Kotselog — Privacy Policy
Last updated: 6 August 2026 · Applies to Kotselog version 1.0 for Android and to the browser version at app.kotselog.com
Kotselog (“the app”) is a driver companion that helps you track your vehicles, fuel, expenses, maintenance, trips, documents and registration/licence renewals. Kotselog is local-first and private by design: your records live on your device, in a private app database, and they stay there unless you deliberately turn on the optional account sync described below.
Kotselog is free to use. Everything that keeps your logbook — vehicles, fuel, expenses, maintenance, service history, trips, documents, reminders and reports — works without paying, without an account, and without ads. There is an optional tip jar, and cross-device sync requires a subscription; both are described under “Payments” below.
What the app stores on your device
- Vehicle & logbook data — vehicles, fuel fill-ups, expenses, service and maintenance records, trips, violations, fuel prices, shops you save, and the driver & emergency details you choose to enter. All of it is typed in by you and stored on your device.
- Document photos — images you attach (OR/CR, licence, insurance, receipts) are copied into the app's private storage on your device.
- OBD-II readings — live diagnostics read from an ELM327 adapter, kept on the device.
Location
Kotselog asks for location permission so it can:
- Log a trip's route, distance and duration for your mileage log, and
- suggest the nearest fuel station when you tap “Use nearest station”, and
- include your position in an emergency/SOS message that you choose to send.
Kotselog v1 does not use background location. The Android app declares no
ACCESS_BACKGROUND_LOCATION permission and never starts a background location service. Trip
logging works only while Kotselog is open on screen; if you leave the app or lock your phone, location
collection stops.
What a recorded trip contains. When you use automatic GPS trip logging, Kotselog saves the full route — a list of points, each with a timestamp, latitude, longitude and speed — plus the distance, duration, and average and top speed. It also converts the first and last points into a place name (“from”/“to”), which is a network lookup: the coordinates are sent to your device's own geocoding service (on Android, Google Play services) to get a street and city back.
Read this if you use sync. Recorded routes stay on your device only for as long as you stay signed out. If you sign in to a Kotselog account, your trips — including that complete point-by-point route geometry and the place names — are uploaded to our sync server along with your other records. This is precise location history, so we want to be unambiguous about it. See “Optional account & cross-device sync” below for exactly when that upload happens and what control you have over it.
Bluetooth
Bluetooth is used only to connect to an ELM327 OBD-II adapter and read your car's live diagnostics.
The app is read-only against your car, and the Bluetooth scan is declared neverForLocation
— Kotselog does not derive or infer your location from Bluetooth.
Camera & photos
The camera and photo library are used only when you attach or scan a document. Selected images are copied into the app's private storage. Kotselog does not browse or upload your photo library.
Notifications
Reminders (registration, licence, maintenance and document expiry) are scheduled locally on your device. Kotselog does not run a push-notification server and does not register a push token.
When information leaves your device
Kotselog works offline. These are the only cases where anything is sent off the device, and each one follows from something you chose to do in the app:
- Nearest fuel station. When you tap “Use nearest station”, your current
coordinates are sent to the OpenStreetMap Overpass API
(
overpass-api.de) to look up fuel stations within about 1.2 km. Only the coordinates are sent — no account, name, or device identifier — and the result is used to fill in a station name you can edit or ignore. - Optional account & cross-device sync (subscription, off by default). Kotselog works
fully without an account. If you create one, you provide an email address and
password, and your logbook records are then stored on our sync service (hosted at
sync.kotselog.com; older installs may still reach the same service under its previous name,garahe.apps.taraki.dev) so they can appear on your other devices.What is uploaded: vehicles, fuel logs, expenses, maintenance, service records, trips (including the complete GPS route: every recorded point with its timestamp, coordinates and speed, plus the reverse-geocoded start and end place names), fuel prices, document entries, violations, saved shops, shop reviews and your maintenance-interval settings.
What is never uploaded: your driver profile, your emergency contact details, OBD-II diagnostic logs, performance-run records, fleet settings, and the image files behind your document entries (the document's title, type, expiry date and file name do sync — the picture itself does not).
When it happens, and your control over it. Sync is not automatic in the background. It runs at two moments: immediately when you sign in, and whenever you tap “Sync now”. There is no scheduled or background upload. Sync is all-or-nothing: there is no setting that lets you sync some record types but not others, so you cannot keep your fuel and expense records synced while holding your trip routes back. If you do not want your routes uploaded, the options are to not sign in, to sign out, or to delete the trips before you sync. Signing out stops any further uploads from that device, but it does not delete what has already been uploaded — for that, email us (see “Data retention & deletion”).
