Skip to content
TollGate
  • How it works
  • Alarms
  • Privacy
  • Pricing
  • FAQ
View pricing
Legal

Privacy Policy

Last updated: 15 August 2026

On this page

  • Overview
  • Information we collect
  • How we use it
  • Data retention
  • Deleting your data
  • Third-party services
  • Children's privacy
  • Security
  • Your rights
  • International users
  • Changes to this policy
  • Contact us

Overview

TollGate is an app that gates chosen apps and alarms behind a physical toll — push-ups or jumping jacks, verified by your camera. This policy explains, plainly, what data that involves and what doesn't leave your phone.

The short version:

Your camera feed is processed entirely on your device to count reps. We never see it, store it, or upload it.

If you allow measurement, we use Firebase Analytics and AppsFlyer to understand app usage and which campaigns lead to subscriptions. Crashlytics helps us fix crashes. None of them receives camera footage.

If you opt into the leaderboard, we store a display name, a country flag emoji, your rep count and level — tied to an account ID. Your real name and email are never published on it.

If you choose to pair with someone in an accountability pact, that one person is told when you bail out of a toll, and sees only that and your display name. Either of you can leave at any time, which deletes what you shared.

Subscriptions are handled by the Apple App Store or Google Play. We receive confirmation that you're subscribed, not your card details.

Signing in is optional. If you turn on "Back up my progress", we store your streak, XP, badges and session history so a new phone can restore them — and your email address, only to identify the account. We never back up which apps you gate.

You can erase your local data at any time from Settings → Reset all data, and delete your account and everything stored under it from Settings → Delete account.

Information we collect

TollGate is built so that the feature at the center of the app — camera-based rep counting — requires no data collection at all. The categories below cover everything else the app does.

Camera and exercise data

When you pay a toll, TollGate opens your device camera and runs pose detection using Google's ML Kit, entirely on your device. This is used to count your reps and check your form — elbow angle for push-ups, arm elevation for jumping jacks.

No camera frame is ever recorded, saved, or transmitted off your device. There is no server that receives your camera feed, no video file written to disk, and no image uploaded to TollGate or to any third party. Each frame is analyzed in memory to produce a pose estimate and then discarded. What we retain afterward is a small set of numbers — rep count, session duration, and whether the toll was completed — described below under Usage Analytics.

On-device profile

Setting TollGate up asks you a series of questions, and the answers are saved on your phone so your plan survives closing the app. They are: a first name or nickname (optional — you can skip it), the categories of app that pull you in, roughly how much screen time you have a day, when you lose the most time, what you do when you wake up, whether you've tried a blocker before and what happens when you try to stop, what you want back from this, your fitness level, which exercise you chose, how many reps you can do in one go, how strict you want your gates, and whether you want a gated alarm and at what time.

None of these answers leave your device unless you ask them to. By default there is no account, nothing is uploaded, and no server holds a copy. Analytics records which setup screen you reached and the size of the starting toll your plan worked out to — not the answers behind it.

There are two ways that changes, and both are switches you throw yourself. Your name becomes your display name if — and only if — you switch the leaderboard on, which is off until you do. And if you turn on Back up my progress, these answers are included in the backup so a new phone can rebuild your plan; see below.

Usage analytics

If you choose “Allow” in TollGate's measurement notice, we use Firebase Analytics (a Google service) to understand how the app is used in aggregate — which screens are viewed, which gates are triggered, whether a session completed, and similar app-usage events. Firebase Analytics automatically collects a device identifier (such as an Android Advertising ID or Apple's identifier for advertisers, where permitted) along with general device information: device model, operating system version, language, and approximate region derived from IP address. This data is associated with your device, not with your name or email — TollGate does not require either.

We also use AppsFlyer to attribute an install and later subscription to the advertising campaign that produced it. AppsFlyer receives a random install identifier, campaign and app-event information, and, on Android where you consent and the device provides one, the resettable Advertising ID. We do not send your name, email, camera data, exercise video or payment-card details. We do not use this data to build personalised advertising audiences. You can allow or stop measurement at any time in TollGate's Settings.

Crash diagnostics

We use Firebase Crashlytics (a Google service) to detect and diagnose app crashes. When TollGate crashes or encounters a serious error, Crashlytics collects a stack trace, the app version, device model, operating system version, and the state of the app immediately before the crash. This helps us fix bugs. Crash reports do not include camera frames or pose data.

