← Garaj

Privacy Policy

Effective August 22, 2026

Garaj ("we", "us", "our") is a social platform for car enthusiasts. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to the Garaj mobile app and related services.

Effective date: August 22, 2026.

1. Information You Provide

Account: username, email address, and a password (stored hashed) if you sign up with email. If you sign in with Apple or Google instead, we receive basic profile information from that provider and you do not create a password with us. Profile details you choose to add: display name, bio, location, avatar, and cover photo.

Vehicles & content: vehicles you add to your garage (year, make, model, trim, color, mileage, VIN if you choose to share it), posts, photos, maintenance logs, drives, inspections, spot reports, reviews, comments, likes, saves, and messages you send to other users.

Support: messages you send us via email, including any diagnostic information you choose to include.

2. Information Collected Automatically

Device & usage: app version, operating system, device model, crash reports, and feature-usage events tied to your account (for example: "a post was created" or "the feed was refreshed"). These events are used to diagnose bugs and understand which features are used.

Location: when you record a drive, we collect GPS coordinates for the duration of that drive to compute your route, distance, and speed — including in the background while the drive is active, so recording continues if you switch to another app. You control whether each drive's route and speed are shown publicly. When you choose to add a location to a spot or a post, we use your current coordinates or a place you search for. Your profile location is a free-text field: we store only what you type there. Location is collected only while you are actively using one of these features — we do not track your location in the background except during an active drive.

Push tokens: if you enable push notifications, we store a device push token so we can deliver alerts.

3. How We Use Your Information

To provide and operate the app: sign-in, rendering your garage, delivering posts and notifications, and enabling social features like following and messaging.

To improve the app: analyzing aggregate usage patterns, diagnosing crashes, and measuring which features are adopted.

To communicate: account-related emails, such as verification and password reset.

To keep the community safe: reviewing reports, enforcing community guidelines, and preventing abuse.

4. Third-Party Service Providers

Supabase (database, authentication, file storage): stores your account and content.

Apple and Google (sign-in): if you choose to sign in with Apple or Google, that provider authenticates you and shares basic profile information (such as your name and email) with us.

Sentry (error monitoring and crash reporting): receives error and crash reports — including a truncated component stack, device metadata, and your account's user identifier and username so we can trace an issue to a session. Errors captured during normal use, not only hard crashes, may be included. We strip cookies before events are sent and do not send your messages, post contents, or precise location.

PostHog (product analytics): receives feature-usage events and your account's user identifier and public username so we can understand how features are used. This is first-party analytics only — we do not use your device's advertising identifier (IDFA), we do not track you across other companies' apps or websites, and we do not share these events with advertising networks or data brokers. We do not send your email, precise location, VIN, or the contents of your posts to our analytics provider.

Anthropic (AI features): when you use an AI feature — such as identifying a vehicle from a photo, reading a VIN from a photo, estimating market value, scanning a receipt, document, or dyno sheet, mapping a spreadsheet you import, detecting modifications, or generating an inspection analysis, health briefing, or listing — the photos, documents, and text involved are sent to Anthropic's Claude API through our secure server proxy to generate the result. For some features this includes details already saved in your garage: for example, a health briefing sends your car's details, recent service titles and part names, and installed modifications. Separately, when you add a part to a maintenance log, the part's description text is sent to Anthropic automatically to standardize its name, brand, and category. Some AI features may also run a web search to help answer your request. Per Anthropic's API terms, this data is not used to train their models.

Expo (push notifications and app updates): we deliver push notifications through Expo's push service, so a device push token and the notification payload (which may include a message preview) pass through Expo. Expo also delivers over-the-air app updates and receives basic device information when your app checks for one. Apple and Google deliver the finished notification to your device.

Apple Maps (place search): when you search for a place, the search text is sent to Apple's Maps service so we can offer businesses, landmarks and addresses. Where you have granted location access, your approximate coordinates — rounded to about a kilometre, never your exact position — are sent with it so nearby places rank higher. This request is made by our server rather than by your device, so Apple receives the search text and that approximate area but not your device's IP address or any identifier for your account.

OpenStreetMap / Nominatim (geocoding): if a place search returns no results from Apple, the same search text is sent to the OpenStreetMap Nominatim service. Nominatim is also used whenever we convert coordinates into a place name — for example to label where a drive started — in which case the GPS coordinates are sent.

Photon by Komoot (place search fallback): if a place search returns no results from either Apple or Nominatim, the same search text is sent to Komoot's Photon service, which searches the same OpenStreetMap data. Where you have granted location access, your approximate coordinates are sent with it so nearby places rank higher. This only happens when the earlier searches found nothing.

OSRM (route planning): when you ask Garaj to plan a drive, your current location and your chosen destination are sent as GPS coordinates to an OSRM routing server so it can calculate the route. Garaj uses OSRM's public server by default.

NHTSA (recalls and vehicle data): to show open safety recalls and complaints for a vehicle and to populate the make and model lists, the year, make and model are sent to the United States National Highway Traffic Safety Administration's public API. If you enter or scan a VIN when adding a vehicle, that VIN is also sent to NHTSA's public VIN-decoder service (VPIC) to auto-fill the vehicle's make, model, year, trim, and engine.

Map imagery (CARTO, and Google Maps on Android): to draw maps of drives, spots, and locations, your device requests map tiles from these providers, which reveals your device's IP address and the map area being viewed.

RevenueCat (subscription management): receives a user identifier and your purchase / subscription status to manage your Garaj Pro entitlement. Payment is processed by Apple (or by Google Play on Android); we never receive your card details.

Each provider processes data under its own privacy policy. We do not sell your personal information.

5. Your Choices

Privacy controls: you can change the privacy level of each post, drive, spot, review, inspection, or maintenance log (public, followers-only, or private).

Analytics scope: Garaj uses only first-party, product-usage analytics tied to your account to improve the app; we do not track you across other apps or websites and do not use advertising identifiers. If you would like us to stop collecting product analytics for your account, email us and we will honor the request.

Push notifications: you can disable notifications in the app's settings or from the operating system settings.

Account deletion: at any time, you can permanently delete your account from Profile → Settings → Delete Account. This permanently removes your profile, your personal content (posts, drives, messages, and standalone photos), and any vehicles still in your garage along with the maintenance logs, inspections, drives, reviews, and photos you created on them. One category is retained in de-identified form, explained under "Data Retention" below: content you attached to a vehicle that another member owns — for example a car you transferred to someone else, or a spot you tagged to another member's vehicle — stays with that vehicle but is unlinked from your account.

Data export: you can save a copy of your data (your garage, logs, drives, posts, and more) as a file at any time from Profile → Settings → Export Data.

Data access and correction: email us and we will help you access or correct your data.

6. Data Retention

We keep your information for as long as your account is active. When you delete your account, we permanently remove your profile, your personal content, and the maintenance logs, inspections, drives, reviews, and photos on vehicles you still own, within 30 days.

Content attached to another member's vehicle: some content lives on a vehicle rather than only on your profile — for example the service history of a car you transferred to another owner (maintenance logs, inspections, drives, reviews, posts, and photos), and spots you tagged to vehicles owned by other members. So the vehicle keeps an accurate history for the person who owns it — much like a paper service book that stays with the car when it is sold — this content is retained, but we unlink it from your account by removing your user identifier so it no longer identifies you.

A vehicle's basic identity record (such as make, model, and VIN) may also remain in our vehicle database in de-identified form, without a link to your account, so its history stays coherent for current or future owners.

Suspended accounts: if your account is suspended and you then delete it, we keep a one-way scrambled version of your email address for as long as the suspension lasts, so the suspension cannot be avoided by deleting the account and signing up again with the same address. It is not reversible, it is not linked to your name, your content, or anything else about you, and we cannot read your address from it. A temporary suspension's record expires with the suspension. If the suspension is lifted while your account still exists, the record is deleted immediately. If you had already deleted the account, we no longer hold anything that connects the record to you, so lifting it is not automatic — contact us and we will remove it.

Some information (for example, abuse reports and transaction records) may be retained longer where required for legal, safety, or accounting reasons.

7. Children

Garaj is not directed to children under 13, and we do not knowingly collect information from children under 13. If you believe a child under 13 has created an account, contact us and we will remove it.

8. Security

We use industry-standard safeguards (encryption in transit, hashed passwords, scoped database access) to protect your information. No system is perfectly secure; please use a strong, unique password and keep your device up to date.

9. International Users

Your information may be processed in the United States or other countries where our service providers operate. By using Garaj, you consent to this transfer.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the app or by email. The "effective date" above will reflect the latest version.

11. Contact

Questions about this policy? Email us at mycarsgaraj@gmail.com.