legal · privacy
Privacy, without vague promises.
Tappex is local-first. Optional Free text sync is designed so the relay cannot decrypt your captures. Pro cloud AI is a separate, optional data flow: when enabled, selected content is temporarily processed by Tappex and OpenAI.
01
Who this policy covers
This policy applies to the Tappex website and Tappex applications on supported Apple, Android, desktop, and browser platforms. “Tappex,” “we,” and “us” mean Daniel Schwarz, the independent developer operating Tappex from Spain.
Tappex is the data controller for account, entitlement, service-operation, and support data. A destination you choose—such as Apple, Google, Linear, Todoist, Notion, or another connected service—handles the information it receives under its own terms and privacy policy.
02
Data we process
Local captures
Text, voice recordings, links, timestamps, local classifications, and other capture data are stored on your device first. Free does not require a Tappex account for local use. If you create an account and enable encrypted text sync, supported text capture state is sent to Tappex only as ciphertext. Your operating system or computer may include local app data in a platform-managed backup; that backup is controlled by Apple, Google, or your computer provider rather than Tappex.
Account and device data
When you create an account for sync or Pro, Tappex processes:
- a pseudonymous identifier and issuer supplied by the configured sign-in provider;
- device ID, device name, platform, public encryption key, public signing key, approval state, and last-seen time;
- hashed session tokens, session expiry, subscription plan, entitlement expiry, and AI credit allowance;
- content-free AI metering such as the task type, credits charged, token counts, web-search call count, and provider response ID; and
- security and delivery metadata such as IP address, request time, request ID, response status, ciphertext size, and rate-limit events where generated by the service or its hosting edge.
The current server does not need or store your email address from Sign in with Apple.
Encrypted sync data
Approved devices encrypt supported text capture state before upload and sign their sync envelopes. The relay stores ciphertext, nonces, signatures, event sequence numbers, opaque cursors, encrypted checkpoints, and wrapped device key packages. It does not receive note plaintext, audio, attachments, vault keys, private device keys, or your recovery key. Protocol v1 does not upload audio recordings or general attachment blobs.
Support and billing data
If you contact us, we process your email address, message, and anything you deliberately attach. Do not send capture content, credentials, API tokens, vault keys, or recovery keys. App stores and payment providers process payment details; Tappex receives only the transaction and entitlement information needed to provide Pro and satisfy accounting, fraud-prevention, refund, and legal obligations.
03
Why we process it
We do not use capture content for advertising or train a Tappex model on it. Account-specific corrections may improve your own future routing only when stored inside your encrypted vault.
04
Cloud AI is an explicit exception
Pro may use OpenAI for capture analysis, structured extraction, daily review, and research with web search. Voice-note analysis can run automatically only after you enable cloud AI and after the recording has been transcribed and committed locally. Text notes are sent only when you choose Analyze or explicitly request an AI-dependent action.
The authorized app sends the minimum selected text and relevant locale or timezone to the Tappex AI gateway over TLS. The gateway checks the account, approved device, entitlement, credits, rate limits, and request bounds, then forwards the request to OpenAI. Tappex does not persist AI prompts or responses in the gateway. If you save an AI result, it becomes encrypted account data in your vault.
According to OpenAI’s API data controls, API data is not used to train OpenAI models by default. Tappex requests store: false, does not create persistent OpenAI conversations, and does not opt into API data sharing. OpenAI may still retain abuse-monitoring data for up to 30 days unless Tappex is approved for additional retention controls. We will not claim Zero Data Retention unless it is actually enabled for the production project. Web research can also transmit a query to OpenAI and involves information retrieved from third-party websites.
You can disable cloud AI without disabling encrypted sync. Doing so also disables features that require AI interpretation or research.
05
Integrations you choose
Initial integrations are designed to execute on an approved device. The device builds the provider payload and sends only the content needed for the action you requested. Tappex does not need note plaintext for integration delivery and does not manage the external object after creation.
