Privacy policy

The short answer

The BookGate app keeps your books, nightly photos, spoken takeaways and streak on your iPhone only; there is no account and no BookGate server. It sends anonymous usage statistics — which screens people reach, whether sessions are completed — never your content, not linked to you. App shielding runs through Apple's Screen Time framework, which never tells BookGate which apps you open. The only personal data is an email address, if you join the waiting list.

Last updated: 6 September 2026

This policy covers the BookGate iPhone app and the website at bookgate.app. It is written to be read, not to be survived.

The short version: your reading stays on your phone. There is no account to create and no BookGate server holding your books, photos, recordings or history; everything the app knows about you is stored on your phone and may also be included in your own device backup. The app sends anonymous usage statistics — counts of which screens people reach and whether sessions are completed — never your content, and never linked to you. Deleting the app removes its local data. The website stores one thing, and only if you ask it to: an email address for the launch waiting list, which is deleted after launch.

Who I am

BookGate is made and published by Collin Arumai Harinath Mendons Jeyaseelan, an independent developer based in Switzerland. For the small amount of data described below, I am the data controller. Contact: hello@bookgate.app.

What the app collects

Nothing personal. BookGate does not collect, transmit or store your personal data on any server. There is no account, no sign-up, no sync, no cloud backup built into the app and no BookGate server holding your data. StoreKit communicates with Apple to load prices, process purchases and confirm your subscription, but BookGate sends it none of your books, photos, recordings or reading history. The one thing that does leave your phone is the anonymous usage statistics described in the next section.

This is also what BookGate declares to Apple. Its App Store privacy manifest lists three data types — product interaction, purchase history and a device identifier — all marked not linked to you and not used for tracking, and sets NSPrivacyTracking to false. The two extensions declare no collected data at all: one only records when emergency access was taken, and the other only draws the barrier you see over a shielded app.

Anonymous usage statistics

BookGate sends a small number of anonymous, aggregate events so I can tell where people get stuck — for example, how many readers finish onboarding versus how many stop partway, and how often the camera check works versus how often the manual button is needed.

What is sent: the name of the onboarding page reached; whether a subscription screen was shown, and whether a purchase was made and for which plan; whether the camera gate was passed by the camera or by the manual button; whether a session was completed or ended early, and its scheduled length; whether a spoken takeaway was saved; and how the weekly step-up prompt was answered. Alongside each event the analytics provider attaches technical context: device model, iOS version, app version, language, region, time zone and iOS accessibility settings such as larger text or reduced motion.

What is never sent: your books or their titles, the journal photos, the recordings, your alarm time, your streak or history, which apps you shield, or any free text. Nothing that describes a particular person’s evening.

No tracking, no advertising. There is no IDFA, no App Tracking Transparency prompt and nothing that follows you across other apps or websites. There are no advertising SDKs, and the data is never sold or shared.

Who processes it. The analytics provider is TelemetryDeck GmbH (Augsburg, Germany), acting as my data processor. Events are tied to a per-install identifier that is hashed on your device before it is sent, so it is not linked to your name, your email or your Apple Account. TelemetryDeck hosts data with providers in Ireland, Germany and the United States.

Not linked to you. These are usage statistics, not a profile. They are not tied to your name, email, Apple Account or anything I could use to identify you, and I make no attempt to. The legal basis is my legitimate interest (Art. 6(1)(f) GDPR) in understanding how the app is used so I can fix what is broken.

Your data on your device

All of the following live on your iPhone — inside the app’s own storage and a shared App Group used by its shield extensions — and are never uploaded to BookGate:

  • The books you add: titles, authors, and any cover photograph you take
  • Your reading schedule: the alarm time, the session length, which nights
  • The photograph taken at the start of each reading session, kept as that night’s journal entry
  • Your spoken takeaway recordings
  • Your history of nights read, your streak and your progress
  • Your settings, including which apps you have chosen to shield
  • A record that your subscription is active, so the app works offline

Deleting the app removes its local copy of this data. There is no BookGate sync between devices and no copy on a BookGate server.

If your iPhone is included in an iCloud or encrypted local backup, this data may be included in that backup. That backup is made and controlled by Apple and by you, not by me — I have no access to it.

Camera

BookGate uses the camera in two places: the back camera photographs a book cover you are adding, and the front camera takes the photo that starts a reading session and becomes that night’s journal entry.

The cover photo is read on-device by Apple’s Vision framework to pull the title and author off it, so you do not have to type them. That happens entirely on the phone; the image is not sent anywhere to be analysed.

The session photo is checked on-device for a face, a hand and a book, so the app can tell that you have actually settled down with the book. It does not identify whose face it is and performs no facial recognition. There is a manual fallback if the check does not work. Nothing from the camera is ever uploaded.

