Car 2 Home Privacy Policy
Version 1.2, last updated May 26, 2026
By accessing or using the Car 2 Home Service, you acknowledge that you have read, understood, and agreed to all the terms of this Privacy Policy and our Terms of Service. If you do not agree to such terms, please stop using the Car 2 Home Service.
We are committed to protecting the privacy of the personal information we obtain from you through the Car 2 Home Service. This Privacy Policy informs you about how we collect, use, and share your personal information, and about our privacy practices in general.
We may update this Privacy Policy to reflect changes in our practices. We encourage you to review it periodically and check the "last updated" date above. Material changes will be announced inside the App, by email, or through an in-app notice.
1. Terms of Service
Use of the Car 2 Home Service is subject to our Terms of Service, which is incorporated into and made part of this Privacy Policy. By using the Car 2 Home Service, you agree to be bound by our Terms of Service.
2. Minimum Age Requirement
The Car 2 Home Service is intended for users who are at least 18 years of age. We do not knowingly collect personal information from individuals under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@car2home.ai so we can promptly delete that information.
3. Information We Process
This section describes every category of information the Car 2 Home App processes, why it processes it, and where it goes. Each subsection ties the data to the specific feature that requires it, so you can see at a glance what is at stake.
3a. Account and Subscription Data (optional)
You can use the free tier of the Car 2 Home App without creating an account or signing in. If you choose to subscribe to a paid plan, you may sign in with Google or Apple so that the subscription can be associated with your account across your devices. From the chosen provider we receive only the user identifier and the email address.
Sign-in is required only to attach a paid subscription to a portable identity. It is never required to use the free features of the App.
3b. Vehicle and OBD Data
The Car 2 Home App reads data from your vehicle through an OBD-II adapter (such as speed, RPM, fuel level, temperature, and other sensor readings) and may also read your vehicle's VIN for profile configuration purposes.
Vehicle and OBD readings, trip logs, parking locations, refueling events, Drive Score history, and DTC records are stored in a local database on your device. By default, this information stays on the device — we have no access to your vehicle's data.
This information may leave the device in two distinct cases, both opt-in: (i) when you sign in to a Car 2 Home account and enable the Cloud Sync described in Section 3j, specific categories of trip and event data may be synchronized to the Car 2 Home backend so they can be restored on your other devices; and (ii) when you enable one of the home automation transports described in Section 5 (the native Home Assistant transport via the Car 2 Home plugin, or an MQTT broker).
3c. Location Data
When you use trip-tracking features, the App captures your device's location (GPS, network-assisted positioning, and similar geolocation technologies) so it can record your routes, compute distances and driving statistics, detect parking events, and tag parking photos.
While a trip is being recorded, the App runs a foreground service so that your route is not interrupted when the screen is off. Background location is collected only while a trip is active. You can stop tracking at any time, or revoke location permission from your device's system settings.
Location information is stored locally on your device. By default, it is not transmitted off the device. When you opt in to Cloud Sync (Section 3j), trip route data, start/end coordinates, and parking addresses may be synchronized to the Car 2 Home backend so they can be restored on your other devices. Location also leaves the device via the home automation transports described in Section 5 when you have enabled them.
The full terms governing location collection, retention, and your withdrawal rights are set out in the Location Information Consent Agreement bundled with the App.
3d. Camera, Photos and Videos
If you choose to attach a photo to a parked-car location (so you can find your car later), the App uses the device's camera to capture that photo. The camera may also be used, optionally, to photograph vehicle parts, receipts for consumables or maintenance, and fuel-station receipts you record in the fuel log. Photos are saved in the local database on your device. They are not shared with third parties.
When you opt in to the Media Sync category of Cloud Sync (Section 3j), photos and documents you attach to refueling, expense, income, service or consumable events are uploaded to the Car 2 Home backend so they can be restored on your other devices. Other photos (such as parking photos and dashcam imagery) are not uploaded to the backend.
