TAP Privacy Policy
Last updated: August 29, 2026
This policy is for the TAP app only (com.neverhold.tap). Neverhold Lite / dialer has a separate Privacy Policy. The same signed-in account can be used in both apps (loyalty and some store entitlements). Categories and third parties below match TAP’s in-app Request my data export (PDF + JSON).
1. Who we are
Neverhold (“we”) publishes TAP. Contact: support@neverhold.co. Website: neverhold.co.
2. CCPA/CPRA categories (aligned with Request my data)
Under California CCPA/CPRA (Cal. Civ. Code §§ 1798.110, 1798.130), these are the categories of personal information TAP may collect about you. The same list appears in your export package.
- Identifiers (account id, email, phone, username)
- Customer records / profile (display name, company, job title, address)
- Internet / network activity (app usage related to TAP features)
- Geolocation (only if you grant location for a feature that needs it — e.g. Nearby on some Android versions)
- Professional / employment-related (job title, company on cards)
- Inferences drawn from profile / loyalty tier
- Sensitive personal information — Medical ID / health data you entered (optional)
- Commercial information (purchases, entitlements, loyalty points)
Categories of sources
- You (account signup, profile, Medical ID, cards, preferences)
- Your device (local Æther contacts database, app state)
- Authentication providers (email OTP / phone verify via Supabase Auth + Twilio)
- App stores / billing (entitlement purchase status when applicable)
- Optional connected accounts (Gmail / Microsoft) if you connect Business Account sync or free Æther Drive/OneDrive backup
Business or commercial purposes
- Provide TAP proximity exchange and Æther contact cards
- Account authentication and verification
- Loyalty rewards and referral program
- In-app purchases and entitlement fulfillment
- Emergency / Medical ID features you enable
- Customer support and security
- Show in-house or AdMob ads unless you are ad-free
- Backup and restore of your Æther data when you choose
Categories of third parties / processors
- Supabase (auth, cloud entitlements, loyalty RPCs, optional storage)
- Twilio (SMS/voice one-time codes for phone verification)
- Google Play Billing / Apple In-App Purchase (as applicable)
- Google AdMob (ads), unless Remove Ads / day pass applies
- Firebase Crashlytics (crash diagnostics), if enabled in the build
- Google / Microsoft when you sign in with those providers or connect Drive/OneDrive Æther backup or Business Account sync
- OS share targets you choose when sharing a .tapcard or a data export
We do not sell personal information. In-house ads and AdMob may process device advertising identifiers per this policy when ads are shown.
3. What TAP collects (detail)
Account
Email, password (hashed by our auth provider), optional username, optional verified phone (SMS/voice one-time code via Twilio). Google or Microsoft sign-in sends us an identifier, name, and email — not those passwords. Google/Microsoft login does not verify a phone number.
TAP cards and contacts
Fields you put on a TAP card (name, photo, phones, email, socials, company). Device contacts you grant access to, used to seed Æther People. Free Æther backup may upload contacts and personal/business .tapcards to Google Drive or Microsoft OneDrive you connect. Business Account optional Supabase sync is separate. Medical ID is never included in Æther backups.
Photos and camera
Card and profile pictures use the Android system Photo Picker, or the camera if you take a new photo. TAP does not request photo-library access. TAP does not scan TAP-card QR codes for exchange.
TAP exchange
Nearby / Bluetooth (and on some Android versions, location permission) so two phones can find each other when both start TAP. We do not use that for ads or maps. We do not track you in the background for exchange.
Medical ID (optional)
Health and emergency-contact information you type. Not sold, not used for ads, not attached to ordinary TAP cards without your verified share flow. Lock-screen Send may SMS only those emergency contacts. TAP does not read your SMS inbox.
Purchases, ads, crashes
Google Play Billing for Business Account, Extra Business Card, and Remove Ads. Free TAP may show AdMob ads (advertising ID). Firebase Crashlytics may receive crash reports (not Medical ID).
4. How we use it
- Run TAP: account, cards, nearby exchange, Message Center;
- Optional Medical ID and emergency SMS you enable;
- Loyalty and entitlements shared with Neverhold for the same account;
- Ads on the free tier; not using Medical ID or SMS for advertising;
- Improve reliability (crashes).
5. Sharing
We do not sell your personal information. Processors are listed in section 2. A TAP card or Medical ID you send to another person is sharing you start — not a sale to a company.
6. Retention and deletion
On-device data stays until you delete it, uninstall, or delete your account. In-app: Profile → About TAP → Delete account. Web: delete-account.html.
7. Your rights (access / Request my data)
Access, correction, and deletion under CCPA/CPRA, PIPEDA, Mexican LFPD, and GDPR where they apply. In TAP: Profile → App settings → About TAP → Request my data (free PDF and/or JSON; local-first). Under CCPA/CPRA § 1798.130(b), we are not obligated to regenerate this package more than twice in 12 months; re-sharing your last local package is unlimited. Contact support@neverhold.co.
8. Children
TAP is not directed at children under 13 (or 16 where a higher age applies). Do not create an account for a child.
9. Neverhold Lite / dialer
The Neverhold dialer may collect call-related data described in the Neverhold Privacy Policy. TAP does not operate a dialer or call log.
By using TAP you agree to this policy and the TAP Terms of Service.