Last updated September 12, 2026

CarBindr Privacy Policy

Last updated: September 12, 2026 Effective: September 12, 2026

CarBindr is run by James Millington, an individual doing business as CarBindr ("we", "us"). If you have a question about anything here, email carbindrhq@gmail.com — a person reads it.


The short version

  • We collect what you type in and what you upload.
  • Today we run no analytics and no third-party trackers, and we have never sold anyone's information. We reserve the right to do all three — see What we reserve the right to do. We will tell you before we do, and give you a way to opt out of any sale.
  • If you use the AI features, the photos you scan are sent to Anthropic to read them. See AI features.
  • You can export everything as a PDF, and you can delete your account and everything in it, at any time, from inside the app.
  • CarBindr is in beta. How it handles data is expected to change before general release. See Beta.

1. What we collect

Everything below is either something you typed, something you uploaded, or something the service has to record to work at all.

Your account

Your name, email address, username, and a bcrypt hash of your password. We never store your password itself and cannot recover it. You may optionally add a phone number, which is used only for SMS reminders if you turn them on.

Your vehicles

Whatever you choose to record: year, make, model, trim, engine, transmission, colour, nickname, VIN, licence plate, odometer readings, purchase date, and free-text notes.

A VIN and a licence plate can identify a specific vehicle and, indirectly, its owner. We treat them as personal information even where the law is unsettled on the point.

Your service history

Service dates, mileage, costs, and the name, address, phone number, email and website of the shop that did the work — as you entered them. Parts records include brand, part number, price, where you bought it, and a purchase link if you added one.

Documents and photos you upload

Files you file under Purchase, Registration, Insurance, Tax, Miscellaneous or a folder you created, plus receipts and paperwork attached to a service visit, and a photo of the vehicle itself. These frequently contain sensitive material — bills of sale, titles, insurance policies, and tax documents carry names, addresses, signatures, policy numbers and financial detail. We store them as you gave them to us, and we do not read, index or analyse them unless you explicitly ask us to (see AI features).

Technical records

Server logs recording the time, path and status of requests, kept briefly for debugging and abuse prevention. If error reporting is enabled, unhandled errors are reported with your account's internal ID attached — never your name, email, IP address, or the contents of your request.


2. What we do not do today

This describes CarBindr as it currently runs. It is not a promise about the future — see the next section for what we reserve the right to do.

  • No analytics or product telemetry. We do not currently know which buttons you press.
  • No advertising or marketing trackers, and no ad networks.
  • No location tracking. Photos are re-encoded in your browser before upload, which strips EXIF metadata including GPS coordinates as a side effect.
  • Nothing has been sold. We have never sold, rented or traded anyone's information, and we are not doing so now.
  • No social logins, so no profile data from anywhere else.

3. What we reserve the right to do

We want to be straight with you rather than promise something and quietly change it later.

We reserve the right to collect usage analytics, to use tracking technologies, and to sell or share personal information with third parties. We are not doing any of these today. If we start, this policy will say so before it happens.

What that could include:

  • Usage analytics — which features are used, how often, and where people get stuck, to decide what to build.
  • Tracking technologies — cookies, pixels or similar, including third-party ones, for analytics or advertising.
  • Selling or sharing information — including to data brokers, advertisers, automotive-industry buyers, or analytics partners. This may cover vehicle and service data, and may be identifiable, pseudonymous or aggregated.

What we commit to before any of that

  1. Notice first. We will update this policy and email you at least 30 days before any sale or sharing of personal information begins.
  2. An opt-out. If we ever sell or share personal information, we will publish a "Do Not Sell or Share My Personal Information" control, honour requests through it, and respect Global Privacy Control signals from your browser — regardless of whether California law requires it of us at the time.
  3. Your documents are treated differently. Files you upload — titles, bills of sale, insurance policies, tax documents — contain signatures, policy numbers and financial detail. We will not sell or share the contents of uploaded documents, and we will not make their contents available to any buyer, in any form.
  4. You can leave. If you don't like a change, export your data and delete your account. Deleting removes your information from the live service, and we will not sell information belonging to a deleted account.

A note on retroactivity. If we adopt a looser practice later, it applies going forward. Information collected while a stricter version of this policy was in force stays governed by the promise in force when we collected it, unless you agree otherwise.


4. Why we have it

WhatWhy
Account detailsTo sign you in and secure your account
Vehicle and service recordsTo provide the service — they are the service
Documents and photosTo store and show them back to you, and include them in exports you generate
Phone numberTo send SMS reminders, only if you turn them on
Email addressPassword resets and essential service notices
Server logsDebugging, and detecting abuse

We do not currently use your records to train any model, build a profile of you, or target advertising at you. See what we reserve the right to do.


5. Who else can see it

We currently use a small number of service providers. Each sees only what it needs to do its job, and none of them may use your data for their own purposes.

This table lists everyone who receives your information today. It does not limit who might in future — see what we reserve the right to do — but we will update it before anyone is added.

ProviderWhat it seesWhy
Amazon Web Services (RDS, us-west-1, Northern California)Everything stored in the databaseIt is the database
AnthropicOnly the images you choose to scanAI extraction — see below
TwilioYour phone number and reminder textSMS reminders, only if enabled
ResendYour email address and namePassword reset emails
Cloudflare R2Uploaded files, if object storage is enabledFile storage
SentryError reports with your internal account IDError monitoring, if enabled

We may also disclose information if we are legally required to — a subpoena, a court order, or a law we cannot lawfully refuse. If that happens we will tell you unless we are forbidden from doing so.

We do not currently sell personal information, and we do not currently share it for cross-context behavioural advertising, as those terms are defined under California law. We reserve the right to do both — see section 3 for the notice and opt-out you would get first.


