Privacy
What Taper knows about you
Your account, your sources, your filters, and what you chose to save. Not what you read, not how long you read it, and nothing that goes anywhere else.
Last updated 6 August 2026
The short version
Taper holds your account, the editions and sources you set up, and the items you chose to save. It does not hold what you read.
- Editions are built the moment you open them and are gone when you leave the page. The only article content on our servers is what you saved yourself.
- There is no read state anywhere in the product, so there is no record of what you opened, how long you stayed with it, or how far down you got.
- Visits to these public pages are counted with Google Analytics, and only if you accept it — decline and nothing of Google's loads, so nothing is set and nothing is sent. Nothing at all is counted inside the app, whatever you chose out here. There is no session recorder, no heatmap, no split testing and no advertising pixel anywhere.
- Nothing is sold, rented or shared for advertising. There is no ad network to sell it to, and the commitment never to build one is on the front page.
- You can take every source out as an OPML file, and close the account for good, without asking anyone.
That is a summary and not the policy. Where it and the sections below disagree, the sections below are what actually happens.
Who is responsible for it
Taper is operated by PANDA DESIGN CITY SRL, registered in Cluj-Napoca, jud. Cluj, Romania. Under the GDPR we are the controller of everything described on this page, which means we decide what is held and why, and we are answerable for it.
Write to hello@taper.news about anything on this page. It is the same address as everything else — there is no separate privacy department, and a request sent there reaches a person rather than a queue.
What Taper stores
All of it, and nothing else:
- Your account
- An email address and a password. The password goes from your browser to our authentication provider, which keeps only a hash of it — it never passes through Taper's own servers in a form anyone could read, including us.
- Your editions
- The name you gave each one, its mark, its size, the shelf it sits on, its keyword filters and filter expressions, the filter sets you saved, and any word you have muted along with the date the mute runs out.
- Your sources
- The address of each feed, the title it goes by in your list, and the tier you gave it in each edition. Sources you add to the catalogue for yourself are held the same way, and are visible only to you.
- What you saved
- The headline, link, summary, picture address, publisher, publication time, and which edition you saved it from. This is the only place an article a publisher wrote is stored, and it is there because you asked for it.
- Your plan
- Free or paid, its status, the date a paid period ends, and the reference our payment provider knows your subscription by. The reference is an identifier, not a card.
- Sign-in records
- Our authentication provider keeps the ordinary bookkeeping that makes signing in work and makes abuse visible: when you signed in, from what address, and from what kind of browser.
What Taper never stores
These are absences in the schema, not settings. There is no table for any of them:
- Articles. An edition is blended from your sources when you open it and discarded with the page. Nothing is warehoused, and there is no second copy to search.
- What you read. Taper has no read state, no open history, no dwell time and no scroll depth — the product is built to remove the unread model, and recording one would put it back.
- A profile of your interests. Nothing about your source list is used to suggest anything, because there are no suggestions and there is no algorithm deciding what rises.
- Card details. Payment is handled entirely by our payment provider, on their own pages. We are told that a subscription is active and nothing more — the number never reaches our servers.
- Anything about a visitor who said no. Analytics out here runs on your consent and nothing else, so declining means no script, no cookie and no identifier — not a quieter version of the same thing. And whichever way you answered, the reader's app counts nothing: there is no page view, no event and no session from inside it, and the counter is refused every address under it besides.
Cookies, and the things that are not cookies
One cookie is necessary, and it is the session cookie that keeps you signed in. It is set and refreshed by our authentication provider — refuse it and signing in cannot work, which is why it is not something you are asked about — and it carries nothing about what you read. There are no advertising cookies and no preference cookies, on any page.
Your reading preferences are not cookies at all. The theme, whether pictures load, the size a new edition starts at, which shelves you have shut, and your answer to the analytics question below are kept in your browser's local storage. They stay on the device, they are never sent to a server, and clearing your browser data removes them.
Then there are the analytics cookies on these public pages, and they are the ones you are asked about. If you accept, Google Analytics sets two — one called "_ga" and one named after our property — which last two years and let Google tell a returning visit from a new one. They are set when you say yes and at no other moment. Decline, and the script is never loaded at all, so there is nothing on your device to clear.
You can change your mind in either direction, at any time, from the link in the footer of these pages, and it takes effect immediately rather than on the next visit — withdrawing stops the script sending anything further and deletes those two cookies from your device there and then. What it cannot do is undo counting that already happened. Your answer is remembered in your browser rather than on our servers, so clearing this site's data resets the question rather than answering it.
None of this reaches the app. There is no banner behind sign-in and no cookie question there, because there is nothing to ask about: the reader's screens load no analytics, set no analytics cookie, and report nothing anywhere.
The site went a long time without asking you to accept anything, and giving that up was a real cost rather than a formality. What we can still say is that the choice is a choice: nothing of Google's runs before you answer, declining takes the same one click as accepting, and a no is not asked again on the next page. If any of that ever stops being true, this paragraph is the thing that has to come off the page.
Who else sees any of it
- Our database and authentication provider
- Supabase holds every table described above and runs sign-in. They process it on our instructions and for nothing of their own.
- Our hosting provider
- The application runs on managed infrastructure. Requests pass through it, so it sees the ordinary web server record: the address a request came from, the page asked for, and when.
- Google, and only if you let them
- Google Analytics counts visits to these public pages. Accept it and your browser loads Google's script and tells them which page you opened, roughly where in the world you are, what referred you, and what kind of device and browser you used. Decline and they are told nothing, because nothing loads. It runs on the public pages and nowhere else — no page inside the app has ever loaded it and none may. We have turned off the settings that would let Google use any of it for advertising, and the record of an individual visit is deleted after 14 months, leaving only totals that are about nobody.
