Data controller
[PLACEHOLDER: legal entity name, registration number, country] operating the Car Diagnostics platform at obdllm.com and the Android application com.obd.diagnostics is the controller of your personal data under the GDPR and the Law of Ukraine on Personal Data Protection.
Privacy contact: [email protected]. We respond to all privacy inquiries within 30 calendar days.
What data we collect
| Category | Details |
|---|---|
| Account data | Email address, display name, registration date, sign-in method (email/password or Google OAuth). For Google Sign-In we receive only your public profile email and name — never your Google password. |
| Vehicle data | VIN, make, model, year, mileage you enter or that is read from the OBD-II adapter. |
| OBD-II telemetry | Diagnostic Trouble Codes (DTC), live parameter IDs (PIDs — RPM, coolant temperature, fuel trim, O₂ sensors, and others), freeze-frame data, I/M readiness monitor states, session timestamps. |
| Device data | Anonymous device identifier (deviceId), app version, Android OS version, Bluetooth adapter model. |
| Payment & billing data | Subscription tier, billing period, payment status, invoice identifiers. Card numbers are processed exclusively by Monobank and PrivatBank — we never receive or store them. |
| Analytics data | Page views, feature interactions, session recordings and heatmaps — only after you accept the cookie banner. |
| Technical logs | IP address (anonymised after 90 days), HTTP user-agent, request timestamps, error traces. |
| Support correspondence | Content of emails or in-app messages you send us. |
| Newsletter (opt-in) | Email address only. Withdraw consent at any time via the unsubscribe link in any email. |
We do not collect Special Categories of data (GDPR Art. 9) such as health, biometric, racial, or political data.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing diagnostics, reports, and AI analysis | Contract performance — GDPR Art. 6(1)(b) |
| Account management and authentication | Contract performance — GDPR Art. 6(1)(b) |
| Subscription billing | Contract performance + legal obligation — GDPR Art. 6(1)(b)(c) |
| Security and fraud prevention | Legitimate interest — GDPR Art. 6(1)(f) |
| Product analytics (aggregate) | Legitimate interest — GDPR Art. 6(1)(f) |
| Session recordings (Microsoft Clarity) | Consent — GDPR Art. 6(1)(a) |
| Firebase / GA4 analytics | Consent — GDPR Art. 6(1)(a) |
| Email marketing and product updates | Consent — GDPR Art. 6(1)(a) |
| Accounting and tax records | Legal obligation — GDPR Art. 6(1)(c) |
How OBD-II data flows
Understanding where your vehicle data goes at each step:
| Step | Where it happens | Data involved |
|---|---|---|
| Bluetooth scan | Locally on your device — data never leaves your phone during the scan itself | DTCs, live PIDs read from the adapter |
| Session storage | Encrypted on our servers, linked to your account | DTCs, PIDs, timestamps, VIN |
| AI analysis | Transmitted to our AI provider to generate a response | DTCs, PIDs, VIN — no personal identifiers |
| Reports and history | Stored on our servers | Full session data, linked to your account |
Guest mode: if you use the app without an account, session data is stored locally on your device only and is lost if you uninstall the app or clear app data. AI features require an account.
Blog comments
Our blog supports reader comments hosted on our own infrastructure (no third-party comment platforms). When you post a comment we collect:
- Display name — the name you enter when commenting (does not need to be your real name).
- Comment text — limited to 2,000 characters.
- Browser fingerprint — a non-persistent, anonymised identifier used solely to prevent spam and abuse. It is not linked to your account or used for tracking across pages.
- Post reference — which blog post your comment belongs to.
If you are signed in, your comment is additionally linked to your account so it can be associated with a verified user badge. Comments are retained as long as the associated blog post exists. You may request deletion of your comments at [email protected].
AI features and data processing
Fault analysis, predictions, repair recommendations, reports, and in-app AI chat are generated by [PLACEHOLDER: LLM provider name] under a Data Processing Agreement that prohibits use of your data for model training. To generate a response, your vehicle's DTCs, PID values, and VIN are transmitted to that provider.
Important limitation: AI output is provided for informational purposes only and does not constitute professional vehicle repair advice. Do not make road-safety or maintenance decisions based solely on AI output — always consult a qualified mechanic for critical faults.
