Skip to content
Tapcount
Theme
In force since September 7, 2026

Privacy Policy

In short
  • What you count stays on your phone. Counter names, sheet names and count values are never sent anywhere.
  • There is no sign-in and no user account, so there is nothing of yours on a server of ours.
  • The app does send usage and crash reports to Google's Firebase, on servers in the United States. They carry an identifier for the installation and details of the device, and never anything you typed.
  • Those reports are on from the first launch. Turning them off is one row in Settings, and the app behaves identically without them.
  • No advertising identifier, no cross-app tracking, no ads, and no profiling.

This summary is informative and does not replace the sections below, which prevail in case of divergence.

1. Who processes the data

The Tapcount application is developed and operated by Isaque Hernandes Freitas de Santana Tecnologia da Informação Ltda, a Brazilian private legal entity registered under CNPJ no. 38.003.112/0001-79, with registered office at Rua Iandara, 135, apto. 101 — Campo Grande, Rio de Janeiro/RJ, CEP 23071-330, Brazil, trading as Hernandes Tech (the "Company").

The Company maintains a channel of communication with data subjects, under article 41, § 2, item I, of Brazilian Law no. 13.709/2018 (the General Personal Data Protection Law, "LGPD"):

2. What this policy covers

This policy covers the processing of personal data carried out by the Company in connection with the Tapcount application and the website tapcount.hernandestech.com. For the purposes of this policy:

  • Application: the Tapcount program, in its Android and iOS versions, and the updates the Company makes available.
  • User: the natural or legal person who installs and uses the Application.
  • User Content: everything the User creates inside the Application, including sheet names, counter names, count values, steps, goals and the event log that records each count.
  • Reports: the usage and crash reports described in section 5.

Processing carried out by the app stores, and by the payment methods they operate, is governed by the privacy policies of those companies, which this policy does not override.

3. Where your content lives

3.1. User Content is written to the storage of the User's own device and stays there. The Company operates no server that receives, stores or reads it.

3.2. Counting, undoing, redoing, resetting, editing, naming and exporting all run on the device and work with the device offline.

3.3. The Application asks for no sign-in and creates no user account. There are no credentials, and there is no profile of a person held by the Company.

3.4. The Reports of section 5 measure how the Application is used and how it fails. They carry no User Content: no sheet name, no counter name, no count value, and nothing the User typed.

4. Data, purposes and legal bases

The table below describes the personal data processed by the Company, the specific purpose of each processing operation, the legal basis that authorises it and the retention period, under articles 7 and 9 of the LGPD.

Data Purpose Legal basis Retention
User Content held on the device Running the Application No processing by the Company: it stays on the device For as long as the User keeps it
Installation identifier generated by the reporting libraries, which is reset when the Application is reinstalled or its data is cleared Attributing reports to one installation, so that a defect can be counted once rather than many times Legitimate interest (art. 7, IX) 90 days alongside a crash report; in the installations service, until the identifier is deleted
Device model, operating system version, application version and language reported by the device, and the country or region Google derives from the masked IP address of the connection Reproducing a defect on the device where it happened, and knowing which systems the Application still has to support Legitimate interest (art. 7, IX) 2 months
Crash and non-fatal error reports, with the exception stack and the state of the Application at that moment Finding and correcting defects, including the ones that never reach support because the person does not notice them Legitimate interest (art. 7, IX) 90 days
Usage events: which screens were opened, which features were used, and whether the screen that offers the purchase was opened Understanding which parts of the Application are used, so that what is built next answers a measurement instead of a guess Legitimate interest (art. 7, IX) 2 months
Purchase status reported by the store Unlocking the purchased features and honouring the restore of a purchase already made Performance of a contract (art. 7, V) Applicable statutory limitation period
Content of the messages sent to the channels in section 1 Answering the request and evidencing the answer Performance of a contract (art. 7, V) and regular exercise of rights (art. 7, VI) Applicable statutory limitation period

The Application does not use advertising networks, advertising identifiers, cross-app tracking, behavioural profiling or third party audience measurement, and it does not carry out automated decisions producing legal effects on the data subject.

