TapTrap runs on your phone and keeps what it records there. This page says exactly what the app stores, what the two outside services it uses receive, and how to delete everything. TapTrap is made by MNP; you can reach us at pekdemir.mn@gmail.com.
The short version
- No account, no sign-in, no server of ours. Nothing you record is sent to us, and we have no way to read it.
- The app records one thing: where the screen was tapped, and when. Not who tapped.
- Your decoy screenshot, your catches and your settings stay in the app's own storage on your phone. There is no upload, export or share button anywhere in the app.
- Without TapTrap PRO you see one full-screen Google AdMob ad, after a Classic "Don't tap" game ends — never during a trap. Google receives device and advertising data to serve it.
- Purchases run through the App Store or Google Play and are checked with RevenueCat under a random, anonymous ID. We never see your card or your store account.
1What the app records
While a trap or a Classic game is running, TapTrap saves for every tap:
- the position on the screen (x and y),
- the moment it happened.
And for the session as a whole: when it started and ended, how many taps it got, whether it was a trap or a Classic game, the screen size at the time, and the file name of the decoy image so the heatmap can be drawn over it later.
That is the entire record. TapTrap does not know who tapped. It takes no photo of them, uses neither the camera nor the microphone while a trap is running, and reads nothing from your messages, your keyboard, your notifications, your contacts, your location or any other app. A running trap only draws your own image and listens for taps on its own screen.
Your own exit taps are taken back out of the record when you leave a trap, so they never show up as somebody else's.
2Where it is kept on your phone
In two places, both private to the app:
| Place | What is in it |
|---|---|
| App preferences (iOS UserDefaults, Android SharedPreferences) |
Catches and their tap logs (tap_sessions), a trap that is still running (active_session), the hash of your PIN (pin_code), the file names of your decoy and reveal images, your reveal message and tap threshold, language, Classic theme, haptics, whether onboarding is done, and the free-trap counter. |
| App documents folder | The decoy image you picked (custom_bg_….png), a copy kept with each catch so its heatmap still has a background (session_bg_….png), and the reveal image (reveal_img_….png). |
None of this is sent anywhere. We hold no copy of it and cannot ask for one.
3Photos and camera
Exactly two screens in the app can reach your photos or your camera:
- picking the decoy image — the fake screen a snooper sees;
- picking the reveal image — the optional "caught you" picture.
Both offer the same choice: Take a photo or Choose from gallery. Take a photo and the camera opens for that single shot. Choose from gallery and your phone's own picker opens and hands the app only the image you selected — TapTrap never browses, scans or indexes your library. Either way one image is copied into the app's private folder, and that copy is all the app keeps.
On Android the app declares no camera, photo or storage permission at all; the system picker and the camera app do that work.
4Your PIN
You can set an optional 4-digit PIN that is asked for when you open Catch History. The PIN itself is never stored. The app stores a SHA-256 hash of it and compares hashes when you type it in.
Be clear about what that PIN is: a lid, not a safe. Your catches themselves are not encrypted, and anyone who can open the app on your unlocked phone can change or remove the PIN in Settings without entering the old one. That is also what you do if you forget it — there is no reset code and no recovery e-mail, because there is no account behind it.
5Ads — free users only
- One format, one place. A full-screen Google AdMob ad, shown after a Classic "Don't tap" game session ends.
- Never anywhere else. No ad runs during a trap, when you exit a trap, in Catch History, on a heatmap, or when you open the app. There are no banner ads in TapTrap 1.1.1.
- Ad content is capped at the "G" (general audiences) rating.
- When TapTrap PRO is already active as the app starts, the Google Mobile Ads SDK is never started at all: no ad is requested, no advertising ID is read, and you never see the tracking prompt.
