← Garaj

Privacy Policy

Effective April 15, 2026

Garaj ("we", "us", "our") is a social platform for car enthusiasts. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to the Garaj mobile app and related services.

Effective date: April 15, 2026.

1. Information You Provide

Account: username, email address, password (stored hashed), and profile details you choose to add (display name, bio, avatar, cover photo).

Vehicles & content: vehicles you add to your garage (year, make, model, trim, color, mileage, VIN if you choose to share it), posts, photos, maintenance logs, drives, inspections, spot reports, reviews, comments, likes, saves, and messages you send to other users.

Support: messages you send us via email, including any diagnostic information you choose to include.

2. Information Collected Automatically

Device & usage: app version, operating system, device model, crash reports, and aggregate feature-usage events (for example: "a post was created" or "the feed was refreshed"). These events are used to diagnose bugs and measure which features are working.

Location: when you record a drive, we collect GPS coordinates for the duration of that drive. You control whether the route and speed are shown publicly via the privacy settings for each drive. Location is not collected outside of an active drive session.

Push tokens: if you enable push notifications, we store a device push token so we can deliver alerts.

3. How We Use Your Information

To provide and operate the app: sign-in, rendering your garage, delivering posts and notifications, and enabling social features like following and messaging.

To improve the app: analyzing aggregate usage patterns, diagnosing crashes, and measuring which features are adopted.

To communicate: account-related emails (verification, password reset), and optional weekly activity digests if you opt in.

To keep the community safe: reviewing reports, enforcing community guidelines, and preventing abuse.

4. Third-Party Service Providers

Supabase (database, authentication, file storage): stores your account and content.

Sentry (crash reporting): receives exception reports, device metadata, and a truncated component stack when the app crashes. We strip cookies before events are sent.

PostHog (product analytics): receives aggregate feature-usage events and, when you consent via the App Tracking Transparency prompt on iOS, a user identifier.

Anthropic (AI features): when you use an AI feature (vehicle identification, market value estimates, receipt and document scanning, or AI inspections), the photo(s) and/or text you submit are sent to Anthropic's Claude API through our secure server proxy to generate the result. Per Anthropic's API terms, this data is not used to train their models.

RevenueCat (subscription management): receives a user identifier and your purchase / subscription status to manage your Garaj Pro entitlement. Payment is processed by Apple; we never receive your card details.

Apple and Google (push delivery): receive a push token and the notification payload when we send you an alert.

Each provider processes data on our behalf under their own privacy policies. We do not sell your personal information.

5. Your Choices

Privacy controls: you can change the privacy level of each post, drive, spot, review, or inspection (public, followers-only, or private).

Analytics opt-out: on iOS, you can decline the App Tracking Transparency prompt; your events are still counted in aggregate but are not linked to an identifier.

Push notifications: you can disable notifications in the app's settings or from the operating system settings.

Account deletion: at any time, you can permanently delete your account from Profile → Settings → Delete Account. This removes your profile, vehicles, posts, drives, and all other content from our servers.

Data access and correction: email us and we will help you access or correct your data.

6. Data Retention

We keep your information for as long as your account is active. When you delete your account, we remove your content within 30 days. Some information (for example, abuse reports and transaction records) may be retained longer where required for legal, safety, or accounting reasons.

7. Children

Garaj is not directed to children under 13, and we do not knowingly collect information from children under 13. If you believe a child under 13 has created an account, contact us and we will remove it.

8. Security

We use industry-standard safeguards (encryption in transit, hashed passwords, scoped database access) to protect your information. No system is perfectly secure; please use a strong, unique password and keep your device up to date.

9. International Users

Your information may be processed in the United States or other countries where our service providers operate. By using Garaj, you consent to this transfer.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the app or by email. The "effective date" above will reflect the latest version.

11. Contact

Questions about this policy? Email us at mycarsgaraj@gmail.com.