AutoSpotterX - Privacy Policy

Last Updated: October 4, 2026

1. Introduction

AutoSpotterX ("we," "our," or "us") values your privacy. This Privacy Policy explains how we collect, use, and protect your information when you use the AutoSpotterX Application (including our mobile apps for Android and iOS, and our web application). It applies to all users and covers the data collected through our applications.

2. Information We Collect

We collect the following types of information:

Account & Profile Data: Username, optional profile photo, optional social media links (Instagram and TikTok, available to users with more than 1,000 AutoXP), account creation date, and AutoXP points (which determine your public XP rank badge displayed to other users), a public profile country used to display your country and filter country leaderboards, and public aggregate collection statistics (total likes, total spots, and spot counts by rarity). We initially suggest the country from your phone or browser regional setting, not GPS or IP location; you may change it in Edit Profile. Common-car records remain on your device; only their aggregate count is included in these public statistics. Authentication is handled by Firebase Authentication (email/password, Google sign-in, or Sign in with Apple). We also store a unique account identifier (Firebase UID) and whether you accepted our Terms of Service and Privacy Policy (including the current version). Your email address is used for authentication, account support, and authorized administrator account search.

User Content: We collect the following user-generated content:

  • Photos & Videos: Vehicle photo upload depends on originality and rarity. Common cars are saved only on your device. Photos flagged as non-original stay local unless your account is verified by the server; verified users are trusted to provide originals, so eligible photos may still be uploaded despite a detection warning. For public profiles, original uncommon cars upload to Firebase only (visible on the public profile but hidden from global discovery), while original rare+ cars upload to Firebase and Cloudinary for the public profile, Feed, Country Spots and Car Explorer. For private profiles, eligible original Uncommon and Rare+ cars store only a processed low-quality Firebase thumbnail visible to accepted connections; they do not enter public surfaces or Cloudinary. Secondary photos and videos stay local. Separately, choosing cloud AI identification sends the selected photo to the AI provider, including for local-only spots.
  • Car Details: Make/model, captions/notes, timestamps, and country name/code (derived from location).
  • Privacy Settings: Whether your profile is Public or Private. This setting controls whether eligible spots may be uploaded and shared.
  • Social Interactions: Likes, friend connections/requests, and in-app notifications.
  • Feature Requests: Requests you submit, their title, description, category, your display name and account identifier, plus upvotes, downvotes and reports. Requests and vote totals are visible to signed-in users; individual vote identifiers are used to prevent duplicate or conflicting votes.
  • Moderation: Reports you submit, account restrictions, moderation reasons, expiration dates and audit information needed to protect the community and process appeals.
  • AI Usage: Service usage counts to enforce rate limits.
  • Photo Metadata: We analyze EXIF data (location, camera info, timestamps, editing software) locally on your device for originality detection. The server-verified exception described above can allow a photo despite a detection warning. Exact coordinates are not included in new Firebase car uploads; country name/code is retained. Geocoding providers may receive coordinates to determine that country.
  • Photo Processing: Car photos are processed on-device (watermarking, privacy blurring, manual blurring) before upload decision. We upload only processed versions. For public profiles, low-quality versions are stored in Firebase (uncommon+) and high-quality versions are stored on Cloudinary only for rare+ cars. For private profiles, eligible Uncommon and Rare+ processed low-quality thumbnails are stored in Firebase for accepted connections only; no private-profile photo is sent to Cloudinary. Secondary photos and videos remain local; separately requested cloud AI processing may send the selected photo to Google.

Device & Usage Data: We collect technical data from your device, such as IP address, browser type, device model, and operating system version to ensure app compatibility and security. With your optional analytics consent, we also collect selected interaction data as described in the PostHog section below. Declining analytics does not prevent the account and security processing needed to provide the app. For security purposes, Firebase App Check generates device-integrity tokens through native device attestation on mobile and reCAPTCHA on the web to verify requests come from genuine devices. These verification tokens are used for security, separately from optional product analytics.

Push Notifications: To provide you with real-time updates (such as likes and friend requests), we collect your unique device identifier (FCM Token). You can opt out of these notifications at any time through the in-app settings. When you delete your account, your device token is permanently deleted from our servers.

