Privacy Policy
Effective date: August 8, 2026 · Last updated: August 8, 2026
AutoSpottr (“AutoSpottr,” “the app,” “we,” “us,” or “our”) is an iOS car‑spotting game. You photograph real cars you spot, the app identifies them, scores them for rarity, and files them into your personal catalog with experience points (XP). Optional social features let you compare with friends, appear on a global “Auto‑Race” ladder, join crews, and share spots to a community feed.
This policy explains what information the app handles, how it is handled, and the choices you have. It covers the AutoSpottr app only.
If you do not agree with this policy, please do not use the app.
The short version
We built AutoSpottr to collect as little as possible, and to protect the photos you take:
- Your full‑resolution photos never leave your phone. The original photo of every car you spot is stored only in the app on your device. It is never uploaded to our servers.
- License plates and faces are masked on your device before any image is shared, using a solid, non‑reversible block — not a blur.
- Photo location data (EXIF/GPS) is removed from images before anything leaves the device.
- We do not store your location. A single, coarse location check happens on your device to warn you near restricted‑photography sites, and is then discarded. Only the two‑letter country of a spot is saved, so cars caught abroad can count toward achievements.
- We never store license‑plate data of any kind — not the characters, not a partial, not a hash.
- We do not run advertising and we do not use third‑party analytics or tracking to build a profile of you.
The rest of this policy describes these practices in full.
1. Information we collect
By using AutoSpottr you consent to the collection and use of information as described in this policy. Where the law requires it, we rely on your consent — which you can withdraw at any time (see Section 7). The app only requests access to data relevant to its core functionality (for example, the camera to photograph cars), and each system permission is explained in a purpose prompt at the moment it is needed.
Account information
You can use much of AutoSpottr as an anonymous “guest.” To save your catalog to an account and use social features, you can sign in with:
- Sign in with Apple — we receive a unique Apple identifier and, if you choose to share it, your name and email address. If you use Apple’s “Hide My Email” feature, we only receive Apple’s private relay address.
- Email and password — we receive the email address you register.
Authentication is handled through Google Firebase Authentication. We store an anonymous user identifier (UID) that ties your account to your data.
Profile information
When you have an account, we store a profile that may include: your display name, an optional profile photo (avatar), your country, an auto‑generated friend code, your XP, level, car count, account creation date, your crew (if any), your chosen profile customizations (showcase cars, accolades, banner style), and your subscription status.
Cars you catch (captures)
For each car you photograph, the app records details about the car, such as make, model, year, body style, paint color, rarity tier, estimated 0–100 performance figure, and the two‑letter country where the spot was taken.
Photos
The full‑resolution photo stays on your device and is not uploaded. When you have an account and syncing is on, only reduced‑size, masked, metadata‑stripped image renditions are uploaded so your catalog can appear on other surfaces:
- a small thumbnail used in friends’ list views, and
- a small rendition used in the community feed (only if you publish to the feed).
Every image that leaves the device has first been through the on‑device masking and metadata‑stripping described in Section 2.
Location
AutoSpottr asks for “when in use” location access at the moment you take a photo, and only if the restricted‑zone feature is active. When granted:
- A single, coarse position is read and compared, on your device, against a bundled list of restricted‑photography areas. The result is a yes/no warning. The coordinate is never stored, uploaded, logged, or attached to a capture — it is discarded immediately.
- Separately, to support “world‑tour” achievements, the app determines the two‑letter country code of a spot. This requires a one‑time reverse‑geocoding lookup, which is performed by Apple’s mapping service; the coordinate is used for that lookup and discarded. Only the country code is saved — never a coordinate, and never anything more precise.
Declining location access is fully supported; the app still works, and captures are allowed through.
Community content
If you use social features, we process the content you create and the connections you make: feed posts (the masked rendition plus the car details above), reactions, comments (short text), the friends you add, the crews you found or join, reports you submit, and the accounts you block.
Subscription and purchase information
AutoSpottr offers an optional auto‑renewing subscription. Purchases are processed by Apple through the App Store, and subscription status is managed through RevenueCat, which performs receipt validation and tells the app whether your subscription is active. We do not receive or store your payment card details; those are handled by Apple. We store a flag indicating whether your account has an active subscription.
Technical information
To keep the service secure and working, we use Google Firebase App Check to confirm that requests come from a genuine copy of the app, and standard Firebase infrastructure that processes technical data such as your device’s IP address and basic request information in order to deliver the service. AutoSpottr does not include third‑party advertising SDKs or third‑party analytics/tracking SDKs, does not track you across apps and websites owned by other companies (and therefore does not present an App Tracking Transparency prompt), and does not build a marketing profile of you.
2. How we protect the photos you take
Protecting the photographs you take is central to how AutoSpottr is built.
- On‑device masking. Before any image is shared off the device, license plates and faces are detected and covered with a solid, opaque block. This is a deliberate, non‑reversible redaction — not a blur or pixelation, which can be reversed.
- Metadata stripping. EXIF and GPS metadata are removed from images by re‑rendering them before upload.
- Fail‑closed design. If masking cannot be completed, or if a plate or face is still detected on an already‑masked image, or if the masking check cannot run, the capture stays on your device and is not uploaded.
