Privacy policy
Effective August 6, 2026. Vehicled is a free, non-commercial hobby project โ this page explains, in plain language, what we store and why. It is not a lawyer-drafted document, but it is accurate.
What we collect
- Sign-in details. You sign in with Google or Facebook (OAuth). We store the account identifier the provider gives us, your email address, and your display name. We never see or store a password.
- Your garage. The vehicles you log โ make, model, year, trim, colour, ownership, duration, country, notes โ plus your wishlist, photos you upload, who/what you follow, ๐ reactions, and your in-app notifications.
- Usage analytics. First-party, self-hosted event logs (e.g. "signed in", "added a vehicle", "made garage public", "shared a link") used to understand whether the product works. We do not use any commercial analytics or tracking service, and we don't build advertising profiles.
- Operational logs. Standard web-server logs and security events include IP addresses. We use them for abuse prevention (rate limiting, banning scrapers) and debugging, and prune old events routinely.
Private vs. public garages
Your garage is private by default. Only you (and site administrators, for
support and moderation) can see it. If you turn on public sharing, your garage page at
/u/<your-username> โ including your display name, vehicles, notes, photos,
stats, badges and wishlist โ becomes visible to anyone with the link, appears in Explore, in
"who else drove this" listings, and in community totals. Shared links may show a preview image
(poster/card) generated from your garage. Turning sharing off makes it private again, though
copies others made (screenshots, cached previews) are outside our control.
Photos
- Catalog images are AI-generated illustrations of car models, not photos of your actual car. Your own uploads are labelled as yours; AI renders are labelled "AI render".
- Uploads are re-encoded and EXIF-stripped โ location (GPS) and camera metadata are removed before storage.
- Licence-plate blurring runs on our server by default on your uploads (you can opt out per photo).
- Uploaded photos are served through an access-checked endpoint: photos in a private garage are only viewable by you and administrators.
Cookies and sessions
We use a signed, HttpOnly session cookie to keep you logged in, plus a CSRF token and (during the private alpha) an access-gate cookie. No third-party or advertising cookies.
API tokens
If you create a personal API token, we store only a hash of it. Anyone holding a token can act as your account through the API โ you can revoke tokens at any time.
We may send occasional transactional email (for example, "a photo is now available for your car") to the address from your sign-in provider โ only if outbound email is configured, and never marketing on behalf of anyone else.
Retention and deletion
- You can delete your account from your garage settings at any time; this permanently removes your profile, vehicles, notes, wishlist, photos, follows, reactions, notifications and API tokens.
- Deleting a vehicle or photo removes the underlying file as well.
- Backups exist for disaster recovery and age out on a fixed schedule; deleted data disappears from backups as they rotate.
- Analytics/security events are pruned periodically.
What we don't do
We do not sell or rent personal data, and we don't share it with advertisers or data brokers. Data is only disclosed if the law requires it.
Contact
Questions, or a data request you can't do in-app? Contact [email protected].