Gaugely — Privacy Policy

Effective 17 August 2026 · Last updated 24 August 2026

Gaugely is an OBD2 and vehicle-telemetry dashboard. It reads live data from your car through an adapter you own and shows it on your phone. Almost everything it produces — your gauges, trips, fuel log, PID definitions, CAN definitions, themes, photos — is written to your phone's own storage and stays there unless you deliberately turn something on.

There is exactly one thing that is on by default and sends data off your phone: anonymous usage analytics, described in section 3. You can turn it off in the app's Settings at any time. Everything else — an account, cloud sync, community contributions, photo sharing — is off until you switch it on.

This policy describes what the app and its server actually do, feature by feature. It is written to be checked against the software, not to be vague.

Contents

  1. Who we are and how to contact us
  2. What stays on your phone
  3. Usage analytics (on by default, can be switched off)
  4. Account and cloud sync (optional)
  5. Community vehicle-data contributions (optional)
  6. Vehicle photos (optional)
  7. Your VIN — and why we only keep part of it
  8. Location: used on your phone, never collected
  9. Notification access (optional, and off unless you turn it on)
  10. What we deliberately never collect
  11. Third parties and where data goes
  12. Security
  13. Retention, and how to delete your data
  14. Children's privacy
  15. Changes to this policy

1 · Who we are and how to contact us

Gaugely is developed and operated by Daniel Velez ("we", "us"). We are the party responsible for the data described in this policy.

For any privacy question, data request, or deletion request, email daniel.f.velez@gmail.com. That address is the single route for everything in section 13.

The Gaugely server referred to throughout this policy is gaugely.relentnet.dev, operated by us.

This policy is not legal advice and does not create rights beyond those the law already gives you.

2 · What stays on your phone

Unless you enable an optional feature below, the following never leaves your device. It is not uploaded, not backed up by us, and not visible to us:

Deleting the app removes all of it.

3 · Usage analytics — on by default, can be switched off

To understand which features are actually used and whether the app is working, Gaugely sends anonymous usage events to PostHog, an analytics provider acting on our behalf (US region, us.i.posthog.com).

Analytics is enabled by default. You can turn it off in the app's Settings.

Turning it off is not cosmetic — it calls the analytics SDK's own disable function, and no further events are sent from that moment on. The app is fully usable with analytics off; nothing is gated behind it.

What an event contains

There are six events in the entire app, and none of them carries any data we attach ourselves:

That is the complete list. No screen contents, no vehicle readings, no trip data, no VIN, no email address and no location are attached to any of them.

What the analytics SDK itself adds

We should be straight about this, because it is not zero. The PostHog SDK automatically attaches to each event a randomly generated anonymous identifier that persists for as long as the app is installed, plus standard technical context: app version, device model, operating-system version, locale, timezone, screen size and mobile-carrier name. We do not choose this data individually; it is what the SDK sends.

What we do to keep it anonymous

The random identifier is not linked to you by us, but because it persists it is treated as a device identifier in app-store disclosures, and we describe it as such.

Retention

Analytics events are retained for up to 12 months. On our current plan PostHog deletes them after 30 days; twelve months is the ceiling we will not exceed, not the period we keep. Because these events are not linked to your identity, we generally cannot single out and delete one person's events — the protection is that they are not tied to you in the first place. If you want no further events collected, switch analytics off in Settings.

4 · Account and cloud sync — optional

Gaugely works completely without an account. If you create one, it exists so your data follows you to another device.

What we hold for an account

What syncs when you are signed in

Sync covers these collections, and nothing else: trips, fuel fill-ups (including any odometer readings you record), vehicle profiles (including the partial VIN described in section 7), themes, app settings, metric overrides, PID lists and CAN lists. Vehicle photos sync separately — see section 6.

Every stored record is filed under your account and every read and write is filtered by the signed-in account's identifier on the server. Other users cannot reach your records. When you delete something in the app, the server marks that record deleted so the deletion reaches your other devices; the tombstone is removed when your account is deleted.

As a safety net, the server inspects every record you push and rejects it if it contains a full 17-character VIN, so a bug in the app could not leak one through sync.

Signing out

Signing out deletes the session token from your device. Your account data remains on the server until you ask us to delete it — see section 13.

5 · Community vehicle-data contributions — optional, separate consent

Gaugely maintains a shared database of which sensor definitions ("PIDs" and CAN signals) work on which vehicles, because manufacturers do not publish it. It is built from what users choose to contribute.

This is off unless you turn it on, with its own consent switch in the app, separate from analytics and separate from having an account. Turning it on unlocks the full PID and community-sensor toolkit; leaving it off means standard OBD2 sensors only.

