Privacy Policy

Last Updated: July 22, 2026

This Privacy Policy describes how information is handled in CarOtter for iPhone and iPad. CarOtter is designed to keep information on your device whenever possible and to be clear about the limited cases where information is sent directly from your device to third-party services you choose to use.

CarOtter does not collect or store your app data on developer-operated servers, does not run analytics or advertising trackers, and does not sell your personal information.

Information Stored or Processed on Your Device

Depending on the features you use, CarOtter may access, process, and store the following information locally on your device:

  • Apple Sign In information, including your Apple user identifier and, when Apple provides it, your name and email address for account authentication.
  • Vehicle information, including make, model, year, VIN, and garage photo information that you add.
  • OBD-II information, including live readings such as RPM, speed, temperatures, fuel level, readiness information, and diagnostic trouble codes from a compatible Bluetooth OBD-II adapter.
  • Service and fuel history, including service records, odometer values, fuel logs, receipt-derived values, and notes that you enter or confirm.
  • Chat history, including messages exchanged with the in-app assistant.
  • Images you choose to use, including receipt photos, vehicle photos, and camera scans used for VIN, odometer, or service-document extraction.
  • Voice input, including live microphone audio used to convert speech to text when you use voice input.

What CarOtter Does Not Do

  • CarOtter does not create a developer-hosted account database for your vehicle records, service history, fuel logs, diagnostics, or chats.
  • CarOtter does not upload your routine app data to developer-operated servers.
  • CarOtter does not include analytics SDKs, advertising SDKs, cross-app tracking, or marketing profiling tools.
  • The developer does not have a routine admin dashboard or cloud copy of your on-device app records.

Permissions and Device Access

CarOtter requests device permissions only when a feature requires them.

  • Bluetooth is used to discover and connect to a compatible OBD-II adapter.
  • Camera is used to scan VIN plates, odometer readings, service documents, fuel receipts, and garage vehicle photos.
  • Photo Library is used to import saved receipt photos or vehicle photos from your device.
  • Microphone is used to capture live audio when you use voice input.
  • Speech Recognition is used to convert speech to text for the chat composer.

When Information Leaves Your Device

Most CarOtter information stays on your device. Information may leave your device only in the following situations:

  • Sign in with Apple. When you sign in, Apple handles the authentication request and returns account information to the app. CarOtter does not run a separate developer-hosted account server for this process.
  • AI-powered features. If you enable the AI assistant or optional cloud document review and provide your own API key, the information needed for that feature may be sent directly from your device to the provider you choose, currently OpenAI, Google Gemini, Anthropic (Claude), or xAI (Grok). This may include prompts, chat context, selected images, OCR text, relevant vehicle context, and redacted service-document previews that you review before sending. These requests are not proxied through developer-operated CarOtter servers.
  • VIN decoding. If you use VIN lookup, the VIN is sent directly from your device to the National Highway Traffic Safety Administration (NHTSA) vPIC service to decode vehicle details.
  • Voice transcription. If you use voice input, audio or transcription data may be processed by Apple's speech recognition services depending on device capability, language support, and iOS behavior. CarOtter does not store raw audio after transcription, and the developer does not receive raw audio through CarOtter.
  • Support contact. If you email the developer directly, your email provider will send your email address and any information you include in that message to the developer.

Many document and image extraction flows can also run locally on your device. When a feature completes on-device, the underlying document, image, and extracted text do not leave your device unless you later choose a cloud-assisted option.

How Information Is Used

CarOtter uses information only to provide the features you choose to use. The developer does not use your app data for advertising, analytics, profiling, or resale.

  • To display your vehicle profile, service history, fuel history, and diagnostics.
  • To run Bluetooth OBD-II diagnostics and readiness checks.
  • To scan VINs, receipts, odometer readings, and service documents.
  • To provide in-app chat responses or optional cloud document review using the context you choose to include.
  • To let you review, export, delete, or erase supported app data.

Storage and Security

  • Most app data is stored on-device using iOS file protection.
  • Sensitive values such as your AI API key and Apple authentication anchor are stored in the iOS Keychain.
  • OBD debug logs are stored in the device cache area and excluded from backups.
  • On-device records remain there until you delete them, erase app data, or remove the app.
  • If you choose an external AI provider, any information sent to that provider is handled under that provider's own terms, privacy policy, and retention practices. CarOtter does not keep a separate cloud copy.
  • The developer does not have a built-in way to browse or retrieve your stored app records from a CarOtter backend because CarOtter does not operate one for routine app data.

Sharing and Selling

CarOtter does not sell your personal information and does not share your personal information for advertising, cross-app tracking, or marketing profiling.

The developer does not receive or keep a separate server-side copy of your vehicle records, service history, fuel logs, diagnostics, chats, or scans through CarOtter's own systems.

The only third parties that may receive information are the services you explicitly choose to use through the app, such as Apple for authentication or speech services, your selected AI provider, or NHTSA for VIN decoding.

Your Controls

CarOtter includes in-app controls that let you manage your data.

  • Export. From Settings > Your Data, you can export a JSON file containing supported account, service-record, and fuel-log data.
  • Delete by category. You can delete service records, fuel logs, chat history, OBD data, or AI settings individually.
  • Erase all data. You can wipe all app data stored by CarOtter from your device.
  • Sign out. Signing out requires re-authentication, but local data remains unless you choose to erase it.

Children's Privacy

CarOtter is not directed to children under 13. CarOtter does not provide a developer-operated backend for routine app data, and the developer does not knowingly collect personal information from children through CarOtter's own systems.

Changes to This Policy

If this Privacy Policy changes, this page will be updated and the Last Updated date above will be revised.

Contact

If you have questions about this Privacy Policy or how CarOtter handles information, contact divyanshugoyal.g25@gmail.com.

If you contact the developer directly, the developer will receive your email address and any other information you choose to include in your message.