Last Updated: May 16, 2026
This Privacy Policy explains what information AutoAngel collects, how we use it, and the choices you have. We try to keep this short and plain — if anything is unclear, contact us through the in-app Support page.
• Account: email address, display name, and (optional) profile photo • Vehicles: make, model, year, trim, mileage, body type, fuel type, oil type, nickname, (optional) car photos, and (optional) Vehicle Identification Number (VIN) • Maintenance history: every service you log creates a permanent record — date, service type, mileage, and (optional) cost, vendor, and notes • App settings and preferences • Support tickets: subject and description you submit through the in-app Support page
• Device information: platform (iOS / Android), OS version, app version — used to triage support tickets and crash reports • Approximate location: when you grant permission, we use coarse GPS to fetch local weather. Location is reverse-geocoded to a city name; raw coordinates are not stored • Crash and performance data: see "Crash Reporting" below • Subscription status: see "Subscription Management" below
AutoAngel uses the U.S. National Highway Traffic Safety Administration's public APIs (vPIC and recallsByVehicle) for two purposes: • Recall Lookup: when you use the Recall Lookup tool, we send a VIN or year/make/model to NHTSA to look up safety recalls. These requests are anonymous and we do not store the VINs you enter into the Recall Lookup tool. • VIN Auto-Fill: when you enter a VIN on the Add Vehicle or Vehicle Detail screen, we send that VIN to NHTSA to auto-fill the vehicle's make, model, year, trim, fuel type, and body type. NHTSA receives the VIN or year/make/model in both cases but does not receive any AutoAngel user identifier. NHTSA may log standard server request data. Auto-Fill results are saved to your account only after you confirm by saving the vehicle.
Every time you log a maintenance service in AutoAngel, we create a permanent record of that event. Each record lives in two places: • Your personal account workspace, where you can view, edit, and delete it. • If you've entered a VIN for the vehicle, a separate VIN-keyed maintenance bundle (stored under a hashed VIN identifier). This bundle is what makes the optional "transfer your maintenance history when you sell" feature work — see the next section. Why we treat VIN with extra care: when a VIN is linked to your AutoAngel account, the U.S. Federal Trade Commission considers it "reasonably linkable to a consumer" — meaning it's treated as personal information. We only collect a VIN when you choose to enter one, and we use it only for (a) auto-filling your vehicle details, (b) tying your maintenance records to a specific vehicle for authenticity, and (c) enabling the optional transfer flow described next. You can remove a VIN from a vehicle at any time on the Vehicle Detail screen; doing so unlinks the VIN but does not delete your maintenance records.
If you sell a vehicle, you can transfer your maintenance history to the next owner through AutoAngel. This is an opt-in feature that requires a separate, affirmative consent at the time of transfer. Method 1 — Transfer Code (works for any vehicle, with or without VIN): You generate a one-time transfer code from the vehicle's settings. You share the code (or a PDF report that includes a QR code) with the buyer. The buyer enters the code in their AutoAngel to import the history. Method 2 — Buyer Claim with Title Verification (requires VIN): If you didn't provide a transfer code, the buyer can still claim the history by: • Entering the VIN in their AutoAngel • Uploading a photo of the vehicle title showing their name and the matching VIN • Waiting 7 days for you to confirm or deny via push notification or email (or 14 days if your AutoAngel account has been deleted — see Section 14 on the optional 30-day grace period) Title images are processed by an automated OCR (optical character recognition) service to verify the VIN and the buyer's name. Title images are discarded immediately after verification; we do not retain them. What's transferred to a buyer: the maintenance event log only — dates, service types, mileage, costs, vendors, and notes you've entered. Your name, email address, profile photo, and other personal information are never transferred to a buyer. All transfer events (codes generated, claims submitted, confirmations/denials, completions) are logged for audit purposes for 1 year.
