AvtoMate
Privacy
Short version: we store what you put in, we show publicly only what you choose to publish, and you can have all of it back or deleted by asking.
Before you publish this: this describes what AvtoMate actually does today, but it is not legal advice and has not been reviewed by a lawyer. If you have users in the EU, have someone check it against GDPR โ you will likely also need to name a data controller and a legal basis for processing.
What we store
- Account: your email address and password (hashed โ we never see it), plus when you joined.
- Profile: username, display name, bio, country, avatar and banner images, your chosen colours and widgets. Your profile page is public.
- Garage: the cars you add and everything you log against them โ expenses, mods, reminders and their attachments, mileage readings, photos. This is private to you unless you list a car for sale.
- Community: your posts, comments, reactions, saved posts, follows and direct messages.
- Listings and meets: whatever you choose to publish.
What is public
- Your profile page, your posts and comments, your listings while they are live, and meets you organise or attend.
- Your garage log is private. When you list a car, the details you put in the listing become public โ but your private expense entries, receipts and reminders do not.
- AI deal reports are visible only to the person who generated them.
Who else is involved
- Supabase hosts the database, authentication and file storage.
- Vercel hosts and serves the application.
- OpenAI processes the prompts behind Cardex entries, valuations and deal reports. Those prompts include car details and the ownership record for the car being analysed. They do not include your email address or password.
- We do not sell your data, and there is no advertising network on AvtoMate.
Cookies
- We use a session cookie to keep you signed in. There are no advertising or tracking cookies.
Your rights
- You can see and edit most of your data directly in the app.
- You can ask for a copy of everything we hold, or ask us to delete it, by emailing function(){throw Error("Attempted to call CONTACT_EMAIL() from the server but CONTACT_EMAIL is on the client. It's not possible to invoke a client function from the server, it can only be rendered as a Component or passed to props of a Client Component.")}.
- Deleting your account removes your profile, garage and listings. Posts in shared threads may remain with your name removed, so conversations other people took part in stay readable.
Retention
- We keep your data while your account exists. Deleted content is removed from the app immediately and from backups as those backups age out.