Privacy Policy
Last updated: 09/11/2026
This Privacy Policy explains how the developer of the "Tapa" application (hereinafter — "Application", "we", "developer") collects, uses, and protects personal data of its users.
1. Data Controller
The Application is developed and maintained by an individual: Ivan Mironov.
Contact email: apptapatap@gmail.com
2. Data We Collect
The Application does not use email/password registration — users sign in via VK ID or Yandex ID. We never create or store user passwords. The only exception is a service account used by app stores (Google Play, App Store) to review the Application: it is accessed with a username and password provided to the reviewers and is not linked to any user data.
When you use the Application, we may collect the following categories of data:
- Account data: received from VK ID and/or Yandex ID upon sign-in — account identifier, name, email address, and phone number (if provided by the respective provider and you granted the corresponding permission).
- Profile data: avatar (either pulled from VK/Yandex or stored on our own server), display name.
- Usage data: habits and goals created by you and members of your groups (names, descriptions, settings), completion records, statistics and streaks.
- Physical activity data (only with your explicit permission): daily step count, if you connected Android Health Connect to auto-sync the "Steps" habit. Without your permission to access Health Connect, this data is never requested.
- Push token: a technical device identifier used to send reminders and notifications via Google Firebase Cloud Messaging.
- Technical data on server requests: IP address and standard web server logs (for security and debugging purposes).
We do not use any app-usage analytics services (Firebase Analytics or similar) and do not collect anonymized behavioral statistics beyond what is listed above.
3. Purposes of Processing
Collected data is used solely for:
- providing Application functionality and syncing data across devices;
- identifying the user within their account and signing in via VK ID / Yandex ID;
- sending push reminders about habits (only if you enabled notifications);
- syncing physical activity metrics with Health Connect (only with your explicit consent);
- providing technical support to users.
4. Legal Basis for Processing
We process your data on the following legal grounds:
- Performance of a contract — to provide the features of the Application;
- Your consent — for signing in via VK ID / Yandex ID, push notifications, and Health Connect sync (each can be turned off independently);
- Legitimate interest — to ensure the security and stability of the Application.
5. Data Storage and Transfer
The database and files (including uploaded avatars) are stored on a server that we (the developer) control ourselves, not on third-party cloud infrastructure.
We do not sell your data and do not transfer it to third parties for commercial or advertising purposes.
To provide certain features of the Application, data is shared with the following services:
- VK ID (VK LLC) and/or Yandex ID (Yandex LLC) — when you sign in to the Application through the respective service. We receive an access token and basic profile data from them (name, avatar, email and/or phone — depending on what the provider supplies and what you consented to share). We never receive or store your VK or Yandex account password.
- Google Firebase Cloud Messaging (FCM) — used solely to deliver push notifications to your device. We send the notification text and a technical device token to FCM.
- Google Health Connect (on-device, not transferred to Google's cloud) — if you enabled step sync, the Application reads data directly from your device and sends it to our server.
We may share data if required by competent government authorities in cases provided for by law.
6. Data Retention
Data is retained for the duration of your account. Upon account deletion, data is removed within 30 days, unless retention is required by law.
7. Your Rights
You have the right to:
- obtain a copy of the data we hold about you;
- correct inaccurate data;
- delete your account and associated data (available directly in the Application settings);
- turn off push notifications and Health Connect sync at any time, in the Application or OS settings;
- lodge a complaint with the data protection authority in your country.
To exercise your rights, contact us at: apptapatap@gmail.com
8. Security
We apply reasonable technical measures to protect your data: encryption in transit (HTTPS/TLS), authorization via short-lived JWT tokens rotated on refresh, and restricted access to the server and database.
9. Children
The Application is not intended for persons under the age of 13. We do not knowingly collect data from children. If you believe a child has provided us with their data, please contact us at apptapatap@gmail.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time — for example, when new features affect the data we collect. The current version is always available in the "About" section of the Application. Continued use of the Application after changes are published constitutes your acceptance of the updated Policy.