6. AI features

This is the part worth reading carefully, because it is the only time your data leaves our own infrastructure for processing.

CarBindr can read a window sticker or a service receipt photograph and fill in a form for you. When you use that feature — and only then — the image you selected is sent to Anthropic's API to be read. Nothing else goes with it: not your name, not your email, not your other records.

Those images often contain personal information, because that is what is printed on them: a VIN on a window sticker, and a name, address and prices on a receipt.

Three things constrain this:

  1. It only happens when you ask. No image is ever sent automatically. If you never press a scan button, nothing is ever sent.
  2. Under Anthropic's commercial terms, API inputs are not used to train their models. We rely on that; you should verify it for yourself at https://www.anthropic.com/legal/commercial-terms.
  3. Nothing is saved without you. Every extraction is a draft that pre-fills a form. You review it and press save, or you don't.

Images are re-encoded and downscaled in your browser before upload, which caps their size and strips EXIF metadata including any GPS coordinates.

If you would rather no image ever left our systems, simply don't use the scan buttons — every field can be typed in by hand, and the app is fully usable that way.


7. Sharing with a repair shop

You can generate an invite code that gives a repair shop access to one vehicle's history, so they can read what has been done and log what they do.

  • Codes expire — 72 hours by default, and never longer than 7 days.
  • Access covers that vehicle only, never your account or your other vehicles.
  • You can revoke it at any time, and revocation takes effect immediately.

This sharing happens only when you deliberately create a code and give it to someone.


8. Cookies

One cookie today: spanner_token. It holds your sign-in session, is httpOnly (unreadable by scripts), sameSite: strict (not sent from other sites), and transmitted only over HTTPS in production.

It is strictly necessary to sign in, so there is currently no consent banner — there is nothing optional to consent to. If we later add analytics or advertising cookies, we will update this section and provide whatever consent mechanism the law then requires. Today there are no analytics, advertising or preference cookies, because we don't use any.


9. How long we keep it

We keep your data until you delete it. There is no automatic expiry, because a maintenance history is only useful if it's complete — a record of an oil change from four years ago is the point.

When you delete your account, the records are removed from the live database immediately, and uploaded files are removed from object storage at the same time. Encrypted database backups persist for up to 7 days before being overwritten on their normal cycle; we do not restore deleted accounts from them. So a deletion is complete in the service at once, and complete everywhere within a week.


10. Your choices

These apply to everyone who uses CarBindr, not only California residents. California's CCPA/CPRA may not currently apply to a business of this size, but we would rather honour these than argue about thresholds.

  • See what we hold. Everything is visible in the app, and the Share panel exports a complete PDF — vehicle details, documents, schedule, full service history and your charts.
  • Correct it. Every field is editable.
  • Delete it. Delete individual records, documents or vehicles at any time, or delete your entire account — which removes your vehicles, service records, documents, photos and settings. This cannot be undone.
  • Opt out of any sale or sharing. We are not selling or sharing personal information today. If that ever changes, you will be able to opt out through a "Do Not Sell or Share My Personal Information" control, or by emailing carbindrhq@gmail.com, and we will honour Global Privacy Control signals sent by your browser. You can register an objection in advance by emailing us, and we will apply it if and when it becomes relevant.
  • Object or complain. Email carbindrhq@gmail.com.

We will not discriminate against you for exercising any of these — you will not get a worse service or a higher price for opting out.

To make a request, email carbindrhq@gmail.com from your account's address. We aim to respond within 30 days.


11. Security

  • Passwords are hashed with bcrypt (cost 12) and never stored or logged in the clear.
  • All traffic runs over HTTPS, and the database connection requires TLS.
  • Sessions use signed tokens in an httpOnly, sameSite: strict cookie.
  • Every request for a vehicle is checked against its owner. This is covered by an automated test suite that runs against a real database.
  • Password reset tokens are stored only as a SHA-256 hash, single-use, and expire in one hour — so even a database leak cannot be used to reset anyone's password.

No system is perfectly secure, and we won't pretend otherwise. If we discover a breach affecting your personal information, we will notify you and any authority we are required to, without undue delay.


12. Children

CarBindr is for adults. You must be 18 or older to use it. We do not knowingly collect information from anyone under 18. If you believe a child has given us information, email carbindrhq@gmail.com and we will delete it.


13. Where your data lives

CarBindr is operated from the United States and its data is stored in the United States (us-west-1, Northern California). It is offered to United States residents. If you access it from elsewhere, you are doing so on your own initiative and your data will be processed in the US.


14. Beta

CarBindr is pre-release software in beta testing. That matters for privacy in two specific ways.

This policy will change before general release. It describes a product still being built. We expect to revise it — including the practices in section 3 — and we will tell you when we do.

We intend to keep what you enter. Our aim is that your account and records carry through to general release with nothing to re-enter, and we will take reasonable care to make that happen. We will not discard beta data for convenience.

We still cannot guarantee it. Data could be lost to a bug, a failed migration, or a problem we have to fix by resetting something. If a reset ever becomes necessary we will tell you first and give you time to export — but please don't treat CarBindr as the only copy of anything during beta. The PDF export in the Share panel exists for exactly this.

We will tell you when beta ends. Before CarBindr leaves beta we will email you to say what is changing, what happens to your account and your data, and whether there is anything you need to do.

Beyond that, everything in this policy applies to beta users in full: your data is handled the way described above, and you have every right listed in section 10.


15. Changes

If we change this policy we will update the date above. For anything that materially affects your rights, we will tell you by email before it takes effect. Continuing to use CarBindr afterwards means you accept the new version.


16. Contact

Email: carbindrhq@gmail.com Postal: 71 Columbine Road, Milton, MA 02186

James Millington, doing business as CarBindr.

Questions about this document? Email carbindrhq@gmail.com.