AutoSpotterX - Privacy Policy
Last Updated: August 29, 2026
1. Introduction
AutoSpotterX ("we," "our," or "us") values your privacy. This Privacy Policy explains how we collect, use, and protect your information when you use the AutoSpotterX Application (including our mobile app available on Google Play, and our web application). It applies to all users and covers the data collected through our applications.
2. Information We Collect
We collect the following types of information:
Account & Profile Data: Username, optional profile photo, optional social media links (Instagram and TikTok, available to users with more than 1,000 AutoXP), account creation date, and AutoXP points (which determine your public XP rank badge displayed to other users). Authentication is handled by Firebase Authentication (email/password or Google sign-in). We also store a unique account identifier (Firebase UID) and whether you accepted our Terms of Service and Privacy Policy (including the current version). Your email address is used only for authentication.
User Content: We collect the following user-generated content:
- Photos & Videos: Vehicle photo upload depends on originality and rarity. Non-original photos (screenshots, downloads or photos that detected as non original) and common cars are saved only on your device (never uploaded). For public profiles, original uncommon cars upload to Firebase only (visible on the public profile but hidden from global discovery), while original rare+ cars upload to Firebase and Cloudinary for the public profile, Feed, Country Spots and Car Explorer. For private profiles, new spots stay only on the device and are not uploaded. Secondary photos and videos never leave your device.
- Car Details: Make/model, captions/notes, timestamps, and country name/code (derived from location).
- Privacy Settings: Whether your profile is Public or Private. This setting controls whether eligible spots may be uploaded and shared.
- Social Interactions: Likes, friend connections/requests, and in-app notifications.
- Feature Requests: Requests you submit, their title, description, category, your display name and account identifier, plus upvotes, downvotes and reports. Requests and vote totals are visible to signed-in users; individual vote identifiers are used to prevent duplicate or conflicting votes.
- Moderation: Reports you submit, account restrictions, moderation reasons, expiration dates and audit information needed to protect the community and process appeals.
- AI Usage: Service usage counts to enforce rate limits.
- Photo Metadata: We analyze EXIF data (location, camera info, timestamps, editing software) locally on your device for originality detection. Non-original photos are automatically saved locally only. Precise location stays on your device only. We only collect country name/code for uploaded cars.
- Photo Processing: Car photos are processed on-device (watermarking, privacy blurring, manual blurring) before upload decision. We upload only processed versions. For public profiles, low-quality versions are stored in Firebase (uncommon+) and high-quality versions are stored on Cloudinary only for rare+ cars. Private-profile spots, secondary photos, and videos never leave your device.
Device & Usage Data: We collect technical data from your device, such as IP address, browser type, device model, and operating system version to ensure app compatibility and security. We also collect information about how you interact with our services, including pages viewed, features used (such as app opens or photo sharing), and buttons clicked. This usage data is linked to your account identifier (UID) solely to improve our application and troubleshoot technical issues. For security purposes, Firebase App Check generates device integrity tokens (via Google Play Integrity on Android, or reCAPTCHA on the Web) to verify requests come from genuine devices. These tokens are temporary and do not contain personal information.
Push Notifications: To provide you with real-time updates (such as likes and friend requests), we collect your unique device identifier (FCM Token). You can opt out of these notifications at any time through the in-app settings. When you delete your account, your device token is permanently deleted from our servers.
App & Browser Permissions: Camera (to take photos), Location (for mapping features), Internet (for cloud sync), and Network State (to check connectivity). The application does not request broad external storage permissions; any necessary local caching or saving of photos and data is handled safely within the application's own sandboxed storage (such as SharedPreferences or IndexedDB). You can change or revoke permissions through your device or browser settings.
3. Third-Party Services and Partners
AutoSpotterX uses third-party services (each has its own privacy policy):
- Firebase (Google): User accounts, database storage, and backend services. (Firebase Privacy Policy)
- Firebase Cloud Messaging (Google): Used to deliver push notifications to your device. We share your device token with this service to facilitate delivery. (Firebase Privacy Policy)
- Firebase App Check (Google): To protect our backend resources from abuse, we use App Check with Play Integrity (on Android) to verify that requests originate from our authentic app. This service may analyse device integrity tokens but does not retain personal data. (Firebase Privacy Policy)
- Google ML Kit (Android) & ONNX Runtime Web (Web): On-device detection used for privacy blurring (best-effort). Processing happens 100% locally on your device or in your browser. The application also provides an on-device/in-browser manual blur tool.