- logo.dev
- Publisher marks in your source list come from logo.dev, and your browser asks for them directly — so logo.dev sees that request and the address it came from. Turning pictures off in reading settings stops every one of those requests.
- The publishers you follow
- Pictures in an edition load from the publisher's own servers, so those servers see a browser asking for a picture. The feeds themselves are fetched by Taper's server rather than by you, which means a publisher does not learn that you subscribe to them.
- Our payment provider
- Stripe takes the payment, on their own pages, and holds the card. We are told your email address, that a subscription started or ended, and when the paid period runs to.
- The human-check provider
- Cloudflare Turnstile runs on the sign-in and sign-up forms when they look automated. It loads a script from Cloudflare, sends them the challenge result, and tells us only whether you passed. We do not see the puzzle or any score.
- Our email sender
- Resend sends the transactional emails this app sends on its own — account confirmations, billing notices, and the like. They see the address, the subject, and the body long enough to deliver it, and keep the ordinary logs a provider keeps. Password resets and address confirmations are sent by Supabase Auth, using SMTP credentials in our Supabase project, not by Resend.
- Nobody else
- No advertising network, no data broker, no marketing platform, and nobody at all beyond the names above. The typefaces are served from our own servers, so loading a page asks Google Fonts for nothing — the analytics above is the only thing on this site that reaches Google, and it is the only thing you are asked about.
- Not Google Search Console, despite appearances
- We use it to see how the public pages appear in search results. It reports Google's own crawling and its own search data back to us; it loads nothing on this site, sets no cookie, and is told nothing whatsoever about you.
We will hand something over if a court in a jurisdiction that binds us orders it, and we will tell you when we are allowed to.
Why we are allowed to hold it
- To do what you asked
- Your account, sources, editions, filters and saved items exist because running them is the service you signed up for. Article 6(1)(b) — performance of a contract.
- To keep it working and honest
- Sign-in records and server logs exist to make sign-in work, to keep accounts apart, and to make abuse visible. Article 6(1)(f) — legitimate interests, and the interest is narrow enough that we can name it in a sentence.
- Because you said yes
- The analytics on these public pages runs on your consent and on nothing else. Article 6(1)(a), and Article 5(3) of the ePrivacy Directive for the cookies themselves. We do not claim a legitimate interest in it — that is the argument a site makes when it wants the measurement without the question, and it is the wrong one for a cookie that follows you. Withdraw and it stops; the withdrawal costs you nothing, because nothing on this site is gated behind having accepted.
- Because the law says so
- Invoices for a paid account are kept for the period Romanian tax law requires, whatever else you ask us to delete. Article 6(1)(c).
How long it is kept
As long as the account exists, and no longer. Closing your account deletes it — the account row goes, and everything that hangs off it goes with it in the same operation: editions, sources, filters, filter sets, mutes, shelves, saved items, catalogue contributions and the plan record.
There is no soft delete, no grace period, no recovery window and no copy kept for our records. That means it cannot be undone, which is the trade for it being real.
The analytics on these public pages is on its own clock, because it is not attached to an account and closing one cannot reach it. Google deletes the record of an individual visit after 14 months, and the cookies on your device run out after two years unless you clear them or withdraw first. What is left after that is counts of pages, which are about nobody.
Two exceptions, and both are narrow. Database backups held by our infrastructure provider can carry a deleted account until that backup rolls off on its own schedule, and they are never read back to restore one account. Invoices for a paid account are kept as long as tax law requires, because that obligation outranks a deletion request.
What you can ask for
The GDPR gives you the following, and most of them are faster to use yourself than to ask us for:
- A copy of what we hold
- Write to hello@taper.news. We will answer within a month, and usually the same week.
- A correction
- Every field described above is editable in the app. Your email address is in account settings.
- Erasure
- Account settings, at the bottom. It is immediate and it is complete — see the section above.
- Your sources, in a portable form
- OPML export, from the sources screen, any time and without asking. It is the format every other reader imports, which is the point: leaving has to be as easy as arriving or the free tier is a trap.
- To take back the analytics consent
- The link in the footer of these pages, any time, and it takes effect at once. You do not have to write to us, give a reason, or be signed in, and nothing about the product changes either way.
- To object, or to restrict what we do
- Write, and say which processing you mean. In practice there is very little here to object to, because there is no profiling and no marketing to opt out of.
- To complain about us
- the National Supervisory Authority for Personal Data Processing (ANSPDCP) supervises us, and you can complain to them directly, or to the authority where you live. You do not have to raise it with us first, though we would rather you did.
Where it is held
Your data sits with our database provider, and the application runs alongside it.
Where a provider processes something outside the European Economic Area, it happens under the European Commission's standard contractual clauses.
Everything in your account stays inside that arrangement, and nothing about it is sent anywhere for a purpose of our own. The analytics on these public pages is the one thing that leaves it: our contract is with Google Ireland Limited, and Google may process what it collects in the United States. That transfer rests on Google LLC's certification under the EU-US Data Privacy Framework, with the standard contractual clauses behind it. It is also the one thing on this site you can refuse outright, and refusing it means the transfer never happens.
Age
Taper is not built for children and is not marketed to them. You need to be 16 to hold an account. If you believe a child has made one, write and we will remove it.
When this page changes
The date at the top moves whenever the words below it do, including for a change that only makes something clearer. A change that alters what we hold or who sees it is also written up in the changelog and, if it matters enough, emailed to you before it takes effect.
Nothing here is applied retroactively to data already deleted, because there is nothing left to apply it to.