Last updated: 4 September 2026
This Privacy Policy explains how TAAAPIT ("TAAAPIT", "we", "us", or "our") collects, uses, shares, and protects your personal information when you use the TAAAPIT mobile app and the website at taaapit.com (together, the "Service"). We are the data controller for the personal data described here.
1. Information we collect
Information you provide
- Account details — your email address, and (depending on how you sign in) your name. If you sign in with Google or Apple, we receive basic profile information (name, email, and a unique identifier) from that provider.
- Card content — the information you add to your card(s): name, job title, company, phone number(s), email(s), website, social links, address, a profile photo, and any custom fields you create.
- Contacts you save — cards other people share with you, which are stored in your in-app Log Book.
- Messages — the content of chats you send to other TAAAPIT users through the app: text, and any images or documents you attach to them.
- Purchases — if you subscribe, a record of which plan you hold, when the period ends, and the store that sold it. Card numbers never reach us: payments are taken by Apple or by Stripe.
- Voice notes — audio you record against a contact in your own Log Book, so what was said is not lost. The recording is stored in Firebase Storage under your account and nobody else's, and it is transcribed to text by Google Cloud Speech-to-Text so you can search it later. Deleting a note deletes its audio with it. Voice notes count against your plan's AI actions.
- Approximate location (Nearby) — Nearby is off by default. If you turn on "Show me in Nearby", we store a coarse grid cell — roughly 1 km across, computed from your device's location — together with your public card snapshot, so it is visible to other signed-in TAAAPIT users as a distance band (for example "under 2 km") and nothing more precise: never an address, a map pin, or your exact coordinates, which we never store at all. It is refreshed only while you have the Nearby tab open with the switch on, and is deleted the moment you turn the switch off or delete your account. We do not sell this, or any other, location data.
- Support communications — information you send us when you contact us (for example, by email).
Information collected automatically
- Usage and device data — basic technical information needed to run the Service, such as app/version, device type, and diagnostic logs.
- Card views — a count of how many times a public card has been viewed, and by which route (tap, QR code, link, wallet pass). These are counters only: nothing about the visitor is recorded, and they cannot be traced back to a person. Anyone who opens a card you shared as a web page is a visitor with no account, and stays anonymous to us and to you.
- Named views inside the app — separately from those anonymous counters: when a signed-in TAAAPIT user opens someone else's card in the app, that card's owner is shown who it was — their name, their own card link, and when they last looked. It is one entry per person, holding the last look rather than a history of every look. You can stop your own name being shared this way at any time, in Settings → Privacy → "Browse without being named", and we tell you the first time it happens so that choice is a real one. This applies only between signed-in TAAAPIT users; web visitors have no account and stay anonymous, as above.
- Website analytics — on the marketing pages of taaapit.com we use Google Analytics to count visits and see which pages people land on. This does not run on public card pages: if someone opens a card you shared, nothing about that visitor is recorded. See our Cookie Policy.
- App measurement — counts that tell us how the app is doing overall: how many people install and open it, how often, whether they come back, and the app version, operating system, device model, country and language, together with a random identifier for the app installation. We deliberately do not record what you do inside the app: not which screens you open, not which features you use, and never what is on your cards, your messages, or anything you type.
- Push notification token — if you enable notifications, a device token so we can deliver them.
2. How we use your information
- To create and operate your account and your card(s).
- To publish your public card at your chosen link and let you share it by tap, QR code, or link.
- To deliver features you use — saving contacts, chat, exporting to your phone contacts, and adding your card to Apple Wallet or Google Wallet.
- To send you a one-time verification code by email when you sign in.
- To send notifications you have enabled.
- To keep the Service secure, prevent abuse, and fix problems.
- To comply with our legal obligations.
3. Legal bases (UK/EU users)
If you are in the United Kingdom or the European Economic Area, we rely on the following legal bases under the UK GDPR / EU GDPR:
- Performance of a contract — to provide the Service you signed up for (your account, cards, sharing, and messaging).
- Consent — for optional features such as push notifications and adding your photo to your public card. You can withdraw consent at any time.
