Skip to content
tape

Revision: 2026-08-20 · Last updated: 2026-08-20

Archived version. This is Privacy Policy revision 2026-08-20, last updated 2026-08-20. Read the current Privacy Policy.

Privacy Policy

Last updated: 2026-08-20

Tape captures your conversations and writes them up for you. Your audio and its transcript stay on your device. This policy explains the limited information Tape ("Tape," "we," "us") collects, what we do with it, and the choices you have.


The short version

  • Your audio and transcripts live on your device. Transcription runs on your device with an on-device model; audio is never uploaded to us.
  • Summaries send transcript text off your device. For signed-in accounts that include summaries, a summary is generated after each capture. With Tape's managed summarizer, the transcript goes through the Tape server to Google's enterprise Gemini and is discarded once the summary is written. With your own provider key, it goes directly from your device to the Anthropic, Google, or OpenAI API you chose, under your own account, never through Tape's servers.
  • Optional integrations you control: a read-only local connector for Claude Code and Codex (the assistant reads your tapes only when you ask it something that needs them), Google Docs in your own Google Drive, and Backup & Sync through your own Google Drive. None of these pass through Tape's servers.
  • The account information we hold is small: your name and email from sign-in, encrypted authorization tokens, plan status, and usage metadata. Signed-in analytics may be linked to your account so we can operate the service and help you — never to your conversation content.

We don't claim "nothing ever leaves your device": summaries and the optional integrations above send content where you choose. This policy describes exactly what happens.


1. Who we are

Tape is provided by Tape, based in Israel. For privacy questions, or to exercise your rights, contact us at or@usetape.app.

For users in the European Economic Area (EEA), the United Kingdom, or Switzerland, Tape is the data controller for the account and usage data described here. For conversation content you choose to send for a summary or to store in your own Google Drive, you decide what to send, and Tape processes it only on your instruction.


2. What stays on your device — always

The following stays on your device and is not sent to us to operate Tape:

Stays on deviceWhere it lives
The audio you captureOn your device, protected by your device's encryption settings (data protection on iPhone, FileVault on Mac)
The transcriptOn your device, same protection
Speaker labels, your edits, your notesOn your device, same protection

Turning speech into text runs entirely on your device. If you're signed out, or summaries aren't enabled for your account, no conversation content leaves your device through Tape.

One exception you control — Backup & Sync. If you turn on Backup & Sync (it's off by default), Tape keeps a copy of your library in your own Google Drive account, in a hidden app-only area, and uses it to keep your Tape devices in sync: complete tapes and their transcripts, summaries, notes, speaker labels and people, the linked calendar event, chat, and kept audio travel between your devices through that Drive area, and a new or replaced device recovers the latest synced state from it. Deleting a tape on one device removes it from every synced device and from Drive. The backup lives under your own Google storage; Tape's servers do not receive or hold it. It is encrypted by Google at rest but is not end-to-end encrypted. You can turn Backup & Sync off on a device (the Drive copy stays for your other devices), delete the whole backup from Google Drive in Tape's settings, or remove it yourself in Google Drive under "Manage apps".

Another exception you control — Google Docs. If you connect Google Drive for documents, Tape sends the title, date, duration, people, summary, notes, and transcript of a completed tape directly from your device to your own Google Drive as a Google Doc. Audio and chats are not included. New completed tapes are added automatically unless you turn that setting off; adding older tapes is a separate choice. The documents remain private until you share them or authorize another service to access them through Google Drive. Turning the feature off leaves existing documents in Drive. Tape's servers do not receive or hold these documents.

Recording and consent

Tape is a tool you control — you decide when to capture a conversation. Where the law requires consent from other participants before a conversation is captured or transcribed, obtaining that consent is your responsibility (see the Terms of Service, Section 4). Any on-screen indicator Tape shows while capturing is a courtesy to the people around you, not a substitute for the consent the law requires.


3. Information we collect

Providing personal data is voluntary — there's no legal duty to provide it; without it, the signed-in features simply won't work.

