HabitToll Privacy Policy
Last updated: 5 October 2026
HabitToll puts a price on the apps you want to open less. This policy explains what data the app uses, where it goes and what you can do about it.
The short version
- Which apps you block, and how long you use them, are never sent to us. Device backups may contain a copy (see “Android and this version”).
- There’s no account. We never ask for your name, email, Apple Account or Google Account.
- In this version, the app sends nothing to us. Your purchases go through Apple or Google Play.
- A later update will add our own server for purchase records, Friends and optional usage statistics. Sections 4 to 8 already describe how they’ll work. We’ll tell you in the app before any of it starts.
- We don’t sell data, don’t show ads in the app and don’t track you across other apps or websites.
- We may advertise HabitToll on platforms such as Apple, Google or Meta. The app and this website contain no advertising or tracking code, and this website sets no cookies (sections 14 and 15).
Android and this version
This policy covers HabitToll on iPhone and Android. In version 1.0 on both platforms, purchase records, Friends, usage statistics and server logs described in sections 4–8 are not sent to our servers: those server features are not enabled. We will tell you before a later version enables them.
What Android uses. You enable usage access and
permission to display over other apps during setup. While blocking is on
and your screen is on, usage access lets HabitToll identify the app in
front. Permission to display over other apps lets it show the pause
screen over an app you chose to limit. The package names of the apps you
select, such as com.instagram.android, stay on your phone.
We do not receive your usage history or the identities of the apps you
block. During setup, “Your last 7 days.” reads your daily usage for the
preceding seven days and calculates an average on your phone. That
calculation is not saved or sent. A persistent notification tells you
when HabitToll is guarding your apps.
Purchases and refunds. On Android, a 10-minute pass is purchased through Google Play. Google handles payment and refunds under Google’s privacy policy. We do not receive your card details or Google Account details from the app. The app does not send Google Play its installation ID. The app stores its purchase records locally and sends none to our servers in this version. Refund requests go through Google Play. The iPhone option “Confirm delivery to Apple” does not apply on Android. Google is responsible for the data it handles in Google Play and its backup service under its own policy.
Device backups. Your phone’s backup may contain HabitToll’s settings, history, streak and hashed partner code. Android permits Google device backup and transfer to a new device; iPhone backups may include app data in iCloud or a computer backup. The backup provider may hold a copy outside your phone; we never receive it. Uninstalling removes the app’s local files, but does not necessarily remove an existing device backup. Manage those copies through your backup provider.
There is no HabitToll account on either platform. We do not ask for your name, email, Apple Account or Google Account. Sections describing Apple’s Screen Time, purchases and delivery confirmation apply to the iPhone app; the Android details above apply instead on Android.
1. Who we are
The controller responsible for your data is:
Comads OÜ Ahtri tn 12, 15551 Tallinn, Estonia Registry code: 17276947 Email: help@habittoll.com
We haven’t appointed a data protection officer; the law doesn’t require one for us. For anything about your data, write to help@habittoll.com.
2. What stays on your iPhone
The app does its work on your iPhone. These things are stored only there, and we never receive them:
- the apps and websites you block. Apple gives the app only coded tokens, and iOS itself draws their names and icons;
- when and how long you use them, every block screen you see and every time you walk away;
- your settings: price, monthly limit, free minutes, block times, the settings lock and the partner code;
- your answers during setup, such as your daily phone time and age range;
- your history, your monthly bill and your streak;
- the names you give your friends in the app.
The app uses Apple’s Screen Time framework to block apps. We don’t send any of this Screen Time information anywhere.
Reminders such as “1 minute left on your unlock” are scheduled on your iPhone. We don’t send push notifications.
“Delete my data” (Settings → Your data) erases your history and setup answers on the phone. Deleting the app erases everything it stored on your iPhone.
3. A random ID instead of an account
When you first open the app, it creates a random ID for this installation (the “install ID”). It isn’t linked to your name, email, phone number, Apple Account or device. We use it:
- to match purchases to this installation. Apple stores it with each purchase (as the “app account token”);
- for usage statistics, only if you choose to share them (section 7);
- as your support ID. The first 8 characters are shown in Help, so we can find your data when you write to us.
Friends uses a separate random ID (section 6), so friends data is never joined with your purchases or statistics.
4. Purchases
You buy unlocks from Apple, through Apple’s purchase sheet. Apple handles the payment. We never see your card or payment details, your name or your Apple Account. Apple’s privacy policy applies to that part: apple.com/legal/privacy.