Leaderboard data

The leaderboard is optional. If you choose to appear on it, TollGate stores the following in Firestore (a Google Cloud database):

FieldPurpose
Display nameShown next to your rank. Chosen by you — a real name is never required.
Country flag emojiShown next to your display name. Self-selected, not derived from your location.
Rep count and levelThe scores the leaderboard ranks on.
Account IDA random identifier used to attribute your entry to your device. It carries no email address or real name, and none is published on the board. If you later sign in to back up your progress, that identifier becomes linked to your email address privately, on our side only — it changes nothing about what other people can see here.

Leaderboard entries are visible to other users of the app. You can remove yourself from the leaderboard, or reset your progress entirely, from within the app.

Accountability pact data

An accountability pact is optional, and pairs you with exactly one other person so that bailing out of a toll is not something you can do unnoticed. It exists only if you create an invite code or type in someone else's — nothing is shared until both people have agreed, on their own device.

If you form one, TollGate stores the following in Firestore (a Google Cloud database), readable only by the two of you:

FieldPurpose
Display nameHow your partner sees you named. The same name the leaderboard would use — a real name is never required.
Account IDIdentifies each of you within the pact. Your pact partner never sees an email address or real name — only the display name you chose.
Bail recordsThat you left a toll unfinished, and when. Nothing else.

What a pact deliberately does not share: which app or alarm the toll was for, how many reps you did, your streak, your level, your session history, your leaderboard row, or anything at all about the tolls you complete. Your partner learns that you bailed and when, and that is the entire contents of the feature.

Reports are not instant. TollGate has no server that can push a message to another person's phone, so a report reaches your partner the next time they open the app, not the moment it happens.

Either of you can leave a pact at any time, from the pact screen in the app. Leaving stops all sharing immediately and deletes the records you contributed, along with your name and account ID from that pact.

Account and progress backup

TollGate does not require an account. Gates, alarms and rep counting all work without one, and nothing in the app is held back until you sign in. The only thing an account does is stop a new phone costing you your streak.

If you choose Back up my progress in Settings, you sign in with Apple or Google and we store a copy of your progress so another device can restore it. That copy contains:

DataPurpose
Email addressSupplied by Apple or Google when you sign in. Used only to identify your account so the right backup comes back to you. We never email you with it unless you contact us first. If you use Apple's Hide My Email, we only ever see the relay address.
Account IDThe same identifier already used for the leaderboard and pacts. Signing in attaches your identity to the ID you already had, rather than creating a second one.
Streak, XP, level and badgesThe progress a new phone would otherwise lose.
Session historyDate, exercise, reps and duration of past tolls, so your stats and charts survive. Long histories are trimmed oldest-first to fit; your streak and totals are never trimmed.
Setup answers, plan, alarms and app settingsSo a restored phone rebuilds the plan you already had instead of asking the eighteen setup questions again.

Two things are deliberately never backed up. The first is which apps you gate — that list stays on the device that made it and is never uploaded, because it is nobody's business but yours. The second is your subscription status, which always comes from Apple or Google directly, on every device, rather than travelling in a backup.

Your backup is private to your account. It is not shared, not published, not used for analytics, and not readable by anyone else — including the person you share an accountability pact with. You can delete it, and the account holding it, at any time from Settings → Delete account, or by writing to us at the address in Contact us. Signing out simply stops future backups; it leaves everything on your phone untouched.

Subscription and purchase data

TollGate subscriptions are sold and billed by the Apple App Store or Google Play, not by TollGate directly. We never see or store your payment card number, billing address, or Apple or Google account credentials. Apple and Google share with us only what's necessary to unlock paid features on your account — your subscription status, product identifier, and transaction/purchase token. Their own privacy policies govern how they process your payment information.

How we use it

We use the information described above to:

  • Run the core feature of the app — counting and verifying reps, entirely on-device.
  • Understand how people use TollGate so we can fix what's broken and improve what isn't.
  • Diagnose and fix crashes.
  • Operate the optional leaderboard.
  • Operate an optional accountability pact between you and one person you invite.
  • Confirm and manage your subscription entitlement.
  • Respond to support requests you send us.

We do not sell your data. We do not use your data to serve you third-party advertising within TollGate.

