NoCheck
PrivacyTerms
  • English
  • العربية
  • Čeština
  • Deutsch
  • Español
  • Français
  • עברית
  • Magyar
  • Bahasa Indonesia
  • Italiano
  • 日本語
  • 한국어
  • Nederlands
  • Polski
  • Português (Brasil)
  • Română
  • Русский
  • Svenska
  • Türkçe
  • Українська
  • Tiếng Việt
Home/Privacy Policy

Privacy Policy

Last updated: 8 September 2026

This Privacy Policy explains how NoCheck (“NoCheck”, “we”, “us”, or “our”) handles information when you use the NoCheck mobile app and the website at nocheck.app (together, the “Service”).

NoCheck is a vehicle and maintenance tracker. It is offline-first: the data you enter lives on your device, and most of it never leaves it. This policy sets out exactly what we do — and do not — collect, why, who processes it on our behalf, and the rights you have over it.

By using the Service you agree to this Privacy Policy. If you do not agree, please do not use the Service.

The short version

  • NoCheck works offline. Your vehicles, mileage, service logs, and settings are stored on your device.
  • We do not run ads, use an advertising ID, track you across apps or websites, use any analytics SDK, or collect your location.
  • To sign in we collect your name and email (from Google, Apple, or a passwordless email link) so you have an account.
  • Your garage data is copied to the cloud only if you are a Premium subscriber with backup enabled. On the free plan it stays on your device.
  • Subscriptions are billed by Apple, Google, or Samsung, not by us — we never see your card or payment details.
  • You can delete your account and all associated data at any time, from inside the app or via nocheck.app/delete-account.

Who we are and how to contact us

NoCheck is the provider of the Service and is responsible for the personal data described in this policy (in data-protection terms, the “controller”). For any privacy question, request, or complaint, contact us at support@nocheck.app.

What we collect and why

Account and identity

When you sign in, we create an account and process a small amount of identity data through Firebase Authentication (a Google service):

  • Email address. Required to identify your account. If you sign in with Apple and choose “Hide My Email”, we receive Apple’s private-relay address instead of your real one.
  • Name / display name. Provided by Google, or by Apple the first time you authorise sign-in. Some sign-in methods (for example, the passwordless email link, or Apple sign-in on Android) do not supply a name, in which case we do not have one.
  • A user ID and sign-in provider identifiers. A unique account identifier and a record of which methods (Google, Apple, or email) are linked to your account.

The passwordless email option signs you in with a one-time link — it never sets a password on your account, and we never ask you to choose one. The email address you enter is kept on your device only to complete that sign-in.

Your vehicle and maintenance content

This is the data you create in the app — your garage. It includes your vehicles (name, make, model, year, type, mileage or engine-hours readings, and unit preferences), the maintenance items and reminders you set up, your service logs (including dates, readings, and any free-text notes you add), your reading history, and any custom maintenance types you create.

  • On the free plan, this content is stored only on your device and is not transmitted to us or anyone else.
  • If you are a Premium subscriber with cloud backup enabled, a copy of this content is backed up to the cloud so it can be restored and synced across your devices. See “When your data leaves your device” below.

The photo you can add to a vehicle is part of this content. Adding one is optional and available on every plan, and you choose the picture yourself from your camera or photo library — the app never reads your photo library, it receives only the picture you pick. On the free plan the photo stays on your device; with Premium backup enabled it is copied to our cloud file storage along with the rest of your garage.

Device features the app can use

Two optional features use hardware on your phone. Both do their work on the device, and neither sends what it reads — a camera frame, a Bluetooth address — to us or to anyone else. (If the app itself crashes, the report described under Diagnostics and crash data below is still sent; a crash report cannot carry an image, and we never attach your camera frames or a linked Bluetooth address to one.)

  • Camera (odometer scanner). The scanner opens a live camera preview and reads the number with a text-recognition model bundled in the app. No photo or video frame is uploaded or saved — only the number, and only when you save the reading.
  • Nearby devices / Bluetooth (car reminders, Android). If you link a vehicle to your car’s Bluetooth, the app is told when your phone connects to a paired device, so it can remind you to update your reading. It matches only the Bluetooth address you linked, which stays on your phone — it is not part of your NoCheck cloud backup and we never receive it. (Your phone’s own system backup, run by Apple or Google, may include it; that copy goes to your account with them, not to us.) The app does not scan for nearby devices and does not use Bluetooth for location. On iOS the same reminder is run by a Shortcuts automation you create yourself.