App & Browser Permissions: Camera (to take photos), Location (for mapping features), Internet (for cloud sync), and Network State (to check connectivity). The application does not request broad external storage permissions; any necessary local caching or saving of photos and data is handled safely within the application's own sandboxed storage (such as SharedPreferences or IndexedDB). You can change or revoke permissions through your device or browser settings.

3. Third-Party Services and Partners

AutoSpotterX uses third-party services (each has its own privacy policy):

  • Firebase (Google): User accounts, database storage, and backend services. Firebase SDK components may also process limited installation and technical diagnostic data for service delivery, reliability, and service-quality analytics; this SDK data is not used by us for advertising or tracking. (Firebase Privacy Policy)
  • Firebase Cloud Messaging (Google): Used to deliver push notifications to your device. We share your device token with this service to facilitate delivery. (Firebase Privacy Policy)
  • Firebase App Check (Google): To protect our backend resources from abuse, we use App Check with native device attestation on mobile and reCAPTCHA v3 on the web. It processes device-integrity or verification tokens needed to verify that requests originate from our authentic app. (Firebase Privacy Policy)
  • Google ML Kit (Android) & ONNX Runtime Web (Web): On-device detection used for privacy blurring (best-effort). Processing happens 100% locally on your device or in your browser. The application also provides an on-device/in-browser manual blur tool.
  • Google Gemini API: Optional cloud-based car identification on iOS and other platforms. Only after you explicitly choose “Allow & identify”, a resized copy of the selected photo (including applied blur edits, with EXIF and coordinates stripped) and a car-identification instruction are sent to Google Gemini through Firebase AI. Service usage counts are stored to enforce rate limits (one attempt per account across platforms). Firebase authentication and app-verification information may also be processed to secure the service. (Gemini API Terms · Google Privacy Policy)
  • Google Play In-App Review (Android Only): Used to request app ratings within the app. (Google Privacy Policy)
  • Google Play In-App Updates (Android Only): Used to check for and notify users of app updates. (Google Privacy Policy)
  • Android Geocoder (Android) & Nominatim (OpenStreetMap): Used to look up a location search and derive country name/code from the approximate coordinates you select. These requests do not include your Firebase account identifier, but the provider receives the search or coordinates and ordinary connection information and may retain them under its own practices. Only the resulting country info is stored in our database. (OpenStreetMap Copyright)
  • Cloudinary: High-quality photos of eligible rare+ cars from public profiles are stored on Cloudinary for the Feed, Country Spots and Car Explorer. The Cloudinary object identifier includes the Firebase UID and car record ID needed to organize and delete the photo. Private-profile spots, common cars, and other local-only spots are never uploaded to Cloudinary. (Cloudinary Privacy Policy)
  • Appwrite: Provides server functions for Cloudinary deletion, social-notification delivery, and authorization of the shared AI usage limit. Requests include the Firebase ID token and only the action-specific record IDs needed for that operation. Hosted in Frankfurt, Germany. (Privacy Policy)
  • PostHog: With your optional consent, we use PostHog to measure website visits, landing-section views, selected globe countries, FAQ opens and app-store link clicks, as well as active users, retention, signup and onboarding funnels, feature use and regional trends. Website visitors can allow analytics before signing in using a browser identifier. When you sign in and separately allow account analytics, we use the same account ID across web, iOS and Android to link usage. An app-store click measures a visit to the store, not an install. It receives your account ID when identified, device/browser identifier, app and device details, and selected actions (app opens, onboarding, registration, feed views, likes and saved-car make/model/local-only status). It also receives generic screen/page navigation and, on web/iOS, limited button/link clicks without their text or destinations. Your IP address may be used to estimate country, region, city and approximate location; this is not GPS location. We exclude emails, usernames, photos, notes, content IDs, raw URLs, typed input and GPS/photo coordinates. Screen recording and session replay are disabled. Analytics is not used for advertising or selling personal information. You can decline and still use the app, or turn analytics off in Settings or the website analytics controls. Website consent choices are dated, versioned and saved for up to six months in this browser; PostHog starts after optional consent. Account choices remain separate. The website footer provides Analytics preferences to change or withdraw the choice. See Sections 6, 7 and 10 for access, deletion and retention. (PostHog Privacy Policy)
  • App store reports: We also use aggregate reports supplied by Apple and Google about app downloads, discovery, usage and reliability, where available, and may import them into PostHog for internal analysis. These reports follow the stores’ reporting rules and privacy controls. We do not link store-report totals to individual AutoSpotterX accounts or use them to override your optional in-app analytics choice.
  • OpenFreeMap: Provides map tiles for the web and fallback map. Requests do not include your Firebase account ID, but can reveal the map area displayed and include ordinary connection information. (OpenFreeMap)
  • FlagCDN: Provides country-flag images. Requests contain the displayed country code and ordinary connection information, not your Firebase account ID. (FlagCDN)
  • Apple MapKit: Provides the native map and location picker on iOS. MapLibre GL is retained only as a non-iOS fallback.