Data retention

Camera frames are never retained — they exist only for the moment it takes to process a single frame during an active toll. Session history (rep counts, XP, streak data) is kept locally on your device and is capped in size, with older entries dropped automatically. Your setup answers stay on the device until you reset your data or delete the app. Analytics and crash data collected through Firebase are retained by Google according to Firebase's standard retention windows, after which they are deleted or anonymized. Leaderboard data persists until you remove yourself from the leaderboard or reset your account. Pact data persists until you or your partner leaves the pact; leaving deletes the records you contributed at that moment, and the last person out deletes the pact itself. Invite codes stop working fifteen minutes after they are created, or as soon as someone has used one — whichever comes first.

Deleting your data

Deleting your account

If you signed in to back up your progress, open TollGate and go to Settings → Delete account. This permanently deletes your account and the backup stored under it — your streak, XP, badges, session history, setup answers and plan. It cannot be undone. The copy on the phone in your hand is left alone, so deleting the account does not cost you your streak on that device; use Reset all data below if you want that gone too.

If you cannot reach the app — you have lost the device, or uninstalled it already — email betacarryapp@gmail.com from the address you signed in with, asking us to delete your TollGate account. We will delete the account and its backup and confirm when it is done, normally within 30 days.

Deleting everything else

Open TollGate and go to Settings → Reset all data to erase your local session history, streaks, XP, settings, and the setup answers described above from your device immediately. To remove your leaderboard entry specifically, use the leaderboard opt-out in Settings. To delete what you shared in an accountability pact, leave the pact from the pact screen — that removes your bail records, your name and your account ID from it straight away. If you'd like us to delete data associated with your anonymous account ID from our servers — including leaderboard records — email betacarryapp@gmail.com and we'll process the request. Deleting the app from your device removes all locally stored data but does not automatically delete analytics events already recorded by Firebase; contact us if you'd like those removed as well.

Third-party services

TollGate relies on the following services to operate. None of them receive your camera feed.

  • Google ML Kit — on-device pose detection. Runs locally; no data leaves your device for this purpose.
  • Firebase Analytics (Google) — app-usage analytics, as described above.
  • AppsFlyer — privacy-controlled install, campaign and subscription attribution, as described above.
  • Firebase Crashlytics (Google) — crash diagnostics, as described above.
  • Cloud Firestore (Google) — stores optional leaderboard entries, optional accountability pacts, and your optional progress backup.
  • Firebase Authentication (Google) — holds the account you create if you choose to back up your progress, and the email address Apple or Google supplies with it.
  • Apple App Store / Google Play — process subscription payments and any pay-to-skip charges, and share transaction status with us.

We do not share your information with data brokers or use it for cross-app advertising profiles. We may disclose information if required to by law, or to protect the rights, safety, or property of TollGate or its users.

Children's privacy

TollGate is not directed at children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact betacarryapp@gmail.com and we will delete it.

Security

Data transmitted to our third-party service providers (Firebase Analytics, Crashlytics, and Firestore) is encrypted in transit. Because the camera feed and pose data never leave your device, they are not exposed to network transmission risk at all. No method of storage or transmission is perfectly secure, but we design TollGate so that the most sensitive data — what your camera sees — is never collected in the first place.

Your rights

Depending on where you live, you may have rights to access, correct, or delete personal information we hold about you, or to object to certain processing. Because TollGate doesn't require an email address, real name, or other directly identifying information to function, most of what we hold is tied to an anonymous account ID and a device — reset that device or contact us at betacarryapp@gmail.com to exercise these rights, and we will respond within a reasonable time.

International users

TollGate's third-party service providers (Google Firebase) process data on infrastructure that may be located outside your country of residence. By using TollGate, you understand that your information may be processed in other jurisdictions, which may have data protection laws different from those in your own country.

Changes to this policy

We may update this policy as TollGate changes. If we make a material change, we'll update the "last updated" date above and, where appropriate, notify you in the app. Continued use of TollGate after a change takes effect means you accept the updated policy.

Contact us

Questions about this policy or your data? Email betacarryapp@gmail.com.

TollGate

A blocker you can turn off isn't a blocker. TollGate makes friction physical, not optional.

Product

  • How it works
  • Alarm gates
  • Privacy & on-device
  • Game layer
  • Pricing
  • FAQ

Company

  • Privacy Policy
  • Terms of Service

Contact

  • betacarryapp@gmail.com
© 2026 TollGate. iOS and Android.
Privacy Terms