- Google Gemini API: Optional cloud-based car identification. (Google Privacy Policy)
- Google Play In-App Review (Android Only): Used to request app ratings within the app. (Google Privacy Policy)
- Google Play In-App Updates (Android Only): Used to check for and notify users of app updates. (Google Privacy Policy)
- Android Geocoder (Android) & Nominatim (OpenStreetMap): Used to derive country name/code from coordinates (see Section 5.4). We only send raw coordinates; no personal identifiers are attached. Only the resulting country info is stored in our database. (OpenStreetMap Copyright)
- Cloudinary: High-quality photos of eligible rare+ cars from public profiles are stored on Cloudinary for the Feed, Country Spots and Car Explorer. Private-profile spots, common cars, and other local-only spots are never uploaded to Cloudinary. (Cloudinary Privacy Policy)
- Appwrite: Helps securely delete photos when you delete a car or your account. Hosted in Frankfurt, Germany. (Privacy Policy)
- PostHog: We use PostHog to help us understand how our users interact with AutoSpotterX. This involves collecting usage data (such as pages visited or buttons clicked) and linking it to a unique identifier (UID) associated with your account. We use this information solely to improve our services and fix technical issues. (PostHog Privacy Policy)
- OpenFreeMap: Open-source map tile provider for displaying location maps. We do not share personal data, only anonymous tile requests. (OpenFreeMap)
- Apple MapKit: Provides the native map and location picker on iOS. MapLibre GL is retained only as a non-iOS fallback.
4. How We Use Your Information
We use your information to:
- Account & Features: Create and authenticate your account (via email/password or Google sign-in), manage your car collection, calculate stats and XP, and provide AI-powered car identification (with usage tracking to enforce rate limits).
- Social Features: Enable friends, public feed sharing, Country Spots, Car Explorer, likes, and notifications.
- Privacy & Control: Respect your Public or Private profile setting and your location-attachment preference.
- Maps & Location: Display your private map with spot locations (stored only on your device; only you have access to exact locations). Country names are stored on our servers to display the country in the public feed, Country Spots, and Car Explorer.
- Photo Processing & Upload: Process photos on your device (EXIF analysis, watermarking, privacy blurring). Private-profile spots and common cars are saved locally only. For public profiles, eligible uncommon cars upload to Firebase only and appear on the public profile (not global discovery); eligible rare+ cars upload to Firebase and Cloudinary for the public profile and global display. Secondary photos and videos remain on your device only.
- Support & Safety: Provide app updates, troubleshoot issues, moderate reported content, and enforce our Terms of Service. We use Firebase App Check to verify that requests to our backend services (including Appwrite for photo deletion) come from authentic app installations, protecting against abuse and unauthorized access.
- Compliance & Legal: Track your acceptance of our Terms of Service and Privacy Policy (including version numbers) to ensure legal compliance.
5. Data Sharing
We share specific data in limited scenarios as described below:
5.1 Service Providers
We engage third-party service providers to facilitate our services:
- Firebase (Google): For user authentication, database storage, and backend services. As our primary backend, Firebase stores all app data described in Section 2, except for GPS coordinates and secondary photos/videos which remain on your device only. Email is stored in Firebase Authentication only for login purposes.
- Cloudinary: For high-quality photo storage and delivery in the Feed and Country Spots. We upload only eligible rare+ cars from public profiles. Private-profile spots, common cars, uncommon cars, and other local-only spots are never uploaded to Cloudinary.
- Appwrite: Securely processes photo deletions when you delete content. We verify it's really you before deleting anything.
- PostHog: Receives usage analytics and interactions (like login, registration, and photo sharing consent choices) linked to your account.
- Google Services (ML Kit, Gemini API) and Android Geocoder: For on-device processing, optional AI identification, and country derivation via device geocoding. Data shared is limited to what is necessary for each service (see Section 3 for details).
- OpenFreeMap: For map tile services. We do not share personal location data, only anonymous map tile requests.
5.2 Public & Social Features
Information shared with other users through the app's social features:
- Public Feed: Eligible rare+ cars from public profiles appear in the Feed. Private-profile spots, common cars, uncommon cars, and other local-only spots are excluded. The feed displays: car photos, profile photos, usernames, car names, likes, rank badges, country, and optional captions. Content shared publicly may be used for promotional purposes. Exact location is never shared, only country (see Section 5.4).
- Country Spots: Users can browse eligible rare+ cars from public profiles by country. Displays only car photos and car names: no username or profile info. Only country name is shown, never the exact location.
- Car Explorer: A searchable database where users can find specific car models and community-spotted photos. Only eligible rare+ cars from public profiles appear here. This section displays only the car photo and spotting date: no usernames, profile photos, or exact locations.
