Courtesy translation. This document was translated from Portuguese for your convenience and is not a certified legal translation. In case of any conflict, ambiguity, or discrepancy, the original Portuguese (Brazil) version prevails and is the only legally binding one.
Read the official Portuguese version1. Data We Collect
1.1. Account and identification: name or nickname, email, internal user identifier and, when you sign in with Apple or Google, the identifier of that account.
1.2. Health and plan (SENSITIVE data, LGPD Art. 11): age, weight, height, biological sex, body measurements, goal, activity and experience level, medical conditions, allergies and dietary restrictions that you declare, routine and schedules, available equipment, history of workouts, meals and water, and progress and assessment photos.
1.3. Content you send: meal photos, voice recordings, messages and attachments (image, video or PDF) sent to the AI Coach.
1.4. Phone: your phone number, when you provide it in your profile.
1.5. Subscription and purchase: plan, start, renewal and cancellation dates, amount and currency, and identifiers of the purchases in the stores. TapFit does not receive or store your card details: payment is made on the Apple App Store or Google Play.
1.6. Device and advertising: operating system, model, language, app version, notification token, IP address, user-agent, advertising identifiers (IDFA on iPhone, only if you allow tracking; GAID on Android) and click and install identifiers coming from ads.
1.7. Usage: screens and features used, events from sign-up and from the subscription screen, technical errors and technical logs of AI usage (date, feature, model and amount of processing, without the content).
1.8. Consent records: each acceptance of the Terms, the Privacy Policy and other authorizations, with the type, version and SHA-256 hash of the accepted text, the server date and time, the platform, and the account identifier and email.
2. Artificial Intelligence
2.1. Providers: TapFit's AI features (plan generation, AI Coach, meal photo reading, voice logging, food swaps) are processed by OpenAI (OpenAI, L.L.C., USA), the primary provider, and by Google Gemini (Google LLC, USA), used when the primary provider fails or for specific features.
2.2. What is sent: the data in clause 1.2 needed for each response and the content you send (clause 1.3). TapFit does not send your email or your phone number to the AI providers: the request is identified by an internal code. Your first name may be used to personalize the Coach's response.
2.3. Purpose: to generate the content shown in the app and to organize customer support. TapFit does not use the data sent to the AI for advertising.
2.4. Consent: sending health data to the AI providers, with international transfer to the USA, depends on your specific consent, given on the app's consent screen. Without it, the AI features do not work. Revocation: clause 6 of this Policy and Terms of Use §12.
2.5. Providers' policies: openai.com/policies/privacy-policy and policies.google.com/privacy.
3. Who We Share Data With
3.1. TapFit shares data only with the suppliers below, each for the purpose indicated:
- Google Cloud and Firebase (Google LLC): authentication, database, server functions and file storage. The database is located in São Paulo (Brazil); the server functions run in the USA.
- OpenAI and Google Gemini: artificial intelligence (clause 2).
- Apple and Google, as stores: payment, subscription and sign-in with Apple or Google.
- RevenueCat (USA): subscription management. Receives the user identifier and the stores' purchase receipts.
- Superwall (USA): display of the subscription screen. Receives the user identifier, device data and the events of that screen.
- Meta Platforms (USA), the company behind Facebook and Instagram:
- ad measurement and optimization: through the Facebook SDK in the app and the server's Conversions API, it receives usage and purchase events (such as viewing the offer, starting and completing the subscription, and the amount paid), the user identifier, the advertising identifier, the IP address, the user-agent, click identifiers, and your email and phone number in encrypted form (hash).
- Paywallo: attribution of campaigns and promotional links. Receives email, phone number, first name, last name and sex, to identify the source of your installation and send campaign events to Meta.
- AppsFlyer (USA): attribution of installs and purchases coming from ads. Receives device and advertising identifiers, purchase events and revenue.
- Sentry (USA): error monitoring. Receives the internal user identifier (pseudonymized data) and technical information about the error.
- Expo (USA): app updates and delivery of notifications (notification token).
3.2. Health data never goes to advertising: weight, measurements, medical conditions, photos, meals and conversations are not sent to Meta, Paywallo, AppsFlyer or Superwall.
3.3. TapFit does not sell your personal data and does not transfer it to insurers, pharmacies, health plans or employers.
3.4. Advertising controls: on iPhone, tracking for advertising depends on your permission (Settings → Privacy & Security → Tracking). On Android, you can delete or reset the advertising ID in the device settings. You can also object to the use of your data for ad measurement through the DPO's email, and the request will be reviewed under art. 18, §2, of the LGPD.
3.5. Authorities: data may be provided to authorities when required by law or by court order.
3.6. International transfer: several of these suppliers are located outside Brazil, mainly in the USA. The transfer takes place on the basis of your specific consent (Art. 33, VIII) for the features that depend on it, and of the contractual data protection guarantees offered by these suppliers (Art. 33, II).
4. What We Use Your Data For
- a) to provide the service: build and adjust your plan, log workouts, meals and progress;
- b) to generate AI responses and analyses (clause 2);
- c) to process and validate your subscription;
- d) to send the notifications you have authorized;
- e) to measure and improve our ads (clause 3);
- f) to ensure security, prevent fraud and fix errors;
- g) to comply with legal obligations and defend ourselves in legal proceedings.
