Privacy Policy — PushGate
Unofficial English translation for your convenience. The German version (Datenschutzerklärung) is the legally binding version; in case of any discrepancy between the language versions, the German version prevails (§ 14).
Last updated: 28 August 2026
1. Controller
Raphael Stedler
Martin-Opitz-Straße 22, 13357 Berlin
Email: kontakt@pushgate.app
(see Legal Notice)
2. Principle
PushGate is deliberately built to minimize data collection: camera footage never leaves the device, and there are no advertising SDKs, no tracking, and no external analytics services (as of this document). This policy nonetheless describes in full which data is generated — including the few items that actually reach our backend.
3. What data we process
3.1 Account
Upon registration/sign-in: email address and password hash, or — when signing in with Apple/Google — the user ID (and, optionally, name/email) provided by Apple/Google. Processed on our self-hosted backend (Supabase software, see section 5).
3.2 Profile
Display name, optional short bio, time zone (the latter technically necessary so that "day" is unambiguous for streak calculation).
3.3 Device data
Per installed device: platform (iOS/Android), device model, OS and app version, timestamp of the last synchronization. No device identifier suitable for recognition beyond the app on other services.
3.4 Gate settings and blocked targets
How many repetitions you set as a prerequisite, how long an unlock lasts, and which apps/domains/categories you block. On Android as package name (e.g. the name of a social media app); on iOS, for technical reasons, only as a count/category without app names.
3.5 Sessions (completed training sets)
Per completed attempt: start and end time, number of repetitions achieved, target count, whether the goal was reached, platform, day. No camera footage, no raw motion data — only these numbers and timestamps.
3.6 Override events
If you open a blocked app via an override function without training, this is logged with a timestamp and the affected app (on Android: its package name) — for your own behavioral insight, not for advertising purposes.
3.7 Challenges and achievements
Progress on self-chosen or preset challenges and confirmations of achievements earned.
3.8 Camera and motion data — treated separately as particularly sensitive
To count repetitions, the app uses the front-facing camera and a pose-detection model (Apple Vision framework on iOS, or the platform-equivalent method on Android). This processing takes place exclusively locally on your device. Neither camera footage nor data derived from it (such as joint positions) is stored or transmitted to our servers or to third parties. Only the figures described in section 3.5 (reps, timestamps) are generated.
3.9 Accessibility service (Android only)
To detect when a blocked app comes to the foreground, the Android version uses an Accessibility Service. It reads only the package name of the app currently in the foreground from window-change events — no screen content, no text input, no screenshots. This information is evaluated only locally to display the block screen and is not transmitted to our backend. Independently of this, we store the block list you configured and override events, including the respective package name, on our server (see sections 3.4 and 3.6).
On iOS, Apple's Family Controls / Screen Time framework is used instead, which for technical reasons does not allow app detection outside Apple's own sandbox.
3.10 Purchase/subscription data
Purchases are handled entirely through Apple's App Store or Google Play, technically mediated by RevenueCat. We receive neither payment-method nor full billing data, only the entitlement status ("active subscription: yes/no") linked to your user ID.
4. Purposes and legal bases
| Processing | Purpose | Legal basis |
|---|---|---|
| Account, profile, devices | Contract performance, device synchronization | Art. 6(1)(b) GDPR |
| Gate settings, blocked targets, sessions | Core function of the app | Art. 6(1)(b) GDPR |
| Override events, achievements, challenges | Contractual function / statistics for you | Art. 6(1)(b) GDPR |
| Subscription status | Unlocking paid features | Art. 6(1)(b) GDPR |
| Abuse/error prevention | Operational security | Art. 6(1)(f) GDPR |
Providing your email address and password (or signing in via Apple or Google) is contractually required to create an account; without it, registration and therefore use of the app is not possible. There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR; which apps are blocked and how many repetitions are required is determined exclusively by you.
Special categories of personal data (Art. 9 GDPR): we do not store physiological measurements, raw camera or motion data, or information about illnesses. We store repetition counts and timestamps as well as the block settings you chose; in our assessment, these do not constitute health data within the meaning of Art. 9 GDPR, because they make no statement about your state of health. Should we introduce features in the future that allow further-reaching inferences (e.g. server-side evaluation of training or goal information), we will obtain your explicit consent beforehand.
