Privacy Policy
Effective Date: 2026-09-21
Table of Contents
- Introduction
- Information We Collect
- How We Collect Information
- How We Use Information
- Information Sharing and Disclosure
- Data Retention
- Your Privacy Rights
- Cookies and Tracking
- Global Privacy Control and Do Not Track
- International Data Transfers
- Children's Privacy
- Data Sale and Sharing
- Security Measures
- Changes to This Policy
- Contact Information
1. Introduction
Kaiju Mechanic is an AI-powered vehicle management application for Android and iOS, operated by RB ZILLA LLC ("we," "us," or "our"). Our app lets you ask car questions, track maintenance history, scan documents using optical character recognition (OCR), and optionally connect an OBD-II adapter for live vehicle diagnostics. Most features work with any vehicle; OBD-II diagnostic features require a 1996 or newer vehicle with a supported adapter.
This Privacy Policy explains what personal information we collect when you use the Kaiju Mechanic mobile application and the website at www.kaijumechanic.com (collectively, the "Service"), how we use and share that information, how long we keep it, and what rights you have over it.
Orders placed at our merchandise store, shop.kaijumechanic.com, are not covered by this policy. That store publishes its own Privacy Policy and Terms of Service, which govern purchases made there.
This policy applies to all users of the Service. By using Kaiju Mechanic, you acknowledge that you have read and understood this policy. If you do not agree with our practices, please discontinue use of the Service.
Controller Identity: RB ZILLA LLC is the data controller for all personal information processed through the Service.
2. Information We Collect
2.1 Account and Identity Information
When you create an account, we collect your name, email address, and a password-derived credential (we do not store plaintext passwords). If you register or sign in using a social login provider, see Section 2.2 below.
2.2 Social Login Data
You may create or access your Kaiju Mechanic account using Google or Apple as an OAuth identity provider. When you choose one of these options, the provider shares the following profile data with us:
| Data Element | Apple | |
|---|---|---|
| Display Name | Your full name as stored in your Google account | Your full name as stored in your Apple ID (if you choose to share it) |
| Email Address | The primary email address associated with your Google account | Your Apple ID email, or a private relay address if you use Hide My Email |
| Profile Photo URL | A link to your Google profile picture | Not provided |
| Provider UID | A unique, stable identifier assigned by Google to your account | A unique, stable identifier assigned by Apple to your account |
We use this data solely to create and authenticate your Kaiju Mechanic account. We do not receive your password, contacts, calendar, or any other account data beyond the fields listed above. If you use Apple's Hide My Email feature, we receive only the private relay address and cannot see your real email.
2.3 Vehicle Information
We collect information about the vehicles you add to the app, including make, model, year, trim, VIN, engine type, fuel type, transmission, drivetrain, mileage, and any notes or maintenance records you enter manually. If you connect an OBD-II adapter, we also collect live sensor data transmitted from your vehicle's onboard diagnostic system (e.g., engine RPM, coolant temperature, fault codes). See Section 2.9 for details.
2.4 User-Generated Content
We collect the questions, prompts, and messages you submit to the AI assistant, as well as any documents or images you upload for OCR scanning. This content may include vehicle-related information, repair descriptions, or other details you choose to share.
2.5 Subscription and Purchase Information
We collect records of your subscription tier, in-app purchases, and entitlement status. Payment card details are processed directly by the app stores (Apple App Store, Google Play) and by RevenueCat; we do not receive or store raw payment card numbers.
2.6 Support and Feedback Data
When you contact us for support, submit feedback, report a bug, or request a feature, we collect your name, email address, the content of your message, and any attachments you provide.
2.7 Usage and Analytics Data
We collect information about how you interact with the Service, including features used, screens visited, session duration, button taps, and feature flag assignments. On the mobile app, this data is collected through Firebase Analytics (which feeds Google Analytics 4) and PostHog. On the website, this data is collected through Google Analytics 4, which the website loads directly from Google (the Google tag, gtag.js) only when your cookie choice allows it.
Analytics collection on the mobile app requires your explicit opt-in. On the website, analytics collection is governed by your cookie consent preferences (see Section 8).
2.8 Device and Technical Information
We collect device type, operating system version, app version, device identifiers (we do not collect advertising identifiers such as IDFA or AAID), IP address, browser or app metadata, crash reports, and performance metrics. Crash reports are collected through Firebase Crashlytics and Sentry on the mobile app. We do not collect the Android Advertising ID (AAID) or Apple Identifier for Advertisers (IDFA).
2.9 OBD-II Diagnostic Data
If you choose to connect a compatible OBD-II adapter, we collect live and historical sensor readings from your vehicle, including but not limited to engine parameters (RPM, coolant temperature, fuel trims, intake pressure), emissions-related data, and diagnostic trouble codes (DTCs) with freeze-frame data. Connection occurs over a local Bluetooth or Wi-Fi link between the adapter and your device; data is then synced to our servers. This feature is optional and requires explicit setup by you.
2.10 Location Data
Categories of personal information (CCPA): geolocation data — approximate.
What we collect. When you tap the weather icon on the dashboard and grant location permission via your operating system, we receive your device's approximate latitude and longitude (rounded to roughly city-block precision, ~1 km).
Legal basis (GDPR Art. 6(1)(a)): your consent, expressed via the operating system's location permission grant.
How it's used. We forward the rounded coordinates to our edge infrastructure (Cloudflare) to fetch local weather from an upstream weather data provider. Your IP address is visible to Cloudflare as a normal artifact of network routing, but is not forwarded to the upstream weather provider — the upstream provider sees only anonymous coordinates from a Cloudflare datacenter.
