Legal Document

Privacy Policy

Effective: September 10, 2026 Car Catalog App Android & iOS

This Privacy Policy applies to the Car Catalog app (the "Application") for Android and iOS, and to the website at carcatalog.app, both operated by the Car Catalog team (the "Service Provider", "we", "us"). The Application is an ad-supported service provided "AS IS".

📝

This policy replaces the version dated March 16, 2026. It was rewritten because the Application gained features that genuinely process your data — photo uploads, reports, notifications and usage analytics. The previous version stated that no data was collected at all, which is no longer true.

📖

1. Scope and Who We Are

Car Catalog is a reference catalogue of car brands, models, generations and specifications, together with automotive news. Most of the Application is read-only: browsing the catalogue requires no account, no sign-up and no personal details.

🔑

There are no user accounts. We never ask for your name, email address, phone number or password in order to use the Application. The only exception is a copyright or content complaint about a photo, where the law requires us to know who is making the claim — see section 3.

Some features do process data, and this policy describes each of them plainly: which data, why, for how long, and what you can do about it.

🔍

2. What We Collect — At a Glance

The table below is a summary. Each row is explained in full in the section it points to.

WhatWhenWhyKept for
Device identifier
Randomly generated by us
First launch To keep your favourites and history on your device without an account Until you uninstall or ask us to delete it
Photos you upload
Plus a note of which terms you accepted
Only if you upload one To review and publish them in the catalogue Published: indefinitely. Rejected or withdrawn: files deleted after 30 days
Reports and feedback
Name and email only for photo complaints
Only if you send one To investigate and answer Indefinitely, as a moderation record
Usage analytics
Screens opened, requests, errors
Continuously To find bugs and see which parts of the catalogue are used 90 days
IP address
And approximate country/city derived from it
Every request Abuse prevention, rate limiting, coarse regional statistics 90 days
Push token Only if you enable notifications To deliver the notifications you asked for Until you disable them or uninstall
Favourites and history As you browse To show you what you saved and recently viewed Until you clear them, uninstall, or ask us to delete
Purchase records
Store transaction identifiers, plan, status and dates — never your card details
Only if you buy Premium To switch the ads off on your device and keep Premium working after a reinstall While Premium is held by your device or account; anonymised afterwards and deleted after 3 years
ℹ️

We do not sell your data, do not build advertising profiles of you ourselves, and do not send marketing email. Advertising is served by Google AdMob under its own policy — see section 8.

✍️

3. Information You Provide

Three features let you send us something. All three are optional, and none of them is needed to browse the catalogue.

Photos

If you upload a photo of a car, we receive the image file and store it. What happens to it is described in full in section 4. Uploading requires your permission to access the camera or photo library; your device will ask, and you can refuse.

Reports about content

You can report a photo, or report an error in a catalogue entry. A report records the reason you chose, any comment you wrote, which item it was about, and the device that sent it.

📧

Reports about photos require your name and email address. This is the only place in the Application where we ask for contact details, and the reason is narrow: a complaint about a photo may be a copyright claim, and a copyright claim has to be answerable to a real person. Reports about catalogue data, and general feedback, can be sent anonymously.

Feedback

A general message with no particular subject. You may leave an email address if you want a reply; if you do not, we simply read it.

📷

4. How We Handle Your Photos

📍

Location metadata is removed before anything is stored. Phone photos normally carry EXIF metadata including GPS coordinates, the camera serial number and the exact time of capture. We decode and re-encode every uploaded image, which discards that metadata entirely — it never reaches our storage, and it is never published. A photo of your own car cannot reveal where you keep it.

The rest of the process:

  • Nothing is published automatically. Every upload arrives with the status "pending review" and is invisible to other users until a moderator approves it.
  • You confirm the photo is yours to give. The Application shows you the upload terms and records which version you accepted, so it is always clear what you agreed to.
  • Accepted formats are JPEG, PNG and WebP, up to 10 MB. We store a fingerprint (a SHA-256 hash) of the processed image so the same photo is not reviewed twice.
  • You get a management key. When you upload, the Application receives a one-time key that lets you withdraw that photo later — even after reinstalling the app. We store only a hash of it and cannot recover it for you.
  • Approved photos are published in the catalogue alongside the car they show, and may be served through a content delivery network.

If a photo is rejected or you withdraw it

The image files are deleted from storage after a 30-day grace period. The database record is deliberately kept, without the image, because it holds three things that must survive:

  • the fingerprint, so a rejected photo cannot simply be uploaded again
  • the reason for rejection, which is what you were told
  • the moderation history, which is the case file if the photo was ever the subject of a complaint

This record contains no personal data beyond the device identifier that uploaded it. It can be removed on request — see section 13.

📡

5. Information Collected Automatically

Device identifier

On first launch, our server generates a random identifier for your installation and issues your device a secret token to prove it. This identifier is created by us — it is not your phone's serial number, IMEI, advertising ID or any hardware identifier, and it is not shared with third parties.

