Privacy Policy
Last updated 5 September 2026
Credentials and bills
API keys, tokens, and account identifiers you enter stay on this device, each system using its own lock.
- iOS / iPadOS
- iOS Keychain, with WhenUnlockedThisDeviceOnly. Not iCloud Keychain, and not system backups.
- macOS
- This Mac’s Keychain, same class. Not shared with iPhone or iPad.
- Android
- The in-development build in the repo encrypts them with Android Keystore and keeps them on the phone, out of cloud backups. It has not shipped.
- Windows
- The in-development build in the repo puts them in Windows Credential Manager, readable only on that PC. It has not shipped.
Fetch requests leave this device for each vendor’s official API. TollCat’s servers do not proxy them and never see those credentials.
History, subscriptions, and preferences live on the device. On iOS they sit in the App Group container shared by the app and the widget. The widget cannot fetch on its own.
This site and the optional server
tollcat.app is a static site: no accounts, no cookies, no analytics scripts. After a Cloudflare deploy, the edge will see connection metadata (IP, user-agent, time) for delivery and abuse prevention. We do not use it to identify you.
api.tollcat.app is the project’s only server, separate from this site. It handles tip messages, in-app feedback, a public setup catalog (copy, plan prices, FX rates; no URLs or credentials), a reading inbox for vendors without an official billing API, and anonymous page counts. None of those paths receive provider credentials.
Inbox keys are stored as SHA-256. Each inbox keeps only the latest amount per service. A dump would leak anonymous numbers that do not attach to a person — not keys that can spend money.
Moving devices
Credentials are kept out of iCloud on purpose. To change phones, export an encrypted .tollcat file and type the 10-character code on screen. Leave the import page and the code is gone. The file cannot be imported after 24 hours; that only shrinks the window if you sent it by mistake, and is not the strength of the encryption. History does not travel with the file — refresh after import.
Local reminders
You can schedule a local reminder to look at the number. The notification never includes an amount. There are no threshold alerts and no remote push.
Feedback and tips
In-app feedback may be anonymous. If you leave a contact, it is used only to reply to that message. Environment details sent with feedback are listed on the same screen before you submit.
Tips go through Apple In-App Purchase. Apple processes payment under its own policy. We see a completed purchase and any note you leave, not a full card number.
Anonymous page counts
The app reports which screens you opened to api.tollcat.app so we can see daily opens and per-screen enters. The payload is: platform (iOS, Android, macOS, or Windows), app version, an allowlisted screen name, and whether this is the first open of the UTC day.
These counts have one more use: TollCat may one day carry a small amount of unobtrusive advertising to pay for itself. Whether to do that, and on which screens, depends on knowing which screens people actually read. If it happens, this page will say so first.
There is no account, advertising identifier, device fingerprint, or stable anonymous ID. Staying on the same screen counts once. The server only increments totals — no event log, and IP is not used to recognise you. Screen names do not include which vendors you connected.
What we do not collect
No advertising identifier, no cross-site tracking, no selling of bills. Items on the Privacy Nutrition Label exist because a feature needs them (for example a tip purchase, or anonymous product interaction counts) and tracking is off.
Children
TollCat is not directed at children under 13. We do not know a user’s age because there are no accounts.
Changes
Material changes update the date on this page. Keep using the app and you are looking at this version.
Questions: open the app → Settings → Feedback, or use the contact page on this site. Both hit api.tollcat.app. Neither carries credentials.