Last updated 4 September 2026
Privacy policy
In short. Your vehicle passport is stored on your device. Bortio works without an account and without sending your vehicle history anywhere. One optional feature (reminders that survive a phone restart) sends a small, closed set of data to our server, and it stays off until you turn it on.
1. Who is responsible
The Bortio mobile application and this website are operated by Nikita Afanasiev, an individual software developer ("Bortio", "we"). For the processing described below, he acts as the data controller.
Contact for any privacy question or request: privacy@bortio.com.
2. What stays on your device
Everything that makes up your passport is written to a database in the app's private storage on your phone, and to the app's private file sandbox for attachments:
- vehicles, including VIN, registration number, make, model, year and powertrain;
- maintenance, fuel, charging and expense records, with amounts and currency;
- mileage readings and odometer history;
- reminders, their due dates and target mileage;
- notes you write;
- photographs and documents you attach;
- your settings, such as units and currency.
We have no copy of any of this. It is not uploaded, not synchronised to a backend and not readable by us. Deleting the app deletes it, so keep your own backups of anything you would not want to lose.
3. Photographs and media
Attachments are chosen through the operating system's own picker, which runs outside the app. Because of that, Bortio never asks for access to your whole photo library. It only receives the specific file you picked. The file is copied into the app's private sandbox and linked to one record.
When you explicitly choose Scan receipt, Bortio processes the selected image on your device using bundled ML Kit Text Recognition on Android or Apple Vision on iOS. The image and recognised text are not sent to Bortio or to a cloud AI provider. Suggested fields remain editable, and the original attachment stays in the app's private sandbox.
4. Accounts
Bortio is usable with no account at all. If you use a feature that needs one, an anonymous identifier is created for your installation through Firebase Authentication. It is not connected to your name, email, or phone number.
You may optionally link that anonymous account to Sign in with Apple or Sign in with Google, so it can be restored on a new device. If you do, we receive the account identifier that the provider returns to us and, depending on your choices with that provider, an email address. We use it only to recognize you when you sign in.
5. Optional server-side reminders
Local notifications can be lost. Android clears scheduled alarms on restart, and an app that has not been opened since then has nothing scheduled. To close that gap you can enable server-side reminders. The switch is in Settings and is off by default. While it is off, the app remains entirely local.
When it is on, one record per pending notification is sent to our server:
| Field | What it is |
|---|---|
| Account id | Your anonymous identifier, not linked to your identity. |
| Device token | The push token issued to your installation by Apple or Google. |
| Send time | When the notification should be delivered, in UTC. Your device calculates it. |
| Slot id | An internal key identifying which reminder and which lead time this is. |
| Title and text | The words you would see on screen, already translated by your device. |
Our server does not compute dates, does not translate text and does not know what any reminder is about. It only hands due records to the push service.
What is never sent, under any setting:
- your notes, which contain policy numbers and mechanics' phone numbers;
- photographs and documents;
- mileage, and any reminder measured in distance rather than time;
- VIN, registration number, make, model or year. A vehicle's name appears in the title only when you have more than one vehicle, and only as the text already shown on your screen;
- amounts, prices, currency, or your record history.
One consequence we state plainly rather than hide: because the send time is transmitted, an approximate due date can be inferred from it. That is unavoidable for a server that sends reminders on time, and it is the reason the feature is opt-in.
Legal basis: your consent (Art. 6(1)(a) GDPR). Switching the feature off withdraws it, and the pending records are removed.
6. Notifications
Permission to send notifications is requested in context, after your first reminders exist, not on first launch. You can decline, and refuse or revoke it later in system settings; the app stays fully usable, with deadlines visible on screen instead.
7. Analytics
In the app
We use Firebase Analytics to understand which flows people use and where they get stuck. It measures product usage, never the passport itself. Events are restricted, by design and by automated tests, to a fixed list: a screen was opened; a vehicle was added, with its type and powertrain; a record was added, with its type; a reminder was added; an account was linked, with the provider used; an onboarding lesson was begun or finished; a capacity limit was reached; the plan screen was opened, and a purchase was started, completed or cancelled; a purchase was restored, with the outcome; something was shared, with the kind of thing shared.
Analytics events can never contain:
- VIN, registration number, make, model or vehicle nickname;
- identifiers of records, vehicles, reminders or accounts;
- notes, work titles, document names or any other text you entered;
- mileage, dates, coordinates or attachment contents;
- the amounts and currencies of anything you recorded yourself.
One event is the exception, and only for the money you paid us: when a purchase completes, we report it with the price and currency code that the store returned for that product, and with the store's order number, which is how Firebase discards duplicates. It is the price of a fixed product, not a sum derived from your records, and it identifies the purchase rather than you: no account, no email, no device. Nothing about what you recorded — a fuel receipt, a service bill, a cost total — is ever sent to analytics.
The advertising identifier is deliberately excluded on both platforms: on Android the advertising-id library is not linked and the permission to read the identifier is removed from the app, and the optional iOS identity component is not included. We do not set a user id in analytics. We do not use your data for advertising, profiling or automated decision-making, and we do not sell it.
Analytics also derives an approximate location — a country or region, no more precise — from the network address your device connects from. The address is truncated by Google before the location is derived. The app requests no location permission and reads no device location: there is no way for it to know where you are beyond that.
Legal basis: our legitimate interest in improving the app (Art. 6(1)(f) GDPR).
On this website
Website analytics is off until you explicitly allow it. If you do, Firebase Analytics records only a page category, selected call-to-action clicks, whether the Early Access section was viewed, and whether a submission succeeded or failed. It never receives an email address, form contents, a full URL, query string, referrer, or free text.
