Most privacy claims are promises. This one is a wall.
When you pick apps to guard, the picker you use belongs to Apple, not Tollgate. And when you tap Done, Apple does not hand Tollgate a list of app names. It hands over an opaque token, a sealed envelope that iOS itself can read but the app cannot. Tollgate passes that envelope back to iOS when arming the guard, and iOS does the shielding.
The result:
The onboarding screen puts it directly: “Your picks never leave your phone. Even we can’t see them.” Both sentences are literal.
Whatever you guard, a dating app, a gambling app, a competitor’s app, an ex’s feed you check too often, is nobody’s business, including ours. Because the names never enter Tollgate’s process, they cannot leak in a crash report, cannot be subpoenaed from us, cannot appear in analytics, and cannot be mishandled by a bug. The strongest data protection is not storing the data at all.
This is why Tollgate’s copy always says “your guarded apps” and never “Instagram.” The app literally cannot name your picks, so shields say “Close this app” generically, and stats are never broken down per app. A small price for a promise with no fine print.
More on the overall picture in What data leaves your phone.