• Provide the AutoAngel maintenance tracking service • Calculate maintenance schedules and vehicle health scores • Auto-fill vehicle details from your VIN via NHTSA's public API • Send push notifications for maintenance reminders (with your permission) • Sync your data across devices • Generate maintenance history reports (PDF export, Pro feature) • Enable transfer of maintenance records between owners when you initiate the transfer flow (with your explicit consent) • Diagnose and fix bugs and crashes • Respond to support requests • Process and verify subscription purchases
Your account data, vehicles, and maintenance records are stored in Google Firebase (Cloud Firestore + Firebase Authentication). Photos are stored in Firebase Cloud Storage. VIN-keyed transfer bundles described in Section 5 are stored separately in Firestore under a hashed VIN identifier and can only be read through server-side Cloud Functions that enforce the verification rules in Section 6. Data is encrypted in transit (TLS) and at rest, and access is restricted by per-user security rules.
We use Sentry to capture crash reports and performance data. Sentry receives: • Stack traces and error messages from app crashes • Your account email and user ID, attached so we can correlate crashes with support tickets • A short anonymized "session replay" (a sketch of the screens you visited just before a crash — no keystrokes, no photo content, no Firestore data) Replay sampling is set to 10% of normal sessions and 100% of error sessions. You can opt out of crash reporting from the in-app Settings.
AutoAngel Pro subscriptions are managed through RevenueCat, which connects to the Apple App Store and Google Play. RevenueCat receives: • Your anonymous app user ID (linked to your Firebase user ID) • Subscription transaction status (active, expired, trial, etc.) • The product purchased and price RevenueCat does not receive your name or email. Apple and Google handle the actual payment — AutoAngel and RevenueCat never see your credit card details.
The home page weather is fetched from Open-Meteo, a free public weather API. We send the city you've selected (or your coarse location, if you granted permission) and receive a temperature and weather condition in return. No account information is sent.
AutoAngel may send push notifications for upcoming maintenance, mileage reminders, transfer-claim confirmations (if a buyer is attempting to claim a vehicle's history from you), and (Pro tier) weather-aware tips. You can disable notifications at any time in the in-app Settings or your device's system settings.
These third parties may receive data as described above: • Google Firebase (Auth, Firestore, Storage, Cloud Functions) • Sentry (crash + performance monitoring) • RevenueCat (subscription management) • Apple App Store / Google Play (payment processing) • NHTSA vPIC + Recalls API (VIN decoding and recall lookups) • An automated OCR service (only used for title-photo verification during buyer-claim transfers, as described in Section 6; images discarded after verification) • Open-Meteo (weather) We do not sell, trade, or rent your personal information to any third party for advertising or marketing.
You have the right to: • Access the personal data tied to your account • Correct inaccurate data — edit your profile, vehicles, and maintenance records directly in the app • Delete your account and all associated data — go to Profile → Danger Zone → Delete Account. This permanently removes your account, vehicles, photos, VIN data, and maintenance history from both your personal workspace and any VIN-keyed transfer bundles. • Optional 30-day grace period at deletion: if you're in the process of selling a vehicle when you delete your account, you can opt in at the deletion confirmation screen to retain an anonymized copy of that vehicle's maintenance bundle for 30 days, so the buyer can still claim the history. Your name, email, and other personal identifiers are stripped immediately; only the maintenance event log and the VIN-keyed bundle remain. After 30 days, this anonymized data is automatically and permanently deleted. This grace period is opt-in only — by default, deletion is immediate and total. • Linked support tickets are anonymized — we keep the ticket content for our records, but your identifying info is removed • Disable analytics, crash reporting, location, and notifications from the in-app Settings • Export your data — contact us via the in-app Support page and we'll provide a download Residents of California (CCPA) and the EU/UK (GDPR) have additional rights including the right to lodge a complaint with a supervisory authority. Contact us through Support to exercise any of these rights.
AutoAngel is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us information, contact us through Support and we will delete it.
We may update this Privacy Policy as the app evolves. Significant changes will be surfaced in-app or via email. Continued use of AutoAngel after a change means you accept the updated policy.
Questions about this Privacy Policy or your data? Use the in-app Support page (Menu → Support) or email [email protected].