To serve and measure those ads, Google collects and processes — we never receive any of it:
- Advertising identifiers. On iOS, the IDFA, and only if you allow it at the App Tracking Transparency prompt. On Android, the Google advertising ID (the app ships the
AD_IDpermission because the Ads SDK requires it). - Device and app data. IP address, device model, OS version, language, screen size, the app's package name and version, and an approximate location derived from the IP address.
- Ad interactions. Which ad was shown, viewed or tapped, and related diagnostics.
What you can do about it
- iPhone: the tracking prompt appears once, shortly after you open the app. Say no, or change your mind later in Settings > Privacy & Security > Tracking. The app behaves exactly the same either way — you simply get non-personalised ads.
- Android: reset or delete your advertising ID and switch off ad personalisation in Settings > Google > Ads.
- Either: buy TapTrap PRO and the ads stop for good.
- This version does not show a Google consent form (UMP) of its own. The controls above are the ones that apply.
- Saw an ad that seemed wrong? Settings > Report an ad opens an e-mail to us.
Google explains its side in its Privacy Policy, in How Google uses information from sites or apps that use its services and in its advertising technologies page.
6Purchases
TapTrap PRO is sold by Apple and Google, not by us. RevenueCat validates the purchase and answers one question for the app: is PRO active on this device? RevenueCat starts at every launch, whether or not you have PRO, because that is the question it answers.
RevenueCat gives your installation a random, anonymous App User ID. It is not your name, your e-mail or your store account. RevenueCat receives your TapTrap purchase and subscription history, the store receipt or purchase token, and technical data such as device model, OS version, app version and IP address. See its Privacy Policy.
We never receive your card number, your billing address or your Apple/Google account. What reaches the app is a single yes or no.
7Permissions
iPhone — asked only when you use the feature
- Photos — to pick a decoy or reveal image from your library.
- Camera — to take one, if you choose "Take a photo".
- Tracking — for personalised ads only. Decline and the app works exactly as before.
Never requested: microphone, location, contacts, health, notifications.
Android — what the SDKs merge into the shipped app
INTERNET,ACCESS_NETWORK_STATE— ads and the purchase check.VIBRATE,WAKE_LOCK.com.google.android.gms.permission.AD_IDand Google's Privacy Sandbox ad permissions — the Google Mobile Ads SDK.com.android.vending.BILLING— Google Play purchases.
No camera, photo or storage permission is declared.
8Deleting your data
- Settings > Reset All Data deletes every catch and tap log, your decoy image, your reveal image and message, and your PIN. It keeps your language, Classic theme, haptics and the free-trap counter.
- Catch History > the trash icon deletes the catches, their tap logs, and the screenshot copies only those catches used. It leaves your decoy image, your reveal image and message, and your PIN alone.
- Replacing or removing the decoy or reveal image deletes the old file, unless a saved catch still needs it as its heatmap background — that copy goes when you delete the catch.
- Uninstalling the app removes everything it stored.
Because none of it ever reached us, there is nothing to ask us to delete. Data held by Google (advertising) and by RevenueCat, Apple or Google (purchases) is kept under their own policies; the links above are how to reach them. Your purchase history is also what lets PRO be restored on a new phone.
9Device backups
The app's storage can be included in your own device backup — iCloud on iPhone, Google account backup on Android — if you have it switched on. Those backups belong to your Apple or Google account and we cannot see them. You can exclude TapTrap in your device's backup settings.
10Children
TapTrap is not made for children, and we do not knowingly collect anything from a child under 13. Ad content is capped at the "G" rating.
11Your rights
Everything the app records is already in your hands: the delete options above are complete and take effect at once. Where you have rights under the GDPR, the UK GDPR or the CCPA/CPRA over data processed by Google or RevenueCat, use their controls linked above, or write to us and we will point you at the right request.
12Changes to this page
If a later version of the app changes what is stored or what leaves your phone, this page changes with it and the date at the top moves. This page describes TapTrap 1.1.1.
13Contact
Questions about this policy, or about anything the app did? Write to pekdemir.mn@gmail.com. A real person reads it.