Retention (GDPR Art. 13(2)(a)): we do not persistently store your location. Approximate, rounded coordinates may be cached at our edge for up to one hour, keyed on the rounded coordinates and not associated with your account, solely to reduce upstream weather provider load.
Your control. You can revoke this permission at any time in your device's Settings; revoking it does not affect any other app feature. You may also override the auto-detected location with a manually-chosen city in Kaiju Mechanic Settings, in which case no device location is collected.
2.11 Promotional Items Requested Through This Website
When you request a promotional item that we offer free of charge through this website, we collect your name, email address, and postal shipping address so that we can mail the item and send you an order confirmation.
Checkout is hosted by Stripe on Stripe's own domain. You enter your details there, not on our website. We receive your name, email address, shipping address, and what you requested. No payment card details are collected, because the item is free of charge.
We do not collect a phone number when you request a promotional item through this website. Stripe may separately offer to save your details with Stripe Link, its own saved-checkout service. If you accept, Stripe collects a phone number and creates a Link account for you. Stripe does that for its own purposes, as an independent controller under its own privacy policy, rather than processing on our behalf.
Requesting a promotional item does not require a Kaiju Mechanic account.
Paid merchandise is sold through a separate store. Paid Kaiju Mechanic merchandise is sold at shop.kaijumechanic.com, which runs on a different platform and is not part of this website. For a store order we receive the buyer's name, email address, postal shipping address, phone number, and order contents. That store publishes its own Privacy Policy, which governs the data collected there. The store may offer its own optional store account; a store account is not a Kaiju Mechanic app account.
3. How We Collect Information
We collect information through the following methods:
- Directly from you — when you create an account, enter vehicle information, submit questions to the AI assistant, upload documents for OCR, contact support, or submit feedback.
- Automatically — when you use the app or visit our website, we collect device information, usage data, crash reports, and performance metrics through integrated analytics and error-tracking tools, subject to your consent preferences.
- From third-party identity providers — when you choose to sign in with Google or Apple, we receive the profile data described in Section 2.2 directly from the provider's OAuth service.
- From your vehicle — when you connect an OBD-II adapter, data is transmitted from your vehicle's diagnostic port to the app over a local Bluetooth or Wi-Fi connection and then synced to our servers.
- From app stores and payment processors — RevenueCat provides us with subscription status, entitlement records, and purchase event data on your behalf after transactions are completed through the Apple App Store or Google Play.
4. How We Use Information
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Create and authenticate your account | Art. 6(1)(b) — Performance of a contract |
| Provide AI-powered vehicle assistance and answer your questions | Art. 6(1)(b) — Performance of a contract |
| Store and display your vehicle profiles and maintenance history | Art. 6(1)(b) — Performance of a contract |
| Process and display OBD-II diagnostic data | Art. 6(1)(b) — Performance of a contract |
| Process OCR document scans and return results | Art. 6(1)(b) — Performance of a contract |
| Manage your subscription, entitlements, and billing records | Art. 6(1)(b) — Performance of a contract |
| Respond to support requests, bug reports, and feedback | Art. 6(1)(b) — Performance of a contract; Art. 6(1)(f) — Legitimate interests |
| Analyze product usage to improve features and user experience | Art. 6(1)(a) — Consent (in-app opt-in) |
| Analyze subscription and revenue performance, using subscription records we receive server-to-server from RevenueCat (not controlled by the in-app analytics opt-in) | Art. 6(1)(f) — Legitimate interests |
| Monitor app performance and detect/fix errors and crashes | Art. 6(1)(f) — Legitimate interests |
| Protect against fraud, abuse, and unauthorized access | Art. 6(1)(f) — Legitimate interests |
| Send transactional and service-related communications (e.g., receipts, security alerts) | Art. 6(1)(b) — Performance of a contract |
| Send personalized lifecycle and push messages you have opted into (e.g., onboarding tips, maintenance reminders) | Art. 6(1)(a) — Consent |
| Provide local weather using your device location | Art. 6(1)(a) — Consent (OS permission) |
| Comply with legal obligations (e.g., tax records, law enforcement requests) | Art. 6(1)(c) — Legal obligation |
| Enforce our Terms of Service and protect our legal rights | Art. 6(1)(f) — Legitimate interests |
| Mail free promotional items you request through this website | Art. 6(1)(b) — Performance of a contract |
Fulfil, support, and where necessary refund or replace orders placed at our store, shop.kaijumechanic.com |
Art. 6(1)(b) — Performance of a contract |
5. Information Sharing and Disclosure
We do not sell your personal information. We share personal information only with the service providers listed below, each of whom processes data on our behalf under contractual obligations consistent with this policy.
5.1 Mobile Application Service Providers
| Service | Role | Data Shared | Purpose |
|---|---|---|---|
| Google Cloud / Firebase | Cloud infrastructure, database, authentication, analytics | Account data, vehicle data, usage events, device info, crash reports | Host the Service, store app data, authenticate users, measure feature usage (Firebase Analytics feeds Google Analytics 4) |
| Anthropic | AI language model provider | AI assistant messages, vehicle context provided with your questions | Power the AI assistant that answers your vehicle questions (processed server-side; your prompts are not stored by Anthropic beyond their data retention policy) |
| RevenueCat | Subscription and purchase management | App user ID, subscription tier, purchase events, entitlement status | Manage subscription entitlements and synchronize purchase events from app stores |
| PostHog | Product analytics and feature flags | Usage events, session data, feature flag assignments, device info; subscription records received from RevenueCat (first- and last-seen dates; last-seen country, platform, platform version and app version; and the product, offering and entitlement catalogue), keyed to your app user identifier — synced server-to-server for billing and subscription observability, processed under legitimate interest and not consent-gated | Analyze product usage, manage feature rollouts, replay sessions for debugging (requires your opt-in), and analyse subscription and revenue performance |
| Sentry | Error tracking and performance monitoring | Error reports, stack traces, device info, breadcrumb context | Detect, diagnose, and resolve application errors (PII scrubbing enabled; no personal data sent by default) |
| Firebase Crashlytics | Crash reporting | Crash reports, device info, app state at time of crash | Identify and fix application crashes |
| Customer.io | Lifecycle messaging orchestration (email, push, in-app) | Firebase UID, email address, vehicle Year/Make/Model, subscription tier and status, notification preferences, locale, platform, and activity timestamps. Lifecycle emails also carry an open-tracking pixel: when your email application loads it, Customer.io receives the fact and time of the open, plus the IP address and mail-client information that request carries (see Section 5.5) | Send onboarding, winback, and billing-recovery messages; orchestrate push fan-out via FCM; deliver email via authenticated subdomain mail.kaijumechanic.com; measure whether a lifecycle email was opened, for open-rate and campaign performance reporting; respect quiet hours and frequency caps |
| Cloudflare (mobile app) | Edge proxy for weather and geocoding lookups | Approximate latitude and longitude (when location permission is granted), city-name search queries (when manual override is used). The device IP terminates at the Cloudflare edge and is NOT forwarded to the upstream weather data provider. | Strip client-identifying headers before forwarding coordinates to the upstream weather data provider, so that no personal data is shared with the upstream provider |
| Resend | Transactional email delivery | Email address, purchased-credit balance metadata (credit counts; purchased credits do not expire), and subscription renewal details (plan name, price, renewal date) | Deliver transactional account notices we are required or committed to send (for example, billing-failure, security, purchase-confirmation, and subscription renewal-reminder and pre-renewal notices). These are not marketing and are not subject to the lifecycle-messaging opt-out |
5.2 Website Service Providers
| Service | Role | Data Shared | Purpose |
|---|---|---|---|
| Cloudflare | DNS, CDN, DDoS protection, hosting (Cloudflare Pages), DMARC aggregate report collection | IP address, request metadata; DMARC aggregate reports (sending/forwarding mail-server IP addresses, SPF/DKIM authentication results, aggregate message counts) | Deliver the website reliably, protect against network-level attacks, and monitor email authentication for the kaijumechanic.com sending domain |
| Google Analytics 4 | Website analytics, loaded directly by the website with the Google tag (gtag.js) |
Page views and interaction events, device and browser information, and your IP address, which Google uses to derive your approximate location and does not log or store | Measure website traffic and understand visitor behavior. On by default in the United States until you opt out; elsewhere only after you accept; never while your browser sends Global Privacy Control (see Sections 8 and 9) |
| Postmark (ActiveCampaign, LLC) | DMARC aggregate report (RUA) collection and analysis | DMARC aggregate reports for the kaijumechanic.com sending domain: sending and forwarding mail-server IP addresses, SPF/DKIM/DMARC authentication results, aggregate message counts, and envelope/header From domains. No message content, recipient addresses, or subscriber lists are shared. |
Monitor email authentication and detect spoofing of our sending domain. Postmark is not used to deliver our email (see Resend in Section 5.1) |
| Codex Titan (RB ZILLA LLC) | Support platform, legal document hosting, consent audit logging | Contact form submissions (name, email, subject, message), DSAR requests, pseudonymized consent events | Manage support tickets, serve legal documents, and maintain GDPR Art. 7 consent audit trail |
| Stripe, Inc. | Hosted checkout for free promotional items requested through this website | Name, email address, postal shipping address, order contents. No payment card details are collected, because the order total is $0. | Collect free-promotion requests on a Stripe-hosted checkout page and send order confirmation. Stripe additionally acts as an independent controller for Stripe Link (see Section 2.11) |
Our merchandise store at shop.kaijumechanic.com also uses Stripe to take payment. That is the store platform's own payment processing, not our Stripe account, and we receive no data through it. The row above covers only the Stripe-hosted checkout for free promotional items requested through this website.
5.3 Additional Disclosure Circumstances
Beyond the service providers listed above, we may disclose personal information:
- Legal compliance: When required by applicable law, court order, subpoena, or governmental authority.
- Protection of rights: When necessary to enforce our Terms of Service, protect the safety of our users or the public, or defend against legal claims.
- Business transfers: In connection with a merger, acquisition, asset sale, or reorganization of RB ZILLA LLC, in which case the acquiring entity will be bound by this policy or will provide you with notice of any material changes.
- With your consent: For any other purpose with your explicit prior consent.
5.4 AI Processing
We use AI to power diagnostic, maintenance, and document features in Kaiju Mechanic — including answering your questions, explaining diagnostic trouble codes, generating and personalizing maintenance schedules, and extracting data from documents you scan. We may add or refine AI-powered features over time within these categories.
The AI features are powered by Anthropic, our third-party AI processor. When you use AI-powered features, the following information is sent to Anthropic to answer your request:
- Your prompt or input (the text of your question, or the image or PDF you scan)
- Vehicle profile data
- Recorded modifications and recent service history
- OBD-II diagnostic data (diagnostic trouble codes, sensor readings, calibration identifiers)
Categories sent vary by feature; we send only what the feature needs to function.
Free-text fields (prompts, descriptions, notes) may contain personal information you choose to include. Do not enter information you do not want sent to Anthropic.
