Privacy Policy
Last updated: August 31, 2026
Zapper is an iPhone app for discovering, pairing with, and controlling compatible Samsung TVs. This policy covers current and upcoming Zapper releases. A service or feature described below applies only to app versions that include it. It explains what stays on your device, what is sent to disclosed internet services, and what is sent directly to a TV on your local network.
Summary
Zapper:
- does not require an account,
- does not provide an app-owned cloud service for TV control,
- does not include third-party advertising SDKs,
- uses RevenueCat to process in-app purchases, deliver the purchase screen, validate entitlements, and measure purchase performance,
- uses Apple’s privacy-preserving AdServices attribution to measure Apple Ads campaigns without requesting App Tracking Transparency permission or accessing the IDFA,
- collects limited, first-party, aggregate usage diagnostics so we can confirm core flows and purchases are working, and
- is designed to communicate directly with a compatible Samsung TV, usually on the same local network.
Depending on your Apple device settings, Apple may collect crash diagnostics and may make them available to developers through App Store Connect.
Data Zapper stores on your device
Examples of information Zapper or its purchase SDK stores locally so it can reconnect to your TV, restore app state, and preserve purchase access include:
- Saved TV details in UserDefaults — such as the selected TV’s device identifier, local IP address, display name, model name, port, and MAC address when available.
- Pairing token in the iOS Keychain — when a TV issues an authorization token during pairing, Zapper stores that token locally in Keychain so you do not have to pair again every time.
- Local app preferences and purchase-flow state — for example, demo-mode flags, free-use counters, and aggregate purchase source/region state used only to recognize a later completed purchase and retry its aggregate completion event until the analytics service acknowledges it. During that retry phase, Zapper also stores a random, one-time delivery token used only to prevent the same completion from being counted twice. This state contains no account, transaction, device, or TV identifier and is removed after acknowledgment or when Zapper next checks it after seven days.
- RevenueCat purchase SDK state — RevenueCat may cache its randomly generated anonymous app-user identifier and entitlement information on your device so purchases can be validated and restored. Zapper does not tie that identifier to an account or known person.
Zapper removes the pairing token from the saved TV record before writing the TV object to UserDefaults.
Information sent over the local network
To discover and control a TV, Zapper sends network requests from your iPhone directly to the selected TV or candidate TV addresses:
- Discovery traffic on the local network, including SSDP multicast requests used to look for compatible TVs.
- Device validation requests to a TV’s local REST endpoint, typically
http://<tv-ip>:8001/api/v2/, to confirm that the device is a compatible Samsung TV and retrieve the TV name/model information it reports. - Remote-control and pairing traffic over the Samsung TV WebSocket interface, typically on local ports
8001or8002. - Wake-on-LAN packets if you use the app’s wake feature.
- Pairing token reuse when reconnecting to a TV that previously issued a token.
This communication is intended to happen directly between your device and your TV over the local network. Because the app also supports manual IP entry, do not rely on this statement as a guarantee that every user-entered destination will always remain on the same LAN in every network setup.
Permissions
Local Network access
Zapper requests Local Network permission because it needs local network access to find and control compatible Samsung TVs. Without this permission, live TV discovery and control may not work.
Bonjour service declarations
Zapper declares Samsung TV Bonjour service types used for device discovery and connection support.
Zapper does not currently request permissions such as Contacts, Photos, Camera, Microphone, Location, Calendars, or Bluetooth for its core TV-remote behavior.
Data collection by the developer
Zapper does not include personal information, account information, advertising identifiers such as the IDFA, TV names, TV IP addresses, pairing tokens, typed text, or remote-control command details in developer-controlled analytics event payloads.
As with any internet request, the hosting provider receives the request’s source IP address as transport metadata while servicing the request. Zapper’s analytics application does not read or retain source IP addresses for Zapper requests and does not write them to analytics storage, use them to build a profile, or use them for advertising or tracking.
