1. Who is responsible
Andrzej Nowakowski operates CarTuning.ai and is the controller of the personal data described here. For support and privacy requests, contact support@cartuning.ai.
This policy covers the CarTuning.ai app, its API, and these support pages. Apple and other providers also publish notices for the processing they perform through their own services.
2. Information we use
- Account and device information: randomly generated account and installation identifiers, credential verifiers, a purchase account token, account settings and onboarding preferences. If you sign in with Apple or Google, we also use the provider name, its stable account identifier (subject), and a verified email address when supplied, including an Apple private relay address. We do not request your name or a Google profile. Authentication also uses short-lived sign-in challenges and app-session records.
- Your content: uploaded car or interior photos, any metadata embedded in those original files, vehicle details, modification instructions, saved projects and generated images.
- Purchases and preview allowances: Apple transaction and subscription identifiers, product, purchase and expiry dates, renewal/refund status, and the record of previews granted or used. We do not receive your full payment-card details from Apple.
- Security and service operation: IP addresses, account/installation association markers, access restrictions and generation status or error codes. Hosting infrastructure processes network information needed to deliver requests.
- Support: messages, contact details or attachments you voluntarily send to support.
Photos can contain people, registration plates, locations or other identifying information. Crop or obscure anything unnecessary before uploading. We do not need identity documents, payment-card numbers or recovery codes in support messages.
3. Why we use it
Account access, saved projects and purchase verification deliver the requested service (GDPR Article 6(1)(b)). Sending chosen images and instructions to fal.ai for AI generation requires your consent (Article 6(1)(a)).
Security, preventing repeated trial claims or payment replay, fault investigation and handling claims support legitimate interests (Article 6(1)(f)). Any applicable legal recordkeeping obligation uses Article 6(1)(c). Read the GDPR.
Providing content is optional, but image generation cannot work without the selected image and instructions. Device proof protects account access. Optional Apple or Google sign-in identifies the same server account across devices and lets us verify the login without receiving your provider password. Optional partner email offers require a separate consent. Using visualization categories to personalize those offers requires an additional consent. We do not sell personal data or perform cross-app tracking.
4. External providers
fal.ai — image generation
Pressing Generate sends your selected photo or a previous result from your account, together with editing instructions, through our server to fal.ai to create your image. A short notice is shown next to the Generate button. Selecting a photo or browsing the app alone does not upload it for AI processing. Each new visualization requires a new press of Generate; requests already submitted are not retracted by leaving the screen.
Our generation requests disable fal's saved JSON input/output history and request expiry of the temporary model-output CDN files after 24 hours. Uploaded photos, reference images and copies of completed results used by your saved garage are stored separately in fal.ai storage without an automatic expiry, until you delete the content or account. Our application server processes image bytes in memory and stores only file addresses and metadata in its database; it does not save photo files on its disk. Account deletion also requests deletion of those saved files from fal.ai, with retries if storage is unavailable. These controls do not promise immediate erasure from every provider system. See fal's retention documentation and privacy policy.
This release uses your uploaded photos and your app-generated results. Online product-image search and importing photos from product websites are not available.
Apple and Google — optional sign-in
The selected provider authenticates you and supplies a signed identity token. We verify it and identify your account by the provider and its subject identifier, never by matching email addresses. Apple sign-in requests email only; Google requests the openid and email scopes. We do not request the Apple full-name field, Google profile scope, contacts or mailbox access.
For Apple sign-in, the server stores a refresh token encrypted with a separate encryption key so it can revoke the authorization when you delete your account. For Google, the app exchanges the authorization code and sends only the identity token to our server; our server does not receive or store Google access or refresh tokens. The providers process sign-in under their own policies: Sign in with Apple and Google privacy policy.
Apple, hosting and communication
Apple processes in-app purchases and provides signed transaction information for server verification. Hosting and communication providers process data needed to operate the API and answer your messages. Information may also be disclosed when required by a valid legal obligation or to protect legal claims.
External providers may process information outside the European Economic Area. The applicable location and transfer arrangement depend on the provider and service. Contact us for information about a specific recipient and the safeguards applicable to a transfer. We do not claim that all processing stays in the EEA. EU information on international transfers.
5. Storage and deletion
Your account content is kept to provide your saved garage and history until you delete it or request erasure. Deleting an account removes its account record, linked Apple/Google identities and email, app sessions, sign-in challenges, projects, uploaded photos, generated images and recovery verifier from our active service. A generation already in progress must finish before account deletion can complete. File cleanup is retried if a storage operation fails.
If the account has an Apple sign-in authorization, we revoke it with Apple before completing deletion and remove the stored encrypted token. If revocation fails, deletion is not completed and must be retried. Our server has no Google access or refresh token to revoke. Deleting your app account removes its Google identity and app sessions; any remaining Google connection permissions can be managed in your Google account.
Limited records can remain after deletion: detached Apple transaction identifiers and purchase account tokens prevent the same transaction from being assigned again; hashed installation and credential markers prevent another free starter claim. These are retained only while needed for those purposes or applicable claims, rather than under an automatic fixed expiry. They do not preserve your photos or garage.
IP/account observations that have not been seen for 90 days are eligible for scheduled cleanup when the associated address is not actively banned. Active restrictions or a specific security investigation can require longer retention. Support correspondence is retained as needed to resolve the request and any related obligation or claim; there is no blanket promise of a fixed number of days.