If you use the Dashcam feature, the App records trip videos with the device's camera and saves them to the public Movies/Car 2 Home folder of your external storage. Audio recording through the microphone is optional and controlled by the "Record audio" toggle under Settings → Dashcam; when disabled the microphone is not used. Listing the recorded videos inside the in-app Dashcam Gallery requires the READ_MEDIA_VIDEO permission, used solely to read the files the App itself wrote; no other videos on your device are accessed. Dashcam videos are NEVER uploaded to Car 2 Home servers and are not shared with third parties. You can delete videos at any time from the in-app Gallery or your device's file manager, and you can revoke camera and microphone permissions in the system settings.
3e. Bluetooth
The App uses Bluetooth scan and connect permissions to discover and pair with the OBD-II adapter you choose, and, optionally, to detect the presence of that adapter or the vehicle's Head Unit so the App can auto-start when you enter the car. Auto-start is opt-in and can be disabled at any time from the App's settings. The App does not advertise itself over Bluetooth, does not exchange data with other Bluetooth devices, and does not use Bluetooth for proximity tracking or marketing.
3f. Diagnostics and Crash Reports
To keep the App stable, we use a third-party crash reporting service (Sentry) that automatically captures unhandled errors and crashes. The information collected is limited to: stack traces, app version, operating system version, device model, and an anonymized event identifier.
The crash reporting service does not receive any sensitive information from the App. It does not collect OBD readings, your vehicle's VIN, location coordinates, account credentials, photos, or any personal identifiers from sign-in.
Sentry operates servers located in the European Union and complies with GDPR and LGPD requirements for international data processing. Their privacy practices are documented at https://sentry.io/privacy/.
3g. Advertising Data (free tier)
The free tier of the App is supported by advertising delivered by Google AdMob. To serve ads, AdMob may collect the device's advertising identifier (Advertising ID on Android, IDFA on iOS), the IP address, ad interaction events, and approximate location.
The first time you launch the free tier, the App shows a consent dialog (the Google User Messaging Platform, or UMP, prompt) asking whether you agree to receive personalized ads. You can change your choice at any time from the App's settings. If you refuse personalization, the App displays only non-personalized ads. Granting or refusing consent does not affect access to the App's core features.
If you subscribe to a paid plan, all advertising is removed for the duration of your active subscription.
The full terms governing the advertising consent are set out in the Personalized Advertising Consent Agreement bundled with the App. Google's ad data practices are documented at https://policies.google.com/technologies/ads.
3h. Subscription and In-App Purchase Data
Paid subscriptions are processed exclusively by Google Play Billing on Android and by the Apple App Store (StoreKit) on iOS. Car 2 Home does not see, collect, or store payment card numbers, billing addresses, or any other financial details.
From the platform we receive only a non-sensitive purchase token or receipt identifier, used to verify that the subscription is active and to link it to your account when you have signed in. Refunds, billing disputes, and renewal management are handled by Google or Apple under their respective terms.
3i. Non-Personally Identifiable Information
Non-Personally Identifiable Information does not identify a specific person. This includes general aggregated usage statistics (such as which features are opened and how often), browser type when interacting with the website, mobile carrier information, and aggregated location data. We use this information to troubleshoot, administer the Service, analyze trends, comply with applicable law, and cooperate with law enforcement. We may share aggregated, non-identifying statistics with authorized service providers to measure the overall effectiveness of our products.
3j. Cloud Sync (opt-in)
When you sign in to a Car 2 Home account, you can opt in to synchronize selected data between your devices through a Car 2 Home backend server operated under our control. Cloud Sync is gated by category: each category can be turned on or off independently from the App's settings, and the entire feature can be disabled without losing the local copy on your device.
The categories are:
- Configuration (turned on once you sign in): vehicle profiles, OBD adapter pairings, dashboard layout, custom PID definitions, panel preferences, App settings, and Home Assistant / MQTT configuration. Small payloads (typically under 100 KB per user) that let you restore your setup on a new device.
- Transactional (opt-in via a remote flag): trip logs, trip events, refueling events, parking records, expenses, income, maintenance services, consumables, reminders, DTC fault scans, freeze-frame captures, TPMS readings, acceleration tests, and aggregated per-PID trip statistics.