Apple Reminders and Calendar actions use platform permissions. Other providers receive information under their own privacy policies. You can disconnect a provider or disable AI-dependent connectors. Tappex does not collect your entire contact list, calendar, browsing history, or provider account merely because an integration is available. It processes only what the operating system or provider supplies for an action you authorize.
06
Recipients and international transfers
Depending on the feature you use, data may be processed by these recipient categories:
- the configured identity provider, initially Sign in with Apple;
- OpenAI for optional cloud-AI operations and web research;
- production hosting, database, encrypted object-storage, security, and email providers;
- Apple App Store, Google Play, or another disclosed payment processor for purchases; and
- a destination provider you explicitly connect or select.
Some providers may process data outside Spain or the EEA, including in the United States. Where GDPR requires it, we rely on an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism. Regional processing is used where the selected provider and feature support it, but it does not guarantee that every item of service metadata remains in one region.
We do not sell personal data or share it for cross-context behavioural advertising.
07
Retention and deletion
- Active sync account: account metadata and encrypted relay data remain while needed to provide encrypted text sync, subject to fair-use limits and the checkpoint/history compaction policy.
- After Pro expires: Pro-only AI, integrations, automation, and the five-device allowance stop after the applicable billing grace period. Basic encrypted text sync continues under the Free fair-use policy; if more than three devices are approved, you choose which three continue syncing. Pro expiry does not start a relay-data deletion clock.
- AI gateway: Tappex does not store prompts or responses. Account-linked AI metering is kept only for the current billing month. OpenAI’s separate retention is described above.
- Operational logs: account-linked logs are deleted or de-identified within 30 days where operationally possible. Non-personal aggregate counts may be kept longer.
- Account deletion: active account data, sessions, relay ciphertext, and operational metadata are deleted within seven days; backup copies expire within 30 days.
- Billing records: limited transaction records may be retained longer when tax, accounting, fraud-prevention, or legal-claims law requires it.
- Support: correspondence is kept only as long as needed to resolve the request and meet legal obligations.
Deleting an account does not silently erase local notes from your devices and does not automatically cancel an App Store or Google Play subscription. See Delete your Tappex account.
08
Security and recovery
Tappex uses approved-device public keys, signed sync envelopes, encrypted payloads, bounded requests, hashed session tokens, rate limits, and deletion controls. No system is risk-free. The final cross-platform vault protocol and client implementations require independent cryptographic review before encrypted sync is described as production-ready.
Your recovery key is created for you to store. Tappex does not receive it. If every approved device and the recovery key are lost, Tappex cannot decrypt or restore the vault.
09
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a portable copy of your personal data; object to certain processing; withdraw consent; and appeal a privacy decision. Withdrawing consent does not affect processing that was lawful before withdrawal.
EEA users may complain to their local supervisory authority. In Spain, this is the Agencia Española de Protección de Datos. To exercise a right, email daniels@tappex.app. We may need to verify that the account is yours. We normally respond within one month, subject to legally permitted extensions.
Tappex does not discriminate against users for exercising applicable privacy rights.
10
Website data and cookies
The Tappex website does not use advertising trackers, third-party analytics, cookies, browser fingerprinting, or local storage. Fonts and website assets are served locally. Our hosting provider may process ordinary connection information such as IP address, user agent, requested path, response status, and time to deliver and secure the site.
If non-essential analytics or browser storage is introduced later, it will remain disabled until any consent required by applicable law is obtained, and this policy will be updated.
11
Children
Tappex is not directed to children under 16 and we do not knowingly create Pro accounts for them. If you believe a child has provided personal data, contact us so we can investigate and delete it where required.
12
Policy changes
We will update the effective date when this policy changes. Material changes will be explained in the app, on the website, or by another appropriate channel before they take effect when required. A privacy notice explains processing; it is not a request for blanket consent to new purposes.
13
Contact
Daniel Schwarz operates Tappex as an independent developer in Spain. For privacy, support, or legal questions, contact daniels@tappex.app.