5. Recipients and processors
Our backend runs on self-hosted Supabase software (open source), not on the hosted Supabase cloud. Supabase Inc. therefore has no access to our data and is not a processor. The processor is instead the provider on whose hardware the server physically resides:
| Provider | Role | What it receives |
|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Server/infrastructure operation (Helsinki, Finland data center), processor (Art. 28 GDPR) | all data from sections 3.1–3.7, stored on its hardware |
| RevenueCat, Inc. | Subscription/purchase management — processor (Art. 28 GDPR) | User ID, purchase/entitlement status |
| Apple (App Store, Sign in with Apple) | Payment processing, sign-in — independent controller | Purchase data (at Apple), identity token (upon sign-in) |
| Google (Play Store, Google Sign-In) | Payment processing, sign-in — independent controller | Purchase data (at Google), identity token (upon sign-in) |
We have a data processing agreement with Hetzner pursuant to Art. 28 GDPR. Hetzner provides the DPA as a standard agreement in the Hetzner Cloud console, available for one-click conclusion (account settings → data processing); since both Hetzner (Germany) and the data center used (Helsinki, Finland) are located in the EU, no third-country assessment is required for this.
We have a data processing agreement (DPA) with RevenueCat pursuant to Art. 28 GDPR.
Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI), Husarenstraße 30, 10115 Berlin. production operations start — add date and, if applicable, contract number here.]
6. Transfers to third countries
RevenueCat, Apple, and Google are US companies. For the transfer, the following applies per recipient (as assessed on 2026-08-26):
- Google LLC: certified under the EU-US Data Privacy Framework (entry verified on 2026-08-26 at dataprivacyframework.gov).
- Apple Inc.: not listed in the Data Privacy Framework registry. Transfers are based on Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2) and/or the Global Cross-Border Privacy Rules (CBPR) System.
- RevenueCat, Inc.: not listed in the Data Privacy Framework registry. Transfers are based on Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2) under the RevenueCat Data Processing Addendum.
We will provide a copy of the relevant safeguards (Standard Contractual Clauses) upon request to the email address given in section 1. Since Apple and RevenueCat are not DPF-certified, we rely exclusively on Standard Contractual Clauses for these two recipients; a Transfer Impact Assessment for RevenueCat is documented internally.
The self-hosted database server is located in the EU (Finland); no third-country transfer therefore takes place for the data listed in sections 3.1–3.7.
7. Retention period
Account and profile data: until the account is deleted. Sessions and override events are stored continuously (append-only) for as long as the account exists — they serve your own history view (streaks, statistics). Upon account deletion, all linked records are automatically and immediately deleted as well (see section 8).
8. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21), as well as the right to lodge a complaint with a data protection supervisory authority.
Right to object (Art. 21 GDPR): Insofar as we process personal data based on Art. 6(1)(f) GDPR (abuse/error prevention, our website's server logs), you have the right to object at any time, on grounds relating to your particular situation, to that processing. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Deleting your account: In the app under Settings → Delete account. Deletion removes your auth record on the server immediately; all linked tables (profile, devices, settings, sessions, etc.) are automatically deleted via database cascades.
Competent supervisory authority: Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI), Husarenstraße 30, 10115 Berlin.
9. Minors
The app is directed at persons aged 16 and older; registration requires a corresponding minimum age. Concluding a paid subscription requires the user to be of legal age, or the consent of their legal guardians (see Terms § 3).
10. Cookies, tracking, advertising
The app does not use cookies, third-party tracking, advertising identifiers, or external analytics SDKs. Event logs for diagnostic and product-improvement purposes — including your onboarding answers (e.g. goals and usage motivations) — remain on the device (ring buffer, automatic rotation) and are not transmitted to us.
Important: as soon as a third-party analytics, crash-reporting, or push notification service is introduced in the future, or local logs are to be transmitted to our backend, this section must be updated before rollout — including, where applicable, consent (Art. 6(1)(a) GDPR, § 25 TDDDG).
11. Data security
Connections to the backend are encrypted (TLS). Access to data is strictly limited to each user's own account via database rules (Row Level Security).
12. Users in the United Kingdom (UK)
For users habitually resident in the United Kingdom, the UK GDPR, as amended by the Data (Use and Access) Act 2025, applies in addition. The competent supervisory authority is the Information Commissioner's Office (ICO), ico.org.uk. Pursuant to Art. 27 UK GDPR, we are required to appoint a representative in the United Kingdom:
Raphael Stedler, Martin-Opitz-Straße 22, 13357 Berlin, email: kontakt@pushgate.app
13. Visiting our website
Our website is hosted on a server we operate through Hetzner Online GmbH (see section 5) in the EU. When you access it, the server technically necessarily processes your device's IP address, the date and time of access, the file accessed, the user agent, and the referrer URL (server logs). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in providing the website securely and reliably). Server logs are deleted or anonymized after no more than 14 days.
The website stores your language choice in your browser's localStorage (key "pushgate-lang"). This storage is strictly necessary to provide the language version you selected (§ 25(2) no. 2 TDDDG); no consent is required for this. The website does not use cookies or tracking and does not load content from third-party servers; fonts and media are served locally.
14. Changes to this policy
We update this policy whenever the processing changes. The date at the top shows the version currently in effect.
This policy is also available in a German version. In the event of any discrepancy between the language versions, the German version prevails.