Privacy Policy
Last updated: September 27, 2026
Tapefold is an app for browsing, searching and playing audio loops from sources you add: Telegram channels and chats, Dropbox shared folders, Offtop packs, folders on your own devices, and, on a Mac, iMessage conversations. It is made by Hajar Rashidian-Zadeh, in Ontario, Canada ("we"). Questions about this policy go to [email protected].
Tapefold uses the Telegram API and is part of the Telegram ecosystem. It is not an official Telegram app.
The short version
- Most of what Tapefold knows stays on your devices. Your Telegram session, your folder paths and your iMessage conversations are never sent to us. Your Dropbox and Offtop links are encrypted on your device with a key only your devices hold. We store the encrypted copy so your other devices can get it; we cannot read it.
- To sync between your devices we hold your email address, your devices, your stars and sources, and a description of each loop your other devices can play: its title, caption, file name, source name and where it lives in Telegram.
- We hold audio only when you ask us to, by archiving a loop. If your account has Smart Search, we also hold a fingerprint of each loop for your searches; see "What we hold on our server".
- We count what you do in the app, like adding a source or playing a loop, but never which loop, which source or what you searched, and you can turn that off in Settings. Crash reports come to us automatically, with links, paths and file names removed.
- We show no ads, sell nothing about you, and use nothing you store with us to train AI.
What stays on your devices
We never receive these:
- Your Telegram session. It is encrypted with your system's credential storage (the macOS Keychain, Windows' credential protection, or the iOS Keychain) and used only by the app on that device to talk to Telegram directly.
- Your Dropbox connection. Encrypted the same way. Each device connects to Dropbox itself.
- The paths of folders you add. Encrypted the same way. Files are played where they are and never copied.
- iMessage (Mac only). Tapefold reads the Messages database on your Mac, with the Full Disk Access you grant it, to find audio attachments in the conversations you add. It reads your Contacts on the Mac to show a conversation's name and a contact's photo. Phone numbers, email addresses and photos are never sent anywhere, and photos are never saved. A conversation's name is the one exception; see "What we hold".
- The search index. To browse and search quickly, each device keeps a local database of your loops: source names, file names, titles and captions. It is not encrypted. Anyone who can read files in your user account on that device can read it. It holds no passwords, sessions or links.
- Playback caches, downloads, waveforms, and the title, artist and cover art read from your files.
- Logs. The app keeps a log on each device, with links, sessions and file paths removed. It stays on the device unless you press Send diagnostics in Settings (see "What we hold"). The upload logs carry no titles or file names either.
- Crash dumps. When the Mac or Windows app crashes, the system writes a dump of the app's memory. It stays on your computer and is never sent to us.
What we hold on our server
Only while you have an account:
- Your account. Your email address, your password as an Argon2 hash (we never store the password itself), when you joined, and your plan.
- The invite you signed up with. Which invite code you used to sign up, if it was one made for a person, so we can credit whoever invited you. The code's label (the name of whoever invited you) is kept until we delete the code.
- Your devices. Each signed-in device's name (by default your computer's name, which you can change), its platform, and when it was last seen.
- A new device asking to join. When a device signs in to an account that already has one, it has to be allowed from a device you're already signed in on. Until then we keep its name, its platform, the IP address it asked from and when it asked, so your signed-in device can show you what's asking. We delete all of that a day after the request runs out, and a request runs out after ten minutes.
- Your website sessions. When you sign in to tapefold.app in a browser: the browser's user agent, the IP address it signed in from, and when it was last used. The server also works out a city from that address, using a database file it holds itself, so no third party is told; the website shows you that city (for example "Toronto, Ontario") and not the address. You can see and end each one on the website.
- What you sync. Which loops you starred and when; which sources you added, switched on or off, or removed, and in what order; and which sources you chose to archive. A Telegram source is recorded by its chat number, not its name.
- A description of each loop another device can play. When a device indexes a loop your other devices can play, it publishes the loop's title, caption, file name, source name, date, length, size, file type and its place in Telegram (chat and message number), so your other devices can list it without indexing the same source again. This covers Telegram loops, iMessage loops you chose to keep on Telegram or in the archive, and archived loops from local folders. For an iMessage loop, the source name is the conversation's name, which is usually your contact's name. Dropbox and Offtop loops are never published.
