This policy explains what data AutoEdge (the "App") collects, how it is used, who it is shared with, and what choices you have. AutoEdge is a vehicle-evaluation tool for buyers, sellers, mechanics, and small-volume auction shoppers. We are committed to collecting only what is needed to make the App work.
AutoEdge is developed by James Byland. Questions about this policy or how the App handles your data: james@bylandindustries.com.
If you sign in with Google we receive the following from Google's
OpenID Connect id_token:
We use this data to identify you across devices, populate the "Signed in as" line in Settings, and link your vehicle evaluations, service log entries, and preferences to your account.
If you sign up with email and password instead of Google we collect and store:
After you sign in we issue a session token (an HMAC-SHA256-signed JWT) used to authenticate your subsequent requests. The token expires automatically after 30 days and is wiped from device storage on sign-out.
Our hosting provider (Cloudflare) records standard HTTP request logs (timestamp, request method, URL path, response status, IP address). We do not export these logs into our own datastore; they are retained on Cloudflare's schedule for diagnostic use only and are not used for advertising or analytics.
| Service | What we send | Why |
|---|---|---|
| Google (Sign-In) | Your OAuth grant | To authenticate you |
| Google Play Billing | Your purchase token | To verify subscriptions |
| NHTSA vPIC | VIN string (only) | To decode the vehicle |
| Auto.dev | VIN or year/make/model | To fetch vehicle specs and listings |
| eBay Browse | Search keywords + ZIP | To find comparable listings |
| Cloudflare | HTTP request metadata | To run our backend |
| Microsoft Graph (Office 365) | Your email address (only when you request a password reset) | To deliver password-reset emails from noreply@bylandindustries.com |
We do not sell or rent your personal data, and we do not share it for advertising. We share only what is necessary to power a specific feature you have used.
Account data, vehicle evaluations, service log entries, and settings are stored in Cloudflare D1 (an SQLite database) in Cloudflare's globally-replicated network. Subscription state lives there too. We retain this data as long as your account exists. When you delete your account (see section 7) we remove it within 24 hours.
For email/password accounts, your password is stored only as a salted PBKDF2-SHA256 hash — we cannot recover or display it and a database breach would not expose the original password. Password-reset tokens are stored only as one-way SHA-256 hashes that auto-expire one hour after issuance.
A copy of your most recent vehicle history and service log is also cached locally on your device (in Android AsyncStorage) so the App works without a connection. The cache is wiped on sign-out.
Data in Cloudflare D1 is retained until you delete your account or individual entries. Anonymous request logs are retained on Cloudflare's schedule and cannot be associated with you after account deletion. Data you send to Auto.dev, eBay, or NHTSA is governed by their respective retention policies; we do not control what they keep.
You can delete your account at any time:
users row
(including your password hash, if any), every vehicle history
entry, every service log entry, your saved settings, your
subscription entitlement, your free-tier usage counter, any
pending password-reset tokens, and any link between you and a
redeemed promo code. The promo code itself is retained
anonymously so it cannot be re-redeemed.
Cancelling a Google Play subscription does not delete your data — your account simply drops back to the free tier. Use "Delete account" above for full removal.
Depending on your jurisdiction (GDPR, CCPA, etc.) you may have the right to:
All requests between the App and our backend travel over HTTPS.
If you sign in with Google, your id_token is verified
server-side against Google's published JWK set on every
authenticated request — Google Sign-In never shares your
Google password with us. If you sign in with email and password,
your password is hashed with PBKDF2-SHA256 (100,000 iterations
plus a 16-byte random salt) before it ever leaves the request
handler; we store only the resulting hash and never log,
transmit, or retain the plaintext password. Authenticated
sessions are tracked via short-lived signed tokens (Google
id_tokens for Google sign-in; HMAC-SHA256 JWTs we
issue ourselves for email sign-in), and password-reset tokens are
stored as one-way SHA-256 hashes with a one-hour TTL.
AutoEdge is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has signed in, please contact us and we will delete the account.
If we change this policy materially we will update the Effective date at the top and surface a notice inside the App at next launch. Continued use after a material change constitutes acceptance.
Questions, requests, or complaints: james@bylandindustries.com.