When a paid unlock starts, the app sends our server:
- the install ID;
- Apple’s signed record of the purchase: transaction ID, product (price tier), price and currency, purchase date, App Store country, and whether it was a test purchase;
- the app version and platform;
- your answers to the two consent questions (usage statistics, section 7; delivery confirmation, section 5), with a counter that keeps the answers in the right order.
Our server also records when it first and last heard from the installation.
Apple also informs our server about purchases and refunds (App Store Server Notifications). For example, it tells us that a purchase happened, that a refund was requested and the reason given to Apple, and Apple’s decision.
- Why: to deliver what you paid for, to handle refunds correctly, to prevent misuse and to know how often refunds happen.
- Legal basis:
- our contract with you (Art. 6(1)(b) GDPR);
- our legitimate interest in correct refunds and in preventing misuse (Art. 6(1)(f) GDPR);
- legal record-keeping duties (Art. 6(1)(c) GDPR).
- How long: 24 months after the purchase, then deleted, unless a law requires us to keep a record longer.
5. Refunds: “Confirm delivery to Apple” (off unless you switch it on)
If you ask Apple for a refund, Apple may ask us whether the unlock was delivered. We answer only if you switched on “Confirm delivery to Apple” in Settings → Your data. It’s off until you switch it on, and the app never asks you to.
If it’s on, we tell Apple about that purchase:
- that you consented;
- that the unlock was delivered, but only if the app reported that it was;
- that the pay screen showed what the purchase does and its price before you bought it.
We never tell Apple how many minutes you used. We don’t know.
- Legal basis: your consent (Art. 6(1)(a) GDPR).
- Withdrawing: switch it off at any time. We then stop answering for future requests.
- If it’s off: we don’t answer, and Apple decides alone.
6. Friends (optional)
Friends stays off until you turn it on and invite someone, or accept someone’s invite.
What your friends see, per day:
- how many unlocks you paid for, and how much. You can hide the amounts with “Show amounts”;
- your streak (days without a paid unlock) and your best, which you can hide with “Show streak”.
They never see which apps, what time or for how long. They also never see your walk-aways, your free or emergency unlocks, or your settings.
What our server stores for Friends:
- a random friend ID and a scrambled (hashed) form of its secret key. The key itself stays on your phone;
- the daily numbers above, for the last 35 days, and your streak and best;
- who is linked with whom, and the people you blocked;
- open invite codes, stored only in a scrambled form;
- cheers (a stamp, no text), for 30 days;
- your platform, your three Friends switches and when your profile was last used.
Preventing abuse: we count requests to stop invite codes from being guessed. For a few kinds of request, we count per IP address using a one-way scrambled form that changes every day, and we delete these counters within about two hours. We never store your IP address itself in our database.
- Why: to show your progress to the friends you chose, as you asked.
- Legal basis:
- our contract with you (Art. 6(1)(b) GDPR);
- for the abuse counters, our legitimate interest in keeping the service safe (Art. 6(1)(f) GDPR).
- How long:
- daily numbers: 35 days;
- invites: 30 days after they were used or expired;
- cheers: 30 days.
- Deleting: “Turn off Friends” or “Delete my data”
deletes your friends profile, and everything linked to it on our server,
at once. A profile is also deleted automatically:
- 30 days after its last use, if it has no friends and no open invites;
- 12 months after its last use in any case.
Only people you invited, or whose invite you accepted, see your numbers. You can remove or block a friend at any time.
7. Usage statistics (only if you tap “Share”)
The app asks you once whether to share usage statistics. Until you tap “Share”, nothing is recorded for statistics.
If you share, the app sends events such as:
- setup steps completed;
- a purchase started, completed or cancelled, with its price and currency;
- the monthly limit reached, or a streak milestone;
- your answers to short questions in the app, for example why you stopped blocking;
- your rough daily phone time from setup, as a range;
- once a day, a summary with rough counts, such as “3–5”.
Each event carries the install ID, the app version and when it happened. Statistics never contain which apps you block, app names, how long you used them or anything you type.
- Why: to understand what helps and what doesn’t, and to improve the app.
- Legal basis: your consent (Art. 6(1)(a) GDPR). Keeping the events on your device until they’re sent also needs your consent under the ePrivacy rules of your country (in Germany, § 25 TDDDG).
- Provider: PostHog Inc., in its EU cloud (Frankfurt,
Germany).
- We don’t use PostHog’s app library. The app sends one small request itself: no device identifiers, no automatic tracking, no screen recording, and location lookup switched off.
- As with any connection, PostHog sees the IP address the request comes from. We’ve set PostHog not to store it.