- Your Dropbox and Offtop links, encrypted. Your Dropbox and Offtop links are encrypted on your device with a key only your devices hold. We store the encrypted copy so your other devices can get it; we cannot read it. When you sign in on a new device, it asks your other devices for that key through us: we keep the request, the new device's name and its public key, and delete them once answered or after 7 days. The key itself only ever travels encrypted to that one device.
- Smart Search (only if your account has it). To search by sound, Tapefold sends a low-detail picture of the first ten seconds of each loop to your account on our server. The server keeps a fingerprint for your searches and deletes the picture once it is analysed; a picture that is never analysed is deleted after 24 hours. Fingerprints are deleted when the loop, its source or your account is deleted.
- Audio you archive. When you archive a loop or point a source at the archive, the file is uploaded from your device to Cloudflare R2 storage and named by a fingerprint of its contents (its SHA-256). We record which of your loops point at which file. No other account can see or share your files: the same file archived by two accounts is stored twice.
- Usage counts. Unless you turn off Share usage statistics in Settings, each device sends us events from a fixed list, such as the app being opened, a source added, a loop previewed or a search run. Each carries the time, the device's platform and app version, and at most the kind of source (Telegram, Dropbox, Offtop, folder or iMessage), a rough size or an error code. They never say which loop, which source, which loopmaker or what you typed. We keep them for 90 days, then only as daily totals that no longer say whose they were. Turning the switch off sends nothing more, not even that you turned it off.
- Crash reports. When the app crashes, hangs or hits an unexpected error, it sends us the kind of error, a short message and where in the app's own code it happened, with the app version, platform and operating system version. Links, file paths and file names are removed on your device and again on our server. We keep them for 90 days.
- Diagnostics you send. Only when you press Send diagnostics in Settings: the last day of the app's log, with links, sessions and file paths removed, and the app and system versions. If you also tick "Include the names of my sources and loops", it carries your sources' names and up to 5,000 loop titles as well. We delete those names after 14 days and the rest after 30.
- Security records. Sign-ins, sign-outs, password changes and similar events, with the IP address and device involved. For a failed attempt against an address we do not know, we keep a one-way hash of the email, never the address. These records are kept for 365 days, and failed or refused sign-in attempts for 30. The service itself can add to them but cannot read or change them; only the operator can read them.
We never hold your Telegram session, messages from chats you did not add, your Dropbox or Offtop links in a form we can read, your local paths, or any phone number or email address from iMessage.
Who else is involved
- Cloudflare carries all traffic between your devices and our server, and stores archived audio in R2. It can see the traffic it carries. R2 stores data in Cloudflare's Eastern North America region.
- OVHcloud provides the machine our server runs on, in Canada.
- Telegram, Dropbox and Offtop. Your devices talk to these services directly, with your own accounts, and their privacy policies govern what they receive. We are not in the path.
- Apple. The iOS app is distributed through Apple. We receive whatever crash reports you choose to share through TestFlight. On the iPhone, the crash and hang reports described above come from your phone's own diagnostics (Apple's MetricKit) and are sent by the app to us, not by Apple.
We share nothing else with anyone, except where the law requires us to.
Where it is stored
Our server is in Canada and is run by us. Encrypted backups are made every night and the last 14 are kept, so something you delete can survive in a backup for up to 14 days. Archived audio is in Cloudflare R2, which may be outside Canada.
Your choices
- See and remove devices and browser sessions on tapefold.app.
- Turn off usage statistics in Settings, on each device.
- Take a loop out of the archive from either app. The file is deleted from storage 7 days later, unless you archive it again first. That delay is the only way to undo a mistake.
- Remove a source. Its loops leave every device, and its published descriptions are marked removed.
- Delete your account on tapefold.app, from the account page, with your password. Everything listed under "What we hold", except the security records, is deleted at once, and archived audio straight after. Files on your own devices are not touched. You can also write to [email protected] from the account's email address, and we will do it within 30 days. Either way, backups age out within 14 days after that. Security records are kept until they expire, because they exist to show what happened to an account.
- Get a copy of what we hold about you by writing to the same address.
Security
Connections to our server are encrypted. Passwords are hashed with Argon2. Signing out of a device ends its session on our server, and a password reset signs out every device. If a breach puts you at real risk of significant harm, we will tell you and the Office of the Privacy Commissioner of Canada, as the law requires.
Children
Tapefold is not for children under 13. If you are under the age of majority where you live (18 in Ontario), a parent or guardian must agree to these terms for you.
Changes
If this policy changes in a way that matters, we will say so in the app or by email before the change applies. The date at the top is the date of the current version.