Restricted operational database backups may contain earlier account data. A manual backup has been made for deployment recovery; an automatic rotation schedule and fixed maximum retention period have not yet been established. Deletion from the active service does not immediately erase an existing backup. Backup copies require separate removal or expiry, and a restore must reapply completed deletion requests before affected data is returned to service.
Copies you export, share or save in your photo library are outside the app's deletion function. Data already processed by an external provider follows the controls and notices described above. Uninstalling the app alone does not delete your server account. Deleting the account does not cancel your Apple subscription.
6. Sign-in across devices and private account recovery
If your account is linked to Apple or Google, sign in with that same provider account on another device to access the same server account. Ordinary sign-in supports multiple devices. Choosing a different provider does not merge accounts merely because the email address is the same.
You can also generate a private recovery code from your authenticated account. The code gives access to that same account on another device. Keep it private: the server stores a verifier, not the readable code, and support will never ask you to email the code or your device secret.
Code recovery preserves the existing account and purchases, changes its access secret, and signs out previously connected devices. A code is usable once and can be replaced or revoked. A narrowly matched retry can finish recovery if the success response was lost. Recovery metadata is deleted with the account. A purchase receipt alone does not authorize taking over an account.
7. Your rights and contact
Where the GDPR applies, you can request access, correction, erasure, restriction, or an eligible portable copy of your data, and object to processing based on legitimate interests. You can withdraw consent without affecting earlier lawful processing. Rights have legal conditions and exceptions. EU guidance on your rights.
Email support@cartuning.ai. We may need proportionate information to verify the account belongs to you; do not send authentication secrets. We respond without undue delay, normally within one month; any permitted extension will be explained. Request-handling guidance.
You can complain to a competent data-protection authority, including Poland's President of the Personal Data Protection Office (UODO).
8. Security and your choices
The API verifies account credentials, signed provider identity tokens and Apple transactions. An app session is bound to its installation and is valid for 30 days unless revoked earlier; the database stores only its HMAC verifier. A sign-in challenge is single-use, valid for five minutes and stores a hashed nonce. These validity periods are not a promise that expired database rows are automatically erased at that exact time. Recovery secrets use verifiers; Apple refresh tokens use encryption with a separate key. Recovery, sign-in and code management are rate limited. Technical checks may automatically restrict repeated free-trial use or suspicious account access. Contact support for a human review if a restriction appears incorrect.
The app does not require advertising identifiers, precise GPS location, contacts or biometric identification. It requests camera/photo access for the images you choose. These public pages have no analytics scripts, advertising cookies or external fonts. Device identity and app preferences are stored locally to keep the service working; browser administration may use essential login/security cookies.
We update this policy when the service or processing changes. The date above identifies the current version. Contact us if you need information about a previous version or a specific privacy concern.
Android, Google Play and reports
The Android app uses guest accounts; Sign in with Apple is available on iOS. Android payments are processed by Google Play. We send Google an opaque, randomly generated account identifier and use its Android Publisher API to verify purchases, renewals and entitlement changes. Our database stores encrypted Google purchase tokens, token hashes, order IDs, product and expiry details, acknowledgement state and whether a purchase is a test. We do not receive full card details. Limited transaction records survive account deletion to prevent replay, as with Apple purchases.
Report result sends the selected result identifier and report category to our server for review. It creates no additional photo copy. Reports retain their date and handling status; account deletion removes the account and image links. Staff review reports and deletion requests in the private administration panel.
Deleting an account does not cancel either Google Play or Apple subscriptions. You can also request account deletion online. Read Google's privacy policy for Google's own processing.
9. Optional email offers and business services
Marketing is off by default. You can separately choose email offers from CarTuning.ai about workshops and parts shops, and personalization based on the categories of your completed visualizations. These choices are optional and do not affect purchases, prices or generation. We record your choices, their date, language and policy version. A new or changed email address must be confirmed before receiving campaigns. Withdraw either choice in Offers & privacy, or unsubscribe through an email link. Withdrawal does not affect earlier lawful processing.
Advertisers receive aggregate delivery statistics. Group partners see verified sales totals for their own codes, including refunds; they do not receive customer identities, addresses, photos or individual generation histories. Receipt attribution and bonus records support purchase fulfillment and replay prevention. Unknown receipt prices are not invented.
Contact forms store your name, email, company if supplied and message for answering your request; they do not opt you into marketing. Business accounts use single-use email links, valid for 15 minutes, and essential session cookies. We store campaign materials, quotes and payment references to provide advertising services and meet applicable accounting duties. Stripe is the planned processor for business advertising payments; app subscriptions use Apple on iOS and Google Play on Android. Resend is the planned email delivery provider. These integrations send no payments or emails until configured. When enabled, Stripe handles payment details and Resend receives the recipient address and message, including sign-in or confirmation links. Review Stripe privacy and Resend privacy for provider processing and international transfer information.
Active consent choices remain until changed or the account is deleted. Delivery records retain status and a recipient hash for reporting and duplicate prevention; deletion of the app account removes the link to its marketing preference. Contact correspondence and business financial records are retained while needed for the request, contract, legal duties or related claims. To exercise your rights, contact support@cartuning.ai.