TrustThisCar

Privacy Policy

Last updated: 22 September 2026

TrustThisCar reads a car's on-board diagnostics and turns it into a plain-language report. This page explains exactly what leaves your phone, where it goes and how to get rid of it.

1. Who is responsible for your data

The data controller is Caregnato Consulting, Via Monte di Pietà 7, 36050 Pozzoleone (VI), Italy, VAT 04605580242.

Privacy questions: privacy@trustthiscar.com. Anything else: support@trustthiscar.com.

2. What we collect

DataWhere it comes fromWhy
Your email addressYou, when you create an accountTo sign you in, to link your credits and reports to you, to reply to support requests
Your passwordYouStored only as a cryptographic hash by our authentication provider. We never see it.
Vehicle diagnostic data: VIN, fault codes, freeze frame, live sensor values, readiness monitors, ECU distance and fuel counters, battery voltage, protocol usedThe car's ECU, through the OBD-II dongleTo produce the report you asked for
The mileage you type in, and the make, model and year you type in if we cannot read themYouTo check the odometer against the counters stored in the ECU, and to tailor the report
The generated reportProduced by usSo you can open it again and share it with a seller
Credit and purchase records: how many report credits you bought and used, and whenThe app store, through our payment providerTo run the credit balance and to keep the accounting records the law requires
Server logs: IP address, timestamp, endpoint, error messagesAutomaticSecurity, abuse prevention and debugging

What we deliberately do not collect

The raw scan logs the app can save on your phone for troubleshooting stay on your phone. They are uploaded nowhere. If you choose to send one to us with the share button, you are sending it deliberately, and we use it only to fix compatibility with your dongle and car.

3. A note about the VIN

A VIN identifies a vehicle, not a person, and on its own we cannot tie it to an owner. But if you scan your own car and it is registered to you, treat it as data about you too. That is why VINs are covered by everything below, including deletion.

4. Why we are allowed to process it (legal bases)

5. Who we share it with

We do not sell your data and we do not share it for advertising. We use these providers to run the service:

ProviderWhat it seesWhere
Supabase (database and authentication)Account, scans, reports, credit ledgerEuropean Union (Frankfurt)
Railway (application server)The data in transit while a report is being generatedEuropean Union
Anthropic (the AI model that writes the verdict)The diagnostic data of the scan and the vehicle description. Not your email, not your account.United States
NHTSA vPIC (United States government VIN database)The 17-character VIN onlyUnited States
Apple, Google and RevenueCat (purchases)The purchase event and an anonymous user identifierUnited States and European Union

We may also disclose data where a law or a valid order from a public authority requires it.

6. Transfers outside the European Economic Area

Sending the scan to the AI model and the VIN to the vPIC database involves a transfer to the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and on the data-processing terms we have in place with each provider. You can ask us for details at privacy@trustthiscar.com.

Your diagnostic data is not used to train AI models.

7. How long we keep it

8. Your rights

Under the GDPR (and the UK GDPR if you are in the United Kingdom) you can ask us to give you a copy of your data, correct it, delete it, hand it over in a portable format, restrict how we use it, or object to processing based on legitimate interests. Write to privacy@trustthiscar.com from the address on your account and we will answer within 30 days.

The fastest route for deletion is in the app: Account, then Delete account. See Delete your account for what happens.

If you think we have handled your data badly you can complain to your supervisory authority: in Italy the Garante per la protezione dei dati personali, in the United Kingdom the Information Commissioner's Office, or the authority in your own country.

9. Security

Traffic between the app and our servers is encrypted with TLS. The database sits behind row-level security so one account cannot read another's scans. Passwords are salted and hashed by our authentication provider and are never visible to us. The report link contains a 32-character random token, so it cannot be guessed, but anyone you send that link to can open the report. Share it only with people you want to see it.

10. Children

TrustThisCar is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, write to us and we will delete it.

11. Changes

If we change this policy we will update the date at the top, and for anything that materially affects you we will tell you in the app before the change takes effect.