No AI training on your personal data; we may use de-identified data. We do not use your personal data — including your vehicle data, OBD-II diagnostic data, or AI conversation history — to train, fine-tune, or improve any artificial intelligence or machine learning model, whether our own or any third party's. We may, however, use aggregated or de-identified data that cannot reasonably be used to identify you, your household, or your vehicle to develop, evaluate, and improve our products, services, and features, including AI and machine learning capabilities, and for the other purposes described in Section 6.4. Under Anthropic's Commercial Terms of Service, inputs and outputs submitted through their API are not used to train Anthropic's models.
No cross-context advertising. We do not sell or share AI-related information for cross-context behavioral advertising.
Automated decision-making. AI features generate informational responses based on the data you provide. They do not make binding decisions about you or take autonomous actions that produce legal or similarly significant effects. All AI outputs are presented as information for your review — you decide whether and how to act on them. If you believe an AI-generated response has been used in a way that materially affects you, you may contact us at privacy@kaijumechanic.com to request human review.
Profiling and automated decision-making. Several US state privacy laws — including Colorado, Connecticut, Texas, Oregon and Montana, with Louisiana and Vermont to follow — give you the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning you. We do not carry out that kind of profiling. Our automated processing classifies and routes requests and generates informational responses for your review; it does not evaluate you to reach a decision with legal or similarly significant effects, and a person is available at every step. If you would like a human to review anything we have done automatically, contact us at privacy@kaijumechanic.com.
AI usage metadata. For service operability and abuse detection, we record metadata about each AI call — your user ID, the AI feature invoked, model tier, input and output token counts, latency, cost, and timestamp — independently of the in-app analytics toggle (which controls only client-side product analytics). This metadata is retained for 90 days, then deleted via an automated time-to-live (TTL) policy. It does not contain the content of your prompts or AI responses. We rely on legitimate interest under GDPR Article 6(1)(f) for this processing; you may object under Article 21 by contacting privacy@kaijumechanic.com.
VIN decoding (NHTSA). To decode a Vehicle Identification Number you enter or that your vehicle reports during an OBD-II connection, we transmit the VIN to the U.S. National Highway Traffic Safety Administration's public vPIC service at vpic.nhtsa.dot.gov, routed through our Cloudflare edge proxy, which strips your device's IP address and forwards only the VIN itself. NHTSA is a U.S. government data recipient, not our processor; their handling is governed by U.S. federal records law. Only the VIN is transmitted — no account identifiers.
Opting out. AI processing occurs only when you actively use an AI-powered feature. If you do not engage the AI assistant, scan documents, or request AI-powered diagnostics, no data is transmitted to Anthropic. You may use the maintenance tracking, vehicle profile, and document storage features of the App without engaging AI.
5.5 Lifecycle Messaging (Customer.io)
Customer.io handles our lifecycle messaging — onboarding, re-engagement, feature announcements, and billing-recovery emails, in-app messages, and push notifications. We only initialize the Customer.io SDK in the app when you have granted personalized-messaging consent (the Personalized Messaging opt-in in Settings → Data & Privacy, also offered on first launch) AND our customerio_enabled server-side feature flag is on. This is a separate opt-in from analytics: granting "anonymous usage data" does not enable Customer.io. Anonymous users (no registered account) never get a Customer.io profile.
You can stop lifecycle messages at any time:
- Email unsubscribe. Every lifecycle email includes an unsubscribe link and a preference-center link. Both stop future marketing emails and sync your preference back to the app.
- Withdraw messaging consent. Go to Settings → Data & Privacy and turn off Personalized Messaging. This triggers deletion of your Customer.io profile, not just message suppression (see Section 7.2).
Open tracking in lifecycle emails. Lifecycle emails we send through Customer.io contain an open-tracking pixel — a small, invisible image hosted by Customer.io. When your email application loads that image, Customer.io records that the message was opened and when, and receives the IP address and mail-client information your email application sends with that request. We use this to measure whether our lifecycle emails are opened and how a campaign performed. We do not use open data for advertising, for cross-context behavioral advertising, or to build advertising profiles, and we do not sell or share it — under Cal. Civ. Code § 1798.140(ad) and (ah) this is neither a "sale" nor a "share" of personal information. Individual open events stay inside Customer.io: our reporting webhook discards Customer.io's email.opened notifications without recording them, so we hold no per-message open history about you.
Open tracking applies only to lifecycle emails, which we send only when you have granted the Personalized Messaging opt-in described above. Transactional account notices go through Resend and are not routed through Customer.io, so they do not carry the Customer.io open-tracking pixel. We rely on your consent as the legal basis for lifecycle messaging and its open measurement (GDPR Art. 6(1)(a); for the placement of the pixel on your device, Art. 5(3) of the ePrivacy Directive as implemented in your country), and you can withdraw that consent at any time under Art. 7(3) as easily as you gave it: turn off Personalized Messaging in Settings → Data & Privacy. Doing so stops all lifecycle email and deletes your Customer.io profile (see Section 7.2). Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
Transactional messages — password resets, security alerts, billing-failure notifications, subscription renewal reminders and pre-renewal notices, and similar account notices — are sent separately and are not routed through Customer.io. Where delivered by email, they go through Resend, our transactional email provider (see Section 5.1). Sending them creates no Customer.io profile. Transactional messages are not subject to the lifecycle-messaging opt-out. We do not send purchased-credit expiry reminder notices — purchased AI Credits do not expire.
5.6 Infrastructure Dependencies That Do Not Receive Personal Information
Our weather feature uses Open-Meteo as an upstream weather data provider. Open-Meteo receives only anonymized geographic coordinates (rounded to roughly city-block precision) from our Cloudflare edge infrastructure, with no IP address, account identifier, or other identifying headers. Open-Meteo is therefore not a sub-processor of personal data and is listed here for transparency only.
