Moto Companion

Privacy policy

Nothing is stored. Little is sent.

Effective 7 August 2026

What we collect

No accounts, no analytics, no tracking, no ads, no database. Three features send data off the device to do their job — the mechanic chat, invoice reading, and the add-bike lookup, described below. What they send is processed transiently and not stored by us.

Where your data lives

Your bikes, odometer readings, service schedule, and logbook live on your device. When iCloud is available, they sync through your private iCloud database (CloudKit). Only you can access it — Apple encrypts it against your Apple Account, and the developer has no way in.

The mechanic chat

Your message and the bike file it needs for a useful answer — model, odometer, schedule, recent logbook lines, the conversation so far — are sent encrypted to our server on Vercel and passed to a language model (Google Gemini, via the Vercel AI Gateway) to write the reply. Nothing is stored on our server, nothing is used for training, and nothing in the request identifies you. Vercel and Google act as processors: they handle these requests only to produce the answer, under terms that hold them to protection equivalent to this policy. Each request carries an Apple App Attest check proving it comes from a genuine copy of the app — a cryptographic key, not an account.

Reading invoices

When you scan an invoice, the photo is sent once, encrypted, to the same server and read by the model. The extracted line items come back; the photo is not kept by us, and the same processor terms cover it. Nothing writes to your logbook until you review and apply. The bundled sample invoice is read on the device and sends nothing.

Looking up your bike

When you add a bike the library doesn't know, the app can search the web for the exact model designation and its factory maintenance schedule. What's sent is the bike's make, model, and year — nothing else, nothing personal. The request goes encrypted to the same server, where the language model runs a web search through Google's search grounding (via the Vercel AI Gateway) and shapes the result. Vercel and Google act as processors under the same terms: they handle the query only to produce the answer, and we store none of it.

Push notifications

The app uses silent push notifications for one purpose: keeping iCloud sync fresh. They carry no content and are not used to message you.

Preferences

The app stores settings with the standard user-defaults system, declared in the bundled privacy manifest under reason CA92.1. That is the full extent of it.

Deleting your data

Delete the app and the data on the device goes with it. To remove the synced copy, delete the app's iCloud data in iOS Settings. There is nothing to delete server-side, because nothing is kept there.

Contact

Questions about privacy go to emmanuel@captaindev.io.