Traffic is encrypted in transit (HTTPS/TLS). Your records are used only to provide the sync service — never sold, never used for advertising. - Place names for trip start and end. When an automatic GPS trip finishes, Kotselog asks your device's geocoding service to turn the first and last coordinates into a readable street/city label. On Android that lookup is performed by Google Play services over the network, so those two coordinate pairs leave the device even if you never sign in. Google's privacy policy governs that lookup; we do not receive or store anything from it beyond the returned label, which is saved with the trip.
- Fleet tracking (off by default, your own server). If you turn on the optional Fleet feature, you supply the address of your own tracking server and an access token. Kotselog then sends that token to that server to fetch your vehicles' positions and trip history. The token is held in your device's secure storage. Nothing about this goes to us, and the feature is entirely inactive unless you configure it.
- Emergency/SOS message. Kotselog composes the message and opens your phone's messaging app with it pre-filled; you tap send. The message goes to the contact you chose, through your own carrier. Kotselog does not send it for you and does not receive a copy.
- Maps & navigation links. Tapping a “directions” link opens Google Maps or Waze in your browser or their app, with the destination in the link. Their privacy policies apply once you leave Kotselog.
- Reports and exports. PDF/CSV reports and data-log exports are generated on your device and handed to your system share sheet. Where they go from there is entirely your choice.
Backups
Kotselog can take a full snapshot of your records and encrypt it on your device (AES-256-GCM, with the key derived from your passphrase using scrypt). In this release no cloud backup service is configured, so the encrypted backup file is written to storage on your own device and does not leave it unless you export or share the file yourself. If cloud backup is ever enabled in a future version, only the ciphertext would be uploaded — we would not receive your passphrase and could not read the backup. If you lose your passphrase, the backup cannot be recovered by anyone, including us.
Payments
Two things in Kotselog can involve money. Both are optional, and neither is required to use your logbook.
- Tips. A one-off, entirely optional payment if you want to support development. Tips unlock nothing — no feature, no badge, no removal of anything. They do not renew. The only record Kotselog keeps is a count stored on your own device, which is never uploaded and is used solely to say thank you.
- Cross-device sync subscription. Syncing your records between devices is a paid feature. Everything else stays free.
We never see your payment details. Purchases are processed by Google Play, using the payment method on your Google account. Kotselog does not receive, handle or store your card number, billing address or any other financial information. Purchase and subscription status is managed for us by RevenueCat, which receives an anonymous purchase identifier and the details of the purchase itself in order to tell the app whether a subscription is active — it does not receive your logbook records or your location data. Billing questions, refunds and cancellations are handled through Google Play.
Your data is never held hostage by a subscription. Kotselog is local-first: your records live on your device and stay fully readable, editable and exportable whether or not you have an active subscription. If a subscription lapses, syncing stops — nothing on your device is deleted, hidden, or locked, and you can still export everything from the Reports screen.
Advertising and analytics
The Kotselog Android app contains no advertising, no ad networks, and no third-party analytics, attribution or tracking SDKs. It does not build an advertising profile and does not track you across apps or websites.
For transparency: the browser version of Kotselog at app.kotselog.com
loads Google Analytics 4, which records standard web measurement data (page views,
approximate region, device and browser type). That applies only when you use Kotselog in a web browser
— it is not part of the Android app, and it never has access to your vehicle records, which
stay in your browser's local storage.
What Kotselog does not access
Kotselog does not request or use your microphone, your contacts list, your call or SMS history, your calendar, or permission to draw over other apps. We do not sell your personal information, and the only third parties that receive anything are the specific services named above — the OpenStreetMap Overpass API, your device's geocoding service, and any server you configure yourself.
Data retention & deletion
Data on your device stays until you delete the record, use the in-app options to clear your data, or uninstall the app — uninstalling removes Kotselog's on-device database and attached files.
If you use sync, deletion currently depends on what you are deleting.
- Service logs delete everywhere. Deleting a service log removes it from this device immediately, and removes it from our sync server and your other devices the next time you sync (on sign-in, or when you tap “Sync now” — there is no background sync). It does not come back when another device syncs.
- Everything else is still device-only. For all other records — including trips and their recorded GPS routes, fuel logs, expenses, maintenance, documents, violations and saved shops — deleting in the app removes the record from that device only. The copy already on our sync server remains, and another device that has it keeps it. To have that data removed, email us at the address below and we will delete your account and everything stored against it from our servers.
We are extending the propagating-delete mechanism to the remaining record types; this section will be updated as each one lands, rather than in advance of it.
Children
Kotselog is intended for licensed drivers and is not directed at children.
Contact
Questions or data-deletion requests: theodoro.pelingan@gmail.com
This policy may be updated as the app evolves; the “last updated” date above will change accordingly. Material changes — such as introducing background location or a paid tier — will be reflected here before the feature ships.