tapstep Privacy Policy
Version 1.0 — Effective: [DATE]
DRAFT — review by qualified counsel required before publication. [Entity registration pending: complete controller identification (БИН, registered address) in Section 12 when ТОО "Tapstep" is registered. EU/UK representatives to be appointed before launch — see Section 11.]
This Privacy Policy describes how Tapstep LLP (ТОО "Tapstep"), Republic of Kazakhstan ("Tapstep", "we"), processes personal data when you use the tapstep desktop application, command-line tools, and the tapstep.dev websites and services (together, the "Services"). Tapstep is the controller of the account and service data described below.
Summary (not a substitute for the full policy): tapstep is local-first. Your tests, recordings, and results stay on your machine unless you sign in and use cloud sync, or invoke AI features. We do not sell personal data and we do not run advertising or analytics trackers in the app.
1. Data we process, and why
a) Software without an account (default)
The app works fully locally without sign-in. In this mode:
- Your test data — flows, run results, screenshots, per-step frames, videos, network logs, and AI chat transcripts — is stored only on your device (e.g., under
~/.tapstep/and your project folder). We do not receive it. Note that recordings and logs of the application under test may contain that application's data; treat these folders accordingly. - Update checks — the app periodically requests an update manifest from our server (
s3.tapstep.dev). Like any web request, this exposes your IP address and standard HTTP metadata to our server. We use it only to serve the update. Legal basis: legitimate interest (keeping the Software secure and current).
b) Account and cloud features (optional, on sign-in)
If you create an account and sign in:
- Account data — e-mail address (used as your username), name if you provide it, and credentials, managed by our authentication service (
auth.tapstep.dev). Sign-in tokens are stored in your operating system's keychain, not in plain files. We also record your acceptance of our legal terms (version and timestamp). Legal basis: performance of a contract. - Version history ("Publish") — publishing a project pushes your test files to a git remote that you configure (e.g., your own GitHub repository). That data goes to your chosen git host, not to Tapstep, under that host's terms.
- Cloud runs and sync (CLI) — if you connect the CLI to our backend and push scenarios or run tests in the cloud, we store: your test flows; run reports (steps, pass/fail, duration, device); and run artifacts — a screen recording (if you enable video), and on failure a screenshot, an accessibility-tree snapshot, and a network log which can include request and response bodies of the application under test. Legal basis: performance of a contract.
Transition note: parts of our backend currently operate under our predecessor domain (
qamqor.pro) while migration totapstep.devcompletes. The same policy applies to both.
c) AI features (optional, per your configuration)
When you use AI features, session content is sent to the AI provider you configure:
- Built-in chat/agent (Anthropic API) — sends your prompts, test file contents, on-screen accessibility/element trees (text), and failure reports/network logs. Screenshots of the app under test are shown to you locally but are not sent to the model in this mode.
- Third-party CLI providers (e.g., Claude Code by Anthropic, Codex by OpenAI) — the respective CLI runs under your own account with that provider and may also read files in your workspace as part of its normal operation.
- CLI AI assistance / failure triage — when configured, sends the failing step context, the accessibility snapshot, failed network calls, and a screenshot of the failure to your configured provider.
Because you configure the provider and the API key or account is yours, that data flows directly from your machine to the provider under your own agreement with them — Tapstep is not a party to it. We do not store this content on Tapstep servers. Providers process it under their own terms and privacy policies; check their data-retention and training settings. Do not point AI features at applications containing personal data you are not permitted to share. AI features are off unless you configure an API key or provider. Legal basis (where Tapstep processes anything in this flow): your consent, given when you enable the feature.
Privacy Mode (optional, on-device PII reduction)
Tapstep includes an optional Privacy Mode (ai.privacy in project settings, or TAPSTEP_PRIVACY=1 for the CLI). When enabled:
- Before AI-bound content leaves your machine, a detection model running entirely on your device (OpenAI's Privacy Filter, Apache-2.0) scans it for personal identifiers — names, e-mail addresses, phone numbers, physical addresses, account numbers, and credentials/secrets — and replaces them with pseudonymous placeholders. The mapping between placeholders and original values never leaves your machine.
- Screenshots of the app under test are not sent to AI providers while Privacy Mode is on.
- With third-party CLI providers, coverage is partial: only the messages Tapstep passes to the CLI are pseudonymized. The CLI's own activity (reading workspace files, capturing screens) happens outside Tapstep and is not filtered; the app indicates this whenever such a provider is active.