- Leaderboard: Public leaderboard shows top 50 users by AutoXP (username, AutoXP points, profile photo).
- User Profiles: Any signed-in user can view your public profile (e.g., via the feed or leaderboard), including eligible server-backed Rare+ and Uncommon cars, including compatible cars uploaded by older app versions, plus your username, profile photo, AutoXP points, and optional social links. Common, non-original, moderated, and other device-only spots are not publicly available.
- Friends: Accepted connections can view eligible server-backed legacy cars that remain associated with a Private profile, in addition to public profile information. Device-only spots and exact locations are not available to connections; only country-level information may be shown.
- Feature Requests: Signed-in users can read feature requests and vote totals. A request shows its author display name. Reports are visible only to the reporter, an affected content owner where applicable, and administrators.
- Friend Requests: When you send a friend request (via feed or leaderboard), the recipient can see your display name and profile photo and social media links in the Friends screen and your profile and may receive a push and/or in-app notification (e.g., "[Your username] sent you a friend request"). User IDs are internal only.
- Like Notifications: When you like someone's car, they may receive a push and/or in-app notification showing your username and the car details (e.g., "[Your username] liked your Ferrari F40").
5.3 Legal & Administrative
- Administrators: Administrators may access user data (photos, profile info, reports and content) for moderation and support. They can hide content from public surfaces, delete content, or restrict accounts that violate our Terms of Service. A moderation hide overrides profile visibility. Deleted content is permanently removed from our servers where applicable, and users may be notified in-app.
- Law and Safety: We may disclose your information if required by law or to protect our rights, safety, or property.
5.4 Map and Location Privacy
Your location privacy is fully protected:
- Device-Only Storage: GPS coordinates are stored only on your device (in SharedPreferences on Android, or IndexedDB on the Web). They are designed to reside only on your device and are not uploaded to our servers. Deleted when you clear your browser data, uninstall the app, or delete your account.
- Location Attachment Control: You can control whether location data is attached to your spots through Settings → Privacy → "Attach Location by Default". When disabled, the app will not extract or store location data from your photos. This setting is enabled by default but can be turned off at any time.
- Country Data Only: To enable Country Spots and Car Explorer browsing and show which country a car was spotted in inside the feed, we extract country name/code from coordinates using Android Geocoder (on mobile) or Nominatim/OpenStreetMap (on the web). Only the extracted country name/code is stored on our servers; exact coordinates are not.
- Completely Private: Only you can see exact locations on your personal map. Friends can see your car photos/details but not locations or map markers.
6. Your Rights and Controls
You have control over your personal data and account. You can view and update your profile information, make your profile Private so new spots stay on your device and previously shared spots leave public surfaces, delete photos or entries, request data export, manage connections, control app permissions, and manage optional features such as location attachment and cloud AI identification.
Data Export: You can export your core account data directly through the app settings in a ZIP file. This automated export includes your profile, car collection, media (photos and videos), friends, notifications, and AI usage counts. If you require an export of your usage analytics data from PostHog, you can request it via email.
7. Account and Data Deletion
You can delete your entire account through app settings (processed promptly, typically within minutes) or by emailing us at [email protected] with "Account Deletion" in the subject line (processed within 7 working days). Upon deletion, all personal data will be permanently and automatically removed from our servers, including your Firebase account, your photos on Cloudinary, and your analytics profile on PostHog.
Deleting individual photos or entries removes that content from our servers immediately.
Administrative Deletion: Content may also be deleted by administrators if it violates our Terms of Service. When administrators delete your content for policy violations, it is permanently removed from our servers (Firestore and Cloudinary). You will be notified via in-app notification if your content is deleted for policy violations.
8. Additional (Optional) Features
AutoSpotterX offers several optional features with extra privacy considerations:
Local Video Storage: If you record car videos within the app, they are stored only on your device in encrypted form. These videos are designed to remain on your device and are not uploaded or shared externally. Deleting the associated car entry or your account will erase these videos.
Cloud AI Identification: As mentioned in Section 3, the optional Google Gemini service can analyze car photos. This is an opt-in feature: you must choose to send a photo to Google for identification. Only the image is sent (no personal data). Data handling is subject to Google's Privacy Policy. We track your usage count in Firebase to enforce free usage limits.
Social Sharing: Connections, public profiles, the Feed, Country Spots, and Car Explorer sharing are described in Section 5. The Public or Private profile control in Settings is the sharing control: Private profiles keep new spots on-device and remove previously shared spots from public surfaces; eligible older server-backed spots may remain available to the owner and accepted connections. Public profiles show eligible server-backed Uncommon and Rare+ spots, while only Rare+ spots enter global discovery.
