Privacy Policy
TaperCommunity is run by Velebit Health, Inc., the data controller for everything described here. This policy describes what the service actually stores and sends, not a generic template.
Effective August 12, 2026
The short version
Your journal entries, taper plans, and direct messages are private to you. Your forum posts are public — to other members and to search engines.
We record health information about you: the medication you are tapering, doses, symptoms, and mood scores. We only do this because you choose to enter it, and you can delete your account and everything in it at any time from Settings.
We do not sell your data, and we do not run advertising.
What we collect and why
Account details
Your email address, a password (stored only as a bcrypt hash — we never see it), your display name and username, and when you joined and were last active. Needed to give you an account and let you sign in.
Legal basis: Performance of a contract (GDPR Art. 6(1)(b))
Profile information
Anything you choose to add: the medication you are tapering, your taper stage, whether you have a prescriber, a short bio, your location, and an avatar. All optional except what you fill in at signup.
Legal basis: Consent, and explicit consent for health details (Art. 6(1)(a) and Art. 9(2)(a))
Health information you enter
Journal entries (medication, current dose, symptoms, mood score, free-text notes) and taper plans. This is special-category health data. It is private to you unless you explicitly publish an entry to a forum.
Legal basis: Explicit consent (Art. 9(2)(a)) — you can withdraw it by deleting the entries or your account
Content you post
Threads, replies, votes, follows, and direct messages. Forum content is public. Direct messages are visible only to you and the person you are writing to.
Legal basis: Performance of a contract (Art. 6(1)(b))
Technical and location data
When you sign in, we store the IP address that request came from and a coarse city/region derived from it. We use it to show you deprescribers near you and to route regional content. It is overwritten on your next sign-in — we do not keep a history — and we never collect your device's GPS location.
Legal basis: Legitimate interests — regional relevance and abuse prevention (Art. 6(1)(f))
Usage data
Which pages were viewed, the referring page, a rotating session identifier, and whether the device is a phone, tablet, or desktop. Used to understand what parts of the site help people. This is not linked to advertising.
Legal basis: Legitimate interests — improving the service (Art. 6(1)(f))
Push notification tokens
If you use the iOS app and allow notifications, we store the device token Apple issues so we can send you alerts about replies and messages. Removed when you turn notifications off or delete your account.
Legal basis: Consent (Art. 6(1)(a)) — granted through the iOS permission prompt
Who we share it with
We do not sell personal data. We use a small number of processors, each doing one job:
Hetzner (Germany) — hosting and the database. Your data lives here.
Cloudflare — DNS and CDN in front of the site; sees request metadata in transit.
Resend — sends transactional email (verification, password reset, notification digests). Receives your email address and the message contents.
Plausible — privacy-focused analytics. No cookies, no cross-site tracking, no personal profiles.
Apple — delivers push notifications to the iOS app. Receives the notification text and your device token.
Anthropic— powers the informed-consent guide generator. When you generate a guide, the medication and indication you select are sent to Anthropic's API to write it — never your journal entries, your name, or anything else from your account. This happens only when you press the button, never in the background, and it is not used to train models. Nothing else on the site sends your data to Anthropic.
We may also disclose data where the law requires it, or where it is necessary to investigate a safety issue or a breach of the Terms of Service.
Where your data goes
The database is hosted in Germany. Velebit Health, Inc. is a US company, and some of the processors above are US-based, so data is transferred outside the EEA. Those transfers rely on the European Commission's Standard Contractual Clauses or, where applicable, the EU–US Data Privacy Framework.
How long we keep it
Account, profile, journal, and message data is kept until you delete it or delete your account.
Short-lived security records — email verification codes, password reset codes — expire within hours.
Usage records (page views) are retained in aggregate. When you delete your account these are permanently detached from your identity rather than removed, so they no longer describe a person.
Deleting your account
Go to Settings and choose Delete my account. It is immediate and cannot be undone.
This permanently removes your profile, journal entries, taper plans, threads, replies, votes, follows, direct messages, notifications, and push tokens.
Two things survive by design: page-view records are de-linked from you rather than deleted, and text of yours that another member quoted inside their own reply stays in their post. If you need a quote removed, email us.
Your rights
If you are in the EEA or UK, you have the right to access, correct, delete, export, or restrict processing of your data, to object to processing based on legitimate interests, and to withdraw consent at any time. Withdrawing consent does not affect processing that already happened.
Most of this you can do yourself in Settings. For anything else, email [email protected] and we will respond within 30 days.
You also have the right to complain to your national data protection authority — your local supervisory authority in the EU, or the ICO in the UK.
If you are in California, Washington, or another US state with a comprehensive privacy or health-data law, you have comparable rights — including, under Washington's My Health My Data Act, the right to have consumer health data deleted. Use the same address.
Children
TaperCommunity is for adults. You must be 18 or older to create an account, and we do not knowingly collect data from children. If you believe a minor has an account, email us and we will remove it.
Security
Traffic is encrypted in transit. Passwords are stored only as bcrypt hashes. Access to the production database is limited to the people who operate the service. No system is perfectly secure — if we discover a breach affecting your data, we will notify you and the relevant supervisory authority as the law requires.
Changes and contact
If this policy changes materially we will update it here and change the effective date. Questions, requests, or complaints: Velebit Health, Inc. — [email protected]
Also worth reading: