Privacy Policy
Last updated: 8 September 2026
CalCar (calcar.io) is an online service that helps you understand whether a specific car is worth buying: it checks listings, calculates the cost of importing a car from US auctions and keeps a car assistant with a memory of your preferences. This policy explains what data CalCar collects, why, and what you can do about it.
CalCar is an early-stage product operated by the CalCar project team. The legal entity, its registered address and the applicable law will be added to this page once they are finalised.
What CalCar collects
- Account information. When you sign in with Google or an email link, CalCar receives your email address and, from Google, the basic profile data that Google shares at sign-in (name and profile picture). CalCar uses the email address as your account identity; the profile data is stored by the authentication provider and is not shown publicly.
- Reports and check history: the listings you analyse, the resulting reports and their public share links, if you create them.
- Assistant conversations: your messages to the CalCar assistant and its replies. The current thread is also kept in your browser.
- Assistant memory: a short note about your preferences that the assistant maintains and that you can view, edit or erase in your account.
- Feedback: optional ratings and comments you leave on reports.
- Listing URLs and vehicle data that you submit for analysis, including photos you upload for an import estimate.
- An anonymous browser identifier: a random ID stored in your browser that lets CalCar count visits and analyses without knowing who you are.
- Analytics events: which pages you open, when an analysis is started or completed, when a report is viewed or shared, when the assistant or the memory is opened.
- Acquisition data: UTM parameters and the referring site of your first visit.
- Technical information that analytics providers collect by default: browser and device type, screen size, approximate location derived from the IP address, and session timing.
Analytics
CalCar uses PostHog and Google Analytics (GA4) when they are enabled in its configuration. They help us understand how the product is used: which steps people complete, where they drop off, whether they come back, how well the interface works and where visitors come from.
PostHog may record sessions to help us fix interface problems. In the current implementation all form inputs are masked, and the assistant panel, the memory editor and the sign-in form are excluded from recording, so assistant messages, memory content and sign-in details are not captured as readable content.
Analytics events never include the text of your assistant messages, memory content, seller descriptions or payment details. Analytics providers may set their own cookies or local storage entries.
Authentication and infrastructure
Sign-in is handled by Supabase Auth, using Google OAuth or a one-time email link. Data is stored in Supabase (database and file storage), and the site with its server functions runs on Vercel.
AI processing
CalCar uses third-party AI models (currently OpenAI models) to analyse listings, vehicle data and photos, to write reports and to power the assistant and its memory. The data needed for a given task, including listing text, vehicle data, photos, your assistant messages and your memory note, is sent to the model provider for processing. CalCar does not claim that any provider never receives this data.
Vehicle data
To build the history of a specific car (Vehicle Memory), CalCar may store publicly available data it finds about that car: VIN, listings, prices, mileage readings, seller descriptions, photos, auction and historical records and other public information. This data describes the vehicle, not you, and is kept separately from your personal data. It comes from public listing sites, auction and history sources, VIN decoding services and web search.
Assistant memory
The memory note is created from your conversations with the assistant or from a profile you paste yourself. You can view and edit it in your account, disable its use in report conclusions, or erase it completely. Erasing removes the note from the database.
Feedback
If you rate a report or write what was missing, this feedback is stored together with the report reference and your account or anonymous identifier, and is used only to improve the product.
Cookies and browser storage
CalCar stores the following in your browser: the authentication session, your language choice, the anonymous analytics identifier and first-visit attribution, onboarding state, the current assistant thread, the list of recent checks on this device and other local application state. Analytics providers, when enabled, use their own cookies and storage.
Who receives your data
CalCar shares data with the categories of providers needed to run the service:
- infrastructure and hosting (Vercel, Supabase);
- authentication (Google OAuth through Supabase Auth);
- analytics (PostHog, Google Analytics), when enabled;
- AI model providers (currently OpenAI);
- vehicle data providers and public sources: listing sites, auction and vehicle history sources, VIN decoding services, web search and page-fetching services.
CalCar does not sell your personal data and does not use it for third-party advertising.
Retention and deletion
- You can erase the assistant memory and delete your reports in your account at any time.
- To delete your account and the personal data linked to it, contact us using the details below; we will remove the account, its reports, memory and feedback.
- Public vehicle data collected for Vehicle Memory describes the car rather than a person and may be retained under its own rules even after an account is deleted.
- Analytics data is retained according to the settings of the analytics providers.
Google user data
When you sign in with Google, CalCar requests only the basic sign-in scopes: your email address and basic profile information (name and profile picture). CalCar uses this data solely to create and identify your account and to show that you are signed in. It is not used for advertising, is not sold and is not shared with anyone except the authentication provider that stores it. CalCar's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke CalCar's access in your Google account settings and request deletion of your account data using the contact below.
Changes
We may update this policy as the product evolves. The date at the top shows the latest version.