6. Data Retention
We retain personal information for as long as your account is active and for the periods or, where a fixed period cannot be determined in advance, the criteria specified below.
6.1 Retention by Data Category
| Data Category | Retention Period | Notes |
|---|---|---|
| Account and profile data | Until you delete your account | See Section 6.2 |
| Vehicle data and maintenance history | Until you delete your account | You may delete individual vehicles at any time |
| OBD-II diagnostic data | Until you delete your account | Stored with the associated vehicle profile |
| AI assistant conversation history | Until you delete your account | Individual conversations may be deleted in-app |
| Subscription and purchase records | Until you delete your account, plus any period required by tax law | Financial records may be retained up to 7 years for tax compliance |
| Contact form submissions and support tickets | Up to 2 years after resolution | For support reference and quality improvement |
| DSAR requests and responses | Per statutory requirement | Retained as evidence of compliance |
| Consent audit logs | Not less than 24 months and not more than 25 months from the date of the consent, opt-out, or other privacy-request event, after which the record is permanently deleted | GDPR Art. 7(1) (demonstrating consent) and Art. 13(2)(a); 11 CCR § 7101(a) (24-month recordkeeping for records of consumer requests). Held by Codex Titan and retained after account deletion as permitted by GDPR Art. 17(3)(b) and 11 CCR § 7022(e). |
| Crash reports and error logs | 90 days | Automatically rotated |
| AI usage metadata logs | 90 days | Automatically rotated via Firestore TTL; metadata only — no prompt or response content |
| Analytics data (app) | Governed by Firebase Analytics and PostHog retention settings | Intentional configuration: aggregated and not linked to your identity after 14 months (GA4 default; site-specific retention, not a shorter org floor) |
| Subscription records copied from RevenueCat into our analytics data store (PostHog) | For as long as RevenueCat holds your subscriber record | Not governed by the analytics retention settings above. The copy is rebuilt in full from RevenueCat on a schedule, so once your subscriber record is deleted it is gone from the copy at the next rebuild, normally within a day. Deleting your account deletes that record — see Section 6.2 |
| Analytics data (website) | Event-level data: 2 months. User-level data: 14 months from your most recent activity on the website, because each new activity restarts the period | These are the data retention settings of the website's Google Analytics 4 property. Google deletes data that has reached the end of its retention period on a monthly basis. Aggregated reports are covered by Section 6.4. Collection is governed by your cookie consent preferences (see Section 8) |
| Free-promotion order records requested through this website, including shipping address | Up to 7 years from the order date | Requesting a promotional item does not create an account, so this period runs from the order rather than from account deletion. Order data is also held by Stripe under Stripe's own retention schedule |
Store order records (shop.kaijumechanic.com), including shipping address and phone number |
No fixed period is set by us. These records are retained by Fourthwall, Inc., the platform that operates the store, under its own retention schedule and for the periods that tax and financial record-keeping law require of it as Merchant of Record for store payments and sales tax | We access store order records through the store's merchant dashboard and do not keep a separate copy. The store's own privacy policy governs their retention |
6.2 Account Deletion
You can delete your Kaiju Mechanic account at any time from Settings → Account → Delete Account. Deletion is immediate and irreversible — we cannot restore a deleted account, and you cannot recover it by signing back in.
What happens when you delete your account:
Immediate deletion. When you confirm deletion, we immediately and permanently delete your account: your Firebase Authentication identity, your Firestore documents (profile, vehicles, service records, chat history, scan results, maintenance records), and your Firebase Storage media (photos, scanned documents). This cannot be undone, and signing back in will not restore your account.
Sub-processor propagation. A Cloud Function automatically forwards the deletion signal to each third party that holds personal data about you as a sub-processor. As of the effective date of this policy, the third parties that hold your personal data, what happens to each on deletion, and whether that happens automatically, are:
- Customer.io — your lifecycle-messaging profile is deleted via their Track API. Any queued or scheduled messages to you are cancelled.
- RevenueCat — your subscriber record (if any) is deleted via their REST API. We also hold a copy of these subscription records in PostHog for billing and subscription analytics. That copy is rebuilt in full from RevenueCat on a schedule, so once your subscriber record is deleted it is absent from the copy after the next rebuild — normally within a day. You do not need to make a separate request.
- PostHog — your analytics person profile is deleted via their Persons API (associated events and session recordings are queued for deletion). Subscription records synced from RevenueCat are held in a separate analytics data store rather than in your person profile, so they are not removed by this call; they are removed by the RevenueCat rebuild described above.
- Stripe, Inc. — not deleted. If you requested a free promotional item through this website, Stripe retains that order record (including your name, email address and shipping address) so we can meet tax and financial record-keeping obligations — see the free-promotion order record row in Section 6.1. GDPR Art. 17(3)(b) permits us to decline erasure to the extent the processing is necessary to comply with a legal obligation. If you have never requested a promotional item, Stripe holds no personal data about you.
- Fourthwall, Inc. (the platform that operates our store at
shop.kaijumechanic.com) — not deleted, and not signalled automatically. A store order record is retained to meet tax and financial record-keeping obligations, and GDPR Art. 17(3)(b) permits declining erasure to that extent. Store orders are not linked to a Kaiju Mechanic account and we send no automated deletion signal to the store, so deleting your app account does not delete a store order record. Erasure of a store order is handled manually — see the routing in Section 7.2. If you have never placed a store order, Fourthwall holds no personal data about you.
These calls are best-effort and are retried automatically. If a sub-processor is unreachable, the deletion is queued in our retry system, attempted hourly for up to 24 hours with exponential backoff, and — if still unresolved after 24 hours — escalated as a Sentry alert for manual intervention by our engineering team. Automatic retries stop permanently after 7 days of continuous failure: the entry is marked unreachable, a final alert is raised for our engineering team, and it is not retried again automatically. In that case the deletion is completed manually. Your Firebase deletion is never blocked by a sub-processor failure; the retry ensures eventual consistency.