The Company has no access to the User's payment data. Charging is handled end to end by the store, which reports to the Application only whether the purchase exists.

5. Usage and crash reports

5.1. The Application reports usage and crash diagnostics through Firebase Analytics and Firebase Crashlytics, services operated by Google LLC. The data those Reports carry is the one described in the second to fifth rows of the table in section 4.

5.2. The identifier carried by the Reports is generated by the reporting libraries and identifies one installation, not a person. It is created when the Application is installed and is reset when the Application is reinstalled or when its data is cleared. It is not an advertising identifier and it is not used to recognise the same person across applications.

5.3. The Reports are enabled by default and can be turned off at any time under Settings → Usage and crash reports. Turning them off stops the sending; every counting, editing and export function of the Application behaves identically with them off.

5.4. Turning the Reports off is also the means of objecting to processing based on legitimate interest, under article 18, § 2, of the LGPD. A request to that effect may equally be addressed to privacy@hernandestech.com.

5.5. Receiving a report over the network makes Google record technical data of the connection, such as IP address, date and time, under Google's own terms. Those are records of the provider, not of the Company: the Company has no access to them and cannot obtain them.

5.6. The App Store and Google Play listings of the Application declare the categories the Reports actually carry, linked to the installation and used for application functionality and analytics:

What the Reports carry App Store Google Play
Installation identifier Identifiers — Device ID Device or other IDs
Screens opened and features used Usage Data — Product Interaction App interactions
Country or region derived from the masked IP address Location — Coarse Location Approximate location
Purchase events reported by the analytics library Purchases — Purchase History Purchase history
Crash and non-fatal error reports Diagnostics — Crash Data and Other Diagnostic Data Crash logs and Diagnostics

The listing declares everything the Reports carry, including what the analytics library collects on its own, without the Company writing a line of code for it.

6. Sharing

The Company does not sell personal data and does not share it for advertising purposes. Sharing happens only with the agents below, and only as far as running the service requires:

Recipient Capacity Purpose
Google LLC (Firebase Analytics and Firebase Crashlytics) Processor Receiving and storing the Reports on behalf of the Company
Google LLC (Google Play) and Apple Inc. (App Store) Independent controllers Distributing the Application and charging for the purchase
The website hosting provider Processor Serving the pages of tapcount.hernandestech.com

Data may further be provided to public authorities upon a court order or a lawful request, in which case the Company limits itself to what is strictly determined.

7. International transfer

7.1. The Reports are received and stored on Google LLC infrastructure located in the United States of America. Brazil's national data protection authority has issued no adequacy decision for that country.

7.2. The control the User has over this transfer is the one in section 5.3: turning the Reports off under Settings stops the sending, and the Application keeps working identically. User Content is not transferred in any case, because it does not leave the device.

7.3. The hypothesis of article 33 of the LGPD that authorises this transfer is not defined, and this policy states none before it is. What it affirms about the transfer is what has been verified: who receives the data, the country, the absence of an adequacy decision, and the User's control over whether the transfer happens at all. The hypothesis is part of the legal review this document is pending.

8. Retention and erasure

The retention periods are the ones stated in the table in section 4. Once they end, or once the purpose is met, the data is erased, save for the cases in article 16 of the LGPD.

  • Reports. The installation identifier is retained for 90 days alongside a crash report, and in the installations service until it is deleted. Usage event data is retained for 2 months, which is Firebase's default retention. We do not change it. Crash and non-fatal error reports are retained for 90 days, which is how long Crashlytics keeps them.
  • User Content. It is erased when the User clears the Application's data or uninstalls the Application. Removing a counter or a sheet inside the Application does not erase it, for the reason given in section 9.1. The Company holds no copy of it to erase.
  • Uninstalling. Removes the Application and the User Content on that device. It does not, by itself, cancel a purchase already made, which stays attached to the store account and can be restored.

Residual copies in the providers' security and recovery routines are erased in the ordinary overwrite cycles.

