BortioTM

Last updated 4 September 2026

Privacy policy

In short. Your vehicle passport is stored on your device. Bortio works without an account and without sending your vehicle history anywhere. One optional feature (reminders that survive a phone restart) sends a small, closed set of data to our server, and it stays off until you turn it on.

1. Who is responsible

The Bortio mobile application and this website are operated by Nikita Afanasiev, an individual software developer ("Bortio", "we"). For the processing described below, he acts as the data controller.

Contact for any privacy question or request: privacy@bortio.com.

2. What stays on your device

Everything that makes up your passport is written to a database in the app's private storage on your phone, and to the app's private file sandbox for attachments:

We have no copy of any of this. It is not uploaded, not synchronised to a backend and not readable by us. Deleting the app deletes it, so keep your own backups of anything you would not want to lose.

3. Photographs and media

Attachments are chosen through the operating system's own picker, which runs outside the app. Because of that, Bortio never asks for access to your whole photo library. It only receives the specific file you picked. The file is copied into the app's private sandbox and linked to one record.

When you explicitly choose Scan receipt, Bortio processes the selected image on your device using bundled ML Kit Text Recognition on Android or Apple Vision on iOS. The image and recognised text are not sent to Bortio or to a cloud AI provider. Suggested fields remain editable, and the original attachment stays in the app's private sandbox.

4. Accounts

Bortio is usable with no account at all. If you use a feature that needs one, an anonymous identifier is created for your installation through Firebase Authentication. It is not connected to your name, email, or phone number.

You may optionally link that anonymous account to Sign in with Apple or Sign in with Google, so it can be restored on a new device. If you do, we receive the account identifier that the provider returns to us and, depending on your choices with that provider, an email address. We use it only to recognize you when you sign in.

5. Optional server-side reminders

Local notifications can be lost. Android clears scheduled alarms on restart, and an app that has not been opened since then has nothing scheduled. To close that gap you can enable server-side reminders. The switch is in Settings and is off by default. While it is off, the app remains entirely local.

When it is on, one record per pending notification is sent to our server:

FieldWhat it is
Account idYour anonymous identifier, not linked to your identity.
Device tokenThe push token issued to your installation by Apple or Google.
Send timeWhen the notification should be delivered, in UTC. Your device calculates it.
Slot idAn internal key identifying which reminder and which lead time this is.
Title and textThe words you would see on screen, already translated by your device.

Our server does not compute dates, does not translate text and does not know what any reminder is about. It only hands due records to the push service.

What is never sent, under any setting:

One consequence we state plainly rather than hide: because the send time is transmitted, an approximate due date can be inferred from it. That is unavoidable for a server that sends reminders on time, and it is the reason the feature is opt-in.

Legal basis: your consent (Art. 6(1)(a) GDPR). Switching the feature off withdraws it, and the pending records are removed.

6. Notifications

Permission to send notifications is requested in context, after your first reminders exist, not on first launch. You can decline, and refuse or revoke it later in system settings; the app stays fully usable, with deadlines visible on screen instead.

7. Analytics

In the app

We use Firebase Analytics to understand which flows people use and where they get stuck. It measures product usage, never the passport itself. Events are restricted, by design and by automated tests, to a fixed list: a screen was opened; a vehicle was added, with its type and powertrain; a record was added, with its type; a reminder was added; an account was linked, with the provider used; an onboarding lesson was begun or finished; a capacity limit was reached; the plan screen was opened, and a purchase was started, completed or cancelled; a purchase was restored, with the outcome; something was shared, with the kind of thing shared.

Analytics events can never contain:

One event is the exception, and only for the money you paid us: when a purchase completes, we report it with the price and currency code that the store returned for that product, and with the store's order number, which is how Firebase discards duplicates. It is the price of a fixed product, not a sum derived from your records, and it identifies the purchase rather than you: no account, no email, no device. Nothing about what you recorded — a fuel receipt, a service bill, a cost total — is ever sent to analytics.

The advertising identifier is deliberately excluded on both platforms: on Android the advertising-id library is not linked and the permission to read the identifier is removed from the app, and the optional iOS identity component is not included. We do not set a user id in analytics. We do not use your data for advertising, profiling or automated decision-making, and we do not sell it.

Analytics also derives an approximate location — a country or region, no more precise — from the network address your device connects from. The address is truncated by Google before the location is derived. The app requests no location permission and reads no device location: there is no way for it to know where you are beyond that.

Legal basis: our legitimate interest in improving the app (Art. 6(1)(f) GDPR).

