HomiSoft
CarVitae

Privacy

Privacy

Current product privacy material

Privacy

CarVitae is local-first and account-free for its core workflow.

  • No advertising SDK, cross-app tracking, or sale of vehicle records.
  • No analytics event may contain VIN, plate, exact location, money, receipt text, or attachment content.
  • Location permission is requested only after the user starts a place-assisted action.
  • Camera and photo/file permissions are requested only after an explicit attach/scan action. An optional vehicle hero photo is copied into the private attachment store; the app does not retain a Photos or file-provider URI after selection.
  • Attachments, including optional vehicle photos, remain on device in the shipped local-only build. Any future optional sync must be an explicit opt-in, preserve local access during remote failure, and update this policy before release.
  • Android disables operating-system cloud backup and device-to-device extraction for ledger data, attachments, templates, and preferences. A person must explicitly create and verify a CarVitae backup or transfer package; no implicit Android backup is represented as a recoverable vehicle-history archive.
  • iOS ships a privacy manifest in both the app and WidgetKit extension. It declares only local UserDefaults/App Group state and private attachment-file metadata; it declares no collected data, tracking, or tracking domains. Recheck these declarations whenever an SDK or remote feature is added.
  • Crash reporting, if adopted, must scrub user data payloads.
  • App Lock uses platform authentication and notifications hide sensitive values by default. Date reminders use generic notification text and do not include a reminder title, VIN, plate, cost, location, or receipt data.
  • App Lock is off by default. Turning it on or off requires a fresh platform authentication. iOS locks when the app resigns active; Android locks after it enters the background. iOS accepts Face ID, Touch ID, or device passcode; Android accepts strong biometrics or device credential. CarVitae receives only success/failure and never stores biometric data or a passcode.
  • Android applies secure-window protection while App Lock is on, preventing screenshots and app-switcher previews from revealing ledger content.
  • Widgets expose only a vehicle nickname, current meter, and next task. VIN, plate, costs, documents, OCR text, and exact location are excluded. Siri/launcher shortcuts only request an in-app form and do not save a record by themselves.
  • Data & Seller Pack provides a separately confirmed full local-data erase action. It clears local vehicle records, copied originals, templates, and saved places; already exported backup files and store purchase state are outside this app-local scope and are disclosed before confirmation.

The release build must link a public privacy policy URL after it exists; that external URL is a manual release task, not a blocker for local development.