Now on the App Store — free to download Get Taper

Privacy Policy

Effective September 12, 2026

Taper ("Taper," "we," "our," or "us") builds an AI training coach that helps athletes plan, adapt, and understand their training. This Privacy Policy describes what information we collect, how we use it, who we share it with, and the choices you have. It applies to tapertraining.com, the Taper iOS and watchOS apps, and all related services (collectively, the "Service").

By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.

1. Information we collect

Account information

When you sign up we collect your email address and authentication credentials (managed through Supabase Auth). If you sign in via a third party such as Apple or Google, we receive the basic profile information that provider shares.

Athlete and training data

To provide coaching, the Service processes information about your training and physiology, including:

  • Workouts, planned sessions, goals, races, and training history
  • Heart rate, heart-rate variability (HRV), resting heart rate, wrist temperature, sleep, respiratory rate, VO₂ estimates, and similar metrics from Apple Health / HealthKit when you grant permission
  • Activity files and metrics imported from connected services such as Garmin Connect, Intervals.icu, or Hammerhead, including power, pace, cadence, GPS routes, and session metadata. Strava is no longer offered as a connection — see Section 6
  • Your device's location, when you grant location permission. This is used to show weather for a planned session, and — when you record or log a workout in the app — to save a single coordinate for where that session took place, so the workout can show a small map. We only save that coordinate at the time you are logging the session; we never attach your location to a workout that was imported or synced afterwards, and we never estimate it from your profile
  • Recovery, sleep, strain, and physiological metrics from wearables such as Whoop and Oura when you connect those accounts
  • Subjective inputs you enter, such as RPE, notes, soreness, mood, and schedule preferences
  • Your conversations with the AI coach, including the messages you send and the responses and plan changes they produce
  • Device and app data such as model, OS version, language, crash diagnostics, and — if you enable notifications — a push token used to deliver them
  • Your subscription status from Apple's App Store, so we know which features your account has access to. Payments are processed by Apple; we never receive your card or payment details

Usage information

We collect basic logs about how the Service is used — feature interactions, request timestamps, error traces, and diagnostic information — so we can keep the Service running and improve it.

Communications

If you email us or sign up for the waitlist, we retain that correspondence and the email address you provide.

2. How we use information

  • Generate personalized training plans, daily recommendations, and explanations
  • Adapt your plan based on recovery, fatigue, and recent performance
  • Operate, maintain, secure, and improve the Service
  • Debug issues and monitor reliability
  • Respond to support requests and send essential account notices
  • Comply with legal obligations and enforce our terms

We do not sell your personal information, and we do not use your health or training data for advertising.

3. AI processing

Taper uses third-party AI providers — currently Anthropic and OpenAI — to generate coaching responses, plan explanations, and workout analysis. When you interact with the coach — or when the Service analyzes a session — the training and health context needed to produce that result is sent to the applicable provider's API solely to generate that response.

What we send is limited to what the model needs to answer you:

  • Training history — workouts and their durations, distances, power, pace, and heart rate.
  • Recovery and health metrics from the sources you connect — sleep, HRV, resting heart rate, and similar readings.
  • Profile basics you entered — your first name (so the coach can address you), age, gender, height, weight, thresholds, training availability, and the city or region and time zone you train in, which the coach needs for scheduling and conditions.
  • Your goals, races, and plan, and the messages you write to the coach.

We do not send your email address, your password, or your payment details to an AI provider, and requests are not labelled with an account identifier the provider could use to link them to you.

We ask for your permission in the app before any of this is sent. The app shows you this disclosure — what is sent and which companies receive it — and nothing goes to an AI provider until you agree. You can review what you agreed to, and withdraw that agreement, at any time in Account → AI & your data. Withdrawing stops the transfers, which turns off coaching, plan generation, and workout analysis, because those features are generated by these models.

Under our agreements and provider data settings, our AI providers do not use your prompts or the model's responses to train their models. A provider may retain this content for a limited period (for example, up to 30 days for Anthropic) to monitor for misuse and maintain reliability, after which it is deleted. We only work with AI providers that are contractually committed or configured not to train their general models on your content. We may add, change, or remove AI providers as the Service evolves; any new provider must meet the same commitment, and we will update this policy and ask you again in the app before routing your data somewhere new.

