Privacy at a glance
- Your remote-control content travels between your devices. Tappio does not route your typing, clipboard contents, or remote-control commands through our servers.
- Helping us improve Tappio is optional. Product analytics and Diagnostics & crashes start off. You can choose either, both, or neither, and change your mind in Settings.
- Reports describe how Tappio works, not your private content. We use PostHog’s EU Cloud for these reports. A random installation ID lets us recognize reports from the same installation.
- No Tappio account is needed. We do not sell personal information, show third-party ads, or use reports to track you across other companies’ apps and websites.
- Questions or deletion requests? Email privacy@tappioapp.com.
Who we are
Tappio is operated by Maaya Labs LLC, a one-person studio based in California, United States. This policy covers the Tappio mobile apps, desktop companion software, and Tappio website. Features and reporting availability can differ by platform and version.
Maaya Labs LLC is responsible for the personal information described here (the “controller” under applicable data protection laws). Contact us about privacy at privacy@tappioapp.com, or about the company at contact@maaya-labs.com.
Data on your devices
Tappio connects your phone or tablet to a computer running the desktop companion over your local network. The devices process and exchange the information needed for the features you use:
- Connection and pairing: device names, local network addresses, device identifiers, and pairing credentials help your devices find and trust each other. Saved connection details stay on your devices.
- Mouse, keyboard, and system controls: your input and commands go to the computer you control.
- Clipboard Sync: text or other supported clipboard content moves between your devices when you use this feature.
- App Launcher, Media Remote, and Browser Remote: your devices exchange commands and supported information such as app names and icons, playback status, song information, and artwork.
- Custom Wallpapers: Tappio stores the image you choose locally for your background. We do not upload that image to our servers.
Tappio does not upload this remote-control content as analytics or diagnostics. Actions you take in another app, such as opening a website or pasting into a cloud document, are also subject to that app or service’s privacy practices.
Permissions are for the features you choose
Local Network access lets Tappio discover and connect to your computer. Camera access lets you scan a pairing code. The system photo picker lets you select a wallpaper. Desktop Accessibility and, where needed, Automation permissions allow the companion to perform the controls you request. You can manage permissions in your device’s system settings; turning one off may stop the related feature from working.
Preferences, pairing records, cached content, and local troubleshooting logs may remain on your devices. Some data may also be included in backups managed by your operating system or backup provider. Removing Tappio does not necessarily remove keychain entries, desktop application-support files, or backups. We cannot delete those copies remotely.
Optional analytics and diagnostics
On iPhone and iPad, you can independently choose whether to share these two kinds of reports:
- Product analytics: which Tappio features are opened or used; setup and pairing outcomes; connection timing ranges; the other device’s platform and app version; and paywall, trial, purchase, renewal, or restore outcomes. These reports help us understand which features are useful and where people get stuck.
- Diagnostics & crashes: predefined technical error codes and counts of supported operations that succeeded, failed, or were refused. On iOS, this also includes filtered crash details, such as the Tappio code involved, technical memory addresses, processor architecture, and app/operating-system versions. These reports help us find and fix problems. The Mac companion sends technical diagnostics when permitted, but does not automatically upload native crash reports.
Reports also include a timestamp, platform, app and operating-system versions, reporting-library version, development/release designation, and which reporting categories are enabled.
Reports do not include what you type or copy, screenshots or screen recordings, photos, web addresses or browsing content, media titles or artwork, names of the apps you control, computer names, pairing secrets, payment details, purchase receipts, or Apple transaction identifiers. We do not use session replay or record individual mouse movements or keystrokes.
A random ID, not your identity
When you enable reporting, that Tappio installation creates a random Analytics ID. It is not your name, email, advertising ID, hardware ID, or pairing ID. Your phone and Mac have separate IDs; Tappio does not send either ID to the other device.
Reports from the same installation can be linked over time, so we treat them as pseudonymous personal data, not anonymous data. We do not create PostHog person profiles or use the ID to follow you outside Tappio.
Reports are sent to PostHog’s EU ingestion service. Storage of event IP addresses and location enrichment are disabled. As with any internet connection, the receiving servers and network providers encounter your source IP address; that is different from the local network address used to connect your devices.
Your reporting choices
Both reporting categories start off everywhere. The iPhone/iPad app may invite you to choose after your second successful connection. Dismissing that invitation leaves reporting off. Accepting the Terms and Conditions or reading this policy does not enable reporting.
Open Tappio Settings → Help improve Tappio to change either choice. Your remote-control features remain available if you decline. Activity from before you enabled reporting is not uploaded later.
While connected, your phone sends its reporting choices to the Mac companion. The Mac starts with reporting off on each launch and connection, and reports only the categories allowed by the connected phone. It stops when it receives a withdrawal or detects disconnection. Choices are not synced to other phones.
Turning a category off stops new reports for that category and discards unsent reports. Requests already sent cannot be recalled. Turning reporting off does not automatically delete reports already received; you can request deletion as described below.
On iOS, crash reporting can temporarily save a raw crash file on your device; only a filtered report is eligible for upload. After you turn diagnostics off, the native crash handler may remain active until the app exits, but crashes from the disabled period are not uploaded.
Purchases
Apple handles App Store payments. Tappio uses verified purchase information from Apple to unlock paid features and check subscription, restore, or Family Sharing entitlements. We do not receive your full card number or payment credentials.
