OBD Vault — Privacy Policy

Global Privacy & Data Protection Notice (GDPR, CCPA/CPRA, LGPD & Global Standards) · Effective September 4, 2026

Privacy by Design: OBD Vault is built with a Local-First architecture. You can diagnose your vehicle completely offline without creating an account. Your vehicle telemetry and diagnostic logs belong to you, and we never sell your personal data to data brokers.

1. Data Controller

The Data Controller responsible for the processing of your personal data under global privacy frameworks (including EU/UK GDPR, California CCPA/CPRA, and international data protection laws) is:

Bahdan Hal · OBD Vault
Trader Identification & EU Establishment (DSA / GDPR):
Address: Osiedle Kaszubskie 21/58, 84-200 Wejherowo, Pomorskie, Poland
Phone: +48 721667204
Direct Contact: bahdan.hal@hotmail.com
Privacy Office: privacy@obd-vault.com
Official Website: https://obd-vault.com

2. Core Architectural Principles

  • Local-First: Vehicle telemetry, OBD-II scan sessions, and Diagnostic Trouble Codes (DTCs) are stored in an encrypted local database (SQLCipher) on your device.
  • Data Sovereignty & No Brokering: We never sell, rent, or trade your personal data, VIN, or vehicle telemetry to data brokers, insurers, or unauthorized third parties.
  • Read-Mostly Vehicle Access: The app never issues arbitrary ECU commands. Clearing trouble codes is the only state-altering function and requires explicit confirmation.
  • No Autonomous AI Feeding: We never stream diagnostic telemetry to AI models automatically. Access requires explicit user authorization via OAuth 2.1. AI clients cannot change vehicle or diagnostic records; requesting an export creates a temporary download reference that expires automatically.

3. Categories of Data Processed

Category Examples Storage Location
Vehicle Data VIN, make, model, year, fuel type, engine displacement. Local device; synced to Cloud Vault only if enabled.
OBD-II Diagnostics PIDs (RPM, coolant temp, speed, MAF, voltage), DTC fault codes, freeze frames, readiness monitors. Local device; synced to Cloud Vault only if enabled.
Account Credentials Email address, salted & hashed password (Argon2id). Production PostgreSQL (EU region) only upon registration.
App Analytics & Diagnostics Crash reports, device OS version, adapter BLE connection latency, feature usage counts. Aggregated diagnostic metrics; never correlated with private vehicle VINs.
Technical Logs IP address, request path, status code, rate-limiting counters. Protected server logs (rotated & purged every 14 days).

4. Advertising, Analytics & Service Optimization

To support ongoing development, maintain compatibility across hundreds of vehicle models, and provide a functional free tier, OBD Vault may utilize standard advertising and diagnostic analytics services:

  • Advertising & Sponsored Recommendations: Free editions of the application may display contextual advertisements, sponsored auto-parts recommendations (such as verified replacement sensors or DIY tools), or third-party advertising networks (such as Google AdMob). Paid Vault subscribers receive a 100% ad-free experience.
  • Application Analytics & Crash Diagnostics: We may collect anonymized performance telemetry, crash logs, and aggregated feature metrics to detect adapter communication issues, improve protocol negotiation, and fix stability regressions.
  • User Consent & Privacy Controls: Where required by applicable laws (such as GDPR, CCPA, or Apple's App Tracking Transparency framework), you have the right to consent to or opt out of personalized tracking. Non-personalized advertising and aggregated analytics are provided when opted out.

Optional email marketing: We send OBD Vault news and promotional offers by email only with your explicit consent and after email verification. Consent is optional and can be withdrawn at any time in account settings or using the unsubscribe link in an email. We record your choice, the consent text version, source and time. Registration, verification and password-reset messages are service communications.

5. Legal Basis for Processing (GDPR Art. 6)

We process your personal data strictly according to lawful grounds established by Article 6 of the GDPR:

  • Contractual Necessity (Art. 6(1)(b)): To provide the mobile diagnostic functions, cloud sync across your devices, and user account services.
  • Explicit Consent (Art. 6(1)(a)): For connecting external AI assistants (ChatGPT, Claude) through our OAuth 2.1 Model Context Protocol (MCP) server to access vehicle diagnostics and requested exports, and for personalized advertising/tracking identifiers where mandated by law.
  • Legitimate Interests (Art. 6(1)(f)): Protecting our API against brute force attacks and abuse, serving non-intrusive contextual ads in free tiers, measuring crash telemetry, and improving software stability.
  • Legal Obligation (Art. 6(1)(c)): Retaining transaction and subscription records for mandatory statutory accounting and tax compliance.

6. AI & Model Context Protocol (MCP)

OBD Vault provides an optional connector for AI clients (e.g., ChatGPT) using the open Model Context Protocol (MCP):

  • User-Initiated: Connects only when you explicitly log in and authorize the connection via browser OAuth 2.1 with PKCE.
  • No Vehicle or Record Changes: AI clients cannot clear fault codes, modify diagnostic records, or send vehicle commands. The export tool can create a temporary download reference when you request an export; it expires automatically.
  • Privacy Guard: VIN numbers are masked by default in generic telemetry queries to prevent unnecessary exposure.
  • Revocation: You can disconnect and revoke access at any time from your account settings.

7. Sub-processors & Hosting (GDPR Art. 28)

Data processing is conducted using enterprise-grade infrastructure located inside the European Union:

  • Hosting & Database: OVHcloud SAS (France) & Hetzner Online GmbH (Germany) — ISO 27001 certified, full GDPR Data Processing Agreements in place.
  • App Distribution & Billing: Apple Inc. (iOS App Store) & Google Ireland Limited (Google Play). Payment details are handled entirely by Apple and Google.
  • Advertising & Analytics (Free Tiers): Google Ireland Limited / Google LLC (Google Mobile Ads, Firebase Crashlytics / Analytics) for app reliability and ad delivery in free tiers.

8. Data Retention & Right to Erasure (Art. 17 GDPR)

You have full control over your data lifecycle:

  • Local Data: Cleared immediately upon deleting the mobile app or clearing app storage.
  • Right to be Forgotten: You can permanently delete your cloud account at any time in the mobile app settings or by calling DELETE /api/v1/accounts/me. This triggers an immediate, cascade deletion of all your vehicle records, diagnostic scans, observations, and revokes all active tokens.
  • Data Portability (Art. 20 GDPR): You can export your entire dataset in machine-readable JSON at any time via GET /api/v1/accounts/export.
  • Backups: Database backup dumps are encrypted and automatically deleted after a 30-day rotation cycle.

9. Your Rights as a Data Subject

Under global data privacy frameworks (including the EU/UK GDPR, California CCPA/CPRA, and Brazilian LGPD), you have full statutory rights to access, rectify, erase, restrict processing, obtain data portability, and object to processing or automated profiling. We never sell your personal information or telemetry to data brokers.

To exercise any of your rights, email our Privacy Office directly at privacy@obd-vault.com. Verified requests are fulfilled within 30 days without charge.

10. Device Permissions Summary

  • Bluetooth / Nearby Devices: Used exclusively to communicate with your ELM327 BLE adapter. Never used for beacon tracking or location profiling.
← Terms of Service · Contact Privacy Office