Subscription and purchase information

Premium is sold as an in-app purchase. Billing is handled entirely by the Apple App Store, Google Play or the Samsung Galaxy Store; we never receive or store your payment card or billing details. To manage your subscription status we use RevenueCat, which links your purchases to your account identifier and processes your store purchase records and entitlement status (for example, which plan you have and whether it is active). We store only your entitlement state (such as whether Premium is active and until when).

Diagnostics and crash data

To keep the app stable, released versions include Firebase Crashlytics, which automatically collects crash reports and basic diagnostics — such as the type of crash, a stack trace, your device model, operating-system version, and the app version. This data is not linked to your account or identity (we do not attach your user ID to it). It is collected only in released builds.

Technical and anti-abuse data

  • App integrity (App Check). To protect our backend from abuse, the app attests that requests come from a genuine, untampered copy of NoCheck using Apple App Attest / Google Play Integrity. These are device- and app-integrity tokens, not identifiers of you.
  • Sign-in email rate limiting. To prevent our sign-in email from being used to spam an address, our server keeps a short-lived counter keyed to a one-way cryptographic hash (SHA-256) of the email address. We cannot read the original address back from this hash.
  • Installation identifier. The Firebase services the app depends on (authentication, crash reporting, App Check, remote configuration and, for Premium, cloud backup) each generate a random per-installation identifier. It is created on your device, is not the advertising identifier, and is not used to profile or track you — it exists so those services can tell one installation apart from another. It is regenerated if you reinstall the app.
  • Device registry (Premium sync only). If you use cloud backup, we additionally record a per-installation device identifier, platform, and app version against your account so that syncing across your devices works and so we can apply reasonable limits.

Website

The nocheck.app website is a static site. It does not use tracking cookies, analytics, or advertising. The only thing it stores on your device is a small functional preference (your light/dark theme choice), which never leaves your browser. Because of this we do not display a cookie-consent banner.

What we do not collect

To be explicit, NoCheck does not:

  • show ads or use an advertising identifier;
  • use any analytics or attribution SDK;
  • collect your location;
  • track you across other apps, websites, or companies;
  • send you remote push messages (reminders are generated locally on your device);
  • access your contacts;
  • read or upload your photo library, or upload any other file from your device — the only picture the app receives is the one you pick for a vehicle.

How we use your information

We use the information above to:

  • provide and operate the app and your account;
  • deliver the core features you use (tracking, reminders, and service history);
  • provide Premium cloud backup and sync, when you enable it;
  • process and manage your subscription and entitlements;
  • keep the Service secure and prevent fraud and abuse;
  • diagnose crashes and improve reliability; and
  • respond to your support requests and comply with our legal obligations.

We do not use your data for advertising or profiling, and we do not sell it.

Legal bases (EEA / UK users)

Where the UK GDPR or EU GDPR applies, we rely on these legal bases:

  • Performance of a contract — to give you an account, run the app, provide Premium backup and sync, and manage your subscription.
  • Legitimate interests — to keep the Service secure, prevent abuse (App Check and sign-in rate limiting), and fix crashes so the app stays reliable.
  • Consent — where your device asks you to allow something (such as notifications). You can withdraw such consent in your device settings.
  • Legal obligation — where we must retain or disclose information to comply with the law.

When your data leaves your device

NoCheck is designed to keep data local. Information is transmitted off your device only in these situations:

  • Signing in — your identity data is exchanged with Firebase Authentication; the passwordless option sends your email address to our sign-in service and to our email provider to deliver the link.
  • Premium cloud backup — if (and only if) you are a Premium subscriber with backup enabled, your garage content is copied to our cloud database, and any vehicle photo you added is copied to our cloud file storage. Free-plan data never leaves your device.
  • Subscriptions — your purchase is processed by Apple, Google or Samsung, and your entitlement status is managed through RevenueCat.
  • Crash diagnostics — released builds send crash reports to Crashlytics, not linked to you.
  • Catalog updates — the app may download an updated vehicle make/model catalog. This is an anonymous download of a public file; no personal data is sent.