- If the detection model is not installed or fails, Tapstep refuses to send rather than sending unfiltered content (fail-closed).
- Enabling Privacy Mode triggers a one-time download of the detection model (~0.9 GB) from Hugging Face (huggingface.co); like any web request, the download exposes your IP address to that host. It contains no data of yours.
Privacy Mode reduces, but does not eliminate, personal data in AI traffic. It is a data-minimization aid, not an anonymization technique or a guarantee: detection is statistical and can miss identifiers, especially uncommon formats. It does not change your responsibilities under Section 2 — do not point AI features at applications containing personal data you are not permitted to share, with or without Privacy Mode.
d) Websites; cookies
Our websites serve static content and set no analytics or advertising cookies. Our sign-in service (auth.tapstep.dev) sets strictly necessary cookies only, to maintain your authentication session. [Confirm before launch that no other cookies are introduced.]
e) What we do NOT do
- No advertising, no sale of personal data, no cross-site tracking.
- No telemetry or usage analytics in the app today. The EULA and Terms reserve the right to introduce aggregated, de-identified usage statistics; before any such collection begins, this policy will be updated, and where required by law it will be opt-in.
2. Your responsibilities as a tester
tapstep automates and records applications you choose to test. Screens you record or send to AI providers may contain personal data of your own users. For that data, you are the controller and Tapstep processes nothing unless you sync it to our servers; where you do, Tapstep acts as your processor. [Counsel: a data-processing addendum for business customers to be prepared.]
3. Sharing
We share personal data only with: (a) infrastructure providers hosting our servers (currently Hetzner Online GmbH, data centers in Germany and Finland); (b) the AI providers you yourself configure (Section 1c); and (c) authorities where required by law. We do not otherwise disclose personal data.
4. International transfers
Our servers are hosted by Hetzner in Germany and Finland (EU). Two transfers can occur:
- Access from Kazakhstan. Tapstep personnel administer the Services from the Republic of Kazakhstan, which has no EU adequacy decision; where GDPR applies, this access is safeguarded by the EU Standard Contractual Clauses. [Counsel: put SCCs (Module 4) in place for the Hetzner→Tapstep access leg; consider a transfer impact assessment.]
- AI providers. When you enable AI features, content goes from your machine directly to the provider you configured (often in the US) under your own agreement with that provider; Tapstep does not transfer it.
5. Retention
- Local data: under your control; delete it by deleting the app's folders.
- Account data: kept while your account exists; deleted upon account deletion request.
- Synced content: kept until you delete it or your account; after account termination, removed following the 30-day export window in the Terms of Service.
- Server logs (e.g., update requests): rotated after at most 30 days. [Confirm duration matches server config.]
6. Your rights
Depending on your jurisdiction, you may have rights to access, rectify, delete, export, restrict, or object to the processing of your personal data, and to withdraw consent where processing is based on it. Contact privacy@tapstep.dev to exercise them; we respond within the timelines required by applicable law.
- EU/UK (GDPR): you may also lodge a complaint with your local supervisory authority (in the UK, the ICO).
- United States: we do not sell or share personal information as defined by US state privacy laws; we honor access and deletion requests from all users regardless of location.
- Brazil (LGPD): you may exercise the rights in Art. 18 LGPD via the same contact.
- Kazakhstan (Law No. 94-V): you may request information about, correction of, or deletion of your personal data, and withdraw consent, via the same contact. Cross-border transfer notice: account data is stored in the EU as described in Section 4. [Counsel: Russian/Kazakh versions of this policy and the consent wording under Art. 8(4) to be prepared; localization of databases under Art. 12 under review.]
7. Security; data breaches
Transport encryption (HTTPS) for all Tapstep services; signed and notarized application binaries; signed update packages verified before installation. No method of storage or transmission is 100% secure. If a breach affects your personal data, we will notify you and the competent authorities without undue delay, as required by applicable law.
8. Children
The Services are not directed at children under 16, and we do not knowingly collect their data. If we learn that an account belongs to a child under 16, we will delete it.
9. Changes
We will post updated versions here with a new version number and effective date, and present material changes in the app for renewed acceptance. Prior versions remain available on request.
10. Contact
Tapstep LLP (ТОО "Tapstep") — privacy@tapstep.dev
11. Representatives
[To be appointed before launch and named here: EU representative under Art. 27 GDPR; UK representative under UK GDPR.]
12. Controller identification
Tapstep LLP (ТОО "Tapstep"), Republic of Kazakhstan. [Registered address and business identification number (БИН) to be added upon registration of the ТОО.]