What is contributed, once you have turned it on

How it is de-identified

Contributions are linked to your account for moderation and attribution purposes and are combined with other users' contributions into aggregate vehicle definitions. Those aggregate definitions — which sensor works on which model — are shared with all users of the app. Because a contribution carries no full VIN and no timestamp, the shared result does not describe you or your individual car.

Turning the switch off stops all future contributions immediately.

6 · Vehicle photos — optional, and there are two different things here

You can attach photos of your vehicle (front, side, rear) taken with the camera or chosen from your photo library. The app reads only the photo you pick; it does not browse or index your library.

a) Private photos synced to your own account

If you are signed in, your vehicle photos are uploaded to your account so they appear on your other devices. They are stored under your account's own storage path and are readable only by your account. They are private. They are deleted when your account is deleted.

b) Photos you choose to contribute to the public community pool

Separately, you can offer a specific photo to the shared community image pool, which supplies artwork for vehicles that other users have not photographed. This requires, per photo:

A contributed photo becomes public. Once it passes moderation it can be downloaded and displayed by any other Gaugely user whose vehicle matches. Please do not contribute a photo containing your licence plate, your home, people, or anything else you would not publish. Contributed photos are filed against the vehicle model, not against your VIN.

To have a contributed photo withdrawn from the public pool, email daniel.f.velez@gmail.com.

7 · Your VIN — and why we only keep part of it

A VIN identifies one specific car. The app reads your full VIN from the vehicle so it can tell which car it is connected to, and it may be shown to you on screen. The full VIN is held in memory only. It is not written to our servers, not synced, not put in a contribution and not sent to analytics.

What is stored and, if you sign in, synced, is a masked pattern: positions 1–8 and position 10 are kept; position 9 and positions 11–17 are replaced with asterisks. Positions 1–8 and 10 describe the make, plant, body, engine and model year — the parts that make the vehicle definitions useful. Positions 11–17 are the serial number that identifies your individual car, and they are discarded before anything is stored.

A full VIN never appears in a community contribution at all — those carry make, model, year, engine and the masked partial VIN (section 5). The server independently truncates any VIN it is given and rejects any synced record containing a full 17-character VIN.

If you contribute to the community database, our server sends that masked pattern — and only that pattern — to the NHTSA vPIC public vehicle database to confirm the contribution was recorded on the vehicle it claims to describe. A contribution whose pattern decodes to a different vehicle is held back for review rather than merged into the shared definitions. The result is cached, so the same vehicle is not looked up repeatedly, and a failed or unavailable lookup never blocks a contribution. NHTSA receives no account, no device and no serial number; see section 11.

Files you export or share yourself from the app (probe bundles, captures) apply the same masking before writing the file.

8 · Location: used on your phone, never collected

Gaugely requests location permission and, while it is open, reads your device's position stream. This is worth explaining precisely, because the permission sounds worse than what happens.

From that position stream the app reads exactly three values — altitude, heading and speed — to drive the altimeter, compass and speed gauges on the Overland screen and to measure trip distance. Latitude and longitude are never read by the app. They are not stored, not synced, not contributed and not sent to analytics. There is no map, no route recording and no location history.

The app holds no background-location permission, so it cannot read location when it is not running. Denying location permission simply leaves those gauges blank; everything else works.

9 · Notification access: off unless you turn it on

Gaugely can ask for Android's notification access permission. It is used for exactly two things: controlling whatever music app is already playing (play, pause, skip, seek, and showing the track title and artwork on the dashboard), and reading turn-by-turn directions from Google Maps and Waze. Both need the same Android permission, which is why there is only one to grant.

This permission cannot be granted by the app. There is no code path that can switch it on; Android only lets you do it yourself, in Settings. Until you do, the music bar says the access is off and the navigation feature does nothing at all.

Now the part that has to be said precisely, because it would be easy to say something flattering and untrue. Android delivers every notification on your device to any enabled listener. An app cannot ask to receive only some of them. What an app can control is what it does with them, and Gaugely's rule is: receives all, processes only Google Maps and Waze — plus, from the music app you are already controlling, its cover art when the app publishes artwork nowhere else — and retains nothing else. The service compares the sending app's package name and returns before reading any content unless it is one of those two — a message, an email or a banking alert is never opened, never displayed and never written down.

Even for Maps and Waze, nothing is stored unless you go to Settings → Diagnostics → Navigation capture and start a capture yourself. That tool exists so we can see what those apps actually put in a notification before we write any code that reads it. A capture is held in memory, uses time measured from when you started it rather than a clock time, and goes nowhere until you tap Export and choose where to send it. Nothing from your notifications is ever uploaded to us automatically, and none of it reaches analytics.