Account information

When you sign in with Google or Apple, we receive your name (when available), email address, and the identifiers needed to keep you signed in. Google may also provide your profile image; Apple may provide a private relay address instead of your personal email. We never receive your Google or Apple password. Authorization tokens we hold are encrypted at rest; an Apple authorization is kept only so Tape can revoke it if you delete your account.

Terms acceptance record

When you accept our Terms of Service and Privacy Policy, the app records which version you accepted and when. If you sign in, that record (version and timestamp only) is stored with your account and deleted with it.

Plan record

Your account stores its plan or trial status, period dates, billing provider, and the provider identifiers needed to connect a purchase to your Tape account. These are billing references, not card details.

Calendar connection (only if you connect a calendar)

If you connect Google Calendar, our server stores your calendar authorization tokens (encrypted at rest), the calendar's email address, and your sync preferences. We use them only to fetch your upcoming events and return them to your device. We do not store your calendar events.

Usage and diagnostics

We collect metadata about how Tape performs: feature usage, timings, model and token metadata, success/failure and error codes, app/build/platform, device type and OS version, locale, network type, and random installation and session identifiers. Crash reports include stack frames and exception metadata. When you complete the onboarding questions, analytics also includes your fixed-choice answers (how you found Tape, what you do, how you expect to use it); there are no free-text answers.

When you're signed in, this metadata may be linked to your account ID and email so we can recognize participants, understand how individual users experience Tape, investigate problems, and provide support. We do not attach your name, audio, transcript, notes, or conversation content to analytics or diagnostics, and we do not enrich records with IP-based location.

Product analytics and a small set of operational and diagnostic signals (for example, whether an update succeeded, or a diagnostic breadcrumb stream we can enable when investigating a problem) are collected by default on released builds. There is no in-app opt-out yet; to ask us to exclude you, email or@usetape.app.

Support and bug reports (only if you send one)

When you send a bug report from the app, we receive what you chose to include: your description, any screenshots you attached, and the debug details shown to you before you submit (app version, OS, device model, session identifiers, model and storage state — never conversation content). The report is delivered to our support inbox and internal support tools so we can review and respond to it (see Section 6), and kept while we work on it. A screenshot shows whatever was on your screen — attach one only if you're comfortable sharing it.

Website analytics

Our website (usetape.app) uses PostHog (EU region) to understand how the site is used: pages visited, scrolling, clicks, load performance, errors, and a replay of the visit. This is anonymous — there is no sign-in on the site, we don't connect a visit to a person, we don't record IP-based location, and we strip referrer and campaign parameters. PostHog stores its state in local storage rather than advertising cookies, and replays are kept for a limited period. We honor the Global Privacy Control (GPC) and "Do Not Track" signals: if either is set, the site sends no analytics or replay. We don't use advertising cookies and we don't sell your data.

Summary content

When a summary is generated, your transcript text (with the event title and participant names from your connected calendar, and any notes you add) is sent to generate the summary and then discarded — see Section 5. Your name and email are not attached to it.

What we do not collect

  • ❌ Your audio (it never reaches our servers)
  • ❌ Your transcripts in our database (sent only to generate a summary, then dropped)
  • ❌ Readable summaries in our database. While a summary job finishes, the database briefly holds job status and a result encrypted to a one-time key generated by your device. The running service has no private device key that can decrypt that stored result. The live row is deleted when your device collects it, and swept automatically within about 35 minutes either way. Cloud SQL keeps the seven most recent successful daily automated backups (normally about seven days, but potentially longer if successful backups stop), plus up to seven days of point-in-time recovery logs. Separately created backups follow their own lifecycle. Those layers may therefore retain the already device-sealed ciphertext for those periods
  • ❌ Summary request or response bodies in our application logs or analytics. Our hosting platform separately records request metadata such as URL/path/query and user-agent; Tape's client sends summary content in the encrypted HTTPS body, not in those fields

4. How we use information

We use the information above to:

  • Provide the service — keep you signed in, fetch your calendar events, generate your summaries, manage your plan, and deliver app updates.
  • Keep Tape reliable and safe — diagnose errors, measure performance, prevent abuse, and enforce per-user limits on cloud features.
  • Improve the product, using metadata and product analytics.
  • Communicate with you — service and security notices are part of using Tape; any product news or marketing is opt-in, and you can unsubscribe at any time.
  • Comply with law and enforce our Terms of Service.

