Privacy Policy
Last updated: January 2026
Introduction
Car Reveal is a mobile application that uses artificial intelligence to identify cars from photos. This privacy policy explains how we collect, use, store, and protect your personal information when you use our service.
We are committed to protecting your privacy and being transparent about our data practices. This policy describes the minimal data we collect and how it is used to provide you with car identification services.
Data Controller: Delpha Labs, France
Contact: delphalabs@gmail.com
Legal Basis for Processing
We process your personal data under the following legal bases (as required by GDPR):
- Contractual necessity: Processing your photos for car identification and managing your account are necessary to provide the service you signed up for.
- Legitimate interest: We use anonymized analytics to improve the app's functionality and user experience.
- Consent: You consent to data processing when you sign in with Google and use the service.
Data Collection
Car Reveal collects the following types of data:
- Photos: When you upload a photo to identify a car, we process the image using our AI service. The original full-resolution image is not stored on our servers. Only a small thumbnail (512px width) is saved to Firebase Storage for your scan history.
- User Account: If you choose to sign in with Google, we collect your email address for account management purposes. This is stored securely using Firebase Authentication.
- Scan History: We store information about your car identifications, including the thumbnail image, identified make/model/year, and timestamp. This allows you to access your scan history within the app.
- Subscription Data: If you subscribe to Car Reveal Pro, your purchase is processed through Google Play or the Apple App Store. We use RevenueCat to manage subscription status. We do not directly collect or store your payment information (credit card numbers, billing address, etc.).
- Analytics: We use PostHog for anonymized analytics to help us improve the app. This data is aggregated and cannot be used to identify individual users.
What we do NOT collect:
- Original full-resolution images
- EXIF metadata from photos (location, camera settings, etc.)
- IP addresses
- Device IDs or unique device identifiers
- Payment card details
- Personal information beyond what is necessary for the service
Data Usage
We use the data we collect for the following purposes:
- Car Identification: Your photos are sent to the OpenAI GPT-4o Vision API to identify the make, model, and year range of vehicles. This is the core functionality of our service.
- Scan History: We store your scan history so you can access previously identified cars within the app. This includes thumbnails and identification results.
- Service Improvement: We use anonymized analytics data to understand how the app is used and to improve its functionality and user experience.
- Account Management: Your email address is used to manage your account, enforce scan quotas, and provide customer support if needed.
- Subscription Management: Your anonymous user ID is shared with RevenueCat to manage your subscription status and entitlements.
Data Storage
All data is stored using Firebase (Google Cloud Platform) services:
- Location: Our Firebase project is deployed in the EU region (europe-west1) to ensure GDPR compliance and data residency requirements.
- Thumbnails: Small thumbnail images (512px width) are stored in Firebase Storage. These are associated with your account and scan history.
- Scan Data: Car identification results, timestamps, and metadata are stored in Firestore, Firebase's NoSQL database.
- Authentication: User account information is managed by Firebase Authentication, which uses industry-standard security practices.
All data is encrypted in transit and at rest using Firebase's built-in security measures.
Data Retention
- Scan data and thumbnails are retained until you delete them individually or delete your account.
- Account data is deleted immediately upon account deletion request.
- Analytics data is aggregated and anonymized — it cannot be traced back to you and is retained indefinitely in aggregate form.
We do not retain your data after account deletion. When you delete your account, all associated scans, thumbnails, and account information are permanently removed from our servers.
Data Sharing
We share data only with the following third-party services that are necessary to provide our functionality:
- OpenAI: Photos are sent to OpenAI's GPT-4o Vision API for car identification. OpenAI's API terms state that data submitted via the API is not used for model training. We do not send any personal information beyond the image itself. OpenAI Privacy Policy
- RevenueCat: Your anonymous user ID and subscription status are managed through RevenueCat for in-app purchase processing. RevenueCat does not receive your email, photos, or scan data. RevenueCat Privacy Policy
- PostHog: Anonymized analytics data may be sent to PostHog for app usage analytics. This data cannot be used to identify individual users. PostHog Privacy Policy
- Google (Firebase): We use Google's Firebase services for data storage and authentication. Google Privacy Policy
We do not sell your data to third parties. We do not share your personal information with advertisers, data brokers, or any other parties for marketing purposes.
Your Rights
You have the following rights regarding your personal data:
- Access: You can access all your personal data, including your scan history, through the app.
- Deletion: You can delete individual scans from your history at any time within the app.
- Account Deletion: You can delete your account and all associated data at any time. This will permanently remove all your scans, thumbnails, and account information from our servers.
- Rectification: You can request correction of any inaccurate personal data.
- Restriction: You can request that we restrict processing of your data in certain circumstances.
- Complaint: You have the right to lodge a complaint with a supervisory authority (in France, this is the CNIL — cnil.fr).
To exercise any of these rights, please contact us at delphalabs@gmail.com.
Children's Privacy
Car Reveal is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected data from a child under 13, please contact us at delphalabs@gmail.com and we will promptly delete it.
Security
We take security seriously and implement the following measures to protect your data:
- Authentication: All user accounts are protected by Firebase Authentication, which uses industry-standard security practices including OAuth for Google Sign-In.
- Quota Enforcement: Scan quotas are enforced server-side to prevent abuse and ensure fair usage of the service.
- Secure API Endpoints: All API endpoints use HTTPS encryption to protect data in transit.
- Data Encryption: All data stored in Firebase is encrypted at rest using Google Cloud's encryption standards.
- Access Controls: Data access is restricted to authenticated users and is scoped to their own account data only.
Contact
If you have any questions, concerns, or requests regarding this privacy policy or how we handle your data, please contact us at:
Email: delphalabs@gmail.com
We will respond to your inquiry within 7 business days.
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new privacy policy on this page and updating the "Last updated" date.
Your continued use of Car Reveal after any changes to this privacy policy constitutes your acceptance of the updated policy.