- Refunds: if you share statistics, our server also tells PostHog when a purchase of yours is refunded (install ID, product, price and currency). This measures how often refunds happen.
- How long: 12 months, then deleted.
- Withdrawing: Settings → Your data → Usage stats. From then on nothing is sent, events not yet sent are deleted, and the app tells our server to stop the refund events.
8. Server logs
When the app talks to our server, our hosting provider keeps short technical logs, for example the time, the function called and the IP address. We use them to run the service and fix errors. Our own logs never contain your install ID, friend ID or keys.
- Legal basis: our legitimate interest in a working, secure service (Art. 6(1)(f) GDPR).
- How long: a few days.
9. Who handles data for us
- Supabase Inc. hosts our database and server functions in the EU (Frankfurt, Germany).
- PostHog Inc. stores usage statistics in its EU cloud (Frankfurt, Germany), and only if you share them.
- Cloudflare Inc. forwards email sent to help@habittoll.com (section 13).
- GitHub Inc. hosts this website (section 15).
- Apple runs the App Store, payments and refunds. Apple is responsible for that data itself, under its own privacy policy.
Supabase, PostHog and Cloudflare work only on our instructions, under data processing agreements, and must protect the data at least as well as this policy describes. All of them are US companies. If data is accessed from outside the EU, the European Commission’s standard contractual clauses or the EU-U.S. Data Privacy Framework protect it.
10. Your rights
You have the right to:
- get a copy of your data (Art. 15 GDPR), and receive it in a machine-readable format (Art. 20);
- have it corrected (Art. 16);
- have it deleted (Art. 17), or its use restricted (Art. 18);
- object to uses based on our legitimate interests (Art. 21);
- withdraw any consent at any time (Art. 7(3)). This doesn’t affect what happened before you withdrew;
- complain to a data protection authority. That can be the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, www.aki.ee), or the authority where you live or work.
How to use them. In the app, go to Settings → Your data:
- “Delete my data” erases your history and setup answers on the phone, and your friends data on our server.
- “Ask for a copy or erasure” opens an email to us with your support ID, so we can find your purchase records. We answer within one month.
We don’t know who you are, so we can only find your data through the IDs the app holds. Please send requests from the app.
11. Age
HabitToll is for adults (18+). It isn’t meant for children, and we don’t knowingly collect data from children.
12. Backups
Deleted data can remain in our hosting provider’s backups until those backups are replaced, for at most 30 days.
13. Emailing us
If you write to us, we receive your email address, your message and anything you attach. Mail sent to help@habittoll.com is forwarded by Cloudflare (Cloudflare Email Routing) to the mailbox we answer from, at Google (Gmail). We use your message only to answer you and to settle your request.
- Legal basis: our contract with you, when you write about the app or a purchase (Art. 6(1)(b) GDPR); otherwise our legitimate interest in answering you (Art. 6(1)(f) GDPR).
- How long: until your request is settled, and at most 24 months, unless the law requires us to keep it longer.
14. Advertising for HabitToll
The app shows no ads. Neither the app nor this website contains advertising or tracking code.
We may advertise HabitToll on other services, for example Apple (ads on the App Store), Google (such as Search and YouTube), Meta (Facebook, Instagram) or TikTok. Those ads are shown by the platform under its own privacy policy, and the platform decides, as its own controller, which of your data it uses to show them. From the platforms we receive only overall numbers, such as how many people saw an ad or downloaded the app. They don’t tell us who you are.
If we ever want to measure our ads with tools in the app or on this website, for example from Apple, Google or Meta, we’ll first add them to this policy. Where the law requires consent, we’ll ask for it before anything is read from or stored on your device: in the app with Apple’s “Allow tracking” prompt or our own question, on this website with a clear choice to accept or decline.
15. This website
These pages are hosted on GitHub Pages by GitHub, Inc. (USA). Like any web host, GitHub records the IP address of visitors to keep the service secure; see GitHub’s Privacy Statement. The domain habittoll.com is registered with Cloudflare, Inc., which only points it to GitHub; your visits don’t pass through Cloudflare.
No cookies, no tracking. This website sets no cookies and stores nothing in your browser. It uses no analytics, tracking or advertising code, and loads nothing from other companies; even its fonts come from these pages. That’s why there’s no cookie banner. If we ever add cookies or similar technology that isn’t strictly necessary, we’ll ask for your consent first (Art. 6(1)(a) GDPR; in Germany § 25 TDDDG).
- Legal basis: our legitimate interest in providing these pages safely (Art. 6(1)(f) GDPR).
16. Changes
If we change this policy, we’ll update the date at the top. If a change matters to you, we’ll also tell you in the app.