4. How We Use Your Information

We use your information to:

  • Account & Features: Create and authenticate your account (via email/password, Google sign-in, or Sign in with Apple), manage your car collection, calculate stats and XP, and provide AI-powered car identification (with usage tracking to enforce rate limits).
  • Social Features: Enable friends, public feed sharing, Country Spots, Car Explorer, likes, notifications, and user blocking. A block record stores the two account identifiers needed to hide profiles and content and prevent new connections.
  • Privacy & Control: Respect your Public or Private profile setting and your location-attachment preference.
  • Maps & Location: Display your private map with spot locations (stored only on your device; only you have access to exact locations). Country names are stored on our servers to display the country in the public feed, Country Spots, and Car Explorer.
  • Photo Processing & Upload: Process photos on your device (EXIF analysis, watermarking, privacy blurring). Common, manual local-only and untrusted non-original spots stay local. Private-profile eligible Uncommon and Rare+ spots store a processed Firebase thumbnail for accepted connections only, with no Cloudinary or global display. For public profiles, eligible uncommon cars upload to Firebase only and appear on the public profile (not global discovery); eligible rare+ cars upload to Firebase and Cloudinary for the public profile and global display. Secondary photos and videos remain on your device only.
  • Support & Safety: Provide app updates, troubleshoot issues, moderate reported content and account-behavior concerns, process user blocks, and enforce our Terms of Service. Firebase App Check helps protect supported Firebase services from abuse. Our Appwrite account-cleanup service verifies signed account credentials before processing a deletion request.
  • Compliance & Legal: Track your acceptance of our Terms of Service and Privacy Policy (including version numbers) to ensure legal compliance.

5. Data Sharing

We share specific data in limited scenarios as described below:

5.1 Service Providers

We engage third-party service providers to facilitate our services:

  • Firebase (Google): For user authentication, database storage, and backend services. As our primary backend, Firebase stores the cloud-backed account and car data described in Section 2, not device-only spots, secondary photos/videos or exact coordinates in new car uploads. Email is held in Firebase Authentication and can be used for authentication, support and authorized administrator account search.
  • Cloudinary: For high-quality photo storage and delivery in the Feed and Country Spots. We upload only eligible rare+ cars from public profiles. Private-profile spots, common cars, uncommon cars, and other local-only spots are never uploaded to Cloudinary.
  • Appwrite: Securely processes Cloudinary deletions, social-notification delivery, and AI-limit authorization. We verify the Firebase account token before carrying out those operations.
  • PostHog: Receives the consent-gated website visits, account-linked usage and technical data described in Section 3, and may infer approximate geography from the connection IP. It does not receive photos, notes, raw URLs, typed input, or GPS/photo coordinates. Screen recording and session replay are disabled.
  • Google Services (ML Kit, Gemini API) and Android Geocoder: For on-device processing, optional AI identification, and country derivation via device geocoding. Data shared is limited to what is necessary for each service (see Section 3 for details).
  • OpenFreeMap: For map tile services. Map-tile requests do not include your Firebase account ID, but can reveal the map area displayed and include ordinary connection information.
  • FlagCDN: For country-flag images. Requests include the displayed country code and ordinary connection information, not your Firebase account ID.

5.2 Public & Social Features

Information shared with other users through the app's social features:

  • Public Feed: Eligible rare+ cars from public profiles appear in the Feed. Private-profile spots, common cars, uncommon cars, and other local-only spots are excluded. The feed displays: car photos, profile photos, usernames, car names, likes, rank badges, country, and optional captions. Content shared publicly may be used for promotional purposes. Exact location is never shared, only country (see Section 5.4).
  • Country Spots: Users can browse eligible rare+ cars from public profiles by country. Displays only car photos and car names: no username or profile info. Only country name is shown, never the exact location.
  • Car Explorer: A searchable database where users can find specific car models and community-spotted photos. Only eligible rare+ cars from public profiles appear here. This section displays only the car photo and spotting date: no usernames, profile photos, or exact locations.
  • Leaderboard: Public leaderboard shows top 50 users by AutoXP (username, AutoXP points, profile photo).
  • User Profiles: Any signed-in user can view your public profile (e.g., via the feed or leaderboard), including eligible server-backed Rare+ and Uncommon cars even when a car is hidden from the Feed, plus your username, profile photo, AutoXP points, and optional social links. Common, moderation-hidden, protected legacy and other device-only spots are not publicly available. A verified account may upload an eligible photo despite an originality warning; the original-photo requirement still applies. Basic profile details remain visible to signed-in users even when the car collection is Private.
  • Friends: Accepted connections can view eligible server-backed Uncommon and Rare+ thumbnails from Private profiles, including newly shared Private spots and eligible older server-backed cars. Device-only spots, high-resolution Cloudinary images for new Private spots and exact locations are not available to connections; only country-level information may be shown.
  • Feature Requests: Signed-in users can read feature requests and vote totals. A request shows its author display name. Reports are visible only to the reporter, an affected content owner where applicable, and administrators.
  • Friend Requests: When you send a friend request (via feed or leaderboard), the recipient can see your display name and profile photo and social media links in the Friends screen and your profile and may receive a push and/or in-app notification (e.g., "[Your username] sent you a friend request"). Account identifiers are used to link profiles, cars and connections and may be present in shared records.
  • Like Notifications: When you like someone's car, they may receive a push and/or in-app notification showing your username and the car details (e.g., "[Your username] liked your Ferrari F40").

5.3 Legal & Administrative

  • Administrators: Administrators may access user data (photos, profile info, reports and content) for moderation and support. They can hide content from public surfaces, delete content, or restrict accounts that violate our Terms of Service. A moderation hide overrides profile visibility. Deleted content is permanently removed from our servers where applicable, and users may be notified in-app.
  • Law and Safety: We may disclose your information if required by law or to protect our rights, safety, or property.

5.4 Map and Location Privacy

Exact-location handling:

  • Device-Only Storage: GPS coordinates are stored only on your device (in SharedPreferences on Android, or IndexedDB on the Web). They are designed to reside only on your device and are not uploaded to our servers. Deleted when you clear your browser data, uninstall the app, or delete your account.
  • Location Attachment Control: You can control whether location data is attached to your spots through Settings → Privacy → "Attach Location by Default". When disabled, the app will not extract or store location data from your photos. This setting is enabled by default but can be turned off at any time.
  • Country Data Only: To enable Country Spots and Car Explorer browsing and show which country a car was spotted in inside the feed, we extract country name/code from coordinates using Android Geocoder (on mobile) or Nominatim/OpenStreetMap (on the web). Geocoding may send coordinates to the provider to determine the country. Only the extracted country name/code is included in new Firebase car uploads; exact coordinates are not.
  • Completely Private: Only you can see exact locations on your personal map. Friends can see your car photos/details but not locations or map markers.

6. Your Rights and Controls

You have control over your personal data, profile visibility, and account. You can view and update your profile information, change your profile privacy, delete photos or entries, request data export, manage connections, control app permissions, and manage optional features such as location attachment and cloud AI identification. Common and other local-only spots remain on your device.

Public vs. Private Profiles: Profiles are public by default for all existing and new accounts, allowing other signed-in users to see your public profile and eligible online Uncommon and Rare+ cars. Rare+ cars can also appear in global discovery. Common and other device-only spots are not shared. You can choose to make your profile Private at any time by going to Settings → Private profile. Private keeps your collection off public profiles and global discovery. Eligible original Uncommon and Rare+ spots store a processed low-quality thumbnail in Firebase that only accepted friends can view; they never upload to Cloudinary. Common, manual local-only and untrusted non-original spots stay on your device. Basic profile details remain visible to signed-in users.

The profile setting controls eligible server-backed cars. While Private, they are limited to the owner and accepted friends. After a successful switch to Public, eligible server-backed cars appear on the public profile, but cars already hidden from the Feed stay hidden there. New eligible Rare+ uploads may enter global discovery. Protected legacy records and device-only photos are not published by changing this setting. Changing to Private requires a successful online update for existing server-backed cars; during that update, new public uploads are blocked across devices. If interrupted, retry the same privacy choice to finish. The retired account-wide hide-from-feed preference does not make the profile Private; older photos covered by that preference remain visible only to their owner and accepted friends.