Inactive accounts. Separately from deletion you request, we delete accounts that have been inactive for an extended period. We email you more than once before this happens. If the account is still inactive after those warnings, we delete your stored media (photos and scanned documents) at that point and mark the account for deletion; 30 days later a daily retention job permanently deletes everything that remains, and the sub-processor propagation runs again as a safety net. This 30-day period applies only to inactivity-based deletion — it does not apply when you delete your own account, which is immediate.
Anonymous users. Accounts that were never registered (anonymous Firebase Auth users) are purged on a separate 90-day schedule. No Customer.io or RevenueCat propagation is required because anonymous users never had profiles in those systems. PostHog deletion is still attempted when an anonymous account had opted into analytics, because the anonymous Firebase UID may exist as a PostHog person.
Residual copies in backups. We keep automated daily backups of our database, plus short-term recovery snapshots of our database and file storage, so that we can restore the Service after a technical failure. A backup is a fixed snapshot of a moment in time, and we cannot edit one account out of it without destroying the backup — so a copy of your data remains in any backup taken before your account was deleted. Those backups expire on a rolling schedule and are permanently erased within 90 days of your account being deleted. Until they expire we do not use them to look up, restore, or answer questions about any individual account, and we never use a backup to reinstate a deleted account. If we restore from a backup for any reason, we re-apply every completed deletion to the restored data. This does not extend the timelines described above for deleting your data from our live systems.
Limited deletion record. After your account is deleted we keep a minimal record of the deletion itself for 90 days — an internal identifier plus basic account facts such as when the account was created, when it was last active, and its subscription tier. We keep it for two reasons: to demonstrate that we honoured your deletion request if you or a regulator asks, and so that if we ever restore from a backup we can re-apply your deletion to the restored data. It is not used to contact you, to profile you, or to rebuild your account, and it is erased automatically after 90 days.
If you'd like confirmation that a specific sub-processor has received your deletion signal, contact us at privacy@kaijumechanic.com within 30 days of deletion; we can produce a deletion receipt from our retry queue and/or the sub-processor's own audit log.
Legal basis. This procedure is designed to satisfy GDPR Art. 17 (right to erasure) and Cal. Civ. Code § 1798.105 (right to delete personal information). California regulations expressly permit a business to delay compliance with a deletion request with respect to data held on archived or backup systems (11 CCR § 7022(d)); we go further than that regulation requires by committing to a fixed outer limit rather than waiting for a backup to be restored or accessed. We retain a limited record of the deletion itself as permitted by 11 CCR § 7022(e) and GDPR Art. 17(3)(b). Neither the backup schedule nor this section extends our response deadlines for privacy requests.
Personal information may also be retained beyond this schedule where a longer retention period is required by law (e.g., tax or financial records) or where anonymized, aggregated data has already been derived.
6.2A Purchased AI Credits on Deletion
If you delete your account or submit a verified erasure request, we honor the request even if you still hold purchased AI Credits. Before we complete deletion we disclose any remaining purchased balance; that balance is relinquished as part of deletion. We retain only the minimal financial/transaction record the law permits. Purchased credits otherwise never expire and are not forfeited for inactivity (see Terms of Service §5.6.2).
6.3 Inactive Account Cleanup
Accounts that have never been authenticated (anonymous/guest accounts) are automatically deleted after 90 days of inactivity. Authenticated free-tier accounts with no activity are subject to deletion after 18 months, except that we will not delete an account through inactivity housekeeping while it holds a positive purchased AI Credit balance. In that case the account and balance remain until the credits are spent, you delete the account, or unclaimed-property law requires otherwise (see Terms of Service §5.6.2). We may, but are not obligated to, provide advance notice by email before deletion of inactive accounts that are eligible for cleanup.
6.4 Anonymized Data
We may retain aggregated or de-identified data that cannot reasonably be used to identify you, your household, or your vehicle — derived from operation of the Service — indefinitely, as it no longer constitutes personal information. We may also use such aggregated or de-identified data for any lawful business purpose, including benchmarking, research, content creation, and product development. Where we de-identify data, we maintain it in de-identified form, take reasonable measures to prevent its re-identification, make no attempt to re-identify it, and require any recipient of such data to commit to the same.
7. Your Privacy Rights
7.1 Rights Overview
The table below summarizes the privacy rights available to users under applicable law. Because Kaiju Mechanic primarily serves users in the United States, the rights listed reflect U.S. state privacy law frameworks. Users in the EEA, UK, or Switzerland have equivalent or broader rights under the GDPR/UK GDPR (see Section 7.4).
| Right | Description | Applicable Law |
|---|---|---|
| Right to Know / Access | Request a copy of the personal information we hold about you and information about how we use and share it | California (CCPA/CPRA); Virginia (VCDPA); GDPR |
| Right to Deletion | Request that we delete your personal information, subject to certain exceptions | California (CCPA/CPRA); Virginia (VCDPA); GDPR |
| Right to Correction | Request that we correct inaccurate personal information we hold about you | California (CPRA); Virginia (VCDPA); GDPR |
| Right to Portability | Receive your personal information in a structured, machine-readable format | California (CPRA); GDPR |
| Right to Opt Out of Sale/Sharing | Opt out of the sale of personal information or sharing for cross-context behavioral advertising | California (CCPA/CPRA) |
| Right to Limit Use of Sensitive Personal Information | Restrict our use of sensitive personal information to necessary purposes | California (CPRA) |
| Right to Non-Discrimination | We will not discriminate against you for exercising any of these rights | California (CCPA/CPRA) |
| Right to Appeal | Appeal our decision if we decline to act on your privacy request | Virginia (VCDPA); GDPR (right to lodge complaint with supervisory authority) |
7.2 How to Submit a Request
To exercise any of the rights listed above, you may:
- Submit a privacy request online: https://www.kaijumechanic.com/privacy/data-request
- Email us directly: privacy@kaijumechanic.com
We will verify your identity before processing your request. Verification typically involves confirming your email address or account credentials.