- Legitimate interests — to keep the Service secure, prevent fraud and abuse, and understand aggregate usage through app measurement.
- Legal obligation — where we must process data to comply with the law.
4. How we share information
We do not sell your personal information. We share data only as follows:
- Publicly, at your direction — the fields you mark public on a card, and the public link/QR for that card, are visible to anyone you share them with.
- With other users — when you share your card with, or message, another user, they receive the information you chose to share. Opening another user's card in the app also names you to them, unless you have turned that off — see "Named views inside the app" in Section 1.
- Service providers (processors) — we use trusted providers to run the Service, listed in Section 9. They process data only on our instructions.
- Legal and safety — where required by law, legal process, or to protect the rights, safety, and property of TAAAPIT, our users, or the public.
- Business transfers — if TAAAPIT is involved in a merger, acquisition, or sale of assets, data may be transferred as part of that transaction.
5. AI features
Paid plans include AI actions: scanning a paper card into your Log Book, drafting a follow-up, and asking questions about your own Log Book. When you use one, we send the content it needs — the photo of the card, or the contact details concerned — to Anthropic, who process it for us and return the result. It is not used to train models. We never send your chats, and we never send anything unless you have asked for one of these actions.
Transcribing a voice note is metered as one of the same AI actions, but it does not go to Anthropic: the audio is transcribed by Google Cloud Speech-to-Text — the same Google that already hosts the Service, not an additional company — and only when you record a note.
6. Company accounts and Teams
A company on the Business plan can create accounts for its people. If you are using an account your company created, the contacts you collect with it are shared with that company: its owner and admins can see each contact along with your name as the person who collected it, and which company card brought it in. Your conversations with colleagues are visible to the colleagues in them. You keep your own copy of every contact you collect. An account you created yourself is never shared with a company in this way.
7. International data transfers
The Service is delivered using cloud infrastructure that may store and process data in data centres located in various countries, including outside your own. Where personal data is transferred internationally, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses and equivalent UK mechanisms) provided by our infrastructure providers.
8. Data retention
We keep your personal data for as long as your account is active or as needed to provide the Service. When you delete a card, its public page and link are removed. When you delete your account, we delete or anonymise your personal data, except where we must retain certain information to comply with legal obligations, resolve disputes, or enforce our agreements.
9. Your rights
UK/EU users. You have the right to access, correct, delete, or receive a portable copy of your personal data; to object to or restrict certain processing; and to withdraw consent. You also have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office).
US users. Depending on your state (for example, California), you may have the right to know what personal information we collect, to request deletion, to correct it, and to opt out of "sale" or "sharing" of personal information — noting that we do not sell your personal information. We will not discriminate against you for exercising these rights.
You can exercise many of these rights directly in the app (editing or deleting cards, or deleting your account). For anything else, contact us at securovix@gmail.com and we will respond as required by applicable law.
10. Security
We use industry-standard measures — including encryption in transit and access controls — to protect your data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information and to promptly address any issues.
11. Third-party services
We use these providers to run the Service. Each receives only what its job needs:
- Google (Firebase and Google Cloud) — hosting, database, file storage, sign-in, crash reports, push notifications, app measurement, and voice note transcription (Google Cloud Speech-to-Text).
- Anthropic — the AI features described in section 5.
- Apple and Stripe — subscription payments. They tell us what you bought and when it renews; they do not give us your card details.
- Resend — the emails we send you (verification codes, team invitations, receipts and the weekly summary).
- Apple Wallet and Google Wallet — only if you add a card to a wallet.
We do not sell your information, and we do not share it with advertisers or data brokers. There is no advertising or cross-app tracking in TAAAPIT. Our measurement is first-party only: they are not tied to an advertising identifier and are never used to build a profile of you across other apps or websites.
12. Children
The Service is not directed to children under 16 (or the minimum age required in your country), and we do not knowingly collect their personal data. If you believe a child has provided us personal data, please contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app.
14. Contact us
Questions or requests about this policy or your data? Email us at securovix@gmail.com.
