Your information
Privacy policy
What Tapshore processes, what stays on your devices, and how account deletion works.
Effective 2026-09-08
Who is responsible
Tapshore is provided by 成都微草游方科技有限公司.
Email micrograsstour@163.com for support or privacy questions.
Your screen and remote input
You choose the Mac app or window to view. If you choose Desktop mode, the selected display can include other windows and notifications. Review what is visible before sharing.
Your selected screen view and remote input travel between your devices over an encrypted connection. A relay may carry encrypted traffic when a direct connection is unavailable. The account service does not store screen recordings, keystroke contents, clipboard contents or content from your Mac apps.
App names, icons, available windows and window titles used by the remote picker travel through the private connection between your devices. They are not uploaded as an app inventory to the account service.
Information we process
- Account and sign-in information
- Your account identifier, chosen sign-in method, email address and provider identity. A provider may also supply a display name or profile image. We use these to sign you in and maintain your account. Sign-in codes are temporary; Apple authorization grants are encrypted while retained for required revocation.
- Your trusted devices
- Installation identifiers, public signing keys, device names, platform, remote-access settings and connection status. These let you recognize your Macs, authorize devices and revoke access.
- Connection and security records
- Session and pairing identifiers, timestamps, authentication outcomes, connection setup messages, network information and rate-limit records. Network providers receive IP addresses needed to deliver requests; approximate country information can affect sign-in availability.
- Purchases and connection tests
- Account-linked subscription status, product and store information, renewal or expiry information and connection-test use. Purchases are processed by the relevant app store; Tapshore does not collect your payment card details.
- Device and feature diagnostics
- Software used for sign-in, purchases and optional QR scanning can process installation identifiers, device and app versions, feature use, performance and error information to operate those features and understand their reliability. Subscription services also process purchase analytics.
- Support and deletion requests
- Information you choose to send when asking for help, and the sign-in proof needed to verify an account deletion request. Please leave passwords, verification codes, private keys and sensitive screen contents out of support emails.
We use this information to provide access, keep accounts and sessions secure, verify purchases, prevent abuse and answer requests. Our public information pages have no advertising tags or analytics scripts. The account deletion service requests the information needed to verify your sign-in method and your decision to delete. If you choose Google, that verification page loads Google's sign-in component. The host also processes connection metadata to deliver and protect requests.
Account deletion in your browser
The account deletion service uses necessary cookies to protect verification and let you check a saved request. The verification cookie has a 15-minute lifetime that refreshes as you use the flow. After you confirm deletion, a separate status cookie can last for up to 90 days from confirmation. These cookies do not sign you in to remote access or authorize purchases.
Clearing these cookies removes this browser's access to the saved status; it does not cancel a deletion request you already confirmed. The Google verification component, when selected, also processes information under Google's own policies.
Services involved
Tapshore uses the following services for the functions described here. They receive the information needed for those functions and may process service, device or network metadata under their own policies.
- Cloudflare: website hosting, account and device records, authentication and connection coordination, security controls, and encrypted traffic relay when needed.
- Resend: delivery of sign-in codes and account-deletion verification links, including the destination address, message contents and delivery records.
- Apple and Google: identity verification when you choose their sign-in methods, and purchases made through their stores. Depending on the platform and your sign-in choices, Google's sign-in software can process profile/contact information, including a name, email address or phone number, approximate location, user and device identifiers, and usage information under Google's privacy policy.
- Google ML Kit on Android: optional QR recognition runs on your device. The component processes installation identifiers, device/app information and feature performance, usage and error information as described in Google's data disclosure. Scan images stay on your device. Tapshore sends the code from your Mac’s QR invitation to the account service to check and approve the request to add that Mac.
- RevenueCat: subscription verification, account-linked purchase entitlement management and purchase analytics. See RevenueCat's privacy policy.
Tapshore is operated from China and uses service providers with international infrastructure, including processing in the United States. Sign-in email contents and delivery records are stored by Resend in the United States; an email sending region does not determine its storage location. Account, connection and purchase services may process information outside your country. Tapshore does not promise storage in a particular country. Contact us to request information about the applicable processing and transfer arrangements.
How long information is kept
Active account and device records support your account until they are removed or your account is deleted. Specific authentication records have the following cleanup rules:
- Sign-in challenges expire after ten minutes. Expired challenge records are eligible for cleanup after a further 24 hours.
- Sessions have a maximum 30-day lifetime. Session and refresh-token replay records are eligible for cleanup after their refresh validity ends plus 24 hours.
- If you started or used a connection test, a keyed identity fingerprint is retained for 730 days after it is recorded at account deletion to prevent repeat test use. Recording it again may extend expiry to 730 days from that later record. This fingerprint record contains no email address, provider subject or account ID. It is pseudonymous, not a claim of complete anonymity.
A request to add a Mac with your phone expires after five minutes. Enrollment and recovery records are eligible for cleanup 24 hours after their expiry or recovery deadline, whichever is later. A cancellation record can remain for 24 hours to stop a delayed request from adding a Mac after you cancel.
Web deletion verification links expire after ten minutes, and a verified request must be confirmed within five minutes. Expired verification records are eligible for cleanup after a further 24 hours. Confirmed browser-receipt records become eligible after their 90-day receipt lifetime ends and any deletion still in progress has finished. This is separate from the completed deletion recovery period below.
Cleanup runs periodically in batches, so expiry marks eligibility for removal rather than an exact deletion second.
Deleting your account ends remote sessions and removes live devices, pairings, identities, sessions and entitlements. Apple authorization revocation and RevenueCat customer deletion are queued and retried separately. Encrypted Apple tokens needed for revocation are cleared when Apple confirms success. Deletion status and recovery records remain so interrupted cleanup can finish and its status can be checked.
After account cleanup and all associated provider cleanup have completed, deletion status, recovery keys, completed provider cleanup records and the remaining account record become eligible for removal after 90 days. That period starts at the last successful cleanup step. Unfinished cleanup is retried; records with no reliable completion time are retained for investigation instead of being treated as complete. The separate connection-test fingerprint keeps its own 730-day expiry.
Short-lived security records can remain after account access is removed. Request replay records have a ten-minute validity period; rate-limit counters use windows of up to 24 hours and are then eligible for cleanup. Expired room records are removed after the service confirms that access is closed. At account deletion, retained relay budget records lose their original account and connection links; they remain through the current calendar month or credential expiry, whichever is later. Subscription event references and content digests are retained to detect duplicate messages after the account link is removed; those audit records do not currently expire automatically. Support correspondence, operational logs and service-provider delivery records or backups have separate retention and may outlast live account deletion.
Your choices and requests
Stop remote access from your Mac, remove a trusted device, sign out, or use Account → Delete account in Tapshore. Our account deletion page explains the process and how to request deletion without reinstalling the app.
Depending on applicable law, you may request access to, correction or deletion of your personal information, a portable copy, or restriction of or objection to certain processing. Where processing depends on consent, you may withdraw it without affecting processing already carried out. Contact our support address and describe your request; we may ask for information reasonably needed to verify ownership. You may also complain to the relevant privacy authority. We process information needed to provide the service you request, protect it against abuse, meet legal obligations and, where required, act on your consent.
Email micrograsstour@163.com for support or privacy questions.
Changes to this policy
We will update this page when our practices change and identify its effective date. Material changes will be communicated as required before they take effect.