We aim to acknowledge all privacy inquiries within 5 business days.
Store orders. If your request concerns an order you placed at shop.kaijumechanic.com, contact the store directly at contact@support.shop.kaijumechanic.com. That is where the order record lives, and it is the fastest route. The privacy request form and email address above do not reach store order data; if you send a store-order request to us instead, we will route it to the store. For everything else — the App and this website — use the form or email address above.
Where a request to erase a store order is refused in part, we will tell you and give the reason. As Merchant of Record for store payments and sales tax, the store platform may decline full erasure of an order record to meet tax and financial record-keeping obligations, which GDPR Art. 17(3)(b) permits.
Personalized Messaging consent withdrawal. Withdrawing personalized-messaging consent does more than stop new messages. When you turn off Personalized Messaging in Settings → Data & Privacy, our client deletes its local Customer.io session and the server issues an API call to Customer.io to delete your profile from their platform — not merely suppress messaging to you. This means any event history, profile attributes, and pending journey membership tied to your account are erased from Customer.io as part of the withdrawal flow, with retry on transient API failures so the erasure request is not lost. If you later re-grant Personalized Messaging consent, a fresh Customer.io profile is created; it has no memory of prior activity.
7.3 U.S. Jurisdiction Supplement
California (CCPA/CPRA): California residents have the rights set out in the California Consumer Privacy Act, as amended by the California Privacy Rights Act. We respond to verifiable consumer requests within 45 days of receipt. If we need additional time (up to 45 additional days), we will notify you in writing within the initial 45-day period. If we decline your request, you may appeal by contacting us at privacy@kaijumechanic.com with the subject line "CCPA Appeal." If your appeal is denied, you may contact the California Privacy Protection Agency (CPPA) at https://cppa.ca.gov.
Virginia (VCDPA): Virginia residents have the rights set out in the Virginia Consumer Data Protection Act. We respond to requests within 45 days, with a possible 45-day extension upon notice. If we decline your request, you may appeal within a reasonable time by contacting us at privacy@kaijumechanic.com with the subject line "VCDPA Appeal." If your appeal is denied, you may contact the Virginia Attorney General at https://www.oag.state.va.us.
Other States: Residents of other states with comprehensive privacy laws (including but not limited to Colorado, Connecticut, Texas, Oregon, and Montana) have similar rights under their respective statutes. We apply the same 45-day response standard and provide an equivalent appeal process. Contact us at privacy@kaijumechanic.com to exercise your rights.
7.4 EEA, UK, and Switzerland Supplement
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have additional rights under the GDPR or UK GDPR, including the right to withdraw consent at any time (Art. 7(3)), the right to restrict processing (Art. 18), and the right to lodge a complaint with your local supervisory authority. To exercise these rights, contact us at privacy@kaijumechanic.com. We respond to GDPR requests within one month of receipt. This period may be extended by up to two additional months where necessary, taking into account the complexity and number of requests; we will inform you of any such extension within one month of receipt, together with the reasons for the delay (GDPR Art. 12(3)).
Complaints (United Kingdom). If you are in the United Kingdom, you have the right to make a data protection complaint directly to us before contacting the regulator. You can complain by emailing privacy@kaijumechanic.com. You do not have to use a particular form or channel — if you raise a concern with us any other way, we will treat it as a complaint. We will acknowledge your complaint within 30 days of receiving it and will investigate and respond without undue delay, keeping you informed of our progress. If you are unsatisfied with our final response, you may complain to the Information Commissioner's Office (ICO) at https://ico.org.uk/make-a-complaint/.
8. Cookies and Tracking
8.1 Website Cookies
We use cookies and similar technologies on our website. The table below summarizes the categories.
| Category | Purpose | Examples | Consent Required |
|---|---|---|---|
| Strictly Necessary | Core website functionality, consent state storage | cc_cookie (stores your consent preferences, 366 days; a choice stored on or before 17 September 2026 may instead expire after 182 days) |
No |
| Analytics | Measure website traffic and feature usage | Google Analytics 4 cookies (_ga, _ga_<container-id>) |
Yes outside the United States. In the United States, on by default until you opt out. Never with Global Privacy Control |
You can manage cookie preferences at any time using the "Consent Preferences" button in the website footer or by adjusting your browser settings. On our website, we present consent controls with equal visual prominence for "Accept All" and "Reject All" options (labelled "Opt Out" in the United States).
8.2 Mobile App Tracking
The mobile app does not use cookies. Analytics collection (Firebase Analytics and PostHog) is disabled by default and requires your explicit opt-in through the app's Data & Privacy settings. Crash reporting (Firebase Crashlytics and Sentry) is enabled by default to help us maintain app stability; you may disable it at any time in the app's Data & Privacy settings.
We do not collect the Apple Identifier for Advertisers (IDFA) or the Android Advertising ID (AAID). We do not serve advertisements.
For full details on the specific cookies used on our website, their lifespans, and how to opt out, please refer to our Cookie Policy at https://www.kaijumechanic.com/cookie-policy.