Our legal bases (GDPR) are performance of a contract (providing the service you signed up for), legitimate interests (reliability, security, and product improvement, balanced against your rights), consent (where you opt in, e.g. marketing email), and legal obligation where applicable.


5. Summary providers and the local connector

Summaries are generated automatically after a capture for signed-in accounts that include summaries. You choose the engine — and that choice decides where your transcript goes. If you're signed out, no summary is generated.

Tape's managed summarizer (the default). Your transcript text (with the event title, participant names, and any steering notes) is sent over an encrypted connection to the Tape server, which forwards it to Google's enterprise Gemini (Vertex AI) to write the summary and then discards it. Under the enterprise terms we use, Google is not permitted to use it to train its models, and it is not retained for other purposes. Tape's public server encrypts each queued request with a fresh one-time key before Google Cloud Tasks receives it; Google Cloud KMS wraps that one-time key, and a separate private worker decrypts the request only while processing it. The service necessarily handles readable text in memory while it forwards the request to Gemini, but does not write that text or Gemini's readable response to our database, application logs, or analytics. The database keeps content-free usage and job-status records plus the short-lived device-sealed result described above.

Emailing your summaries to yourself (optional). If you turn on "Email summaries to me," each completed managed summary is emailed to the address on your account through Amazon SES. It goes only to your own address. It's off by default.

Your own provider key (bring your own key). You can add an API key for Anthropic (Claude), Google (Gemini API), or OpenAI. The same content is then sent directly from your device to the provider you selected, under your own account with that provider; it does not pass through Tape's servers, and your key is stored on your device and sent only to its provider. These providers' current commercial API terms state that API inputs and outputs are not used to train their models. Those terms are theirs to change — your agreement with the provider you choose governs what happens to that content.

The local connector for coding assistants (optional). Tape offers a local, read-only connector for Claude Code (Anthropic) and Codex (OpenAI). You register it in that tool yourself and can remove it there at any time. When you ask the assistant something that uses it, it reads the tapes that request needs and sends that content to its provider — Anthropic or OpenAI — to answer, only per request and only what the request touches. Tape's servers are not involved, and that content is handled under your agreement with the provider. Nothing is shared automatically.


6. How we share information — and our subprocessors

We don't sell your personal data, and we don't share it for advertising. We share information only with the service providers ("subprocessors") that make Tape work, each under contract and only for the purpose described:

Provider or service categoryRoleWhat it receives
Google Cloud — Vertex AI / GeminiGenerates summaries on the managed engineTranscript text in transit when a summary is generated; not retained or used for training under the enterprise terms we use
Google Cloud TasksQueues a summary request so it completes reliablyAn encrypted task envelope; normally deleted after successful delivery or the configured active retries (about an hour), but a paused or unavailable queue can retain the ciphertext up to Google's 31-day task limit. It does not receive readable transcript or summary text
Google Cloud KMSWraps the one-time encryption key for a queued summaryA random per-task data-encryption key and integrity metadata — not the transcript or summary
Amazon SES (AWS)Sends your summary emails (if you turn them on) and delivers bug reports you submitThe message content and your own email address, or the bug report content and support address, as needed to deliver the email
Google Calendar APIFetches your eventsCalendar queries; events return to your device and are not stored by us
Google Sign-InAuthenticationIdentity verification; your name and email
Sign in with AppleAuthenticationIdentity verification and authorization exchange/revocation; your name and email (or an Apple private relay address)
Google Cloud (Cloud Run and Cloud SQL)Server and database hostingCloud Run processes your requests; Cloud SQL stores the account, plan, encrypted-token, and usage records described above
Firebase Hosting (Google Cloud)Website, API gateway, and app-update deliveryEncrypted-in-transit web/API requests, including managed-summary request bodies while proxying them to Cloud Run, plus standard request metadata such as IP address
PostHogProduct analytics and diagnostics (EU region)In the app: your account ID and email when signed in, installation and session identifiers, app/device metadata, feature, error, diagnostic, and crash metadata — never conversation content. On the website: anonymous page-use data and visit replays
Support and internal collaboration servicesHelps us organize support requests and operational alertsThe support report and contact details you choose to send; internal operational metadata
CloudflareDomain name service (DNS)DNS lookups for our domain
PolarMerchant of record and hosted checkout for web and Mac subscriptionsAn account identifier from Tape, and subscription/purchase status back. Polar's checkout separately collects the contact, billing, tax, and payment details needed to complete the purchase; Tape never receives your full card details
Apple App StoreApp distribution and iPhone subscriptionsApple handles your payment account; Tape receives signed transaction and subscription status needed to activate Plus, never your payment details

