Privacy Policy
Last updated: June 22, 2026
This Privacy Policy describes how Tapout ("Tapout", "we", "us", or "our") collects, uses, stores, and shares information when you use the Tapout mobile application and the Tapout web dashboard (collectively, the "Services"). By creating an account or using the Services, you agree to the practices described below.
- We collect only the information needed to run your coaching experience: account details, body-composition inputs you type, the progress photos you choose to upload, workout/diet activity, and coach bookings.
- We do not sell your data. We do not use your data for advertising or cross-app tracking.
- You can delete your account and all associated data from inside the mobile app (Me → Delete my account) at any time.
1. Who we are
Tapout is a fitness coaching platform operated from India. If you have questions about this policy or your data, contact us at support@tapout.in.
2. Information we collect
2.1 Information you provide
| Category | Examples | Why we collect it |
|---|---|---|
| Account & contact | Email address, username, password (hashed by our auth provider), phone number (optional) | Authentication, account recovery, and communicating service-related notices |
| Profile & fitness inputs | Age, sex, height, current weight, target weight, daily activity level, fitness goal, dietary preference, food allergies | Calculating BMI/BMR/TDEE and generating personalized diet and workout plans |
| Progress data | Daily logs you record, workout completions, progress photos you choose to upload | Tracking your progress over time and showing it back to you and, where applicable, to coaches you have booked with |
| Bookings & sessions | Coach bookings, session times, and join events | Enabling coach sessions and maintaining your booking history |
| Points & wallet | Points awarded for daily logs and completions, wallet balance, transaction history | Operating the in-app rewards system |
2.2 Information collected automatically
- Authentication events. Sign-in, sign-out, token refresh, and password-reset events are recorded by our authentication provider for security purposes.
- Diagnostic logs. The mobile app writes local debug logs (screen transitions, API call timings, and error messages with sensitive fields redacted) to help diagnose issues. These logs stay on your device and are only transmitted to us if you explicitly send them via a support request.
- Device-provided identifiers. Your Supabase user id is assigned by the authentication system and is used only to scope your data within our backend.
2.3 Information we do not collect
- We do not collect precise location data.
- We do not use third-party advertising SDKs or cross-app tracking identifiers (no IDFA/IDFV use beyond what iOS grants implicitly, and never for tracking).
- We do not read your contacts, calendar, or messages.
- We do not collect data from users we know to be under 13.
3. How we use your information
- To create and maintain your account and keep you signed in.
- To calculate and display your personalized fitness metrics (BMI, BMR, TDEE, progress trends).
- To generate personalized diet and workout plans using your profile inputs when you tap Generate and provide in-app consent (see §5 Third-party services).
- To let you schedule coach sessions, join video calls, and review your booking history.
- To operate the rewards / points system.
- To diagnose crashes and fix bugs.
- To send transactional emails (verification, password reset, and important service notices). We do not send marketing emails without your separate consent.
4. Legal basis
Where applicable (for example, under the EU/UK GDPR or equivalent laws), we rely on the following legal bases:
- Contract: to provide the Services you sign up for.
- Legitimate interests: to keep the Services secure, diagnose issues, and prevent abuse.
- Consent: for optional items such as uploading progress photos, sending optional marketing email, and sharing fitness profile data with Google Gemini when you explicitly agree before generating AI meal or workout plans (see §5 Third-party services).
- Legal obligation: to comply with applicable law when required.
5. Third-party services we use
We rely on the following processors. They act on our behalf, under contractual commitments, and only for the purposes listed below.
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Authentication, database storage, file storage for progress photos, and serverless functions | All account data, profile inputs, progress data, photos, bookings, and points |
| Google Gemini (server-side) | Generating personalized diet plans and workout routines when you tap Generate and agree in the app. Calls are made from our backend; your API key never leaves our server. | Fitness profile questionnaire only: age, sex, height, weight, activity level, fitness goal, diet type, allergies, cuisine/meal preferences, and workout preferences (split, equipment, location, experience). Not sent: email, phone, photos, daily logs, bookings, or device identifiers. You must give explicit in-app consent before any data is shared. |
| Jitsi Meet | Video sessions with your coach when you join a scheduled booking | Real-time audio/video while the call is active. Calls are not recorded by Tapout. |
| YouTube | Embedded curated training videos opened from the Videos tab | Standard YouTube player telemetry governed by Google's privacy policy. |
6. Progress photos
Progress photos you upload are stored in a private Supabase Storage bucket and are accessible via short-lived public URLs that only the Tapout app constructs. These photos are visible to:
- You, through the Photos tab in the mobile app.
- A coach you have explicitly booked with, if they have an active coaching relationship with you.
Deleting your account removes every object stored under your user
folder in the photo-journal bucket.
7. Data retention
We retain your data for as long as your account is active. When you delete your account (Me → Delete my account in the mobile app), we:
- Remove every row we store that is keyed to your user id — profile, daily logs, workout completions, workout routines, diet plans, point ledger, point wallet, bookings, and coach links.
- Remove every object you uploaded under your folder in the progress-photos bucket.
- Delete your authentication record, invalidating all sessions immediately.
Irrevocable backups and logs may be retained for a limited operational window (typically up to 30 days) before being purged on our backup provider's rotation cycle.
8. Your rights
Depending on where you live, you may have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate data (directly in the Profile screen, or by emailing us).
- Delete your data (in-app, as described above, or by emailing us).
- Object to or restrict certain processing.
- Withdraw consent where we relied on consent.
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, email support@tapout.in. We will respond within 30 days.
9. Security
- All data is transmitted over HTTPS/TLS.
- Passwords are never stored in plain text — they are hashed by our authentication provider.
- Database access is governed by row-level security so that each user can only access their own rows.
- API keys that must remain secret (such as the Gemini API key) live on our server and are never shipped in the mobile binary.
No method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security, but we continuously improve our controls.
10. International transfers
Our backend runs on infrastructure that may be located outside your country of residence. Where required by law, we rely on standard contractual clauses or equivalent safeguards for cross-border transfers.
11. Children's privacy
Tapout is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
12. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top and, for material changes, notify you by email or through an in-app notice before the change takes effect.
13. Contact
For questions, requests, or complaints, contact us at:
- Email: support@tapout.in
- Website: https://tapout.in