Privacy Policy
This Privacy Policy describes how Carrus ("we", "our", "the app") handles your information when you use our mobile application.
Carrus is operated by Abdulrahman Ahmed Mohamed, reachable at hello@carrus.app.
1. What we collect
We collect the minimum information needed to run the service.
Account data (only if you sign in):
- Email address (used to identify your account and send password reset links).
- Authentication tokens (managed by our auth provider, Supabase).
- If you sign in with Google: Google also returns your name and the URL of your Google profile picture alongside your email. These are stored on your account record by our auth provider. Carrus itself never displays or uses them — we keep them only because they arrive as part of the sign-in, and they are deleted when you delete your account. Signing in with Apple or with an email and password does not provide your name.
Your vehicle data:
- Vehicle information you enter: make, model, year, nickname, color, vehicle type (car or motorbike), body type, mileage, in-service date.
- Maintenance records you create: service date, mileage, cost, notes, scanned receipts.
- Fuel records you create: fill-up date, volume, cost, and your current tank level.
- Maintenance preferences: notification settings, units (miles/km), region, display currency, theme.
Glovebox documents:
- If you use the Glovebox, we store the document's type (registration, insurance, licence or other), the title you give it, and its expiry date in your account so reminders work across your devices.
- The photographs themselves stay on your phone. They are never uploaded to Carrus and never sent to any third party. They are kept in your app's own storage, which means they are included in your device backup (for example iCloud), and they are deleted when you delete the document, the vehicle, or the app.
Purchase data (only if you subscribe): handled by RevenueCat. Apple/Google retain payment details; we never see your card number.
Subscription state: we keep our own record of your plan (tier, status and expiry date) so that paid features work offline. Payment details are never visible to us.
Diagnostic data: crash reports and error events sent to Sentry, tagged with your account ID so we can tell whether one user hit an error repeatedly. Never your email.
Usage analytics (pseudonymous): interaction events sent to PostHog (which screens you visit, which features you use), linked to your account ID and your subscription tier. Not your email or name, but not anonymous either — the events for one account can be viewed together.
AI features: when you chat with Carson or scan a receipt, your message text or receipt image is sent to OpenAI to generate a response. OpenAI does not retain this data for training, and we do not store the message content on our servers. We do keep a usage counter — which feature you used and when, with no content — so we can enforce plan limits.
2. What we do NOT collect
- We do not collect your phone number, address, or precise location.
- We do not ask you for your name. The only way we ever receive one is if you choose to sign in with Google, which supplies it automatically (see above).
- We do not sell your data to anyone.
- We do not share your data with advertising networks.
- We do not access your phone's contacts, microphone, or location.
- We do not access your photo library except for images you explicitly pick yourself — a receipt to scan, or a Glovebox document. We use the camera only when you choose to photograph a receipt or a Glovebox document.
- We do not upload your Glovebox document photographs. They stay on your device.
3. Where your data is stored
- Account + vehicle + maintenance + fuel data, and Glovebox document details (type, title, expiry): stored in Supabase (United States data centers).
- Glovebox document photographs: your device only — never uploaded.
- Vehicle + maintenance data while offline: stored locally on your device using encrypted system storage.
- Crash reports: Sentry (United States).
- Usage analytics: PostHog (European Union — Frankfurt).
- Subscription state: RevenueCat (United States) and Apple/Google.
If you are in the European Economic Area (EEA) or United Kingdom, your data may be transferred to the United States; these transfers are protected by the relevant standard contractual clauses.
4. Your rights
Under data protection laws (including GDPR if you're in the EU, and CCPA if you're in California), you have the right to:
- Access the data we hold about you. Use the in-app "Download My Data" button (Settings → Manage Account) to export a JSON file containing all your data.
- Delete your account and all associated data. Use the in-app "Delete Account" button (Settings → Manage Account). This is permanent and immediate; deleted accounts are removed from our database within 24 hours. Records held by our processors — your purchase history at RevenueCat and Apple/Google, and analytics events at PostHog — are not removed by this button; email us at hello@carrus.app and we will erase them on request.
- Correct inaccurate data by editing it directly in the app.
- Withdraw consent by signing out and uninstalling the app. Your locally-stored data remains on the device until you uninstall.
To exercise any other right, email us at hello@carrus.app.
5. Children
Carrus is not intended for use by anyone under 13 (or 16 in the EU/UK). We do not knowingly collect data from children. If you believe we've inadvertently collected data from a child, contact us and we'll delete it.
6. Cookies + tracking
Carrus is a mobile app and does not use browser cookies. We don't use any cross-app tracking identifiers (IDFA on iOS, GAID on Android) for advertising.
7. Data retention
- Account data: kept while your account is active. Deleted within 24 hours of account deletion.
- Analytics + crash reports: retained by our providers under their own retention settings, currently up to 90 days for event data.
- AI chat + receipt scans: the message text and images are processed in real time and are not retained on our servers.
- AI usage counters: the record of which AI feature you used and when (never the content) is kept while your account is active, and is deleted with your account.
8. Security
- All data in transit is encrypted using TLS.
- Server-side databases use industry-standard encryption at rest.
- We follow least-privilege access principles for our own staff.
No system is perfectly secure. If you believe your account has been compromised, contact us at hello@carrus.app immediately.
9. Changes to this policy
If we change how we handle data in a material way, we'll update this page and notify active users via an in-app notice at least 30 days before the change takes effect.
10. Contact
Questions, requests, or complaints: hello@carrus.app
If you're in the EU/UK and you believe we're not handling your data correctly, you also have the right to lodge a complaint with your local data protection authority.