Privacy policy
Last updated 5 September 2026
TapRev is an iPhone app published by Yazeed Al Oyoun. This policy describes what the app does with data, in the order a technical reader will want it. The short version: there is no TapRev server, so there is nowhere for your data to go.
1. What the app stores, and where
| Data | Where it lives | Why |
|---|---|---|
| Payment-platform API keys | iOS Keychain, device-only accessibility. Not synced to iCloud Keychain; not included in backups restored to another device. | To read your revenue from each platform. |
| Transactions, subscriptions and customer records (name, email, country where the platform provides them) for the most recent twelve months | The app’s local database on your device. | To calculate MRR, ARR, churn and the rest, and to show history offline. |
| A summary of MRR, trend and platform count | A shared container on your device that the home-screen widget can read. Cleared when there is no active subscription. | So the widget can show a number without opening the app. |
| The date you first opened the dashboard, and a launch count | iOS Keychain, device-only. Not removed by Delete All Data or by deleting the app. | So the free first day can’t be reset by reinstalling. |
| Your settings (display currency, alert preferences, thresholds, daily summary hour) | Local app preferences on your device. | To remember how you set things up. |
2. What the app sends, and to whom
Payment platforms
When you connect a platform, the app sends your API key to that platform’s API over HTTPS, from your phone, and reads back your data. Every request is a read; the app contains no code that writes to a platform. The platforms are Stripe, Paddle, Lemon Squeezy, Polar, Gumroad, FastSpring, Dodo Payments, RevenueCat and Adapty, and each one’s own privacy policy governs what it does with the request.
RevenueCat (subscription verification)
The app includes one third-party SDK, RevenueCat’s purchase SDK, to handle the Pro subscription through the App Store. On launch and when the app returns to the foreground it contacts api.revenuecat.com with your App Store transaction information, a random per-install identifier, the device’s vendor identifier (IDFV, not the advertising identifier), and device model, OS version, locale and storefront. RevenueCat uses this to confirm whether you have an active subscription. It is not linked to your name or email, and it is not used to track you across apps or sites. RevenueCat’s handling of that data is described in RevenueCat’s privacy policy.
Nobody else
The app has no backend, no account system, no analytics SDK, no crash reporter and no advertising. Notifications are generated on the device and never pass through a push server. The app’s privacy manifest declares no tracking and no tracking domains.
3. The App Store privacy label
The label declares one data type — Purchase History, used for app functionality, not linked to your identity, not used for tracking. That is the RevenueCat subscription check described above. Nothing about your revenue, customers or keys is collected by us, because none of it leaves the device.
4. Deleting your data
- Settings → Delete All Data in the app removes every cached record and every API key from the Keychain.
- Deleting the app removes the local database and the widget container, but iOS keeps Keychain items after an app is deleted. Use Delete All Data first if you want the keys gone too, or revoke each key in the platform’s own dashboard, which stops any further reads regardless.
- Data held by a platform or by RevenueCat is subject to their policies and deletion processes.
5. Children
The app is for business use and is not directed at children under 16.
6. Changes
If what the app does changes, this page changes first and the date at the top moves. The current version always lives at taprev.app/privacy.
7. Contact
Questions: taprev@yazeed.com, @yazeedaloyoun on X, or the support page.