Legacy Compatibility: Eligible cars uploaded by older app versions may be assigned the current public-profile visibility marker. This does not place an Uncommon car into global discovery and never overrides an administrator moderation hide. New uploads cannot include latitude, longitude or an exact location string; only derived country name/code may be stored in Firebase.
Feature Requests: You may create, vote on, downvote and report feature requests. Votes are limited to one direction per account. We retain this data while the request exists or as reasonably needed for moderation, safety and abuse prevention.
9. Children's Privacy
You must be at least 13 years old to use AutoSpotterX (age may vary by local law). We do not knowingly allow users under the minimum age to create an account.
Age is verified locally on your device during signup; we do not collect or store your date of birth.
If you are a parent or guardian and believe a child under 13 has created an account, contact us at [email protected] to have it deleted.
10. Other Important Notes
Data Retention: We retain your personal data only as long as necessary to provide the app services or as required by law. When you delete your account, we will remove your data from our systems promptly (typically within minutes, and within 30 days at most), except for any data we are legally required to keep (such as anonymized logs).
AI Accuracy: Our AI features (car identification) are designed to assist you, but they are not 100% accurate. Results should be treated as probabilistic; always verify important information manually.
Local vs. Cloud Processing: Blurring (including manual blur) and watermarking happen on your device. Photos you upload or share are processed locally first (blurred/watermarked as applicable), and we receive/store the processed result. Automatic blurring is best-effort; if it misses something, you are responsible for reviewing your photos and using the in-app manual blur tool before uploading. Third-party servers are used for authentication, data storage, and optional AI identification if you opt in.
Originality Detection: During photo upload, we analyze photo metadata (EXIF data including camera information, GPS data, and timestamps) locally on your device to detect screenshots or downloaded images. Non-original photos are saved only on your device in encrypted storage and never uploaded to any server. They remain visible in your car collection but are not shared with anyone.
Profile- and Rarity-Based Upload: Private-profile spots and common cars are saved locally only and never uploaded. For public profiles, eligible uncommon cars upload to Firebase only (hidden from global surfaces but visible to every signed-in profile viewer), while eligible rare+ cars upload to Firebase and Cloudinary for the public profile, Feed, Country Spots and Car Explorer.
11. Data Protection and International Transfers
Data Protection: We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction. This includes encrypted transmission (HTTPS/TLS), encrypted storage by our service providers (such as Firebase/Google Cloud), secure authentication, and access controls.
Security Limitation: While we implement reasonable and industry-standard security measures to protect your information, no method of transmission over the Internet or method of electronic storage is completely secure. Therefore, we cannot guarantee absolute security of your data.
International Transfers: Your data may be processed in countries other than your own (for example, on servers operated by Google or other service providers worldwide). In such cases, we ensure appropriate safeguards (such as compliance with EU Standard Contractual Clauses or similar measures) are in place to protect your data.
Legal Basis: If you are an EU resident (GDPR), we rely on the following legal grounds for processing:
- Consent: When you give explicit permission (e.g., enabling location services).
- Contract Performance: To perform the services you request (e.g., providing access to your account and collection).
- Legitimate Interests: For app functionality, security, and improvement, balancing our interests against your privacy rights.
- Legal Compliance: To comply with laws and regulatory obligations.
12. GDPR and CCPA Rights
We comply with applicable privacy laws, including GDPR and CCPA.
EU (GDPR) Rights: If you reside in the European Economic Area, you have rights under GDPR, including the right to access, correct, or delete your personal data; the right to restrict or object to certain processing; the right to data portability; and the right to withdraw consent at any time. You may also lodge a complaint with a data protection authority. To exercise these rights, please contact us (see below).
California (CCPA) Rights: California residents have the right to know what personal data is collected and how it is used, the right to request deletion of personal data, and the right to opt out of the sale of personal data. AutoSpotterX does not sell your personal information (ever) – this is a permanent, unchangeable policy. If you wish to request deletion or disclosure of your data, please contact us.
13. Developer and Contact Information
Developer: Zarnox2525 (app developer)
Contact Email: [email protected]
Privacy Inquiries: For any privacy-related questions or requests (including data access or deletion), please email us at [email protected] with "Privacy Request" in the subject line.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time (for example, when adding new features or services). When we make changes, we will update the "Last Updated" date at the bottom of this page and, where appropriate, provide a notice in the app. Continuing to use AutoSpotterX after changes are posted constitutes your acceptance of the updated Privacy Policy.
Last Updated: August 29, 2026