Third-party processors
We share data only with processors contractually bound to act on our instructions:
| Provider | Purpose | Data transferred |
|---|---|---|
[PLACEHOLDER: hosting provider] | Infrastructure, storage | All stored data |
| Monobank / PrivatBank | Payment checkout | Billing metadata only (no card data) |
[PLACEHOLDER: LLM provider] | AI feature inference | DTCs, PIDs, VIN |
| Microsoft Clarity | Session replay, heatmaps | Interaction events (consent only) |
| Google Firebase / Analytics (GA4) | App-linked usage analytics | Anonymised events (consent only) |
| Cloudflare Web Analytics | Aggregate site traffic | Anonymised, no cookies, no cross-site tracking |
We do not sell, rent, or trade personal data. A complete processor list is available at [email protected].
Fleet (corporate) subscriptions
If your organisation uses a Fleet subscription, the fleet administrator account can view diagnostic data for all vehicles registered under that subscription. This includes session history, DTCs, PID readings, and AI analysis results for each vehicle. Individual drivers within the fleet should be made aware by their organisation that their vehicle data is accessible to the fleet administrator. We process this data on behalf of the organisation as part of the contract. If you are an individual user and your vehicle has been added to a fleet account without your knowledge, contact [email protected].
International data transfers
Some processors operate servers outside the EEA or Ukraine. Where such transfers occur, we rely on the European Commission's Standard Contractual Clauses (SCCs) under GDPR Art. 46(2)(c) or an applicable adequacy decision. You may request a copy of the applicable safeguards at [email protected].
Data retention
| Data | Retention period |
|---|---|
| Account, profile, vehicles | Active account life + 30 days after deletion |
| OBD-II sessions, DTCs, PIDs, reports | Active account life + 30 days after deletion |
| AI chat history | Active account life + 30 days after deletion |
| Billing records | 3 years from transaction date (statutory accounting) |
| IP addresses in logs | 90 days, then anonymised |
| Technical error logs | 90 days |
| Session recordings (Clarity) | 30 days (Clarity platform default) |
| Minimal deletion audit record | 1 year (security and legal compliance) |
| Support correspondence | 1 year after resolution |
| Newsletter subscription | Until you unsubscribe |
After the applicable period, data is irreversibly deleted or anonymised so it can no longer be linked to you.
Your rights
| Right | What it means | How to exercise |
|---|---|---|
| Access | Get a copy of the data we hold about you | Email [email protected] |
| Rectification | Correct inaccurate or incomplete data | Email or in-app profile settings |
| Erasure | Request full account and data deletion | In-app: instant · Email: within 30 days (extendable to 3 months for complex requests — we will notify you) |
| Portability | Receive your data in a machine-readable format | Email [email protected] |
| Restriction | Ask us to pause processing in certain circumstances | Email [email protected] |
| Objection | Object to processing based on legitimate interest | Email [email protected] |
| Withdraw consent | Stop consent-based processing (Clarity, Firebase, newsletter) | Cookie banner · Unsubscribe link · Email |
| Complaint | Lodge a complaint with a supervisory authority | EU: your national DPA · Ukraine: Ukrainian Parliament Commissioner for Human Rights |
We will verify your identity before processing any request. We respond within 30 calendar days.
Security
- Transit: all connections use TLS 1.2 or higher.
- Passwords: stored as salted one-way cryptographic hashes — plaintext passwords are never stored or transmitted to us.
- Access control: role-based access; production systems require multi-factor authentication.
- Reviews: regular internal security reviews.
- Breach notification: if a breach poses a risk to your rights, we notify the relevant supervisory authority within 72 hours and affected users without undue delay.
Children
The service is not directed to persons under 16. We do not knowingly collect personal data from children under 16 without verified parental consent. If you believe a child's data has been collected, contact [email protected] and we will delete it promptly.
Changes to this policy
We will announce material changes at least 30 days before they take effect via email and in-app notification. The current version is always available at this URL with the effective date shown at the top. Continued use after the effective date constitutes acceptance of the updated policy, except for changes that introduce new consent-based processing — those require a fresh consent action from you.
Contact
Car Diagnostics · obdllm.com
Email: [email protected]
Response time: up to 30 calendar days.
For account deletion: obdllm.com/delete-account