Privacy policy
Effective 2026-07-30
TaperØff helps you taper off vaping. That means we hold data about a health-related habit, which we treat as sensitive by default. This policy describes exactly what we store, where it lives, who else can see it, and how to get it back or get rid of it. Corkscrew technologies ltd is the data controller.
What we collect
Your account: your name, your email address, whether that email is verified, and a hashed password. We never store your password itself.
If you sign in with Google instead of using a password, we receive your name, email address and profile picture from Google, and we store the tokens that keep that sign-in working. We never see your Google password.
Your sessions: a session token, the IP address and browser or device user-agent the session was created from, and its expiry. We use these to keep you signed in and to spot abuse.
Your plan: your starting puffs per day, how long your taper runs, your waking hours, your start date, your timezone, your currency, what you spend per day if you told us, your typical puffs per session, and which interaction mode you use (windows, counter or passive).
Your activity, which is the sensitive part:
- Puff events: when, on which local date, how many, how they were recorded, which window they answered, whether you vaped or skipped, whether the puffs came from your Puff Bank, and the optional trigger tag you chose (stress, social, boredom, drink, routine or other).
- Craving events: when you opened the craving flow, on which local date, and how it ended.
- Your vape hardware, if you use passive tracking: the kind of device, a label you choose, its rated puffs, its liquid volume and nicotine strength, and when you opened or finished each pod or disposable.
- Plan adaptations: when your plan was eased or brought forward, and to what.
Why we hold it, and on what basis
We hold your account and session data to provide the service you asked for — this is processing necessary to perform our contract with you.
We hold your plan and activity data for the same reason: it is the product. A taper plan cannot exist without a record of the taper. Your trigger tags and craving outcomes are what generate your insights, and insights stay hidden until there is enough data to be honest about a pattern rather than inventing one.
We hold limited security records — including rate-limiting counters keyed to network address — on the basis of our legitimate interest in preventing abuse of the service.
What we don't do
We do not sell your data. We do not share it with advertisers. We do not use it to build advertising profiles, and we do not run advertising trackers on this website or in the app.
The app can count how it is used — screens opened, plans completed, adaptation offers taken — but only if you say yes. It is off until you do, you are asked once, and you can change your answer at any time in Settings. Declining costs you nothing: every feature works either way.
What those counts never include: your puff events, your cravings, your money figures, or anything tied to your name or email address. That is enforced by the shape of the event definitions themselves, not by policy alone — there is no way for the app to attach that information to a usage count. No usage data at all is collected while the setting is off.
Who else touches it
We use a small number of service providers, each processing data on our instructions:
- Google Cloud — hosting for our servers and database, in the europe-west1 region (Belgium). Your plan and activity data lives here.
- Google (Sign-In) — if you choose to sign in with your Google account, Google handles that sign-in and confirms your identity to us. This is separate from our use of Google Cloud for hosting.
- Sentry — crash, error and performance reporting, configured not to attach personal information to reports. It receives technical diagnostics, not your puff history.
- Expo — mobile app builds and over-the-air updates. It delivers app code to your device; it does not receive your account data.
Your account and activity data is stored in the European Union (Belgium). The UK has adequacy regulations covering transfers to the EU, so no additional safeguard is needed for that transfer. Some of our other providers are based outside the UK and the EU; where data reaches them, it is transferred under the safeguards required by UK data protection law.
How we protect it
Traffic between your device and our servers is encrypted in transit. Passwords are stored only as hashes. Our database is not publicly reachable, and access is limited to the accounts that run the service.
Your puff and craving data is scoped to your account. Every request that reads plan data is checked against the signed-in user's ownership of that plan before it returns anything.
Our support staff can see account details — your email address, your name and when you signed up — and can suspend an account that is being used abusively. They cannot read your puff or craving history, and there is no facility for staff to sign in as you. That is enforced by the permissions the support tool is given, not by policy alone.
Signing in on a shared device creates a session record; sign out when you are finished on a device that is not yours.
How long we keep it
We keep your account and its data until you delete your account. Deleting your account removes your profile, your sign-in credentials including any stored Google sign-in tokens, sessions, email-verification tokens, plans, puff events, craving events, hardware profiles and adaptations.
Two things deliberately survive account deletion: abuse-prevention counters, which are keyed to network address and request path rather than to you and hold no account identifier; and error reports already sent to Sentry, which expire on that service's own retention schedule. Neither contains your puff or craving history.
Your rights
Under UK data protection law you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop certain processing, and ask for your data in a portable form.
You can delete your account and all its data yourself, from Settings in the app. It takes effect immediately and is not reversible.
You can download everything we hold on your account yourself, from the web portal. It is a single JSON file: your account details, every plan you have had — including ones a later plan replaced — with its adaptations, every puff event, every craving you logged, and any device profiles and device logs. It is in the same structure the app itself reads, so what you receive is verifiably what we store rather than a summary we prepared for you.
For anything else — correction, restriction, or a question about this policy — email privacy@taperoff.io. We will respond within one month.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk.
Children
TaperØff is not intended for under-18s and we do not knowingly create accounts for them. If you believe a child has an account with us, email us and we will remove it.
Changes to this policy
If we change this policy we will update the effective date at the top, and for material changes we will tell you in the app or by email before the change takes effect.
Contact
Data protection queries: privacy@taperoff.io. Anything else: support@taperoff.io.