Privacy Policy

CostoAuto: Car Expenses and Consumption

Last updated: 3 October 2026 · Versione italiana

The short version

CostoAuto does not sell your data, shows no ads, and performs no cross-app or cross-site tracking. The data you enter (vehicles and their optional photos, fill-ups, expenses, deadlines, attachments) stays on your device. If you choose to sign in (Apple on iOS, Google on Android, or an email code), the same data also syncs to the developer's sync service so it follows you across devices; it is used only to provide sync and is deleted when you delete your account. If you subscribe to CostoAuto Pro, the App Store or Google Play takes the payment and RevenueCat receives the transaction to unlock the app. The only other transmissions are platform geocoding lookups you start yourself, data-minimized usage statistics relayed to PostHog (EU-hosted), and, on Android, the diagnostics Google ML Kit sends to Google for the vehicle photo.

Optional account and sync

If you sign in, your ledger syncs to sync.costoauto.app (Cloudflare Workers with Cloudflare D1/R2 storage) so it survives a phone change, including between iPhone and Android. For sign-in we process your email address (or the pseudonymous identifier Apple/Google supplies) and send sign-in codes via Resend from noreply@costoauto.app. Credentials are stored only as salted hashes; encrypted daily backups expire after roughly 35 days. Signing out keeps your data on the device and server; deleting your account in the app (Profilo → Sincronizzazione → Account → Elimina account, as labelled in the app; step-by-step instructions in Delete your CostoAuto account) erases the server copy with its photos and attachments, with backups expiring on the same ~35-day cycle.

Purchases: CostoAuto Pro

CostoAuto is a free download; using the app after onboarding needs a CostoAuto Pro subscription (annual with a 7-day free trial for new subscribers, or monthly). Payment, billing and cancellation are handled by Apple (App Store) or Google (Google Play): we never receive your card details or your Apple or Google account password. The app shows no ads.

To check your subscription the app uses RevenueCat (RevenueCat, Inc.) as our processor. RevenueCat receives your subscription's store transaction (product, purchase and expiry dates, trial and renewal state, store country and currency), a random identifier generated on the device, the app and OS version and the device language; it validates the receipt with Apple or Google, tells the app whether the subscription is active and gives us aggregate sales statistics. The identifier is not linked to your CostoAuto account, name or email; we send RevenueCat no vehicle data, location or advertising identifier.

If you start the free trial, the app asks permission to show one local notification two days before the trial ends; it is scheduled on the device and sends nothing. Manage or cancel the subscription in your App Store or Google Play account settings (also from Profilo → Abbonamento → Gestisci abbonamento in the app); deleting your CostoAuto account or the app does not cancel it.

Location, camera, notifications, analytics

The camera or photo library is used only when you choose to add a photo of your vehicle. The background is removed on the device and only the cut-out of the vehicle is kept; a number plate the app recognises is blurred. Without an account the photo stays on the device and in backups you export; if you sign in, it syncs with your account like the rest of the vehicle data. On iOS the background is removed with Apple's Vision framework and nothing is sent. On Android it uses Google ML Kit through Google Play services: the photo stays on the device and is not sent, but ML Kit sends Google device information, app information, performance metrics, API configuration, event types, error codes, and device or installation identifiers, encrypted in transit, for diagnostics and usage analytics. Google states that it does not share this data with third parties (ML Kit data disclosure). Google Play services downloads the models ML Kit uses to the device. Location is requested only when you start a station lookup during a fill-up. The platform geocoding service returns a place or station name. If you save the fill-up, its station name and coordinates become part of the local ledger and, when sync is enabled, the synced record. Deadline notifications are generated locally on the device. Our usage analytics use no analytics SDK and are relayed through e.costoauto.app to EU-hosted PostHog. On Android, Google ML Kit, used for the vehicle photo, sends its own diagnostics and usage data to Google, as described above. EEA, UK, and Swiss events are anonymized at the relay; elsewhere events use a random app identifier with no name, email, or advertising identifier. In Germany and Austria (and when the region is unknown) analytics stay off until you consent; elsewhere they can be turned off any time in Profilo → Privacy e dati. Crash and performance reports (MetricKit / Play Vitals) are always on, aggregate, and content-free.

Processors

Retention and international transfers

Local data stays on your device until you delete it. Synced data remains while you keep the account and is erased when you delete it; encrypted backup copies expire within roughly 35 days. Analytics events do not contain your vehicle ledger and are retained only to measure product use and stability. The subscription record at RevenueCat remains until you ask us to delete it. When a provider processes data outside the EEA or United Kingdom, we limit the transfer to what is needed for the requested feature and apply the contractual safeguards required by applicable law.

Your rights

Full CSV export and a backup file are available at any time. Without an account, deleting the app removes your data. With an account, delete it in the app (Profilo → Sincronizzazione → Account → Elimina account) or by email, as described in Delete your CostoAuto account; backups expire within ~35 days. Your subscription record at RevenueCat is not linked to your account: to access or delete it, write to us with your App Store order id or Google Play order number. For access, rectification, erasure, restriction, portability, or objection use the Prighter portal or support@costoauto.app.

Controller and representatives

Controller: Geometry Lab L.L.C-FZ, Licence No. 2651608.01, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates.

EU representative (Art 27 GDPR): Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria. UK representative: Prighter Ltd, 20 Mortlake High Street, London, SW14 8JN, United Kingdom.

Children

CostoAuto is not directed to children and does not knowingly collect children's personal data.

Contact

support@costoauto.app