AutoEdge

Privacy Policy

Effective 2026-09-02 · Published by Byland Industries LLC

This policy explains what data AutoEdge collects, how it is used, who it is shared with, and what choices you have. It covers the AutoEdge Android app, the AutoEdge desktop app for Windows, and the account pages on appautoedge.com (together, the "Service"). AutoEdge is a vehicle-evaluation and dealer-management tool for buyers, sellers, mechanics, and small dealerships. We are committed to collecting only what is needed to make the Service work.

01Who we are

AutoEdge is operated by Byland Industries LLC. Questions about this policy or how the Service handles your data: james@bylandindustries.com.

02What we collect

2.1 Account data — Google Sign-In

If you sign in with Google we receive the following from Google's OpenID Connect id_token:

We use this data to identify you across devices, populate the "Signed in as" line in Settings, and link your vehicles, customers, work orders, and preferences to your account.

2.2 Account data — Email & password

If you sign up with email and password instead of Google we collect and store:

After you sign in we issue a session token (an HMAC-SHA256-signed JWT) used to authenticate your subsequent requests. The token expires automatically after 30 days and is wiped from device storage on sign-out.

2.3 App content you create

Customer records describe your customers, not you. We store them on your behalf and do not use them for our own purposes; you are responsible for collecting that information lawfully.

2.4 Subscription and billing state

2.5 Valuation-improvement data

When you run an evaluation, we record the evaluation's inputs and outputs (for example year, make, model, mileage, condition grade, and the values computed or observed) to calibrate and improve our valuation models over time. This data is about vehicles and prices; it does not include your customers' identities.

2.6 Usage logs

Our hosting provider (Cloudflare) records standard HTTP request logs (timestamp, request method, URL path, response status, IP address). We do not export these logs into our own datastore; they are retained on Cloudflare's schedule for diagnostic use only and are not used for advertising or analytics. We also record which app (phone or desktop) an account signs in from, to support subscription administration.

2.7 What we do NOT collect

03How we use your data

04Where data goes

ServiceWhat we sendWhy
Google (Sign-In)Your OAuth grantTo authenticate you
Google Play BillingYour purchase tokenTo verify Android subscriptions
StripeYour email and subscription detailsTo bill the desktop subscription; your card details stay with Stripe
Intuit QuickBooks OnlineThe invoices, estimates, sales receipts, and customer records you choose to push (only if you connect QuickBooks)To sync your books
NHTSA vPICVIN string (only)To decode the vehicle
Vehicle-data providers (Auto.dev and licensed listing/marketplace providers)VIN or year/make/model, mileage, ZIPTo fetch specs, listings, comps, and listing photos
eBay BrowseSearch keywords + ZIPTo find comparable listings and part prices
AI provider (Google Gemini)Your Ask AI question and the vehicle context shown in the chatTo generate AI answers; not used to identify you
CloudflareHTTP request metadata; your stored contentTo run our backend, database, and file storage
Microsoft Graph (Office 365)Your email address (only when you request a password reset)To deliver password-reset emails from noreply@bylandindustries.com

We do not sell or rent your personal data, and we do not share it for advertising. We share only what is necessary to power a specific feature you have used.

05Business accounts and shared visibility

06Where it's stored

Account data, vehicles, customers, work orders, quotes, settings, and subscription state are stored in Cloudflare D1 (an SQLite database) in Cloudflare's globally-replicated network. Files and photos you attach are stored in Cloudflare R2 object storage. We retain this data as long as your account exists. When you delete your account (see section 8) we remove it within 24 hours.

For email/password accounts, your password is stored only as a salted PBKDF2-SHA256 hash — we cannot recover or display it and a database breach would not expose the original password. Password-reset tokens are stored only as one-way SHA-256 hashes that auto-expire one hour after issuance.

A copy of your most recent vehicle history, work orders, and customers is also cached locally on your device so the apps work without a connection. The cache is wiped on sign-out.

07How long we keep it

Data in Cloudflare D1 and R2 is retained until you delete your account or individual entries. Anonymous request logs are retained on Cloudflare's schedule and cannot be associated with you after account deletion. Valuation-improvement records (section 2.5) may be retained after account deletion in a form no longer linked to you. Data sent to third-party providers (section 4) is governed by their respective retention policies; we do not control what they keep.

08Deleting your data

You can delete your account at any time:

Deleting your account removes: your users row (including your password hash, if any), every vehicle and history entry, every work order and quote (and their public quote links), every customer record, your file attachments, your saved settings, your subscription entitlement, your free-tier usage counter, any pending password-reset tokens, and any link between you and a redeemed promo code. The promo code itself is retained anonymously so it cannot be re-redeemed. Records owned by a business you belonged to remain with that business.

Cancelling a Google Play or desktop subscription does not delete your data — your account simply loses paid features. Use "Delete account" above for full removal.

09Your rights

Depending on your jurisdiction (GDPR, CCPA, etc.) you may have the right to:

10Security

All requests between the apps and our backend travel over HTTPS. If you sign in with Google, your id_token is verified server-side against Google's published JWK set on every authenticated request — Google Sign-In never shares your Google password with us. If you sign in with email and password, your password is hashed with PBKDF2-SHA256 (100,000 iterations plus a 16-byte random salt) before it ever leaves the request handler; we store only the resulting hash and never log, transmit, or retain the plaintext password. Authenticated sessions are tracked via short-lived signed tokens (Google id_tokens for Google sign-in; HMAC-SHA256 JWTs we issue ourselves for email sign-in), and password-reset tokens are stored as one-way SHA-256 hashes with a one-hour TTL. QuickBooks connections use OAuth — we store the tokens Intuit issues, never your Intuit password.

11Children's privacy

AutoEdge is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has signed in, please contact us and we will delete the account.

12Changes to this policy

If we change this policy materially we will update the Effective date at the top and surface a notice inside the apps at next launch. Continued use after a material change constitutes acceptance.

13Contact

Byland Industries LLC · Questions, requests, or complaints: james@bylandindustries.com.