If you use your own provider key or the local connector: your content goes directly to Anthropic, Google, or OpenAI under your own account with that company. On those paths the provider is your processor, not Tape's subprocessor, and your data is handled under your agreement with it.

If you turn on Backup & Sync: your backup travels directly from your device to your own Google Drive account (Section 2); Google is your storage provider on that path, not Tape's subprocessor. Tape's servers keep only a small restore record — an opaque identifier for the backup's Drive workspace, the Google account identifier it is pinned to, and when that pointer last updated — never the Google email address or backup contents.

If you connect Google Drive for documents: the completed-tape fields travel directly from your device to Google Docs in your own Drive (Section 2). Tape's servers receive no document contents or identifiers. If you later let an AI service access those documents through Google Drive, that is between you, Google, and the service you chose.

We may also disclose information if required by law, to protect rights and safety, or as part of a business transfer (merger or acquisition), in which case we'll honor the commitments in this policy.

Google API Services User Data Policy (Limited Use)

Tape's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve Tape's user-facing features. We never use it for advertising, and we never sell it or transfer it to data brokers.

Because a summary can include the linked event's title and participant names from your connected Google Calendar, that calendar-derived data may be sent, together with your transcript and only when a summary is generated, to the AI provider that writes the summary (Section 5). Tape does not use it to train any model.


7. Data retention

  • Audio: kept on your device under your control; we never hold it.
  • Transcript and notes sent for a managed summary: encrypted while queued, handled in readable memory only while the summary runs, and then discarded; never written to our database, application logs, or analytics. The encrypted queued task is normally deleted within about an hour; Google's provider ceiling is 31 days if a queue is paused or unavailable.
  • Summary-job result: the readable result exists in worker memory long enough to return or email it. The live database keeps only device-sealed ciphertext until pickup or the roughly 35-minute expiry. Cloud SQL keeps the seven most recent successful daily automated backups (normally about seven days, but potentially longer if successful backups stop), plus up to seven days of point-in-time recovery logs. Separately created backups follow their own lifecycle; those layers can retain the already device-sealed ciphertext for those periods.
  • Content sent with your own provider key or read through the local connector: goes from your device to the provider you chose; Tape's servers aren't involved and we keep nothing.
  • Account, sign-in grants, calendar connection, plan, and usage records: kept while your account is active and removed when you delete your account, except where we must retain limited records to meet legal obligations. Short-lived sign-in records are deleted when used or expired.
  • Usage counters and diagnostics: metadata only. Analytics events and website replays are retained for a limited period, typically under a year, in PostHog's EU region; diagnostic logs under the service's operational retention. When you delete your account we remove your name, email, and account labels from the analytics profile; a de-identified profile keyed to a random identifier may remain in aggregate counts.
  • Billing-provider notification records: a small number of provider notifications are kept without your account details, for accounting and fraud-prevention purposes, for as long as tax law requires.
  • Server logs: application-emitted fields are metadata only. Hosting request logs also contain URL/path/query and user-agent metadata, retained under the provider's operational settings.