If you enable Product analytics, we may receive the plan and purchase outcome described above, without the receipt or transaction identifier. Apple separately processes purchase and store information under its privacy policy.
Website, updates, and support
Website and downloads. Cloudflare serves our website and download infrastructure. When you visit or download a file, it processes connection information such as your IP address, requested URL, time of request, browser or software information, and security-related traffic data to deliver the service and protect it against abuse.
The website does not currently include PostHog analytics, advertising trackers, or session replay. It stores your light/dark theme choice in your browser’s local storage. You can remove that preference by clearing this site’s data in your browser.
Mac updates. The Mac companion uses Sparkle to check our release service for software updates. Automatic update checks are enabled by default in the distributed Mac app. These requests are separate from optional analytics and expose ordinary connection information to the download infrastructure. Tappio does not enable Sparkle’s optional system profiling.
Support. If you email us, we receive your email address, your message, and any attachments or diagnostic files you choose to send. Our email service processes that correspondence so we can reply and resolve the issue. Avoid sending passwords, pairing secrets, payment credentials, or unnecessary private content.
Providers and international transfers
We use PostHog to process optional reports, Cloudflare to deliver and protect the website and downloads, and email providers to handle correspondence. Apple handles App Store transactions under its own terms. We share information needed for these purposes, not remote-control content for advertising.
PostHog reports are hosted in its EU Cloud region. Maaya Labs LLC operates in the United States, and provider support or subprocessors may process information in other countries. EU hosting does not mean that every access or processing operation stays within the EU.
Where applicable law requires safeguards for international transfers, those transfers must be covered by an appropriate legal mechanism, such as an adequacy decision or standard contractual clauses. PostHog describes its EU, UK, and Swiss transfer provisions in its Data Processing Agreement. You can contact us for information about the safeguards relevant to your data. See also Cloudflare’s privacy policy.
We may disclose information when required by law, to respond to a valid legal request, or when necessary to protect people, investigate abuse, or defend legal rights. If Tappio becomes part of a merger, acquisition, or sale, relevant records may transfer subject to applicable law and appropriate privacy protections.
We do not sell personal information or share it for cross-context behavioral advertising.
How long we keep data
Optional reports: we have selected a one-year retention period for analytics and diagnostic events in PostHog. You can request deletion by emailing us. Deletion of active records and expiry of provider backups are separate processes.
Support messages: we keep correspondence for as long as needed to handle your request, follow up on a recurring problem, and meet applicable recordkeeping or legal obligations. We consider the issue’s status, whether the information is still useful, and whether a dispute requires us to preserve it.
Website and download records: retention depends on the infrastructure service and whether records are needed to investigate an error, security incident, or legal obligation. They are separate from PostHog reports and do not share the one-year analytics retention setting.
On-device data: saved preferences, trust records, and selected content remain until you remove them or the app or operating system clears them. Data already copied into another app or a device backup is controlled there.
We may retain limited information where the law requires it or where it is necessary to establish, exercise, or defend legal claims. Where we cannot fulfill a deletion request in full, we will explain the applicable reason.
Why we can use data
Where EU, UK, or similar data protection laws apply, we rely on:
- Your consent for optional Product analytics and Diagnostics & crashes. You can withdraw it in Settings at any time, without affecting the lawfulness of earlier processing.
- Providing the service you request for necessary app functionality, checking paid-feature access, and handling support needed to fulfill our agreement.
- Legitimate interests in operating a reliable website, distributing updates, securing our services, answering general enquiries, and protecting legal rights, balanced against your privacy rights.
- Legal obligations where we must keep records or respond to a legally binding request.
We do not use your information for solely automated decisions that produce legal or similarly significant effects on you.
Your privacy rights
Depending on your location and the law that applies, you may have rights to access, correct, delete, or receive a portable copy of your information, restrict its use, withdraw consent, and complain to your local data protection authority.
You may object to processing based on legitimate interests where applicable law gives you that right. California and other US residents may also have rights to know about collection and disclosure, use an authorized agent, and appeal a denied request where required by law. We do not discriminate against you for exercising applicable privacy rights.
Send requests to privacy@tappioapp.com. We will respond within the period required by applicable law and explain any permitted extension. We may ask for information reasonably needed to verify the request, but do not require you to create an account.
For reports from your iPhone or iPad, include the Analytics ID shown in Tappio’s reporting settings, if available. Your Mac has a separate ID, so the phone ID cannot identify its reports. If your request also concerns your Mac, tell us so we can help you locate the relevant information. If we cannot reliably identify your reports, we will explain that limitation.
We do not sell or share data for targeted advertising, including when a browser sends a Global Privacy Control or Do Not Track signal. Such signals do not change the optional reporting choices you make inside Tappio.
Children’s privacy
Tappio is a general-purpose utility and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us so we can investigate and delete it as appropriate.
If you are not old enough to give valid consent to optional reporting where you live, leave reporting off unless a parent or guardian can lawfully provide the necessary consent.
Security and policy changes
We use safeguards intended to protect information, including authenticated device pairing, encrypted connections between your devices, and limits on what reports can contain. No device, network, or storage system is completely secure. Keep your devices updated and only pair computers and phones you trust.
We may update this policy as Tappio or our practices change. We will update the date on this page and provide additional notice of material changes when required. If a change requires new consent, we will ask for it before the affected optional processing begins.
Privacy questions: privacy@tappioapp.com.