- Telemetry (opt-in via a remote flag, off by default): high-volume sensor readings during trips (GPS route points, per-PID samples, and continuous live data). When enabled, may be subject to additional constraints such as Wi-Fi-only upload and a configurable sample rate.
- Media attachments (opt-in via a remote flag, off by default): photos or documents you choose to attach to refueling, expense, income, service or consumable events. Dashcam videos are never included. Subject to a per-user storage quota on the free tier; subscribers may receive an increased quota.
Synchronized data is transmitted only over an encrypted HTTPS connection and is encrypted at rest on the server. We do not sell or share Cloud Sync data with third parties for marketing or advertising.
You can stop synchronization at any time by signing out or by disabling individual categories from the App's settings. To request permanent deletion of all data held on the server, use the self-service flow described in Section 12.
4. Data Retention
We retain personal information only for as long as necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
- Account information (name, email, sign-in identifier): retained while your account is active and for up to 1 year after termination or last sign-in.
- Location and trip data: stored locally on your device. We do not retain it on our servers.
- Crash reports and error events: retained by the crash reporting provider in compliance with the main applicable data protection regulations. For the precise retention period, refer to the Sentry privacy policy linked in the sub-processor table at the end of this document.
- Cloud Sync data (when you have opted in): kept on the Car 2 Home backend until you request deletion or close your account. Records you delete from the App leave a soft-delete marker (tombstone) on the server for up to 30 days so that the deletion can propagate to your other devices, and are then purged.
- App usage and analytics data: retained for up to 2 years.
- Legal and compliance records: retained for up to 5 years as required by applicable law.
After deletion or anonymization, we may retain aggregated, non-identifying statistical data for service improvement and business purposes indefinitely. You may request early deletion of your data at any time as described in Section 12.
5. Home Automation Integration
One of the core features of the Car 2 Home Service is the ability to forward vehicle telemetry to a personal home automation server you control. The App offers two independent transports for this. Both are disabled by default and require your explicit opt-in.
5a. Native Home Assistant transport (default option)
This is the default integration. After you install the Car 2 Home plugin in your own Home Assistant instance, you pair the App by typing the Home Assistant base URL plus a 6-digit pairing code shown by the plugin. The pairing exchange returns a long-lived authentication token, which the App uses for a WebSocket session (with an HTTP fallback) to deliver telemetry directly to your Home Assistant instance.
The authentication token is stored in the device's secure key store and is never sent to Car 2 Home servers. The Home Assistant URL you type is also kept on the device and is never disclosed to or contacted by Car 2 Home. Pairing happens directly between the App and your Home Assistant instance, on your local network or through a remote-access tunnel that you control.
Telemetry forwarded through this transport includes vehicle sensor readings and, optionally, GPS location, shaped by the same opt-in settings. You can revoke the token at any time from Home Assistant's own user interface or from the Car 2 Home App's settings, which terminates all transmission immediately.
5b. MQTT transport (alternative)
As an alternative, you may configure any MQTT broker URL, username and password, and TLS options in the App. Vehicle telemetry will then publish directly to the broker you control. This option is useful when you prefer a generic MQTT-compatible automation server, or when you do not wish to install the Car 2 Home plugin in Home Assistant.
Car 2 Home does not intercept, store, or have any access to the data transmitted between the App and your broker.
5c. Your responsibility for security
The security, confidentiality, and integrity of data transmitted between the Car 2 Home App and your home automation infrastructure are your responsibility. We strongly recommend that you:
- Enable authentication on the broker (username and password) and on Home Assistant;
- Use TLS or SSL for connections (MQTTS, HTTPS) where possible;
- Keep firewall and network access rules tight, especially for any remote-access tunnel;
- Apply security updates regularly to the broker, Home Assistant, and the underlying operating system.
Car 2 Home is not liable for data breaches, unauthorized access, or data loss caused by inadequate security configurations on your own infrastructure.
5d. Third-party platforms
If you choose to integrate the Car 2 Home Service with third-party home automation platforms, your use of those platforms is governed by their respective terms of service and privacy policies. We encourage you to review those policies carefully.