9. Erasing your data

9.1. The Application has no user account, so there is no account to close and no profile to delete. Erasing what the Application holds is done on the device:

  • Inside the Application: removing a counter or a sheet takes it off the screen, and does not erase what it held. The Application keeps every change as an entry in a history that is only ever added to, which is what makes a removal undoable. Erasing for good is one of the two paths below.
  • On Android: Settings → Apps → Tapcount → Storage → Clear storage erases everything the Application holds on that device.
  • On iOS: deleting the Application from the device erases everything it holds there.

9.2. Two things on the device act on the Reports, and both take effect at once. Turning them off under Settings stops the sending. Clearing the Application's data, or reinstalling it, resets the installation identifier, so that whatever was sent before stops being attached to the installation that carries on.

9.3. The Reports carry no name, no address and nothing the User typed, and the Company therefore cannot, on its own, tell which of them came from a given person. A request addressed to privacy@hernandestech.com is answered within the periods set by the applicable regulation, saying what can be done for the case at hand.

10. Security and incidents

The Company adopts technical and administrative measures able to protect personal data from unauthorised access and from accidental or unlawful destruction, loss, alteration, communication or dissemination, under article 46 of the LGPD, among them encrypted transport, access control at the provider's console and restriction of internal access to what is strictly necessary.

No security measure removes risk entirely. Where a security incident that may bring relevant risk or damage to data subjects occurs, the Company will inform Brazil's national data protection authority and the affected data subjects, under article 48 of the LGPD and the applicable regulation.

11. Your rights

Under article 18 of the LGPD, a data subject may request, at any time and by petition:

  • confirmation that processing exists;
  • access to the data;
  • correction of incomplete, inaccurate or out of date data;
  • anonymisation, blocking or erasure of data that is unnecessary, excessive or processed in breach of the LGPD;
  • portability to another service or product supplier, upon express request;
  • erasure of data processed on the basis of consent, save for the cases in article 16;
  • information about the public and private entities with which the data was shared;
  • information about the possibility of withholding consent and about the consequences of doing so;
  • withdrawal of consent.

Requests should be addressed to privacy@hernandestech.com and are answered within the periods set by the applicable regulation. The Company may ask for further information to confirm the identity of the requester, so that data is not handed to someone who is not its subject.

Because the Application keeps no account, the data the Company holds about a person is limited to the Reports of section 5, which are attached to an installation and not to a person. The Company holds no means of its own to single out the reports of a given data subject, and says so here rather than promising a search it cannot run. What remains available at any moment, with immediate effect and without asking anyone, is section 9.2: turning the Reports off, and clearing the Application's data.

A data subject may also petition Brazil's national data protection authority, under article 18, § 1, of the LGPD.

12. Children and adolescents

The Application is not directed at children, and the Company does not knowingly collect the personal data of a child. Nothing the Application sends identifies a person: the Reports of section 5 carry an identifier of the installation, and no name, no address and nothing the User typed.

Should processing of a child's data be found without the specific and prominent consent required by article 14, § 1, of the LGPD, the corresponding records are erased. Communications on the subject should be addressed to privacy@hernandestech.com.

13. This website

The website is made of static pages. It uses no cookies, loads no third party scripts, employs no audience measurement tool and builds no visitor profile. There is therefore no cookie banner, because there is no cookie.

The hosting provider records technical access data, such as IP address, date, time and the resource requested, as part of the operation and security of any server. Those records are not used by the Company to identify visitors.

14. Changes

This policy may change to reflect changes in the Application, in the services it relies on, or in the law. The version in force is always the one published on this page, and the date at the top identifies it.

Changes bringing a new purpose of processing, or a substantial change to the conditions described here, are announced inside the Application with reasonable notice.

15. Governing law

This policy is governed by Brazilian law, in particular by Law no. 13.709/2018 (LGPD), Law no. 12.965/2014 (Brazilian Civil Rights Framework for the Internet) and Law no. 8.078/1990 (Consumer Protection Code). The Portuguese version of this policy, available at /pt/privacidade, prevails in case of divergence between the two texts.

Privacy and data protection matters: privacy@hernandestech.com