Alongside it we store the technical details your device reports: platform (iOS or Android), app version, operating system version, device model, language, time zone and declared country. These let us keep an old app version working and tell whether a bug affects one platform or both.

🔄

Uninstalling and reinstalling the Application produces a new identifier. The old one is no longer connected to you, and anything stored under it — favourites, history — is no longer reachable from your device.

Usage analytics

We record which parts of the API the Application calls, how long they took and whether they failed. Each record may include the route that was called (for example "brand detail", never a name you typed), the response status, the duration, your app version, language, platform and device identifier.

Successful requests are sampled — only a fraction is stored — while errors and unusually slow requests are always kept, because those are the ones worth fixing.

We also count how many times each catalogue entry has been viewed. These counters are aggregated: they record that a brand was viewed, not who viewed it.

IP address and log data

Every request to our servers carries your IP address, as every internet request does. We store it with the request record and derive an approximate country and city from it. We use this for abuse prevention, rate limiting and coarse regional statistics. It is retained for 90 days and then dropped along with the rest of the log.

Separately, if the Application crashes, anonymised diagnostics may be collected by Firebase Crashlytics — device type and OS version, app configuration, time of use, and the technical stack trace. This is used only to diagnose and fix faults.

🔔

6. Push Notifications

If you allow notifications, your device gives us a push token issued by Apple (APNs) or Google (FCM). We store it against your device identifier and use it only to deliver notifications you would expect:

  • the outcome of a photo you uploaded — approved, or rejected with the reason
  • the outcome of a report you sent
  • the daily featured car, if that is enabled in the Application

We do not use push notifications for advertising. You can turn them off at any time in the Application or in your device settings; turning them off stops delivery immediately, including for anything already queued. Push tokens are not shared with anyone other than Apple's and Google's delivery services, which is what actually carries the message to your device.

7. Favourites, History and Saved Searches

When you mark something as a favourite, open a car's detail page, or save a set of search filters, we store that against your device identifier so the Application can show it back to you.

  • Favourites — the items you saved, and when.
  • Recently viewed — which catalogue entries you opened and when. This list is capped and older entries fall off.
  • Saved searches — the filter values you saved, stored in a normalised form rather than as raw input.

None of this is linked to a name or an email, because there is no account to link it to. You can clear each of these from within the Application, and clearing them deletes the records on our side.

💳

8. Purchases and Premium

Premium removes advertising from the Application. It is sold as an auto-renewing weekly or monthly subscription, or as a one-time lifetime purchase, through Google Play on Android and the App Store on iOS. Prices are shown in the store in your local currency before you confirm.

Payment is handled entirely by Apple or Google. We never receive or store your card number, billing address or any other payment details. What we receive from the store, and keep on our server, is:

  • the store's transaction and order identifiers and a service token that lets us ask the store about that purchase;
  • which product and plan you bought, its current status (active, cancelled, in a grace period, expired, refunded), and the relevant dates;
  • which store it came from and whether it was a test (sandbox) purchase;
  • the notifications the store sends us about the purchase — renewals, cancellations, billing problems, refunds — so Premium switches on and off at the right moment.

A purchase is linked to the device identifier that made it (and, once accounts exist in the Application, to your account). That link is what lets Premium survive a reinstall through «Restore purchases», and it is why a purchase can be held by only one owner at a time.

Subscriptions renew automatically until cancelled. Cancelling, changing or refunding a purchase happens in your Google Play or App Store subscription settings — uninstalling the Application or deleting your data on our side does not cancel a subscription. Refunds are decided by the store under its rules; when a store refunds or revokes a purchase, Premium ends on our side too.

If our support team grants Premium manually — for example to compensate a problem — that is recorded with the reason, and it can be withdrawn the same way.

🔗

9. Third-Party SDKs and Services

The Application uses the following third-party services, which collect data under their own privacy policies:

These services may collect:

  • Device type and operating system
  • Crash logs and diagnostics
  • Usage patterns and session durations
  • In-app events and performance metrics
  • Advertising identifiers (Android Advertising ID, Apple IDFA) for ad delivery and measurement

Photos you upload are stored on DigitalOcean Spaces, an object storage service, and may be delivered through its content delivery network. Our servers are hosted on DigitalOcean infrastructure.

ℹ️

We do not send marketing or transactional email of any kind. The only email you may receive from us is a reply to a report or a message you sent us first.

📍

10. Location Data

The Application does not request location permission and does not access your device's GPS, precise location or background location — neither for features nor for advertising.

Two qualifications, stated plainly because they are the kind of thing a privacy policy should not bury:

  • Approximate location from IP. Your IP address implies a rough country and city, and we store that with request logs for 90 days. This is country- and city-level at best — it is not your address and not a coordinate.
  • Location in photos is removed, not read. An uploaded photo may contain GPS coordinates in its metadata. We strip that metadata before storing anything and never record its contents. See section 4.
🍪

11. Cookies and Advertising

The Application itself does not use cookies. Third-party services such as AdMob may use cookies or similar technologies to serve personalised ads and measure their performance.

