Privacy Policy
Last updated: July 7, 2026
The short version
Your practice data stays on your device. If you turn on the optional device sync or auto-backup, an end-to-end encrypted copy is stored on our server - encrypted with a key that never leaves your devices, so we cannot read it. We collect nothing else: no accounts, no analytics, no tracking.
Data collection
We do not collect any personal information. No account creation is required. No email, no name, no location, no usage analytics, no device identifiers. We don't know who you are and we don't want to. If you enable device sync or auto-backup, our server stores a randomly generated sync identifier and your encrypted data - neither is linked to your identity in any way.
Data storage
All your practice data - goals, tasks, logs, and settings - is stored locally on your device. The app works entirely offline. Unless you enable the optional device sync or auto-backup described below, no copy of your data exists anywhere else - and even with those on, we have no way to read it.
Sharing features
When you share a goal template via link or QR code, a copy of the template (task names and configuration only - no personal data or logs) is temporarily stored on our server so others can import it. No information about you is attached to shared templates.
Device sync
Sync between your own devices is optional and off by default. When you turn it on, your practice data is encrypted on your device with AES-256 before it is uploaded. The encryption key is derived from a secret that is exchanged only directly between your devices (via QR code or pairing code) and is never sent to us - so we store your data but cannot decrypt or read it. The synced copy is kept until you tap "Delete Synced Data" in Settings → Device Sync, and it is automatically removed from our server after about 6 months of inactivity. Unpairing a device removes the key from that device.
Automatic backups
Auto-backup is optional and off by default. When you turn it on, the app uploads backups of your practice data to our server, encrypted on your device with the same end-to-end encryption and the same key as device sync - so we cannot read your backups either. The server keeps only your three most recent backup versions; older ones are deleted automatically. You can delete individual backups in Settings → Auto-Backup at any time, and backups are removed from our server together with synced data after about 6 months of inactivity. Your recovery key is the only way to restore a backup on a new device - it is never sent to us, so keep it safe.
Third-party services
The app uses Apple's App Store and Google Play for purchases. These platforms may collect their own data according to their respective privacy policies. We do not receive or store any payment information.
Tracking & analytics
We do not use any analytics, tracking, or advertising frameworks in the app. No cookies, no fingerprinting, no telemetry.
Children's privacy
Because we can't read synced or backed-up data and collect nothing else from anyone, there are no special concerns regarding children's privacy.
Changes to this policy
If this policy ever changes, we'll update this page. Given that we don't collect data, we don't expect it to change much.
Contact
Questions? Reach out at support@tapastracker.app