6. Sharing of Personally Identifiable Information
We will not sell your Personally Identifiable Information. We share it only with the parties listed below, and only for the purposes described.
6a. Authorized Service Providers
We work with a small number of service providers that perform functions on our behalf, such as crash reporting, advertising delivery, payment processing, and authentication. We share with each provider only the minimum information they need to perform their function. Their use of your data is governed by their own privacy policies, summarized in the Sub-Processor table at the end of this document.
6b. Advertising and Analytics Partners
We use Google AdMob to deliver ads on the free tier and Sentry to receive crash diagnostics. AdMob is governed by https://policies.google.com/privacy; Sentry by https://sentry.io/privacy/. You can manage Google's use of advertising identifiers at https://adssettings.google.com and revoke ad personalization in the App at any time.
6c. Acquisition
If we are involved in a merger, acquisition, or asset sale, the successor company would acquire the information we hold, including Personally Identifiable Information, but the information will remain subject to this Privacy Policy and you will be notified of any material changes.
6d. As Required by Law
We may disclose your information when we believe disclosure is required by applicable law, by a court order or other legal process, or when necessary to protect our rights, property, or safety, or the rights, property, or safety of our users or the public.
6e. Payment Processors
Subscription payments are processed by Google Play Billing on Android and by the Apple App Store (StoreKit) on iOS. We never see card numbers, banking details, or other financial data; we receive only a purchase token or receipt identifier from the platform.
6f. Authentication Providers
If you choose to sign in for a paid subscription, the chosen provider (Google Sign-In or Sign in with Apple) shares with us your provider-issued identifier and email address. The authentication exchange is governed by that provider's privacy policy.
7. Sharing of Non-Personally Identifiable Information
We may disclose or share Non-Personally Identifiable Information with service providers and the general public for analytical, operational, and promotional purposes. Such information is collected on our behalf and does not identify any individual.
8. Updating Your Information
If you have signed in for a paid subscription, you may update your account information at any time from the App's settings. We encourage you to keep your information current; outdated data may negatively affect your experience.
9. Choices on Collection and Use of Information
You may choose not to provide certain information, though a minimum level of information is required to use the Service. You may opt out of promotional emails at any time by contacting us at support@car2home.ai.
We will delete your personal information when your account is terminated or after more than 1 year of inactivity, subject to the retention periods described in Section 4. Aggregated, anonymized data may be retained for statistical and service improvement purposes.
10. Identifiers and Tracking Technologies
This section explains the identifiers and storage technologies the Car 2 Home App and the car2home.ai website use, and how they differ.
10a. Mobile App
The App does not use browser cookies. It stores data in a local database and a small key-value preferences store on the device. When advertising is active, the App exposes the device-scoped advertising identifier to the ad-serving partner, as described in Section 3g. No cross-device tracking is performed by the App itself.
10b. Website (car2home.ai)
The website uses standard browser cookies for session management and basic analytics. The website's privacy practices are documented in the website's own privacy notice. We urge you to review it if you visit the site.
11. Privacy Settings and Public Areas
Where the App or the website provides privacy settings or public areas (such as community forums or shared content), it is your responsibility to choose the right settings and to take care when sharing personal information publicly. We have no control over how third parties read postings made in public areas.
12. Your Rights as a Data Subject
Regardless of where you are located, you have the following rights with respect to your personal information:
- Right to access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your personal data, subject to legal retention obligations.
- Right to restriction: request that we limit the processing of your data.
- Right to data portability: request your data in a structured, commonly used, machine-readable format.
- Right to object: object to processing of your data for marketing purposes at any time.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting prior processing.
To exercise any of these rights, please contact us at privacy@car2home.ai. We will respond within 30 days. We may request proof of identity before processing your request.
If you have an account, you can also request deletion of your account and all server-side data through our self-service flow at car2home.ai/en/account/delete. You will receive a confirmation link by email; once you click it, deletion is scheduled with a 7-day grace period during which you can still cancel from inside the App. To export the data we hold on the server in a portable format, use the "Export my data" option inside the App's Account screen.