Turning the permission off in Android's settings stops all of this immediately. Every other part of the app works exactly the same without it.

10 · What we deliberately never collect

11 · Third parties and where data goes

RecipientWhat it receivesWhyYour control
Gaugely server
gaugely.relentnet.dev
Only what sections 4, 5 and 6 describe: your account credentials and synced collections; community contributions; photos. Sync your data across your devices; build the shared vehicle database. Optional Nothing is sent unless you create an account or turn contributions on.
PostHog
analytics processor, US
The six events in section 3, plus the SDK's anonymous identifier and device context. No IP (blanked), no identity, no vehicle data. Understand feature usage and app health. On by default Switch off in the app's Settings.
NHTSA vPIC
US government vehicle database
Two things. From the app: a make name and a model year, as part of a public lookup URL. From our server, only if you contribute to the community database: the masked partial VIN described in section 7 — positions 1–8 and 10, never the serial. Nothing about you or your account is sent either way. Populate the make and model pickers when you set up a vehicle; and confirm that a community contribution was actually recorded on the vehicle it claims to describe. Data recorded against the wrong vehicle profile corrupts the shared definitions everyone else relies on. Setup On contribution The VIN lookup happens only when you upload a contribution, and the result is cached so the same vehicle is not looked up repeatedly.
Spotify
if you use the in-app player
Nothing from us about your vehicle or your Gaugely account. The app talks to the Spotify app already installed on your phone, and you authorise it in Spotify's own flow. Show and control what is playing, on the dashboard. Optional Don't connect it, or revoke access in your Spotify account.
Google Play / Apple Whatever the store itself collects for app distribution, under its own policy. We receive nothing about you from the store. App distribution and updates. Governed by Google's and Apple's own privacy policies.

That is the complete list of destinations the app contacts. We do not sell your personal data, and we do not share it with anyone else except processors acting for us under contract, or where we are legally required to.

Our server is hosted at Hetzner Online GmbH's Ashburn, Virginia data centre in the United States. PostHog processes analytics in the United States. If you are outside those regions, using the optional features means your data is transferred there.

12 · Security

No system is perfectly secure, and we do not claim otherwise.

13 · Retention, and how to delete your data

On your device

Data on your phone is kept until you delete it in the app or uninstall the app. Uninstalling removes all of it, including cached photos and recordings.

Your account and synced data

We keep your account, your synced collections and your private photos for as long as your account exists. You can delete individual items (a trip, a fill-up, a vehicle) in the app, and the deletion propagates to the server and to your other devices.

To delete your whole account and everything in it, open the Account screen in the app and choose “Delete account”. The deletion runs immediately and in a single transaction: your account record, your sign-in credentials, your synced collections and your private photos are destroyed. Your community contributions are kept but de-attributed — your identity is stripped from them, so what remains is the vehicle data, not you. If you would rather not use the app, email daniel.f.velez@gmail.com from the address your account uses and we will action it within 30 days. Backups, if any, are purged on their normal cycle. We may retain the minimum records we are legally required to keep.

The step-by-step instructions, and how to delete part of your data while keeping your account, are on the delete-your-data page.

Community contributions

Contributed sensor definitions and driving samples are kept for as long as they are useful to the shared vehicle database. Because they carry no full VIN and no timestamp, they are not personal data about you once submitted, and they may remain in aggregate definitions after your account is deleted. If you want your submitted contributions removed as well, say so in your deletion email and we will remove the records attributed to your account.

Contributed public photos

Photos you contributed to the public pool remain available to other users until you ask us to withdraw them. Ask at daniel.f.velez@gmail.com.

Analytics

See section 3. Switch analytics off in Settings to stop future collection.

Your rights

Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, to object to processing, and to complain to your data-protection authority. Email daniel.f.velez@gmail.com and we will act on the request. We will not charge you or degrade the app for exercising these rights.

14 · Children's privacy

Gaugely is a tool for vehicle owners and is not directed to children. We do not knowingly collect personal data from anyone under 13 (or the minimum age in your country, where that is higher). If you believe a child has provided us personal data through an account, email daniel.f.velez@gmail.com and we will delete it.

15 · Changes to this policy

We will update this page when the app changes what it collects, and we will move the "last updated" date at the top. If a change is material — a new category of data, or a new recipient — we will ask you to review and accept the updated terms in the app before it takes effect. The current version is always at this URL.

Questions: daniel.f.velez@gmail.com.

Gaugely · Privacy Policy · effective 17 August 2026