Who we share data with

We do not sell your personal data and we do not share it for anyone else’s advertising or marketing. We use a small number of trusted service providers (processors) who handle data on our behalf and only as needed to run the Service:

  • Google Firebase — Authentication, Cloud Firestore (Premium backup), Cloud Storage (Premium backup of vehicle photos), Cloud Functions, App Check, Remote Config, Hosting, and Crashlytics.
  • Apple — Sign in with Apple, and App Store billing.
  • Google — Google Sign-In, and Google Play billing.
  • Samsung — Galaxy Store billing.
  • RevenueCat — subscription and entitlement management.
  • Resend — delivery of the passwordless sign-in email.

Each provider processes data under its own privacy terms. When you sign in with, or pay through, Apple, Google, or Samsung, your relationship with them is also governed by their respective privacy policies.

We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, and security of our users, the public, or NoCheck.

Where your data is processed

The Service uses infrastructure in more than one region:

  • Cloud backup data is stored in the European Union — your garage content in a Europe multi-region database, and vehicle photos in a file-storage bucket located in a single European region.
  • Sign-in requests, backup processing, and email delivery are handled by services located in the United States.
  • Apple, Google, Samsung, and RevenueCat process data in their own regions.

Where personal data is transferred internationally (including from the EEA or UK to the United States), we rely on appropriate safeguards for such transfers, such as the providers’ Standard Contractual Clauses and equivalent mechanisms.

How long we keep your data

  • On-device data stays on your device until you delete it or uninstall the app.
  • Account and cloud-backup data is retained while your account exists and is deleted when you delete your account (see below).
  • Crash diagnostics are retained by Crashlytics for a limited period under Firebase’s standard retention (typically around 90 days) and are not linked to you.
  • Subscription records are held by Apple, Google, Samsung, and RevenueCat under their own policies and retention periods.
  • Anti-abuse counters (the hashed-email rate-limit records) expire automatically after a short period.

How we protect your data

We use industry-standard measures to protect your information, including encryption in transit for all data sent to our services, access controls that restrict cloud data to your own account, and app-integrity attestation on our backend. No method of transmission or storage is completely secure, but we work to protect your data using appropriate technical and organisational measures.

Your rights and choices

Depending on where you live, you have rights over your personal data. NoCheck honours these rights for all users where we reasonably can.

Everyone

  • Access and export — most of your data already lives on your device. You can view your garage in the app at any time.
  • Correct — edit your vehicles, logs, and account details in the app.
  • Delete — delete individual items, or your entire account and its data (see “Deleting your account”).
  • Notifications — turn reminders on or off in the app and in your device settings.

EEA and UK users (GDPR)

You have the right to access, rectify, erase, restrict, or object to our processing of your personal data, the right to data portability, and the right to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner’s Office (ICO); in the EEA, your local data-protection authority.

California users (CCPA/CPRA)

You have the right to know what personal information we collect, to access and delete it, to correct it, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share your personal information, and we do not discriminate against you for exercising your rights.

To exercise any of these rights, use the in-app controls or email support@nocheck.app. We may need to verify your identity before acting on a request.

Deleting your account

You can delete your account and all associated data at any time from Settings → Profile → Delete account in the app. Deleting your account removes your sign-in identity and permanently erases your garage data, including any cloud backup. If you signed in with Apple, we also revoke NoCheck’s access to your Apple ID as part of the deletion. If you have already uninstalled the app, email support@nocheck.app from your account’s email address and we will delete it for you. Full instructions are at nocheck.app/delete-account.

Note that records held by Apple, Google, or Samsung about a subscription you purchased are retained by them under their own policies, and anonymous diagnostics that cannot identify you may persist for their normal retention period.

Children

NoCheck is not directed to children. You must be at least 18 years old to create an account and to make purchases. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us at support@nocheck.app and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you in the app. Your continued use of the Service after a change takes effect means you accept the updated policy.

Language

This Privacy Policy was written in English. Where we make it available in another language, that translation is provided for your convenience; if a translation and the English version conflict, the English version is the authoritative one — except where the law of the country you live in says otherwise. Whichever language you read it in, the rights described here are the same, and nothing in this section limits any right you have under mandatory local law.

Contact

Questions about this policy or your data? Email support@nocheck.app.

NoCheck

Legal

PrivacyTermsAccessibility

Contact

Supportsupport@nocheck.app

© 2026 NoCheck. All rights reserved.