Privacy Policy
Last updated: 8 October 2026.
Publisher: Orhan Ege Bilge. Contact for privacy and support: [email protected].
In short
Your API key, your sales reports and Apple's analytics reports for your apps stay on your device. The developer receives nothing from the app unless you switch on the bell, an optional service that is off until you do. The bell service then keeps your phone's push address and when it last registered. It never sees your key, a report or a figure. Without the bell, Tillroll has no server and no account.
What the app keeps on your device
- Your App Store Connect API key, with its key ID, the issuer ID and your vendor number. They are stored in the iOS Keychain, on this device only. The key is not synced to iCloud Keychain and cannot be restored onto another device. The one-time Admin key described below is not stored at all.
- Your daily sales reports, as Apple sent them. They list products, countries, units and amounts. They do not identify your customers.
- Apple's analytics reports for your apps, as Apple sent them, and the storefront figures the app takes from them: for each app and day its impressions, product page views, first downloads and redownloads, and where the app was seen. Like the sales reports they hold counts and do not identify your customers. They are kept beside the sales reports and are deleted with them.
- Settings and small working files: language, display currency, notification choices, the dates the app needs to decide when it may ask for a rating, the last exchange-rate table, a note of which days were already announced, a log of when the app looked for a new slip in the background, and a summary that the widgets read.
- With the bell: the bell account's code and an id for this install, in the iOS Keychain. The code is 32 random bytes made on your device; it holds no name and no email address. Unlike the API key it can travel in a backup to a new phone, so that the account and its routes are not lost. The app also keeps a table of your routes: which of your apps each one rings for.
What leaves your device
Without the bell the app makes three kinds of requests of its own. The bell adds a fourth.
To Apple (
api.appstoreconnect.apple.com), only after you connect a key. A request asks for one day's sales report, for the list of your apps, or for an app's analytics reports: its report requests, the reports they produce, their daily instances and the addresses of their files. A request for a sales report carries your vendor number. Every request carries a short-lived token that the app signs on the device with your key; the token names the key ID and the issuer ID. The key itself is never sent. Apple handles the request under its own privacy policy, as it does when you use App Store Connect yourself.One step is different. Apple produces an app's analytics reports only after they were requested once, and only a key with the Admin role may ask. If your apps have no such request, Settings offers to make it once, with an Admin key that you create for it. The app signs one request per app with that key and sends it to the same address of Apple. The Admin key is held in the memory of that one screen: it is never written to the Keychain or to a file, it is never sent itself, and the app forgets it when Apple has taken the requests or when you leave the screen. The app then tells you to revoke it.
To the address Apple names for a report file. Apple's answer about an analytics report holds the address of each of its files, valid for five minutes, and the app downloads the files from there. This request carries no token and no header of the app's: the address is the permission. The host is Apple's choice; like any web server it sees your IP address and the usual request details.
To a public file host (
cdn.jsdelivr.net), to download a table of exchange rates, and only when the copy on the device is more than twelve hours old. The request is the same for every user. It contains nothing about your account, your sales or your currency. Like any web server, the host sees your IP address and the usual request details; the developer has no access to its records. If the download fails, the app uses a table that is built into it.To the bell service (
bell.codebiy.com), only if you use the bell: once you have switched it on, or when you look up or erase a bell account. The service is the developer's own and runs on Cloudflare. The app sends it your phone's push address (the address Apple's push service gives the app), an id for this install and Apple's signed proof that this copy of Tillroll is genuine, all under the bell account's code. The service keeps the push address, which of Apple's two push environments it belongs to, the id, when the phone first and last registered, when Apple last took a push for it, how many pushes have failed since, and the last report day it rang for. Of the code it keeps only a hash. It checks the proof and keeps nothing of it. It never receives your API key, a report or a figure from one. When a day's report is due, the service sends your phone a push through Apple's push service, and the app then fetches the report from Apple on the phone, as in point 1.
A route is an address you make in the app so that something else can ring your phone: one of your own apps, Apple, or App Store Connect. The service keeps the route's kind, the app's bundle ID, for a route that Apple rings also the app's number in the App Store, a hash of the address, when the route was made and when it last rang, the app's name as a label, and the name of the sound you chose for it. For a route that an App Store Connect webhook rings, it also keeps the webhook's secret, sealed with a key of the service, because every delivery is checked against it. What rings a route passes through the service on its way to your phone and is not kept. From your app that is Apple's signed proof of one purchase of that app, which holds no name and no account of the buyer, and the country of the store. From Apple it is an App Store Server Notification, of which the service passes on the kind of event, the product, its list price, the country and the quantity. The service keeps only a mark that it rang, for eight days: a hash of the purchase's id, or the notification's id. The mark of a test purchase from TestFlight is kept for good. From App Store Connect it is a webhook delivery, of which the service passes on what it is about (a version, a build, a beta or TestFlight feedback) and Apple's name of the state; it holds no figure. Of a delivery the service keeps only a hash of its id, for a day, so that one delivery rings once. To hold the limit of 30 rings an hour, the service also counts how often a route has rung in the running hour, and how many test rings the account asked for. The count never passes 31 and is removed the next day.