Zapper does collect limited, first-party, aggregate usage and technical diagnostics — counts of events such as opening the app, completing TV discovery, enabling Demo Mode, receiving an installed-app catalog, attempting an app launch, viewing the paywall, and completing or restoring a purchase — together with coarse duration, network/error, socket/TLS, command-send, and recovery outcomes and the app version, build, platform, and release channel. Installed-app diagnostics contain only a coarse catalog outcome and app-count bucket, or a coarse launch outcome and launch mode; app names and app identifiers are never included. A retried purchase-completion event may also carry the random, one-time delivery token described above. The analytics service immediately transforms that token with a keyed cryptographic hash, schedules the hash for automatic deletion after 14 days with hourly cleanup, and never exposes it in reporting. These diagnostics are used to confirm that core flows, reliability, and purchases are working. They are not linked to your identity and are not used to track you.
For purchases, Zapper uses a randomly generated, anonymous RevenueCat app-user identifier. RevenueCat receives purchase and entitlement information needed to validate the one-time unlock and provide purchase analytics, including product, transaction, price, currency, and storefront information. Zapper does not create a customer account or send RevenueCat your name, email address, phone number, or advertising identifier.
Zapper also sends Apple’s standard AdServices attribution token to RevenueCat. RevenueCat exchanges that token with Apple and stores the campaign, ad group, keyword, and related attribution fields Apple returns. This is used only to distinguish Apple Ads performance from organic acquisition and does not use the IDFA or track activity across other companies’ apps or websites.
For Apple’s App Privacy disclosures, Zapper reports the following data as collected but not linked to your identity and not used for tracking:
- Purchase History — used for analytics and app functionality.
- Product Interaction — used for analytics and app functionality.
- Other Diagnostic Data — used for analytics and app functionality to measure coarse technical reliability.
- Advertising Data — used for analytics and Zapper’s own advertising or marketing measurement.
Zapper also does not sell your personal data.
Apple-provided diagnostics
If you choose to share analytics or crash data with app developers through Apple, Apple may provide diagnostics to the developer through App Store Connect. That Apple-provided reporting is controlled by Apple and your device settings, not by a third-party SDK embedded in the current Zapper build.
Third parties
Zapper’s core control flow is direct device-to-TV communication rather than a Zapper-operated backend service.
Zapper uses RevenueCat as its purchase and entitlement infrastructure. RevenueCat processes purchase history for app functionality and analytics and receives standard Apple Ads attribution data as described above. RevenueCat’s privacy policy is available at revenuecat.com/privacy.
Zapper’s first-party aggregate analytics endpoint is hosted on Cloudflare Workers. Cloudflare processes requests as Zapper’s infrastructure provider; the Zapper Worker does not enable persistent request logging or store source IP addresses in its analytics or rate-limit data. Cloudflare’s privacy policy is available at cloudflare.com/privacypolicy.
Zapper does not include a third-party advertising SDK, does not request App Tracking Transparency permission, and does not use RevenueCat or Apple Ads attribution to track activity across other companies’ apps or websites.
Data retention and deletion
You can remove the saved TV and its locally stored pairing token from inside the app by using Forget TV. That clears the saved TV record from local app storage and deletes the token from Keychain for that TV.
First-party analytics events are combined into hourly aggregate counters when received. The service does not store a per-device identifier, source IP address, or user timeline for Zapper. For retried purchase-completion events, it retains only a keyed hash of the random one-time delivery token, schedules it for deletion after 14 days, and runs cleanup hourly. Aggregate counts may be retained for historical product-performance comparison because they cannot be associated with a person or device. Because these counters are anonymous and aggregated at ingestion, Zapper generally cannot locate or delete one person’s contribution after it has been counted.
Purchase and attribution records are retained by RevenueCat and Apple as needed to validate purchases, restore entitlements, prevent fraud, and provide historical reporting. To request deletion of purchase-related data associated with Zapper’s anonymous RevenueCat identifier, contact the support address below. We may need diagnostic information from your device to locate the correct anonymous record.
Changes to this policy
This policy may be updated if Zapper’s privacy-relevant behavior changes. When that happens, the public privacy-policy page and the repo source document should be updated together.
Contact
Questions about this policy? Contact: support@commerce-infrastructure.com