Microphone

If you record a spoken takeaway after a session, the recording is saved as an audio file in the app’s own storage on your device. It is meant to be about thirty seconds and is capped at five minutes. It is not transcribed by any service, not uploaded, and not shared. You can delete it in the app.

Photo library

BookGate asks for add-only access, used solely when you tap Save to Photos on a journal entry. The app never reads, browses or scans your photo library, and iOS does not grant it the ability to.

Alarms and notifications

The nightly reading alarm and its re-rings are scheduled locally on your device through Apple’s alarm and notification frameworks, so they reach you through Silent mode and Focus. Nothing about your schedule is transmitted to me or to anyone else.

App shielding and Screen Time

BookGate blocks apps using Apple’s Screen Time and Family Controls frameworks. This matters for your privacy in a specific way: those frameworks do not tell BookGate which apps you use.

When you choose apps to shield, iOS hands the app an opaque token rather than an app name, and the shielding is enforced by iOS itself. BookGate cannot read your usage, cannot see which apps you open, and has nothing to report even if it wanted to. Those tokens are stored on your device in the shared App Group and nowhere else.

Screen Time authorisation can be withdrawn at any time in iOS Settings. Doing so disables shielding and nothing else.

Subscriptions

Subscriptions are sold and processed by Apple through the App Store. I never see your payment details, your card, or your Apple Account. The app receives only a signed confirmation from Apple that a subscription is active, which it stores on the device so the app works offline.

As a developer I receive anonymous, aggregated sales reporting from Apple — totals by country and product, never individual customers. Apple’s own handling of your purchase is governed by Apple’s privacy policy.

The waiting list

If you enter your email address to be told when BookGate launches, the following is stored:

WhatWhy
Your email address, lower-casedTo send you the launch email
The language of the page you submitted fromTo send it in that language
A two-letter country code, from Cloudflare’s CF-IPCountry headerTo know which App Store storefronts to mention
The date and time you signed upHousekeeping and abuse prevention

Your IP address itself is not stored — only the country code derived from it. There is no third-party email service, no cookie and no tracking pixel involved.

Legal basis: your consent, given by submitting the form. You may withdraw it at any time by emailing hello@bookgate.app.

Retention: the waiting list exists only until BookGate is on the App Store. Once the launch email has been sent, the entire list is deleted within 90 days, and the form is removed from the site. It is used for that one email and nothing else — never sold, never shared, never used for any other message.

The list is stored in Cloudflare D1, a database hosted by Cloudflare. This means it may be processed outside Switzerland and the EEA, under the standard contractual clauses in Cloudflare’s data processing addendum.

This website

No cookies. No analytics. This site sets no cookies and runs no analytics, tracking or advertising scripts of any kind. Your light-or-dark choice is kept in your browser’s own local storage on your device and is never sent anywhere; your language is simply part of the URL.

Server logs. The site is served by Cloudflare, which processes requests on my behalf and keeps standard transient logs — IP address, user agent, requested URL — for security, abuse prevention and delivery. I do not use those logs to build a profile of anyone. Cloudflare’s own handling is described in its privacy policy.

Links away from this site. The guides link to other websites. Once you follow a link, that site’s own policy applies. I have no control over them and receive nothing for linking.

Selling and sharing

I do not sell your personal information, and I do not share it for cross-context behavioural advertising, as those terms are used in California law. I never have, and there is nothing in the app that could. BookGate does no tracking, so there is no “Do Not Track” or Global Privacy Control signal to act on — the answer is already no.

Your rights

For the app, I hold nothing that identifies you. The usage statistics are not linked to a name, an email, an Apple Account or any identifier I could trace back to a person, so there is nothing I could find, export, correct or delete for one individual. Deleting the app removes its local data; your own device backup may retain a copy.

If you are on the waiting list, that email address is the only personal data I hold about you. You can ask me to give you a copy of it, correct it, delete it, or object to its use. Email hello@bookgate.app and it will be handled within thirty days, free of charge.

Swiss data protection law applies. If you are in the EU or the UK, the GDPR or UK GDPR gives you those same rights, and you may also lodge a complaint with your national supervisory authority — in Switzerland the FDPIC, in the UK the ICO, in Brazil the ANPD. You are welcome to raise it with me first, but you do not have to.

Children

BookGate is not directed at children and does not knowingly collect data from anyone under 13 — or under the higher age set by your country, which in the EU is between 13 and 16. It requires an Apple Account able to make purchases and a paid subscription to work. If you believe a child has joined the waiting list, email me and I will delete the address.

Changes

If this policy changes, the date at the top changes and the previous version is replaced. Where required, material changes will receive additional notice before they take effect.

Contact

hello@bookgate.app

See also the terms of use.