Tapproval Privacy Policy
Last updated: September 2026
Tapproval is built so that your data stays yours.
What Tapproval collects
Nothing. Tapproval has no accounts, no analytics, no tracking, and no servers of ours. We never see your prompts, your code, your conversations, or your taps.
Where your data lives
- On your own devices. The watch app talks directly to a small helper running on your own computer, over your own network. Prompts, sessions and decisions travel between your watch and your computer — nowhere else.
- In your own iCloud. When the direct connection is unavailable, approval cards travel through CloudKit's private database — storage that belongs to your personal Apple ID. Apple hosts it; we cannot read it. It is the same place your own notes and backups live.
Purchases
The one-time unlock is processed entirely by Apple through the App Store. We receive no payment details and keep no purchase records beyond what StoreKit provides on-device.
What the open-source helper stores locally
The helper keeps a small audit log on your computer (which prompts appeared and how they were answered) so the app can show you your day. It records project folder names only — never full paths, never file contents — and it never leaves your machine.
GDPR
Tapproval is made in Denmark, so European data protection law (the GDPR) applies to it. Most privacy policies use this section to list everything they do with your data. This one is mostly a list of things that never happen — but not entirely, and the exceptions are the honest part.
The app itself
Nothing you do in Tapproval reaches us. Your prompts, sessions, decisions and audit log stay on your own devices and in your own iCloud. We have no servers, no accounts and no analytics, so there is nothing for us to look at, sell, lose or be asked to hand over.
That is not just a promise about our intentions — it is a fact about the architecture, and you can check it. The helper that runs on your computer is open source, and the watch app talks only to it and to your own Apple ID's private iCloud storage.
In legal terms: for what happens inside the app we are not a controller of your personal data, because we never determine what happens to data we never receive. Where processing happens entirely on your own devices, with no access by the developer, that is the generally accepted position.
The one place we do hold personal data
Being honest means naming it. We hold no list of users, no account and no address, so the only way we come to know anything about you is if you tell us.
If you email us. Writing to the address below means we hold your email address and whatever you put in the message, for as long as it takes to answer you and to keep a record of the conversation. The lawful basis is our legitimate interest in answering people who contact us (Article 6(1)(f)) — you contacted us, and replying requires reading what you wrote.
Your rights
For that one narrow set of data, you have the rights the GDPR gives you, and we will honour them:
| Right | What it means here |
|---|---|
| Access | Ask what we hold about you and get a copy |
| Rectification | Have anything wrong corrected |
| Erasure | Have it deleted — always |
| Restriction | Have us stop using it while a dispute is sorted out |
| Portability | Get it in a machine-readable form |
| Objection | Object to our legitimate-interest processing, i.e. the support mailbox |
Ask by writing to the address below. We will answer within one month. There is nothing to pay.
No automated decision-making. Tapproval sorts your commands into risk tiers, but that judgement is about a command, not about a person, and it never produces a decision about you. Nothing we run profiles you or decides anything concerning you automatically.
No selling, no advertising, no third-country transfers of our own. We have no advertising partners and no analytics vendors. We transfer nothing outside the EU ourselves; where Apple does so as part of running the App Store and iCloud, Apple's own safeguards apply.
Complaints
If you think we have handled your data wrongly, please tell us first — it is usually a mistake we can fix. You also have the right to complain to a data protection authority. For us that is the Danish one (Datatilsynet, datatilsynet.dk), because that is where Tapproval is made — it does not depend on where you are. If you live or work in an EU country, you may go to that country's authority instead. You do not have to go through us first.
Changes
If this policy ever changes, the updated text ships with the app update that changes it.
Contact
Questions, and any request about your own data: tapproval@thoughtfulsteward.org
We have not appointed a Data Protection Officer, and are not required to: Tapproval is not a public authority, its core activity is not large-scale monitoring of people, and it processes no special categories of data (Article 37(1)).
Appendix: the GDPR articles behind the section above
For readers who want to check the working. Nothing here changes what the policy says; it just shows where each part comes from.
| Claim above | Where it comes from |
|---|---|
| What must be disclosed at all | Art. 13(1)(a)–(f), 13(2)(a)–(f) — controller identity and contact, purposes and legal basis, recipients, transfers, retention, rights, complaint right, whether data must be provided, automated decision-making |
| "We are not a controller for what happens in the app" | Art. 4(7) — a controller is whoever "determines the purposes and means of the processing". Where processing is local to the user's device and the developer has no access, the developer is generally not a controller. Note this rests on there being no transmission to us; it would change the day we added a server |
| Why the law applies to us at all | Art. 3(1) — established in the Union, so it applies to our processing wherever it happens |
| Support email basis | Art. 6(1)(f) — legitimate interests |
| The rights table | Arts. 15 (access), 16 (rectification), 17 (erasure), 18 (restriction), 20 (portability), 21 (objection) |
| One month, free of charge | Art. 12(3) and 12(5) |
| "No automated decision-making" | Art. 22 — which covers decisions producing legal or similarly significant effects concerning a person. Risk-tiering a shell command is not that |
| Complaint venue | Art. 77(1) — habitual residence, place of work, or place of the alleged infringement |
| No DPO | Art. 37(1)(a)–(c) |
| No processing register kept | Art. 30(5) — under 250 people, and the processing is occasional, low-risk and involves no special categories |
What we deliberately do not claim. We do not say Tapproval is "GDPR certified" — no such certification exists under Art. 42 that we hold. We do not say the GDPR does not apply to us. And we do not promise anything about how Apple handles data it collects in its own right, because that is Apple's to describe, not ours.