.
To exercise any right, email or@usetape.app. We'll verify your request and respond within the period required by applicable law. You may use an authorized agent where the law allows.
10. Deleting your account and data
- Your conversations: delete individual tapes in the app, or remove the app and its on-device data, at any time.
- Your account: you can delete your account and the server-side data tied to it. This removes your account, sign-in and calendar authorizations, plan record, and usage counters. You may need to remove a connected authorization separately through its provider if it cannot be revoked automatically.
- Your backup and subscription: if Backup & Sync was ever set up, account deletion also removes the Drive backup and revokes Tape's Drive authorization. Google Docs created by Tape stay in your Drive. A Plus subscription bought through Polar is cancelled as part of deletion; an App Store subscription must be cancelled in your Apple Account settings.
11. International data transfers
We're based in Israel, where our primary backend is hosted. Our providers may process data in Israel, the European Economic Area, the United States, and other countries. Israel benefits from a European Commission adequacy decision; where required, we rely on Standard Contractual Clauses or equivalent safeguards for transfers to other countries.
12. Children
Tape is not directed to children. You must be at least 16 years old (or the minimum age of digital consent in your country) to use Tape. We don't knowingly collect personal data from children under that age; if you believe a child has provided us data, contact or@usetape.app and we'll delete it.
13. Changes to this policy
We may update this policy as Tape evolves. When we make a material change, we'll update the "Last updated" date and, where appropriate, notify you in the app or by email. Significant new uses of your data will be introduced with clear notice and, where required, your consent. Previous versions remain available.
14. Contact us
Questions, requests, or concerns:
- Legal operator: Or Git
- Service: Tape
- Email: or@usetape.app
- Location: Israel