Data Export: You can export your core account data directly through the app settings in a ZIP file. This automated export includes your profile, car collection, media (photos and videos), friends, notifications, and AI usage counts. If you require an export of your usage analytics data from PostHog, you can request it via email.

7. Account and Data Deletion

You can delete your entire account through app settings (processed promptly, typically within minutes) or by emailing us at zernoxi6@gmail.com with "Account Deletion" in the subject line (processed within 7 working days). Account deletion removes your Firebase account and cloud photos on Cloudinary, and resets the local PostHog analytics association on your device. Our account-cleanup service also requests deletion of your linked PostHog profile and events. PostHog processes this asynchronously. You can request analytics deletion separately, or contact us about incomplete deletion, at the same address.

Deleting individual photos or entries removes that content from our servers immediately.

Administrative Deletion: Content may also be deleted by administrators if it violates our Terms of Service. When administrators delete your content for policy violations, it is permanently removed from our servers (Firestore and Cloudinary). You will be notified via in-app notification if your content is deleted for policy violations.

8. Additional (Optional) Features

AutoSpotterX offers several optional features with extra privacy considerations:

Local Video Storage: If you record car videos within the app, they are stored only on your device in encrypted form. These videos are designed to remain on your device and are not uploaded or shared externally. Deleting the associated car entry or your account will erase these videos.

Cloud AI Identification: As mentioned in Section 3, optional Google Gemini AI can assist with car identification on iOS and other platforms. This is an opt-in feature: only after you explicitly choose “Allow & identify”, a resized copy of the photo (including applied blur edits, with EXIF metadata and exact coordinates removed) is sent to Google Gemini through Firebase AI. Firebase authentication and app-verification information may also be processed to secure the service. This optional processing also applies to Private or device-only spots if you choose to use AI; it does not publish the photo to your profile or the feed. You can decline and enter car details manually. Please review images before sending to avoid transmitting sensitive personal data; automatic blurring is best-effort and may miss faces or plates. The one-attempt allowance is shared across your account and platforms. We store an account-linked usage count; an authorized attempt can be consumed even when identification fails. Google processes requests under its Gemini API terms and Privacy Policy.

Social Sharing: Connections, public profiles, the Feed, Country Spots, and Car Explorer sharing are described in Section 5. The Public or Private profile control in Settings is the account-level sharing control: Private profiles share eligible processed Uncommon and Rare+ Firebase thumbnails only with accepted connections and remove currently feed-visible cars from the Feed after a successful online update. Common, manual local-only and untrusted non-original spots remain device-only. After a successful switch to Public, eligible server-backed cars become visible on the public profile; cars already hidden from the Feed remain hidden there, while new eligible Rare+ uploads may enter global discovery.

Legacy Compatibility: Protected legacy cars without public-profile eligibility remain visible only to their owner and accepted friends; policy acceptance and startup do not republish them. Eligible Firebase thumbnails created under the current Private-profile model become readable on the public profile when the owner switches to Public, without changing their per-car Feed state. This does not upload device-only photos, place already-hidden cars into global discovery, or override an administrator moderation hide. Older clients can continue supported browsing and upload flows but must update to change profile privacy safely; previously public image links and copies may remain accessible. New uploads cannot include latitude, longitude or an exact location string; only derived country name/code may be stored in Firebase.

Feature Requests: You may create, vote on, downvote and report feature requests. Votes are limited to one direction per account. We retain this data while the request exists or as reasonably needed for moderation, safety and abuse prevention.

9. Children's Privacy

You must be at least 13 years old to use AutoSpotterX (age may vary by local law). We do not knowingly allow users under the minimum age to create an account.

Age eligibility is confirmed during signup; we do not collect or store your date of birth.

If you are a parent or guardian and believe a child under 13 has created an account, contact us at zernoxi6@gmail.com to have it deleted.

10. Other Important Notes

Data Retention: We retain personal data only as long as necessary to provide the app services or as required by law. We delete application account content promptly after an account-deletion request, but service-provider backup and deletion schedules can take longer. For example, Firebase Authentication states that associated information can be removed from live and backup systems within up to 180 days after deletion. Account cleanup requests deletion of linked PostHog analytics, but provider processing is asynchronous and a failed request may require follow-up through the contact method in Section 7.