Forwarding is optional and part of Tillroll Pro. If you set a destination (a Slack or Discord webhook address, or a Telegram bot token and chat), the service keeps it sealed with a key of the service, with the language of the app, and never gives it back to the app or to anyone. For each real ring of a route it sends that destination one line of text: the route's label and what happened, such as the product and its list price for an in-app purchase. Slack, Discord or Telegram then handle that line under their own privacy policies. Removing the destination in the app deletes it from the service.
Tillroll Pro. When you hold Tillroll Pro and the phone has a bell account, the app sends the service Apple's signed record of that purchase: after the purchase, and again when the app is opened. The service checks it and keeps, for the bell account, until when the purchase entitles it, whether it came from the App Store or from Apple's test environment, and a hash of the purchase's id; the record itself is not kept. Apple tells the service of a renewal, an expiry or a refund of that purchase. The hash of a purchase that Apple refunded or revoked is kept for good, without an account beside it, so that the same purchase cannot be used again.
Like any web server, Cloudflare sees the IP address of a request and handles it under its own privacy policy. The service limits registrations and new routes per IP address and keeps no IP address in its own database. Its own log holds one line per ring or refusal, with no code and no push address. Of a purchase a line says only that one rang, was counted or was refused: no id and nothing else of it.
When you tap a link (support, this policy, the App Store page or "Send feedback"), iOS opens Safari or Mail. An email you send reaches the developer because you chose to send it. It is used only to answer you. A slip you share as a picture goes where you send it, through the iOS share sheet; the app itself sends it nowhere. The storefront figures are never on that picture.
What the app does not do
No analytics of how you use the app. No advertising. No tracking. No third-party code. No sign-in: the bell account is a random code, not a name or an email address. No access to the microphone, your location or your contacts. The camera is used only when you scan the code of a bell account from another device; no picture is stored or sent. The app can add the picture of a slip to your photos when you ask it to, and cannot read your photos. Before it shows the bell account's code, the app has iOS check Face ID, Touch ID or the passcode, and learns only yes or no. Notifications are written on the device. Without the bell they are local notifications; with it, a push from the bell service wakes the app, which writes the notification on the phone.
Purchases
Tillroll Pro, as a subscription or a one-time purchase, is sold by Apple through the App Store. The app learns from Apple only whether the purchase is valid for you. It never sees your payment details. With a bell account, the bell service learns of the purchase what is described under "Tillroll Pro" above.
Keeping and deleting
- Remove the connection in Settings: the key is deleted from the Keychain. The app then asks whether to delete the stored reports as well: the sales reports, and with them the analytics reports and the storefront figures. The bell, if it was on, is switched off.
- Delete the app: its reports, settings and working files are removed with it. Remove the connection first, because iOS can keep a Keychain item after an app is deleted. If one is left behind, it stays in this device's Keychain, where no other app can read it: connecting again replaces it, and "Remove connection" deletes it. Deleting the app does not tell the bell service: switch the bell off or erase the bell account first. A phone that is gone is dropped by the service the next time Apple refuses its push address.
- Revoke the key at any time in App Store Connect (Users and Access, Integrations). A revoked key is of no use to anyone. Revoke the one-time Admin key as soon as its step is done.
- Switch the bell off on the Bell tab ("On-time delivery"): this phone is removed from the bell service. The bell account and its routes stay, because a route's address may already sit inside one of your apps.
- Erase everything on the bell service on the Bell tab, under "Bell account": every phone and every route of the bell account, its forwarding destination and what the service keeps of your Tillroll Pro purchase for the account are deleted from the service, and the code is deleted from this phone. Only the hash of a refunded purchase stays, as described above.
- Backups: if you back up your device, the backup can include the stored reports and settings, according to your own Apple settings. Restoring it onto another device does not bring the API key with it. The bell account's code can come along.
Without the bell the developer holds no data about you. With it, the service holds what is listed above, under a random code and without your name. The developer cannot tell whose it is, so he cannot look it up, correct it or delete it for you; you can delete it yourself at any time, on the Bell tab. Everything else is on your device and in your hands.
Children
Tillroll is a tool for app developers and is not directed at children. Without the bell it collects no data from anyone.
Apple's services
Downloading the app, Tillroll Pro and its billing, refunds, device backups, the push service that delivers the bell's pushes and Apple's own diagnostics are Apple's services and follow Apple's privacy policy: apple.com/legal/privacy.
Changes
If the app's behaviour changes, this policy and its date change with it.
Tillroll is an independent app and is not affiliated with Apple. App Store and App Store Connect are trademarks of Apple Inc.