Tiny Pad.

Legal / Privacy / App

Tiny Pad App Privacy Policy.

Last updated: July 2026

1. Scope and Who We Are

This policy covers the Tiny Pad app for iPhone and iPad, distributed through the Apple App Store. Tiny Pad Server, the companion application you install on the computer you want to control, is covered by a separate policy: Tiny Pad Server Privacy Policy. The app is published by Tiny Bits Ltd, a company registered in England and Wales (company number 16882060), with its registered office at 61 Bridge Street, Kington, HR5 3DJ, United Kingdom. Where this policy says "we" or "us", it means Tiny Bits Ltd.

2. The Short Version

• The app never sends anything to Tiny Bits. We run no server it could reach. • There is no analytics, no telemetry, no crash reporting, no advertising and no account. • It opens connections to two places only: the computer you paired it with, on your own network, and Apple's App Store services, which iOS uses to check whether you have bought the unlock. • Everything it saves stays on your device. • We do not know that you installed it, how often you use it, or which features you use. Apple does tell us something, but only in aggregate and only about the App Store. Section 10 explains what those reports contain and how to opt out of them.

3. Personal Data We Collect: None

Tiny Bits collects no personal data through the Tiny Pad app. We operate no server that the app can reach, hold no database of users or devices, and receive nothing when you use it. The app contains: • No analytics or telemetry of any kind • No crash or error reporting to us or to anyone else • No usage, feature or behavioural tracking • No advertising identifier (IDFA) and no ad networks • No third-party SDKs of any kind (no Firebase, no Sentry, no RevenueCat, no analytics frameworks) • No accounts, sign-in, email collection or licence server Because the app does no tracking as Apple defines it, it never shows the App Tracking Transparency prompt, and it neither reads nor requests your advertising identifier. An earlier build of the app contained anonymous usage analytics. It was removed before release and never collected anything: the feature was disabled by an unset ingest key throughout its life, and no data was ever received or stored. The app now makes no network requests to us at all.

4. Permissions the App Asks For

iOS asks your permission before the app can use any of the following. Each is used for one narrow purpose, and refusing one only disables the feature that needs it. Camera. Used solely to scan the pairing QR code shown by your computer. The camera runs only while the scanner screen is open. Frames are examined on your device for a QR code and then discarded. Nothing is recorded, saved to your photo library, or transmitted. Local Network. Required for the app to find and talk to Tiny Pad Server. iOS asks for this the first time the app looks for a server. The app browses only for the _tinypad._udp service and connects only to servers you have paired. Motion and Fitness. Used by Pointer mode, where tilting the device steers the cursor, and by the gamepad's steering wheel. Motion readings are turned into cursor or steering movement and sent to your own computer as part of the input stream. They are not stored on your device and never reach us. The app does not ask for, and cannot access, your contacts, photo library, location, microphone, calendar, reminders, health data or files.

5. What the App Stores on Your Device

Everything the app saves is stored privately on your device, where no other app can read it. Most of it sits in the app's own sandbox. Your pairing credentials are the exception: they live in the iOS Keychain, which is deliberately kept separate, and that difference matters when you come to delete the app. iOS Keychain. One entry for each server you have paired, holding the server's ID, the device ID it issued you, the private key seed from the pairing QR code, the server's friendly name, and the last address it was seen at. These are the credentials that let you reconnect without pairing again. They are protected by the Keychain, are not synchronised to iCloud, and are deleted the moment you unpair that server in the app. App preferences. Your settings, stored in the app's own preferences: pointer and touchpad sensitivity, inverted buttons, haptics, auto-lock, the full pencil tuning set (pressure and tilt curves, sampling rate, stroke prediction, hover and click thresholds), toolbar auto-hide, which layout is active, and which server you last connected to. Saved layouts and buttons. Your gamepad layouts, pencil button templates and per-app toolbar overrides, saved as files in the app's Application Support folder. Free trial state. The date you first launched the app, how many seconds you have used it today, and how many purchase prompts you have already seen. This is what makes the trial work and it never leaves your device. See section 9. None of this is transmitted anywhere. Removing it. Deleting the app removes its sandbox, and with it your preferences, saved layouts, pencil templates, toolbar overrides and trial state. Keychain entries are held separately from the sandbox and can outlive the app, so if you want your pairing credentials gone as well, unpair each server inside the app before you delete it. Unpairing removes that server's Keychain entry straight away, and it is also what revokes the app's ability to control that computer, so it is worth doing before passing the device on.

6. What the App Sends, and Where

Your input goes to one destination only: the computer you have paired the app with, over your local network or a USB cable, inside the encrypted channel described in section 8. What it sends is the input you generate: pointer movement, taps, clicks and scrolling; key presses and text; pen position, pressure, tilt and button state; gamepad sticks and buttons; multi-finger gestures; pan and zoom; which mode you have switched to; and, in Pencil mode, the region of the screen you want to watch. That traffic goes straight to your own machine. It does not pass through us, and there is no cloud service, relay or third party anywhere in the path. We could not intercept it if we wanted to, because we operate nothing for it to pass through. The app's only other network activity is with Apple. To know whether you have bought the unlock, it asks StoreKit for the product and its price, checks the purchases currently on your Apple Account, and keeps a listener open for transaction updates such as a purchase made on another device or a family approval. iOS performs those requests against Apple's App Store servers on the app's behalf, when the app starts and when you buy or restore. They go to Apple rather than to us, the app does not attach a user or device identifier of its own, and they are covered by Apple's own privacy policy. Section 9 explains what we do and do not learn from them. Beyond those two, the app makes no internet requests at all: no update checks, no licence server of ours, no remote configuration and no content downloads. There is no Tiny Bits system for it to contact, because we do not run one.

