This policy explains what data AutoEdge collects, how it is used, who it is shared with, and what choices you have. It covers the AutoEdge Android app, the AutoEdge desktop app for Windows, and the account pages on appautoedge.com (together, the "Service"). AutoEdge is a vehicle-evaluation and dealer-management tool for buyers, sellers, mechanics, and small dealerships. We are committed to collecting only what is needed to make the Service work.
AutoEdge is operated by Byland Industries LLC. Questions about this policy or how the Service handles your data: james@bylandindustries.com.
If you sign in with Google we receive the following from Google's
OpenID Connect id_token:
We use this data to identify you across devices, populate the "Signed in as" line in Settings, and link your vehicles, customers, work orders, and preferences to your account.
If you sign up with email and password instead of Google we collect and store:
After you sign in we issue a session token (an HMAC-SHA256-signed JWT) used to authenticate your subsequent requests. The token expires automatically after 30 days and is wiped from device storage on sign-out.
Customer records describe your customers, not you. We store them on your behalf and do not use them for our own purposes; you are responsible for collecting that information lawfully.
When you run an evaluation, we record the evaluation's inputs and outputs (for example year, make, model, mileage, condition grade, and the values computed or observed) to calibrate and improve our valuation models over time. This data is about vehicles and prices; it does not include your customers' identities.
Our hosting provider (Cloudflare) records standard HTTP request logs (timestamp, request method, URL path, response status, IP address). We do not export these logs into our own datastore; they are retained on Cloudflare's schedule for diagnostic use only and are not used for advertising or analytics. We also record which app (phone or desktop) an account signs in from, to support subscription administration.
| Service | What we send | Why |
|---|---|---|
| Google (Sign-In) | Your OAuth grant | To authenticate you |
| Google Play Billing | Your purchase token | To verify Android subscriptions |
| Stripe | Your email and subscription details | To bill the desktop subscription; your card details stay with Stripe |
| Intuit QuickBooks Online | The invoices, estimates, sales receipts, and customer records you choose to push (only if you connect QuickBooks) | To sync your books |
| NHTSA vPIC | VIN string (only) | To decode the vehicle |
| Vehicle-data providers (Auto.dev and licensed listing/marketplace providers) | VIN or year/make/model, mileage, ZIP | To fetch specs, listings, comps, and listing photos |
| eBay Browse | Search keywords + ZIP | To find comparable listings and part prices |
| AI provider (Google Gemini) | Your Ask AI question and the vehicle context shown in the chat | To generate AI answers; not used to identify you |
| Cloudflare | HTTP request metadata; your stored content | To run our backend, database, and file storage |
| Microsoft Graph (Office 365) | Your email address (only when you request a password reset) | To deliver password-reset emails from noreply@bylandindustries.com |
We do not sell or rent your personal data, and we do not share it for advertising. We share only what is necessary to power a specific feature you have used.
Account data, vehicles, customers, work orders, quotes, settings, and subscription state are stored in Cloudflare D1 (an SQLite database) in Cloudflare's globally-replicated network. Files and photos you attach are stored in Cloudflare R2 object storage. We retain this data as long as your account exists. When you delete your account (see section 8) we remove it within 24 hours.
For email/password accounts, your password is stored only as a salted PBKDF2-SHA256 hash — we cannot recover or display it and a database breach would not expose the original password. Password-reset tokens are stored only as one-way SHA-256 hashes that auto-expire one hour after issuance.
A copy of your most recent vehicle history, work orders, and customers is also cached locally on your device so the apps work without a connection. The cache is wiped on sign-out.
Data in Cloudflare D1 and R2 is retained until you delete your account or individual entries. Anonymous request logs are retained on Cloudflare's schedule and cannot be associated with you after account deletion. Valuation-improvement records (section 2.5) may be retained after account deletion in a form no longer linked to you. Data sent to third-party providers (section 4) is governed by their respective retention policies; we do not control what they keep.
You can delete your account at any time:
users row
(including your password hash, if any), every vehicle and history
entry, every work order and quote (and their public quote links),
every customer record, your file attachments, your saved settings,
your subscription entitlement, your free-tier usage counter, any
pending password-reset tokens, and any link between you and a
redeemed promo code. The promo code itself is retained
anonymously so it cannot be re-redeemed. Records owned by a
business you belonged to remain with that business.
Cancelling a Google Play or desktop subscription does not delete your data — your account simply loses paid features. Use "Delete account" above for full removal.
Depending on your jurisdiction (GDPR, CCPA, etc.) you may have the right to:
All requests between the apps and our backend travel over HTTPS.
If you sign in with Google, your id_token is verified
server-side against Google's published JWK set on every
authenticated request — Google Sign-In never shares your
Google password with us. If you sign in with email and password,
your password is hashed with PBKDF2-SHA256 (100,000 iterations
plus a 16-byte random salt) before it ever leaves the request
handler; we store only the resulting hash and never log,
transmit, or retain the plaintext password. Authenticated
sessions are tracked via short-lived signed tokens (Google
id_tokens for Google sign-in; HMAC-SHA256 JWTs we
issue ourselves for email sign-in), and password-reset tokens are
stored as one-way SHA-256 hashes with a one-hour TTL. QuickBooks
connections use OAuth — we store the tokens Intuit issues,
never your Intuit password.
AutoEdge is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has signed in, please contact us and we will delete the account.
If we change this policy materially we will update the Effective date at the top and surface a notice inside the apps at next launch. Continued use after a material change constitutes acceptance.
Byland Industries LLC · Questions, requests, or complaints: james@bylandindustries.com.