💡

You can limit personalised advertising in your device settings.
Android: Settings → Google → Ads → Opt out of Ads Personalisation.
iOS: Settings → Privacy & Security → Tracking (disable), and Settings → Privacy & Security → Apple Advertising → turn off Personalised Ads.

The website at carcatalog.app is a static page and sets no cookies of its own.

🗄️

12. Data Retention

DataRetentionThen
Request logs and analytics events90 daysDeleted automatically
Daily view counters400 daysDeleted automatically; only aggregate totals remain
Device recordWhile the installation existsDeleted on request
Favourites, history, saved searchesUntil you clear themDeleted immediately when cleared
Published photosIndefinitely, as part of the catalogueRemoved if you withdraw them
Rejected or withdrawn photo files30 daysFiles deleted; the record is retained without the image
Reports and moderation recordsIndefinitelyRetained as an audit trail; deleted on request where no legal claim depends on them
Purchase recordsWhile Premium is held by a device or account; anonymised when the owner is deletedDeleted 3 years after the purchase last granted anything — the window in which refunds and payment disputes can still arise
Store notifications about purchases180 daysDeleted automatically

Anything collected by third-party services is subject to their own retention policies, which we do not control.

⚖️

13. Your Rights and Choices

Some of these you can exercise yourself, in the Application, without asking us:

  • Clear your favourites, history and saved searches — in the Application.
  • Withdraw a photo you uploaded — in the Application, using the management key it holds for you.
  • Turn off notifications — in the Application or in your device settings.
  • Limit ad personalisation — in your device settings, as described in section 10.
  • Stop all collection — uninstall the Application.

For anything else, write to [email protected]. You have the right to ask us to:

  • Access the data held against your device identifier.
  • Correct anything inaccurate.
  • Delete your data — see the Data Deletion page for exactly how, what is removed and what is not.
  • Restrict or object to processing.
  • Receive a copy of your data in a portable format.
🔑

To act on such a request we need your device identifier, which the Application can show you in its settings. Without it we have no way to find your data — which is a consequence of not asking for your identity in the first place.

We answer requests within 30 days.

🛡️

14. Moderation and Enforcement

Because users can upload photos, we moderate. Every upload is reviewed before it appears, and anyone can report content they think should not be there. Our content rules are set out in the Terms of Service.

If content is repeatedly rejected or a device is used abusively, we may:

  • Suspend uploading for that device, temporarily or indefinitely, while leaving the rest of the Application working — including the ability to report content.
  • Block the device entirely in serious cases.

We record who took the decision, why, and when it was lifted, so that a decision can be reviewed if you appeal it. Appeals go to [email protected].

👶

15. Children's Privacy

The Application is not directed at children under 13, and we do not knowingly collect personal data from them. Uploading photos and sending reports are intended for users aged 13 and over.

⚠️

If you believe a child has provided us with personal information, contact us and we will remove it promptly.

🔒

16. Security

  • All traffic between the Application and our servers is encrypted in transit (HTTPS).
  • Device secrets and photo management keys are stored only as cryptographic hashes. We cannot read them back, which means they cannot be leaked in a readable form.
  • Photo metadata is stripped on receipt, so location data is never written to storage in the first place.
  • Administrative access is authenticated separately and rate-limited.

No system is perfectly secure, and we do not claim otherwise. If you find a vulnerability, please report it to [email protected] rather than disclosing it publicly, and we will work with you on it.

🌍

17. International Users

The Application is available worldwide and our servers are located in the European Union. If you use it from elsewhere, your data will be transferred to and processed there.

🇪🇺

European Economic Area, United Kingdom and Switzerland (GDPR). You have the rights listed in section 12. Our legal bases are: legitimate interests for security, abuse prevention and improving the Application; consent for notifications and photo uploads, which you may withdraw at any time; and legal obligation where we must retain moderation records. You may lodge a complaint with your local supervisory authority.

🇺🇸

California (CCPA/CPRA). You have the right to know what is collected, to request deletion, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined by California law, and we do not knowingly collect the personal information of anyone under 16 for such purposes.

🇺🇦

Ukraine. Processing is carried out in accordance with the Law of Ukraine "On Personal Data Protection". You may exercise the rights it grants by contacting us at the address in section 18.

🔄

18. Changes to This Policy

We may update this Privacy Policy. The effective date at the top of this page always shows the current version, and material changes will be announced in the Application before they take effect. Continued use after a change takes effect constitutes acceptance of the revised policy.

Previous version: March 16, 2026.

✉️

19. Contact Us

Questions about this policy, requests about your data, or reports of a problem:

🚗

Car Catalog

[email protected]

Please include your device identifier if your request is about your own data — the Application shows it in its settings.