5. Data Security
5.1. We adopt technical and administrative measures to protect your data, including encryption in transit and at rest, access rules that prevent one user from reading another user's data, and administrative access restricted to authorized persons.
5.2. No system is 100% breach-proof. In the event of a security incident that may result in relevant risk or harm, TapFit will notify the ANPD (Brazil's National Data Protection Authority) and the affected data subjects, in accordance with clause 11.
6. Your Rights (LGPD, Art. 18)
You may, at any time:
- confirm whether we process your data and access it;
- export your data in a structured format (JSON), under Profile → Settings → My data → Export my data;
- correct incomplete, inaccurate or outdated data;
- request anonymization, blocking or deletion of unnecessary or excessive data;
- know with whom we share your data (clause 3);
- revoke consents (Terms of Use §12) and object to processing based on legitimate interest;
- delete your account, under Profile → Settings → My data → Delete account (clause 7);
- petition the National Data Protection Authority (ANPD).
For requests that are not available in the app, write to contato@usetapfit.com. Response time: up to 15 days.
7. Retention and Deletion
7.1. We keep your data for as long as your account exists.
7.2. When you delete your account, TapFit erases from its servers your profile, plan, history, conversations with the Coach, the photos and media you sent, at the time of deletion or, at the latest, within 30 (thirty) days.
7.3. Even after deletion, the following are retained:
- a) the consent records (clause 1.8), for up to 5 (five) years, as proof of which documents you accepted (LGPD Art. 16, I, and Art. 7, VI);
- b) purchase records and other data that the law requires to be kept, for the legal period;
- c) technical logs of AI usage and of credits, unlinked from your identity.
7.4. Backup copies: the database has automatic backup copies, which are deleted in cycles. Deleted data may remain in these copies, unused, for up to 100 (one hundred) days, until they are deleted.
7.5. Suppliers: data already received by the suppliers in clause 3 is subject to each supplier's retention periods. After deletion, TapFit stops sending your data to them.
7.6. Deleting your account does not cancel the subscription in the store (Terms of Use §10.7).
8. Minors
TapFit is not intended for minors under 18 and does not intentionally collect data from children or adolescents. If we identify that data from minors was collected without the proper consent of a legal guardian, we will proceed to delete that data.
9. Changes to this Policy
The current version of this Policy, with the date of the last update at the top, is always published on the TapFit website and in the app, under Profile → Settings → Privacy policy. Changes take effect when the updated version is published.
10. Auditable Consent Trail
10.1. In accordance with the LGPD (Art. 8, §2), TapFit keeps a record of each consent given, with the data in clause 1.8.
10.2. The records are kept in the database in São Paulo, in an area that the app cannot modify: only the server functions write to them.
10.3. You can see your consents in the data export (Profile → Settings → My data → Export my data) or request a report from the DPO. After account deletion, they are kept in accordance with clause 7.3, "a".
11. Security Incidents
11.1. In the event of a security incident affecting personal data, TapFit:
- (i) contains the incident as quickly as possible;
- (ii) assesses the scope, severity and data affected;
- (iii) notifies the ANPD and the affected data subjects, when there is relevant risk or harm, within the period set by ANPD Resolution CD/ANPD No. 15/2024;
- (iv) records the incident (LGPD Art. 37); and
- (v) adopts measures to prevent it from happening again.
11.2. Channel for reporting incidents: contato@usetapfit.com, with the subject "LGPD INCIDENT".
12. Legal Bases by Purpose
| Purpose | LGPD legal basis | Article |
|---|---|---|
| Account, sign-up and provision of the service | Performance of a contract | Art. 7, V |
| Health data and AI features | Specific consent | Art. 11, I |
| International transfer to the AI | Specific consent | Art. 33, VIII |
| Subscription and payment | Performance of a contract | Art. 7, V |
| Notifications | Consent | Art. 7, I |
| Ad measurement and optimization | Legitimate interest, with the right to object (clause 3.4) and, on iPhone, the system's tracking permission | Art. 7, IX |
| Security, fraud prevention and error monitoring | Legitimate interest | Art. 7, IX |
| Consent records after deletion | Regular exercise of rights | Art. 7, VI, and Art. 16, I |
| Legal and tax obligations | Legal obligation | Art. 7, II |
13. Website Tracking
13.1. The website usetapfit.com uses
Meta Pixel (Meta Platforms, Inc.) to measure the
effectiveness of advertising campaigns and to build custom audiences for
ads. The Pixel collects browsing data (such as page views), IP address,
browser and device information, and a cookie-based identifier
(_fbp), which are shared with Meta.
13.2. This data is used for ad measurement, campaign optimization and remarketing. You can manage or opt out of this tracking in your Meta account's ad settings (facebook.com/adpreferences/ad_settings) and in your browser's cookie and privacy settings. For details on how Meta handles this data, see Meta's Privacy Policy.
13.3. The website's App Store and Google Play buttons
pass through a Paywallo redirect link (paywallo.link), which
attributes the visit to the campaign before opening the store.
Controller (LGPD Art. 5, VI): Gustavo Vendramin Borges, an individual residing in Paranavaí/PR, Brazil.
Data Protection Officer (DPO – LGPD Art. 41): contato@usetapfit.com
At this stage of the product, the controller and the DPO are the same person, in accordance with ANPD Resolution No. 2/2022 for small-scale processing agents.
Response time: up to 15 days
Brazilian National Data Protection Authority (ANPD): gov.br/anpd