4. How we share information

We share information only as described here:

  • Service providers that run our infrastructure and may only process data on our behalf and under contract: Supabase (database, authentication, storage, and edge functions), Vercel (web hosting), Anthropic and OpenAI (AI coaching and analysis, as described in Section 3, each under terms that require protections equivalent to those described in this policy), Cloudflare (map tiles and content delivery), Open-Meteo (weather and elevation lookups for a location you are training at), Resend (transactional email), Apple (push notification delivery, and App Store subscription status), Mixpanel (product analytics), and Sentry (error and crash monitoring).
  • Connected integrations you authorize, such as Strava or Garmin Connect. Data flows under the permissions you grant; you can disconnect any integration at any time. Strava is closed to new connections; see Section 6 for what happens with the early accounts that still have one.
  • Legal and safety: if required by law, legal process, or to protect rights, safety, or property.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, with notice where required.

5. Apple Health & HealthKit

Data read from HealthKit is used only to deliver the coaching features you request. HealthKit data is never used for advertising, sold, or shared with third parties for marketing. HealthKit data is not shared with entities that would use it for their own purposes. You can revoke HealthKit access at any time in iOS Settings → Privacy & Security → Health.

6. Strava, Garmin, Whoop, Oura & other third-party integrations

When you connect a third-party service — such as Garmin Connect, Whoop, Oura, or Intervals.icu — we access the activities, recovery metrics, sleep data, and profile information you authorize. Most connections use OAuth; for some providers (including Garmin) we securely store the credentials you supply so we can sync on your behalf. Every connection today is made directly between Taper and the provider; if we later route any of them through a health-data aggregation provider acting as our processor (for example Terra), we will update this policy first. We use this data solely to display and analyze your training inside Taper.

Strava is the exception: it is closed to new connections. Taper no longer offers Strava as a way to connect your training data, and a new account cannot connect it at all — it does not appear in onboarding or in your connection settings.

A small number of early beta accounts connected Strava while it was still offered, and those connections remain. For those accounts, and only those, Taper imports activities from Strava — including power, pace, heart rate, GPS routes, and session metadata — and stores them alongside the rest of your training data. Taper also pushes outbound: when coach notes are switched on, it adds a short summary to the description of an activity you already own on Strava. If you are one of those accounts you can disconnect Strava at any time from your connection settings, which stops all further import, and you can delete the imported activities. Once disconnected, Strava cannot be reconnected.

You can disconnect any integration at any time from within the app or from the provider's own settings; when you do, we stop ingesting new data and remove the stored tokens or credentials for that provider. Deleting your account revokes and removes all connected integrations. Each provider's own privacy policy continues to govern data you hold with them.

7. Data retention

We retain account and training data for as long as your account is active, or as needed to provide the Service. You can delete your account at any time from the app's account settings (see Section 9). When you do, we erase your training, health, chat, and account data from our systems, revoke connected integrations, and remove your stored provider tokens and credentials; residual copies in encrypted backups are purged on a rolling basis. Some records may be retained longer where required for legal, security, tax, or audit purposes.

8. Security

We use industry-standard measures to protect your data, including encryption in transit (TLS), encryption at rest for our databases, row-level security policies, and access controls. No system is perfectly secure, and we cannot guarantee absolute security.

9. Your rights and choices

  • Access & export: request a copy of the data we hold about you.
  • Correction: update inaccurate information from within the app or by contacting us.
  • Deletion: delete your account and all associated data at any time directly from the app's account settings, or by emailing us. This permanently erases your data as described in Section 7.
  • Withdraw consent: revoke HealthKit permissions, or disconnect any third-party integration, at any time.
  • Regional rights: residents of Australia have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, including the right to access and correct your personal information and to lodge a complaint with the Office of the Australian Information Commissioner (OAIC). Residents of the EEA, UK, and California may have additional rights under GDPR/UK GDPR/CCPA, including the right to object, restrict processing, and lodge a complaint with a supervisory authority.

10. Children

The Service is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

11. International transfers

Taper is operated from Sydney, Australia. If you access the Service from another region, your information may be transferred to and processed in Australia, the United States, and other countries where our providers operate.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and, where appropriate, notify you through the Service or by email. Continued use after changes take effect means you accept the updated policy.

13. Contact

Questions, requests, or concerns? Email us at privacy@tapertraining.com.