8. How we keep your data secure

  • On-device data is protected by your device's encryption.
  • Authorization tokens we hold are encrypted at rest and are never exposed to the app.
  • All network traffic uses encrypted connections; sessions are short-lived and revocable.
  • Queued summary requests are envelope-encrypted with a fresh per-task key; the public API and private worker have separate identities and split encrypt/decrypt permissions.
  • Among runtime identities only the private worker has decrypt permission. The standing production cloud Owner retains direct administrative queue-read and key-decrypt authority.
  • Gemini implicit caching is disabled for our project, and prediction request/response content logging is not enabled.
  • Our application logs and analytics omit summary request and response bodies; these limits are enforced in code and checked automatically before we ship. Platform request logs retain the request metadata described above.

No method of storage or transmission is 100% secure, but we work to protect your information and to limit how much we hold in the first place. If a security incident affects your personal data, we'll notify you and the relevant authorities as required by law.


9. Your privacy rights

Depending on where you live, you have some or all of the following rights over your personal data. Because your conversations live on your device, you already control most of your content directly — the rights below apply to the limited account data we hold.

Everyone

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and associated data (see Section 10).
  • Withdraw consent where we rely on it (for example, marketing email).
  • Ask us to exclude you from product analytics by emailing or@usetape.app; on the website, we honor Global Privacy Control (GPC) and "Do Not Track" automatically.
  • Opt out of marketing email at any time; you'll still get essential service and security notices.

EEA / UK / Switzerland (GDPR)

In addition to the above: the right to restrict or object to processing, the right to data portability, the right not to be subject to decisions based solely on automated processing with legal effects, and the right to lodge a complaint with your local supervisory authority.

California (CCPA/CPRA)

The right to know what we collect and how it's used, to delete, to correct, and to opt out of sale or sharing — we do not sell or share your personal data, and we do not use sensitive personal data for purposes requiring an opt-out. We will not discriminate against you for exercising these rights.

Israel (Privacy Protection Law)

The right to review the personal data we hold about you, to request its correction or deletion, and to contact us with concerns.

To exercise any right, email or@usetape.app. We'll verify your request and respond within the period required by applicable law. You may use an authorized agent where the law allows.


10. Deleting your account and data

  • Your conversations: delete individual tapes in the app, or remove the app and its on-device data, at any time.
  • Your account: you can delete your account and the server-side data tied to it. Deletion cascades — your account record, encrypted sign-in grants, calendar connection (and its encrypted tokens), plan record, and usage counters are removed. If you used Sign in with Apple, Tape first attempts to revoke that authorization; if it can't, deletion still proceeds and Tape directs you to remove the authorization in your Apple Account settings.
  • Your backup and subscription: if Backup & Sync was ever set up, account deletion also removes the Drive backup (using the restore record described in Section 6, so it works even from a device that was disconnected) and then revokes Tape's Drive authorization. Google Docs created by Tape stay in your Drive. A Plus subscription bought through Polar is cancelled as part of deletion; a subscription bought through the App Store is managed by Apple, and you cancel it in your Apple Account settings — deleting your Tape account does not cancel it.

11. International data transfers

We're based in Israel. Our server and database run in Google Cloud's Israel region. Summary requests are queued in the EU and processed by Google's global Gemini endpoints, which may route to other regions; summary emails are sent from the EU. Our other providers (Anthropic, OpenAI, Apple, Cloudflare, Polar, and PostHog) may process data in the United States, the European Union, and other regions. Israel benefits from a European Commission adequacy decision, so transfers from the EEA to Tape do not require additional safeguards; where a provider processes data outside the EEA we rely on its Standard Contractual Clauses or an equivalent mechanism.


12. Children

Tape is not directed to children. You must be at least 16 years old (or the minimum age of digital consent in your country) to use Tape. We don't knowingly collect personal data from children under that age; if you believe a child has provided us data, contact or@usetape.app and we'll delete it.


13. Changes to this policy

We may update this policy as Tape evolves. When we make a material change, we'll update the "Last updated" date and, where appropriate, notify you in the app or by email. Significant new uses of your data will be introduced with clear notice and, where required, your consent.


14. Contact us

Questions, requests, or concerns:

Tape or@usetape.app

Windows waitlist

Leave your email and we’ll tell you when Tape is ready for Windows.

We’ll use your email only for this update. Privacy Policy