Advertising storage and personalisation remain disabled. Your choice is stored in this browser. You can change it at any time with Cookie settings in the footer; choosing “Reject” stops further collection and removes accessible analytics cookies. Legal basis: your consent (Art. 6(1)(a) GDPR).
Website cookies and similar storage
| Name | Purpose | When and duration |
|---|---|---|
bortio.analytics.choice.v1 |
Local browser storage that remembers whether you allowed or rejected analytics. It is not sent to our server. | After you choose; until you change the choice or clear browser data. |
_ga |
Google Analytics first-party cookie used to distinguish one browser from another. | Only after “Allow analytics”; up to 13 months. |
_ga_<measurement-id> |
Google Analytics first-party cookie used to retain session state. | Only after “Allow analytics”; up to 13 months. |
When you submit the Early Access form, Firebase Authentication and App Check may use necessary browser storage to authenticate that request and reduce automated abuse. This storage is not used for advertising or website analytics.
8. Service providers
We use Google (Firebase) for authentication, push delivery, the reminder records described in section 5, purchase verification as described in section 9, analytics, and hosting of this website. Google acts as our processor and may process data outside the EEA under the European Commission's standard contractual clauses. Apple and Google additionally operate the push notification services that deliver messages to your device.
Two technical details of those services send data of their own, and neither describes you. Firebase Cloud Messaging registers your installation and reports the app's version number, so that a message can reach this device at all. Before our server answers a request, it checks that the request came from a genuine, unmodified copy of the app: on Android that check is Google Play Integrity, which returns a verdict about the app and the device to Google, and on the website it is an invisible reCAPTCHA. The verdict tells us only whether to trust the request. Both are what stop a modified copy from asking our server for paid access or filling the reminder queue with junk.
9. Purchases
Bortio's optional Pro upgrade is bought through Google Play. The payment itself is processed entirely by Google, acting as its own controller of the payment data: we never receive your card details, billing address or name.
Unlocking what you bought does involve our server, and it has to. A purchase proves itself only against Google Play, so the app sends the purchase token to our verification function, which asks Google Play whether that token really is a completed purchase of that product. Access is granted only on Google's answer — never on the app's own word — because anything else would mean handing out paid features to a modified copy of the app.
What we keep on our server for a purchase:
- a hash of the purchase token, not the token itself;
- which product it was, and the time of purchase reported by Google Play;
- the order number, when Google Play provides one — a promo code redemption has none;
- an anonymous Firebase identifier, so the entitlement can be found again;
- for extra Garage capacity only, a flag recording that the purchase was made from your linked Google account, so that capacity survives a reinstall. The account itself is not stored with the record.
Google Play also notifies our server when a purchase is refunded or revoked, so that access ends when the payment does. Restoring a purchase on a new device asks Google Play the same question again. Refunds and receipts are handled in Google Play, under Google's own terms.
This record is the one thing that deleting your data in the app does not remove, and we would rather say so than let you discover it. It is what proves you paid: erase it and the app would take away the features you bought. Deleting your reminder data removes the reminder queue and your anonymous account, and leaves the purchase record standing. Ask us at privacy@bortio.com and we will remove it too — that also ends the paid access it grants. The purchase itself continues to exist in your Google Play account, where only Google can change it. Legal basis for keeping it: performance of the contract you entered when you bought the upgrade (Art. 6(1)(b) GDPR).
On iOS the purchase is not yet available; when it ships, it will go through the App Store on the same terms. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
10. Launch list
If you join the launch list on bortio.com, we store your email address, the platform you selected, submission time, browser language, the referring site's hostname, any campaign labels in the link, and the version of this policy you agreed to. We do not store the referring page, its query string or your vehicle data. The form uses an anonymous Firebase Authentication identifier to prevent the same browser from creating the same request repeatedly.
We use the address for one message when the relevant public build is ready, not for a newsletter or advertising. Legal basis: your consent (Art. 6(1)(a) GDPR). Ask us to remove it at any time at privacy@bortio.com.
11. How long we keep things
- Pending reminder records: until the notification is sent, then deleted; at the latest when you disable the feature or delete your data.
- Anonymous or linked account: until you delete it.
- Analytics events: retained by Firebase Analytics for up to 14 months in aggregate form.
- Early access address: until the launch message is sent, you withdraw consent, or 12 months after launch, whichever comes first, and in any case no later than 24 months after you signed up.
- Purchase entitlement: held by Google Play against your Google account; the local copy lives until you delete the app, and is re-derived from Google Play on restore.
- Server-side purchase record (section 9): kept while the purchase grants access, because it is what proves you paid; removed when the purchase is refunded or revoked, or when you ask us to remove it.
- Everything on your device: until you delete the record, or the app.
12. Your rights
Under the GDPR you may request access to your data, its correction or erasure, restriction of or objection to processing, and portability, and you may withdraw consent at any time. Because the passport is held on your device, you already have direct access to it and can edit or delete any part of it in the app.
For the server-side data, deletion has an address inside the app rather than in a support queue: Settings contains a delete action that erases your account and any pending reminder records. See Delete your data for the steps.
You may also write to privacy@bortio.com, and you have the right to lodge a complaint with your local data protection authority.
13. Children
Bortio is intended for vehicle owners and is not directed at children under 16. We do not knowingly collect data from them.
14. This website
bortio.com is a static site served by Firebase Hosting. It runs no advertising. Firebase Analytics is loaded only after the website consent described in section 7. The Early Access form loads the Firebase client and invisible reCAPTCHA App Check from Google only when needed to authenticate the request and reduce automated abuse. Firebase may receive standard technical request data such as your IP address. Fonts are served from this domain. The hosting server also keeps standard technical request logs for security and diagnostics.
15. Changes
If this policy changes, the date at the top changes with it. Changes that affect what leaves your device will be announced in the app before they take effect.