7. What the App Receives From Your Computer

Your computer sends two things back, and it is worth being clear about both because they can be revealing. The active application. So the app can show the right shortcut toolbar, the server reports the title of your focused window, the application's identifier, its version, and the name of your operating system. Window titles often contain document names and web page titles. The app displays this and keeps it in memory for as long as that window is focused. It is not saved to your device and it is never sent onward to us or anyone else. The Pencil mode screen preview. When you use Pencil mode, your computer streams the chosen region of its screen to the app as image tiles so you can draw on top of it. Those tiles are held in memory to draw the preview and are discarded as they are replaced. They are not written to storage, not added to your photo library, not cached between sessions, and not uploaded anywhere.

8. Pairing and Encryption

All traffic between the app and your computer runs over DTLS with the TLS_PSK_WITH_AES_128_GCM_SHA256 cipher suite, so it is encrypted and authenticated end to end. Pairing. Your computer displays a QR code containing a server ID, the server name, a device ID and a private key seed. Scanning it stores those credentials in your Keychain. Because the QR code carries a secret, treat it as one while it is on screen: anyone who photographs it could pair their own device with your computer. Each connection. The app generates a fresh single-use key pair, signs a challenge from the server with the key from pairing, and receives a session key sealed to that fresh key. The temporary private key is discarded afterwards, so recovering your pairing credentials later would still not decrypt earlier sessions. Unpairing. Removing a server in the app deletes its credentials from your Keychain straight away. If you think a QR code has been seen by someone else, ask the server to issue a new one, which invalidates the old credentials immediately.

9. Purchases and the Free Trial

The trial runs entirely on your device. After a grace period from first launch you get a free window of use each day, after which a dismissible prompt suggests buying the unlock. The dates and counters behind that are stored only in the app's own preferences, as described in section 5. Nothing about your trial is transmitted, so we have no way of knowing whether you are trialling, how long you have used the app, or whether you have bought it. Purchases are handled by Apple. The unlock is a one-time non-consumable purchase processed entirely through the App Store. Your payment details, name and billing address go to Apple and never touch the app or reach us. We do not create or attach any identifier of our own to the transaction. So that the app knows whether to show the purchase prompt, it asks StoreKit at launch for the product's price and for the purchases already on your Apple Account, and it watches for later transaction updates. Those checks run against Apple's servers, as described in section 6. The entitlement result is essentially yes or no; the product lookup also returns its displayed price. Both stay on your device, and we are not told what either said. Apple provides us with sales and financial reports covering units sold by territory. Those are aggregate figures and do not identify individual purchasers. Restoring. The restore option asks StoreKit to re-check purchases already tied to your Apple Account. The app never asks you for an Apple Account, a password or an email address.

10. What Apple Tells Us

This is the only route by which we learn anything at all, and it is worth stating plainly because the app itself tells us nothing. Apple provides every developer with App Store Connect analytics: counts of downloads and installations, sessions, active devices, retention, crashes and deletions, broken down by territory, device type and app version. Apple collects this itself, under Apple's own privacy policy, from users who have left "Share With App Developers" enabled on their device. We receive it as aggregate statistics that do not identify anyone. We chose to rely on this instead of building our own analytics, precisely so that the app does not have to collect anything or store an identifier for us. If you would rather Apple did not share it, you can turn it off for all apps at any time in iOS Settings › Privacy & Security › Analytics & Improvements › Share With App Developers. The Tiny Pad app is unaffected by that choice and behaves identically either way.

11. Children's Privacy

The app collects no data from anyone, of any age, and sends us nothing. It contains no accounts, no messaging, no user-generated content shared with others, no advertising and no external links to unmoderated content. It is a tool for controlling your own computer rather than a service aimed at children. The only purchase it offers is a single one-time unlock handled by Apple, subject to whatever Screen Time and purchase approval settings you have configured on the device.

12. Your Rights

Because the app sends us nothing, we hold no personal data about you as a result of your using it. There is no account to close, no profile to export, and no records of ours to erase. If you contact us, for example by emailing support, we process your email address and whatever you choose to write, solely in order to reply. Our lawful basis is our legitimate interest in supporting the people who use our software, and we keep that correspondence no longer than we need it. Under the UK GDPR and the Data Protection Act 2018 you have the right to access that correspondence, to have it corrected or erased, to restrict or object to our processing of it, and to receive it in a portable form. Write to support@tiny-bits.com and we will respond within one month. If you believe we have handled your data improperly you may complain to the Information Commissioner's Office at ico.org.uk, though we would appreciate the chance to put it right first. Data held by Apple about your purchase or your App Store activity is Apple's to hold, and requests about it should go to Apple.

13. Security

Your connection is protected by the pairing and session design in section 8: your computer accepts only devices it has enrolled, every session uses a fresh key, and all traffic is encrypted and authenticated. Credentials sit in the iOS Keychain rather than in ordinary app storage. Two limits are worth stating plainly. First, Tiny Pad secures its own connection but not the network around it, so on a network you do not trust, be deliberate about what you leave connected. Second, the app can drive your computer, so anyone holding your unlocked device can control any machine it is paired with. Use a passcode, and unpair servers you no longer use.

14. Changes to This Policy

If we change this policy, we will update this page and the date shown above. We removed the app's only data collection before release rather than ask you to consent to it, and we would like to keep it that way. If we ever added anything that sent data off your device, we would say so here in plain terms, describe exactly what it collects, and make it something you switch on rather than something you discover.

15. Contact

Questions about this policy, or about how the Tiny Pad app handles data, are welcome at support@tiny-bits.com. Tiny Bits Ltd 61 Bridge Street, Kington, HR5 3DJ United Kingdom Company number: 16882060