legal
privacy policy
Version 1.0 · Effective 1 July 2026
AutoSense ("we", "us") builds vehicle health software. This policy explains what data we collect through the AutoSense mobile app, fleet dashboard and this website, why we collect it, and the controls you have over it. We wrote it to be read, not skimmed past. It is designed to comply with the Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Regulation (NDPR).
1. What we collect
Account data. Email address, name (optional) and country. Passwords are stored only as salted hashes — we can never read them.
Vehicle data. Make, model, year, engine, mileage and — if you scan it — your VIN. VINs are encrypted at rest with AES-256-GCM.
Diagnostic data. Fault codes, freeze frames, sensor readings (for example battery voltage and fuel trim) read from your vehicle's OBD-II port by an adapter you own. This data describes your car, not you.
Trip and location data. If you enable trip tracking, we record trip start/end times, distance and driving events. Stored locations are coarsened to geohash precision 6 (roughly a 1.2 km × 0.6 km cell) — we deliberately do not keep your exact parking spot.
Payment data. Credit purchases are processed by Paystack. We receive a payment reference and status — never your card number.
Website data. This site uses Cloudflare Web Analytics, which is cookie-free and does not track you across sites. The waitlist form stores the email you submit. The shop stores your vehicle selection in your own browser (localStorage), not on our servers, until you create an account.
2. What we use it for
- Showing you your vehicle's health, history and reminders — the product itself.
- Generating AI explanations when you spend credits (your vehicle context is sent to our AI provider for that request only).
- Crediting your wallet and preventing duplicate or fraudulent payments.
- Sending service, fault and recall notifications you have enabled.
- Aggregated, anonymised statistics — for example the community fuel quality map, which never identifies a person or a vehicle.
3. What we never do
- We never sell your personal data.
- We never share your location or diagnostic history with insurers, lenders or any third party unless you explicitly turn on a sharing feature and can see exactly what is shared.
- We never read your VIN for any purpose other than vehicle identification, recall matching and compatibility.
4. Sharing you control
Mechanic share links, family monitor invites, vehicle history certificates and any future insurer or lender data sharing are all user-initiated, visible in your settings, and revocable. Each shows you what the recipient sees.
5. Where your data lives
AutoSense runs entirely on Cloudflare infrastructure (Workers, D1, R2). Data is encrypted in transit (TLS) and at rest. A local copy lives on your device so the app works offline; it syncs when you reconnect.
6. Your rights (NDPA/NDPR)
You may access, correct, export or delete your data at any time. Export and import are built into the app (Settings → Data). Account deletion is available in-app and removes personal data within 30 days, subject to payment records we must retain by law. To exercise any right by email, contact contact@autosense.app.
7. Retention
Vehicle and diagnostic history is kept while your account is active because its whole value is longitudinal. Waitlist emails are deleted or migrated to accounts within 12 months of launch. Payment records are retained as required by Nigerian financial regulation.
8. Children
AutoSense is not directed at children under 13 and we do not knowingly collect their data. Family Vehicle Monitor invites are intended for licensed drivers and household members with the account owner's consent.
9. Changes
We will notify you in-app and by email of material changes to this policy at least 14 days before they take effect. The current version is always at autosense.app/privacy.
10. Contact
Data questions: contact@autosense.app
Security reports: security@autosense.app (see also /.well-known/security.txt)