tatmapper-app

TatMapper Privacy Policy — beta source

Last updated: 2026-08-01

TatMapper is a local-first tattoo placement and print-planning application. TatMapper does not require an account. The monetized Android build uses Google Play Billing for optional TatMapper Pro, Google Mobile Ads for limited Free advertising, Google’s User Messaging Platform for required privacy choices, and Play Integrity to protect subscription verification from tampered or unlicensed app installs. It does not add TatMapper analytics, crash-reporting, telemetry, or cloud sync.

Data handled on the device

At the user’s direction, TatMapper can access or create placement photographs, imported tattoo artwork, trace and calibration geometry, Print Setup history, processed design previews, and PDF exports. Project media and settings are kept inside TatMapper-owned application storage until the user deletes the saved project or uninstalls the application.

TatMapper does not transmit project content to advertising or billing systems. The user may deliberately send a generated PDF or another file to a destination selected in Android’s share or print interface. That user-directed transfer is controlled by the selected destination.

Camera and files

Camera permission is used only when the user chooses to photograph a placement area. Audio is not captured. File selection uses the Android system picker; TatMapper does not request broad storage access.

Backup and device transfer

The Android beta disables application backup and supplies explicit rules that exclude every app-owned storage domain from both cloud backup and device-to-device transfer. Project JSON, photos, designs, settings, Print Setup history, and temporary exports are excluded. Users should still delete a project before handing an unlocked device to another person.

Deletion

Delete saved project removes TatMapper’s project JSON, owned photographs, owned designs, processed media, and project temporary files. PDFs already saved or shared outside TatMapper must be deleted from their destination separately. TatMapper has no account, so account deletion is not applicable.

Support and user-supplied attachments

For technical support, bug reports, printing questions, or help using TatMapper, email tatmapper@gmail.com. TatMapper does not attach photographs, designs, projects, PDFs, logs, or device identifiers automatically. Remove client-identifying information before sending screenshots or files.

Questions about TatMapper’s privacy practices may be sent to tatmapper@gmail.com.

Advertising and Pro

TatMapper Free may request Google ads on Home, Settings, Help, About, and similarly static screens. It never places ads in camera, Scale, Trace, Design, background-removal, PDF-preview, or other continuous editing workspaces. A user may explicitly choose a rewarded ad to unlock one materially unchanged export. Ad metadata never contains project names, client photos, tattoo designs, geometry, PDF content, or user-defined notes.

TatMapper Pro is an automatically renewing Google Play subscription. Google Play supplies localized prices and manages payment. TatMapper receives purchase tokens and entitlement state needed to verify Pro. Production verification requires an owner-controlled HTTPS service; a build without that service does not accept purchases.

For verification, the app sends the Google Play purchase token, fixed TatMapper package/product identifiers, a hash binding that specific request, and an encrypted Play Integrity token to the owner-controlled service. Google decodes the Integrity token and returns app-recognition, licensing, device-integrity, package, signing-certificate, request-hash, and timestamp verdicts. TatMapper does not use this flow to create an account or send project content.

The verification service stores a one-way purchase-token hash, a Cloud KMS-encrypted token, product/base-plan and entitlement state, expiry and acknowledgement state, notification type, and verification timestamps. It also stores Pub/Sub notification message IDs to prevent duplicate processing. These records contain no TatMapper project, photograph, design, measurement, note, email address, advertising ID, or TatMapper user ID. Entitlement and notification records are scheduled for automatic TTL deletion 90 days after the latest known subscription expiry or processing time. Google Play remains the payment system of record.

The app stores an opaque, server-signed receipt in private app storage so it can ask the service to refresh entitlement. The receipt cannot grant Pro on its own, contains no raw purchase token, and is excluded from Android backup and device transfer.

Depending on location and consent choices, Google may process device, advertising, diagnostics, interaction, and approximate-location-derived data for advertising, fraud prevention, measurement, and compliance. The final Data Safety form must use Google’s current SDK disclosure and the exact signed binary. Privacy choices remain reachable from Settings when required.

Changes

The published policy and Google Play Data Safety answers must be reviewed against the exact signed binary and current Google SDK disclosures before distribution.