On this website

Website analytics is off until you explicitly allow it. If you do, Firebase Analytics records only a page category, selected call-to-action clicks, whether the Early Access section was viewed, and whether a submission succeeded or failed. It never receives an email address, form contents, a full URL, query string, referrer, or free text.

Advertising storage and personalisation remain disabled. Your choice is stored in this browser. You can change it at any time with Cookie settings in the footer; choosing “Reject” stops further collection and removes accessible analytics cookies. Legal basis: your consent (Art. 6(1)(a) GDPR).

Website cookies and similar storage

When you submit the Early Access form, Firebase Authentication and App Check may use necessary browser storage to authenticate that request and reduce automated abuse. This storage is not used for advertising or website analytics.

8. Service providers

We use Google (Firebase) for authentication, push delivery, the reminder records described in section 5, purchase verification as described in section 9, analytics, and hosting of this website. Google acts as our processor and may process data outside the EEA under the European Commission's standard contractual clauses. Apple and Google additionally operate the push notification services that deliver messages to your device.

Two technical details of those services send data of their own, and neither describes you. Firebase Cloud Messaging registers your installation and reports the app's version number, so that a message can reach this device at all. Before our server answers a request, it checks that the request came from a genuine, unmodified copy of the app: on Android that check is Google Play Integrity, which returns a verdict about the app and the device to Google, and on the website it is an invisible reCAPTCHA. The verdict tells us only whether to trust the request. Both are what stop a modified copy from asking our server for paid access or filling the reminder queue with junk.

9. Purchases

Bortio's optional Pro upgrade is bought through Google Play. The payment itself is processed entirely by Google, acting as its own controller of the payment data: we never receive your card details, billing address or name.

Unlocking what you bought does involve our server, and it has to. A purchase proves itself only against Google Play, so the app sends the purchase token to our verification function, which asks Google Play whether that token really is a completed purchase of that product. Access is granted only on Google's answer — never on the app's own word — because anything else would mean handing out paid features to a modified copy of the app.

What we keep on our server for a purchase:

Google Play also notifies our server when a purchase is refunded or revoked, so that access ends when the payment does. Restoring a purchase on a new device asks Google Play the same question again. Refunds and receipts are handled in Google Play, under Google's own terms.

This record is the one thing that deleting your data in the app does not remove, and we would rather say so than let you discover it. It is what proves you paid: erase it and the app would take away the features you bought. Deleting your reminder data removes the reminder queue and your anonymous account, and leaves the purchase record standing. Ask us at privacy@bortio.com and we will remove it too — that also ends the paid access it grants. The purchase itself continues to exist in your Google Play account, where only Google can change it. Legal basis for keeping it: performance of the contract you entered when you bought the upgrade (Art. 6(1)(b) GDPR).

On iOS the purchase is not yet available; when it ships, it will go through the App Store on the same terms. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

10. Launch list

If you join the launch list on bortio.com, we store your email address, the platform you selected, submission time, browser language, the referring site's hostname, any campaign labels in the link, and the version of this policy you agreed to. We do not store the referring page, its query string or your vehicle data. The form uses an anonymous Firebase Authentication identifier to prevent the same browser from creating the same request repeatedly.

We use the address for one message when the relevant public build is ready, not for a newsletter or advertising. Legal basis: your consent (Art. 6(1)(a) GDPR). Ask us to remove it at any time at privacy@bortio.com.

11. How long we keep things

12. Your rights

Under the GDPR you may request access to your data, its correction or erasure, restriction of or objection to processing, and portability, and you may withdraw consent at any time. Because the passport is held on your device, you already have direct access to it and can edit or delete any part of it in the app.

For the server-side data, deletion has an address inside the app rather than in a support queue: Settings contains a delete action that erases your account and any pending reminder records. See Delete your data for the steps.

You may also write to privacy@bortio.com, and you have the right to lodge a complaint with your local data protection authority.

13. Children

Bortio is intended for vehicle owners and is not directed at children under 16. We do not knowingly collect data from them.

14. This website

bortio.com is a static site served by Firebase Hosting. It runs no advertising. Firebase Analytics is loaded only after the website consent described in section 7. The Early Access form loads the Firebase client and invisible reCAPTCHA App Check from Google only when needed to authenticate the request and reduce automated abuse. Firebase may receive standard technical request data such as your IP address. Fonts are served from this domain. The hosting server also keeps standard technical request logs for security and diagnostics.

15. Changes

If this policy changes, the date at the top changes with it. Changes that affect what leaves your device will be announced in the app before they take effect.