Privacy notice
Last updated 6 October 2026
Tapplet is made by Tinkertanker Pte Ltd. Tapplet Studio is an iPad app that helps teachers create tapplets: small interactive activities that students open from a link. Tapplet is in preview, so this notice describes how the current version works. We will update this page when that changes.
This website
This preview website has no forms, cookies, analytics or scripts in our code. It is hosted on Cloudflare, which processes request information such as IP addresses, browser details and the pages requested in order to deliver and protect the site.
The rest of this notice is about the Tapplet Studio app, its online service and published tapplets.
Information kept on your iPad
- Your projects and the images you add to them are saved on the iPad.
- When you activate the app with a class access code, the service gives the iPad a credential that identifies it as the owner of its projects. This is stored in the iPad's Keychain and may be included in encrypted device backups.
Information the online service receives and stores
Creating, revising, restoring and publishing tapplets uses our online service. To do this it stores:
- your activity brief, revision instructions, the current and generated activity HTML, and project details such as title, subject, level, tags and learning objective;
- images you upload, with their descriptions, dimensions and a fingerprint (hash) of the file;
- preview screenshots of your activities that the app uploads;
- publication details, such as the link and its expiry date;
- hashed identifiers for your iPad's owner credential and for the network a request comes from. These are used to keep projects with their owner, enforce daily usage limits and limit report spam.
Like any online service, it necessarily receives your IP address and request details. Operational logging is enabled for the service, so this information may appear in service logs.
The app's Apple privacy manifest declares user content, photos and a device identifier, linked to the user and used only for app functionality. Tapplet does not track you across other companies' apps or websites.
AI processing
Tapplet uses third-party AI model providers configured by us. Depending on what you do, they receive:
- your activity briefs and revision instructions;
- current and generated activity HTML, to create, revise, repair and review tapplets, including a review before publication;
- images you upload, for a safety review.
The providers we use can change, and their own terms govern how they handle the data they receive. AI reviews are advisory: they can flag possible concerns, but they do not decide what you may publish.
Publishing and students
- Publishing makes a tapplet available to anyone who has its link. We ask search engines not to index published tapplets.
- While a tapplet is published, it may be used as an example when generating later tapplets, including for other teachers, and may be sent to AI providers as part of that.
- Students do not need an account. A published tapplet runs in a sandbox in the student's browser, and what students do in it stays in that page while it is open. Tapplet is not a service for collecting student submissions or grades.
- Opening a published tapplet sends a request to our service, which receives the usual request details, such as the IP address.
- Anyone can report a published tapplet. A report is anonymous and records the tapplet's link, the reason chosen and the time.
Guidance for teachers
Please avoid putting students' names, contact details or other personal information into prompts, activities or image descriptions, and do not upload images in which people can be identified unless you have appropriate permission. You are responsible for reviewing a tapplet before you publish it and for deciding who receives its link.
How long information is kept
- Published links expire after 90 days by default. The expiry shown in the app is the one that applies, and you can extend it from the app.
- Unpublishing a tapplet, or its link expiring, stops public access. It does not immediately delete the stored project.
- A daily cleanup removes projects with no live publication that have not been changed for 180 days, reports after 180 days, uploaded images that are at least 7 days old and not part of any saved project version, and daily usage records after 14 days.
Cleanup runs on a schedule, so removal is not instant. The periods listed above do not set retention periods for service logs or for copies held by AI providers. Projects saved on your iPad, and any device backups, are separate and stay until you delete them.
Your choices
- Unpublish a tapplet at any time to stop its link working.
- Delete a project in the app. This removes it from the iPad and asks the service to delete its project records and its publication. Stored files of generated activity HTML are not automatically deleted by the current cleanup; you can email hello@tk.sg to request their removal.
- If you no longer have the iPad that published a tapplet, contact us with the tapplet's link and we can take it down.
Contact
For privacy questions, or to ask about access to or deletion of your information, email Tinkertanker Pte Ltd at hello@tk.sg.
Changes to this notice
We will post any changes on this page and update the date at the top.