- No plate data, anywhere. The app never stores what a license plate says — not the characters, not a partial, not a hash. The recognition system is only asked whether a plate is still visible, and cannot report its contents.
- Shared car renders. The app can generate a stylized illustration of a car spec (for example, a particular model in a particular color). These renders are created from the masked image, not the original, describe a car type rather than a specific moment, and are stored on a shared path that is not tied to any individual user. The photograph itself is never part of a render.
3. How the app identifies cars (automated processing)
When you take a photo, a reduced‑size copy of the image is sent to a third‑party artificial‑intelligence provider — Google’s Gemini model (through Google’s Firebase AI Logic service) — to identify the car and return details such as make, model, year, and body style, and to confirm whether a plate or face is still visible for the safety checks described above. This sharing of the image with a third‑party AI service is integral to the app’s core “spot and identify a car” function; by taking a photo to be identified, you consent to this processing. It is an automated process used to score and file your catch. No license‑plate contents are requested or returned, and the image is not used to train third‑party AI models for other purposes.
4. How we use information
We use the information described above to:
- create and maintain your account and catalog;
- identify the cars you photograph and score them for rarity and XP;
- power the optional social features you choose to use (friends, ladder, crews, feed);
- run the restricted‑zone safety warning and the country‑based achievements;
- process and manage your subscription;
- keep the service secure, prevent abuse, and moderate community content; and
- respond to your support requests.
5. How information is shared
We do not sell your personal information, and we do not share it for advertising. Information is shared only in these ways:
- With other users, when you choose to be social. If you publish to the feed, your masked rendition, display name, country, and the car details appear to other spotters. If your profile is public, your display name and stats can appear on the Auto‑Race ladder and to friends. Comments you post are visible to others. You control this — see Section 7.
- With service providers that operate the app on our behalf:
- Google Firebase (Authentication, Cloud Firestore database, Cloud Storage, Cloud Functions, App Check) — our backend infrastructure.
- Google Gemini via Firebase AI Logic — car identification (a third‑party AI service; see Section 3).
- Apple — Sign in with Apple, App Store purchases, and reverse‑geocoding for the country lookup.
- RevenueCat — subscription/receipt management.
- For legal reasons — if required by law, or to protect the rights, safety, and security of our users, the public, or the app.
We require each third party with whom we share your data — including the AI, analytics, and infrastructure providers named above, and any parent, subsidiary, or related entity that may access your data — to provide the same or equal protection of your data as stated in this policy and as required by the Apple App Store Guidelines. We do not sell your personal data, and we do not share it with third parties for their own advertising or marketing.
6. Data retention
Your full‑resolution photos remain on your device until you delete them (or delete the app). The car details, uploaded masked renditions, profile, and social content tied to your account are retained while your account exists.
When you delete your account (Section 7), the app removes your captures and their uploaded images, your avatar, your friendships, your feed posts, your block list, your crew membership, your friend code, and your user profile. Your comments and reactions on other people’s posts are removed by a server process when your account is deleted. Shared car renders are not tied to your identity and may remain available for other users.
You can request deletion of your data, and withdraw consent to processing, at any time — by deleting your account from within the app (which erases the data listed above), by turning off the relevant settings, or by contacting us at the address in Section 12. We will honor deletion requests as required by applicable law.
7. Your choices and rights
- Feed publishing. Sharing your spots to the community feed is a setting you can turn off. Turning it off stops new posts; you can also withdraw posts you have already shared.
- Profile visibility. You can choose whether your profile is listed publicly on the ladder.
- Blocking. You can block other spotters.
- Location. You can grant or deny location access at any time in iOS Settings. Denying it disables only the restricted‑zone warning and country achievements.
- Account deletion. You can permanently delete your account and its associated data from within the app (in the account settings), as required by the App Store Guidelines. Guest sessions have no account to delete.
- Withdrawing consent. You can withdraw consent for optional data uses by turning off the relevant setting (for example, feed publishing or location) or by deleting your account. Withdrawing consent does not affect processing already carried out.
- Using the app without an account. You can use AutoSpottr’s core spotting features as a guest, without signing in.
- Subscription management. You manage or cancel your subscription through your Apple ID / App Store settings.
Depending on where you live, you may have additional rights over your personal data (such as access, correction, or deletion). To make a request, contact us using the details in Section 12.
8. Children’s privacy
AutoSpottr is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to remove it. The app’s community features are subject to the App Store age rating shown on its store listing.
9. Security
We use industry‑standard measures to protect your information, including authenticated access, server‑side security rules that restrict who can read and write data, and app‑integrity checks. The design also minimizes risk by keeping original photos on your device and never storing plate or precise‑location data. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
10. International data transfers
AutoSpottr relies on service providers (including Google and Apple) whose infrastructure may process and store data in countries other than your own. By using the app, you understand that your information may be transferred to and processed in those locations, which may have different data‑protection laws than your country.
11. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the app after an update means you accept the revised policy.
12. Contact us
If you have questions about this policy or your data, contact us at:
crescent1992@gmail.com
Hitamo