13. Compliance with Brazilian Law (LGPD)
As a Brazilian company, Car 2 Home complies with the Lei Geral de Proteção de Dados Pessoais (LGPD, Lei nº 13.709/2018).
13a. Legal Bases for Processing
- Consent (Art. 7, I): for marketing communications and personalized advertising.
- Contract performance (Art. 7, V): to provide the services you have requested.
- Legitimate interest (Art. 7, IX): for analytics, security, and service improvement, provided such interests do not override your fundamental rights.
- Legal obligation (Art. 7, II): where required by applicable law.
13b. Data Protection Officer
In compliance with Art. 41 of the LGPD, our Data Protection Officer can be contacted at privacy@car2home.ai.
13c. ANPD
You have the right to file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at www.gov.br/anpd if you believe your data protection rights have been violated.
14. Compliance with European Law (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) or equivalent local legislation applies to our processing of your personal data.
14a. Legal Bases for Processing
- Consent (Art. 6(1)(a)): for marketing and personalized advertising.
- Contract performance (Art. 6(1)(b)): to provide the requested services.
- Legal obligation (Art. 6(1)(c)): where required by EU or member state law.
- Legitimate interests (Art. 6(1)(f)): for security, analytics, and fraud prevention.
14b. International Data Transfers
If your data is transferred outside the European Economic Area, we ensure adequate protection through standard contractual clauses approved by the European Commission or other lawful transfer mechanisms.
14c. Supervisory Authority
You have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights under the GDPR have been infringed.
15. Notice to California Residents (CCPA / CalOPPA)
California residents have specific rights under the California Consumer Privacy Act (CCPA) and the California Online Privacy Protection Act (CalOPPA). You have the right to know what personal information we collect, use, disclose, and sell; to request deletion of your personal information; to opt out of the sale of your personal information (we do not sell personal information); and to non-discrimination for exercising your privacy rights.
To exercise your California privacy rights, please contact us at privacy@car2home.ai. Please include your name, address, and email address in your request, along with the label "California Customer Choice Notice." We will respond within 45 days.
16. Security of Information
You can access your personal information through the Car 2 Home Service using your credentials, which are protected by encryption in transit. We advise against sharing your password with anyone.
Your Personally Identifiable Information resides on secure servers accessible only to authorized personnel. While we employ commercially reasonable security measures, no data transmission can be guaranteed to be 100% secure. We are not responsible for the actions of third parties that may receive information transmitted over the internet.
If we believe the security of your information may have been compromised, we will notify you in accordance with applicable law.
17. Contact and Customer Support
For assistance, questions, or requests regarding this Privacy Policy or the Car 2 Home Service, please contact us:
- General support: support@car2home.ai
- Privacy matters: privacy@car2home.ai
- Website: www.car2home.ai
We aim to respond to all inquiries within 30 days.
Appendix: Sub-Processors
The following third parties process personal information on our behalf or on behalf of features you choose to enable. Each is listed with its purpose, the processing region, and a link to its privacy policy.
| Provider | Purpose | Processing region | Privacy policy |
|---|---|---|---|
| Sentry (Functional Software, Inc.) | Crash diagnostics and error reporting | European Union | sentry.io/privacy |
| Google AdMob | Advertising on the free tier | United States | policies.google.com/privacy |
| Google Play Billing | Subscription payments on Android | United States | policies.google.com/privacy |
| Apple App Store / StoreKit | Subscription payments on iOS | United States | apple.com/legal/privacy |
| Google Sign-In (optional) | Account authentication for paid subscription | United States | policies.google.com/privacy |
| Sign in with Apple (optional) | Account authentication for paid subscription | United States | apple.com/legal/privacy |
| Car 2 Home Backend (operated by VS1 Software Ltda.) | Cloud Sync of account-bound data (Section 3j), when enabled | Self-hosted server (production region to be disclosed at launch) | This Privacy Policy |
| Resend (Resend Holding Inc.) | Delivery of transactional emails (e.g. account deletion confirmation link), when applicable | United States | resend.com/legal/privacy-policy |
© 2026 VS1 Software Ltda. All rights reserved.