ScriptTap

Privacy Policy

Effective date: June 10, 2026

ScriptTap is in active pre-release development. This policy describes the app behavior and service integrations currently built or being prepared for launch.

Developer And Contact

ScriptTap is developed by Roman Rashkovskiy. Privacy and support options are listed on the Support page. Account deletion is available through the app and the Account Deletion page.

App Purpose And Local-First Behavior

ScriptTap builds and runs user-controlled Android automation scripts. Scripts, local assets, screenshots, crop outputs, image targets, AI imports/exports, and command data are stored locally by default on the user's device.

Script execution stays local. ScriptTap does not upload screen images, script assets, or command data unless the user chooses a feature that shares or syncs that data, such as personal cloud backup/sync, user-directed AI package sharing, feedback, support, or a future public sharing feature.

Permissions And Sensitive Access

ScriptTap uses Android Accessibility Service to perform user-created taps, swipes, gestures, navigation, UI node reads, and related automation actions. The user defines the scripts that control those actions.

ScriptTap uses Android screen capture / MediaProjection on demand for image matching, pixel checks, GetPixelColor, selected-area OCR, screenshot capture, visual triggers, SmartTap, and user-created automation logic that needs to inspect visible screen content. OCR uses on-device ML Kit recognition on the selected area and does not upload screenshots or recognized text.

Some user-created device commands may request or route the user to Android controls such as Write Settings, Notification Policy Access, supported system settings panels, app-launch selection, the Storage Access Framework file picker, ringtone selection, or TextToSpeech settings. These requests are made only when needed for a user-created command or workflow.

ScriptTap does not use root, runtime ADB, hidden Android APIs, keyguard bypass, unapproved screen capture, silent send/call/share behavior, or permission workarounds. ScriptTap does not use these permissions to read private messages, collect personal data unrelated to user scripts, or control the device outside user-created scripts.

Firebase And Google Services

ScriptTap includes Firebase services for app reliability, configuration, accounts, and future cloud features:

ScriptTap uses an app-scoped random installation ID and local trial state. ScriptTap does not use hardware identifiers such as IMEI or serial number for this purpose.

Trial, Accounts, And Subscriptions

ScriptTap can work without login, but free mode may have limits. A local 7-day premium trial starts on first launch. Premium, subscription, and manual grant status are account/server-backed when available.

Google Play Billing will handle subscription payments when subscriptions are implemented in the public store flow. ScriptTap does not collect payment card details directly. Subscription entitlement recovery foundations do not grant premium from an email match alone.

Personal Cloud And Public Sharing

Personal cloud backup/sync is for signed-in eligible accounts and stores private user script packages, folder state, and compact routine recovery state under the user's account. Script packages may include user-created script data and linked image assets, screenshots, or crop outputs when the user has saved those assets and chooses cloud sync. Free and trial users may be blocked or read-only where premium cloud access is required.

Personal cloud data is not public sharing. Public script sharing is not built yet. Future public scripts will be searchable or visible to other users only when the user explicitly makes them public.

Advertising

ScriptTap can use Google AdMob rewarded ads for free-user unlock gates, including the Main Overlay Play unlock and the local one-hour Routines execution unlock where enabled. ScriptTap does not use banner ads, interstitial ads, startup ads, editor ads, or runtime child-action ads.

AdMob and Google's User Messaging Platform may process ad-related identifiers, consent state, device information, IP address, app/ad interactions such as ad views or taps, diagnostics, and device or account identifiers such as Advertising ID or App Set ID according to Google's policies. This data may be used for advertising, analytics, fraud prevention, and consent handling. Premium/trial users or users with an active unlock may not see the same ad prompts as locked free users.

AI Builder And Public Resources for AI

AI Builder can import reviewed .scripttap.json script packages and export AI-readable .scripttap.zip packages containing script JSON plus linked PNG assets when the user chooses to create or share them. ScriptTap.com AI resources instruct outside AI tools to create script packages only and not to include account data, Firebase data, cloud state, shortcut tokens, logs, screenshots, image bytes, or hidden app data.

Outside AI tools or chat services are separate from ScriptTap. If the user shares exported packages, screenshots, scripts, or text with an outside AI service, that service's privacy practices apply.

Feedback

When you send feedback from inside the app, ScriptTap shows what will be sent before you submit it. A feedback report may include the text you typed, general app/device/account status, update status, and privacy-protecting identifiers used to prevent spam or connect the report to the right app install. Feedback does not automatically include your scripts, screenshots, saved image assets, runtime logs, passwords, payment details, or raw account identifiers.

Closed Test Access

The current ScriptTap.com closed-test flow sends users to the ScriptTap tester Google Group and then to the Google Play closed-test page. ScriptTap.com does not collect a name or Gmail address for this flow.

Google handles Google Group membership and Google Play tester opt-in for the account the user chooses. Use the same Google account for both steps. Earlier closed-test request records submitted through the retired website form, if any, may be retained only as needed to administer tester access or support.

Closed test access is optional and is separate from a ScriptTap app account. Do not enter passwords, payment details, or unrelated private information into Google Group or Play tester forms.

Data Sharing And Service Providers

ScriptTap may use Google, Firebase, Google Play, website hosting, email, and similar service providers to operate the app, website, accounts, diagnostics, subscriptions, and support. These providers may process data for those service purposes.

ScriptTap does not sell personal data. Data may be disclosed if required for legal compliance, security, fraud prevention, abuse investigation, or to protect users, the app, or the developer.

Security

The ScriptTap website uses HTTPS. App service traffic to Firebase and Google services uses encrypted connections provided by those platforms. Local app data remains on the user's device unless the user chooses a feature that uploads or shares it.

Account and personal cloud data are intended to be protected by Firebase security rules so users can access their own user-scoped records and normal app clients cannot write server-managed premium entitlement records.

Retention And Deletion

Local data stays on the device until the user deletes it in the app, clears app data, or uninstalls ScriptTap. Uninstalling or clearing app data may also remove local trial/cache data.

Account, entitlement, private personal cloud, feedback, support data, and earlier closed-test request records submitted through the retired website form may be retained while the account, test access, cloud features, or support need is active, during the scheduled deletion window, and as needed for legal, security, fraud prevention, subscription, support, or account records.

Users can request account and cloud-data deletion in ScriptTap by opening Main Menu > Settings > Account > Delete Account. If the app is unavailable, the public deletion page at /account-deletion.html provides a deletion-only account sign-in flow. The current deletion flow schedules deletion and may allow cancellation during the seven-day window if the user signs in again and stops deletion. Local on-device data must be deleted from the device by the user.

Children

ScriptTap is not intended for children under 13. Do not use ScriptTap if you are not old enough to consent to software and privacy terms in your location.

Changes

This policy may be updated as ScriptTap features, service integrations, or legal requirements change. The effective date above shows the latest version.

Contact

Use the Support page for current support options. Use Account Deletion for account and cloud-data deletion requests.