Privacy Policy
TaperCommunity is run by Velebit Health, Inc., the data controller for everything described here. This policy describes what the service actually stores and sends, not a generic template.
Effective September 2, 2026
The short version
Your journal entries, taper plans, and direct messages are private to you. Your forum posts are public — to other members and to search engines.
We record health information about you: the medication you are tapering, doses, symptoms, and mood scores. We only do this because you choose to enter it, and you can delete your account and everything in it at any time from Settings.
We do not sell your data, and we do not run advertising.
There is one situation in which we may pass information about you to someone outside this service without being asked to: if we believe your life or someone else's is in immediate danger. That is described under Emergency disclosure below.
What we collect and why
Account details
Your email address, a password (stored only as a bcrypt hash — we never see it), your display name and username, and when you joined and were last active. Needed to give you an account and let you sign in.
Legal basis: Performance of a contract (GDPR Art. 6(1)(b))
Profile information
Anything you choose to add: the medication you are tapering, your taper stage, whether you have a prescriber, a short bio, your location, and an avatar. All optional except what you fill in at signup.
Legal basis: Consent, and explicit consent for health details (Art. 6(1)(a) and Art. 9(2)(a))
Health information you enter
Journal entries (medication, current dose, symptoms, mood score, free-text notes) and taper plans. This is special-category health data. It is private to you unless you explicitly publish an entry to a forum.
Legal basis: Explicit consent (Art. 9(2)(a)) — you can withdraw it by deleting the entries or your account
Content you post
Threads, replies, votes, follows, and direct messages. Forum content is public. Direct messages are visible only to you and the person you are writing to.
Legal basis: Performance of a contract (Art. 6(1)(b))
Technical and location data
When you sign in, we store the IP address that request came from and a coarse city/region derived from it. We use it to show you deprescribers near you and to route regional content. It is overwritten on your next sign-in — we do not keep a history — and we never collect your device's GPS location. In an emergency of the kind described under Emergency disclosure below, we may also use it to help work out roughly where you are.
Legal basis: Legitimate interests — regional relevance and abuse prevention (Art. 6(1)(f)); in an emergency, vital interests (Art. 6(1)(d))
Usage data
Which pages were viewed, the referring page, a rotating session identifier, and whether the device is a phone, tablet, or desktop. Used to understand what parts of the site help people. This is not linked to advertising.
Legal basis: Legitimate interests — improving the service (Art. 6(1)(f))
Push notification tokens
If you use the iOS app and allow notifications, we store the device token Apple issues so we can send you alerts about replies and messages. Removed when you turn notifications off or delete your account.
Legal basis: Consent (Art. 6(1)(a)) — granted through the iOS permission prompt
Who we share it with
We do not sell personal data. We use a small number of processors, each doing one job:
Hetzner (Germany) — hosting and the database. Your data lives here.
Cloudflare — DNS and CDN in front of the site; sees request metadata in transit.
Resend — sends transactional email (verification, password reset, notification digests). Receives your email address and the message contents.
Plausible — privacy-focused analytics. No cookies, no cross-site tracking, no personal profiles.
Apple — delivers push notifications to the iOS app. Receives the notification text and your device token.
Clinicians you contact — when you fill in the contact form for a clinician in the deprescriber directory, we email that clinician the details you entered on the form (your name, your email address, the medications you are tapering, how long you have been tapering, the kind of support you asked for, and any notes you added) so they can reply to you directly. A copy goes to our team so we can follow up. Nothing is sent to a clinician unless you submit that form — browsing the directory sends them nothing.
No AI provider receives your data. Nothing you write on this site — your posts, replies, messages, journal entries, or taper plans — is sent to an AI model or used to train one.
We may also disclose data where the law requires it, or where it is necessary to investigate a safety issue or a breach of the Terms of Service.
Emergency disclosure
If we become aware of a serious risk of imminent death or serious harm to you or to someone else, we may pass information about you to a crisis service, emergency services, law enforcement, or a person you have named to us, so that they are able to respond. We disclose only what they reasonably need — usually a way to contact or locate you, and enough of the situation to explain the concern.
These recipients are not our processors. Once we contact them they act on their own responsibility, and we have no control over what they decide to do.
We will ask for your agreement first wherever we can, and we will tell you what we have done unless telling you would increase the risk. We may act without your agreement where we reasonably believe you are unable to act to protect yourself and there is no time to obtain it.
We keep a record of any such step — what we did, when, and why. It is held apart from your account, and it is described under How long we keep it below.
Legal basis: protecting the vital interests of you or another natural person (GDPR Art. 6(1)(d)), and, for health information, Art. 9(2)(c). Where you are able to give it and do, we rely on your explicit consent instead (Art. 9(2)(a)). In the United States we rely on the emergency and safety exceptions in the state privacy and consumer health-data laws that apply to you.
Where your data goes
The database is hosted in Germany. Velebit Health, Inc. is a US company, and some of the processors above are US-based, so data is transferred outside the EEA. Those transfers rely on the European Commission's Standard Contractual Clauses or, where applicable, the EU–US Data Privacy Framework.
How long we keep it
Account, profile, journal, and message data is kept until you delete it or delete your account.
Short-lived security records — email verification codes, password reset codes — expire within hours.
Usage records (page views) are retained in aggregate. When you delete your account these are permanently detached from your identity rather than removed, so they no longer describe a person.
A record of any emergency step taken under Emergency disclosure above is kept for as long as we may need to account for that decision — set by the limitation periods for any claim arising from it, and in no case longer than six years — and is then deleted.
Deleting your account
Go to Settings and choose Delete my account. It is immediate and cannot be undone.
This permanently removes your profile, journal entries, taper plans, threads, replies, votes, follows, direct messages, notifications, and push tokens.
Three things survive by design: page-view records are de-linked from you rather than deleted, text of yours that another member quoted inside their own reply stays in their post, and any record of an emergency step we took under Emergency disclosureabove is kept for the period described in How long we keep it. If you need a quote removed, email us.
Your rights
If you are in the EEA or UK, you have the right to access, correct, delete, export, or restrict processing of your data, to object to processing based on legitimate interests, and to withdraw consent at any time. Withdrawing consent does not affect processing that already happened.
Most of this you can do yourself in Settings. For anything else, email [email protected] and we will respond within 30 days.
You also have the right to complain to your national data protection authority — your local supervisory authority in the EU, or the ICO in the UK.
If you are in California, Washington, or another US state with a comprehensive privacy or health-data law, you have comparable rights — including, under Washington's My Health My Data Act, the right to have consumer health data deleted. Use the same address.
Children
TaperCommunity is for adults. You must be 18 or older to create an account, and we do not knowingly collect data from children. If you believe a minor has an account, email us and we will remove it.
Security
Traffic is encrypted in transit. Passwords are stored only as bcrypt hashes. Access to the production database is limited to the people who operate the service. No system is perfectly secure — if we discover a breach affecting your data, we will notify you and the relevant supervisory authority as the law requires.
Changes and contact
If this policy changes materially we will update it here and change the effective date. Questions, requests, or complaints: Velebit Health, Inc. — [email protected]
Also worth reading: