CarVault
EnglishEspañolУкраїнська

CarVault Privacy Policy

Effective 24 July 2026 · 2026-07-24

Controller and scope

CarVault is operated by Oleksandr Tokariev. Contact alexdeveloper909@gmail.com. CarVault may be offered worldwide wherever its stores and service are available, and is not directed to people under 16.

Information we process

CarVault processes the Google or Apple account identity you select, your settings, and vehicle details, mileage, fuel, expenses, service, reminders, optional notes/vendor names, and statistics calculated from those records.

It also uses short-lived duplicate-prevention and deletion-job records, privacy-bounded operational events, and correspondence you choose to send. The initial release does not collect payment details, advertising IDs, precise location, contacts, photos, documents or receipt images.

Purposes and legal bases

Account and vehicle information is used to provide the service requested under the Terms. Minimal operational information is used for the legitimate interests of reliability, security, duplicate prevention and failure diagnosis. Rights requests are processed where needed to meet legal obligations.

CarVault does not sell personal data or use vehicle records for advertising. There is no marketing, non-essential analytics, session replay or profiling at launch. Reading this notice is not consent to optional processing.

Providers, ChatGPT and transfers

Application data is hosted by AWS in eu-west-1 (Ireland). AWS also provides authentication, logs, queues and the globally delivered legal site. Google or Apple processes sign-in when selected; Google provides the support mailbox; Apple and Google operate the stores; OpenAI processes ChatGPT activity when selected. Their applicable terms and safeguards cover processing that may occur outside the EEA.

The stateless CarVault ChatGPT connector validates and forwards a short-lived CarVault token for the requested tool action. It keeps no separate account, conversation or vehicle-data copy. Sentry diagnostics are disabled at launch.

Retention and deletion

Account and vehicle records remain while the account is active. Account deletion locks the account and removes application data and the Cognito user.

  • Agent-write duplicate-prevention records: 24 hours.
  • Operational logs: 30 days; designed to exclude tokens, bodies, account IDs, record IDs and vehicle free text.
  • Deletion queue: up to 4 days; failure queue: up to 14 days; content-free completion marker: 7 days.
  • AWS point-in-time recovery copies: up to 35 days and unavailable as normal application records.
  • Routine closed support mail: up to 12 months; minimal rights/security evidence: 24 months unless law requires longer.

Your rights

You may have rights of access, correction, deletion, restriction, portability and objection, and may withdraw any separate consent. Contact alexdeveloper909@gmail.com. CarVault may request a proportionate authenticated step but never your password or access token.

You may complain to the privacy or data-protection authority available in your country.

Security and changes

CarVault uses scoped authentication, platform/AWS encryption, private storage, limited operator access and privacy-bounded logs. No online service can guarantee absolute security.

Historical versions remain at versioned links. Material changes will be highlighted and published with a new effective date; separate consent will be requested if legally required.