AI Accuracy: Our AI features (car identification) are designed to assist you, but they are not 100% accurate. Results should be treated as probabilistic; always verify important information manually.

Local vs. Cloud Processing: Blurring (including manual blur) and watermarking happen on your device. Photos you upload or share are processed locally first (blurred/watermarked as applicable), and we receive/store the processed result. Automatic blurring is best-effort; if it misses something, you are responsible for reviewing your photos and using the in-app manual blur tool before uploading. Third-party servers are used for authentication, data storage, and optional AI identification if you opt in.

Originality Detection: During photo upload, we analyze photo metadata (EXIF data including camera information, GPS data, and timestamps) locally on your device to detect screenshots or downloaded images. Photos flagged as non-original stay local for unverified users. If the server confirms the account is verified, eligible photos may be uploaded despite a detection warning, subject to profile privacy and rarity. Verified users must still upload only their own original photos. Optional cloud AI identification is separate from collection storage and sends the selected photo to Google only when requested.

Profile- and Rarity-Based Upload: Common, manual local-only and untrusted non-original spots stay on-device. Private-profile eligible Uncommon and Rare+ spots store a processed low-quality thumbnail in Firebase for accepted connections only, with no Cloudinary or global discovery. Optional cloud AI identification can separately send a selected photo to Google. For public profiles, eligible uncommon cars upload to Firebase only (hidden from global surfaces but visible to every signed-in profile viewer), while eligible rare+ cars upload to Firebase and Cloudinary for the public profile, Feed, Country Spots and Car Explorer.

11. Data Protection and International Transfers

Data Protection: We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction. This includes encrypted transmission (HTTPS/TLS), encrypted storage by our service providers (such as Firebase/Google Cloud), secure authentication, and access controls.

Security Limitation: While we implement reasonable and industry-standard security measures to protect your information, no method of transmission over the Internet or method of electronic storage is completely secure. Therefore, we cannot guarantee absolute security of your data.

International Transfers: Your data may be processed in countries other than your own (for example, on servers operated by Google or other service providers worldwide). In such cases, we ensure appropriate safeguards (such as compliance with EU Standard Contractual Clauses or similar measures) are in place to protect your data.

Legal Basis: If you are an EU resident (GDPR), we rely on the following legal grounds for processing:

  • Consent: When you give explicit permission (e.g., enabling location services).
  • Contract Performance: To perform the services you request (e.g., providing access to your account and collection).
  • Legitimate Interests: For app functionality, security, and improvement, balancing our interests against your privacy rights.
  • Legal Compliance: To comply with laws and regulatory obligations.

12. GDPR and CCPA Rights

Your privacy rights depend on the laws applicable to you and to our services, including GDPR and California privacy law where applicable.

EU (GDPR) Rights: If you reside in the European Economic Area, you have rights under GDPR, including the right to access, correct, or delete your personal data; the right to restrict or object to certain processing; the right to data portability; and the right to withdraw consent at any time. You may also lodge a complaint with a data protection authority. To exercise these rights, please contact us (see below).

California (CCPA) Rights: California residents have the right to know what personal data is collected and how it is used, the right to request deletion of personal data, and the right to opt out of the sale of personal data or sharing for cross-context behavioral advertising. AutoSpotterX does not sell personal information or share it for cross-context behavioral advertising. If you wish to request deletion or disclosure of your data, please contact us.

13. Developer and Contact Information

Developer: Zarnox2525 (app developer)

Contact Email: zernoxi6@gmail.com

Privacy Inquiries: For any privacy-related questions or requests (including data access or deletion), please email us at zernoxi6@gmail.com with "Privacy Request" in the subject line.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time (for example, when adding new features or services). When we make changes, we will update the "Last Updated" date at the bottom of this page and, where appropriate, provide a notice in the app. For the September 1, 2026 profile-sharing update, updated clients display the Public default, explain friends-only Firebase thumbnail sharing for Private profiles, and request explicit policy acceptance. Acceptance does not publish older hidden cars. Opening the notice or reviewing Settings does not record acceptance. The September 13, 2026 analytics update explains optional usage metrics, screen navigation, limited automatic interactions and IP-derived geography. Updated clients request review of this policy; the optional analytics choice remains separate and screen recordings stay disabled. Users on older app versions must update to receive this in-app notice.

Last Updated: October 4, 2026