9. Global Privacy Control and Do Not Track
Global Privacy Control (GPC)
We honor the Global Privacy Control (GPC) signal as a valid opt-out of the sale and sharing of personal information in all jurisdictions where this is required by law, including California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas. When our website detects a GPC signal from your browser (via the Sec-GPC HTTP header or navigator.globalPrivacyControl API), we automatically suppress non-essential tracking: website analytics does not run, in any region, while the signal is on. No additional action is required on your part.
Our GPC compliance declaration is published at https://www.kaijumechanic.com/.well-known/gpc.json.
Do Not Track (DNT)
We do not respond to the Do Not Track (DNT) browser signal. DNT lacks a universally accepted technical standard or legal mandate. If you wish to limit data collection, we recommend enabling Global Privacy Control (GPC) in a supported browser, which we honor as described above.
10. International Data Transfers
RB ZILLA LLC is based in the United States. The service providers we use (listed in Section 5) are primarily located in the United States, with Cloudflare operating a global edge network.
If you access the Service from outside the United States, your personal information will be transferred to and processed in the United States or other countries where our service providers operate. The United States does not have a general adequacy decision from the European Commission. Where we transfer personal data originating from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries without an adequacy decision, we rely on appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) and UK transfer tools: Where required, we rely on the European Commission's Standard Contractual Clauses to govern transfers of personal data from the European Economic Area or Switzerland to countries not recognized as providing an adequate level of protection. For United Kingdom transfers, we use the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, as applicable. Agreements with our service providers incorporate SCCs, the UK IDTA/Addendum, or equivalent mechanisms as appropriate.
- Adequacy decisions: Where the European Commission or another competent authority has issued an adequacy decision for the destination country, we rely on that decision as the transfer mechanism.
- Vendor data processing agreements: We enter into data processing agreements with sub-processors that impose data-protection obligations consistent with applicable law.
For users in the United States, data is processed domestically by our U.S.-based infrastructure and service providers.
11. Children's Privacy
The Kaiju Mechanic Service is not directed at children under the age of 13 (or under 16 where required by applicable law, such as the GDPR), and we do not knowingly collect personal information from children under 13 (or under 16 where required by applicable law). If you are a parent or guardian and believe that your child under 13 (or under 16 where applicable) has provided us with personal information, please contact us at privacy@kaijumechanic.com and we will promptly delete that information.
If we become aware that we have inadvertently collected personal information from a child under 13 (or under 16 where required by applicable law) without verifiable parental consent, we will take immediate steps to delete that information.
12. Data Sale and Sharing
We do not sell your personal information. We do not sell personal information to third parties for monetary or other valuable consideration, as defined under the California Consumer Privacy Act (Cal. Civ. Code 1798.140(ad)) or any other applicable state privacy law. By contrast, aggregated or de-identified data that cannot reasonably be used to identify you, your household, or your vehicle is not personal information, and our use of such data is not a sale of personal information. We maintain such data in de-identified form and do not attempt to re-identify it (see Section 6.4).
We do not share your personal information for cross-context behavioral advertising. We do not share your personal information with third parties for the purpose of targeting you with advertisements based on your activity across different websites, apps, or services.
The service providers listed in Section 5 receive personal information only to perform services on our behalf. Their handling of your data is governed by their own published privacy policies and by the data-protection laws applicable to their processing.
13. Security Measures
We implement industry-standard technical and organizational security measures to protect your personal information against unauthorized access, disclosure, alteration, and destruction:
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security).
- Encryption at rest: Data stored in our cloud infrastructure (Google Cloud / Firebase) is encrypted at rest using AES-256 or equivalent encryption.
- Access controls: Access to personal data is restricted to authorized personnel on a need-to-know basis, enforced through role-based access controls and multi-factor authentication.
- Server-side secrets: API keys for AI services, payment processors, and other backend integrations are stored as server-side secrets and are never exposed in client-side code or app bundles.
- Monitoring: We monitor our systems for anomalous activity and review security controls as part of our release and incident-response processes.
While no system is completely immune to security risks, we are committed to maintaining reasonable and appropriate safeguards proportionate to the sensitivity of the data we process.
13.1 Security Incident Notification
If we become aware of a security incident that compromises personal information we hold about you, we will assess the incident and notify affected users and/or regulators without undue delay where required by applicable law — including GDPR Article 33/34 and comparable duties under applicable US state privacy laws. We do not commit to a shorter contractual notification SLA than those legal obligations require. Where notification is required, we will describe the nature of the incident, the categories of data involved (to the extent known), and the steps we are taking, using the contact channels available for your account.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will notify you by:
- Posting the updated policy at https://www.kaijumechanic.com/privacy with a new effective date;
- Displaying an in-app notification or banner the next time you open Kaiju Mechanic; and/or
- Sending an email to the address associated with your account, for significant changes that materially affect your rights.
Where a change means we will use personal information we already hold about you for a new purpose that is not compatible with the purpose we described when we collected it, we will tell you about that new purpose before we begin the new processing, and — where the new processing relies on your consent — we will ask for your consent first (GDPR Art. 13(3) and Art. 6(4)).
Collecting a new category of personal information for a new feature is not a change of this kind. In that case we describe the new collection in this policy and at the point of collection, at or before the point at which we collect it.
The effective date at the top of this document is the sole identifier of the current version. Prior versions of this policy are available upon request by contacting us at privacy@kaijumechanic.com.
Your continued use of the Service after the effective date of a revised policy constitutes your acceptance of the updated terms. If you do not agree with the revised policy, you should discontinue use of the Service and may request deletion of your account.
15. Contact Information
If you have questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us:
RB ZILLA LLC — Privacy & Security Contact
- Privacy: privacy@kaijumechanic.com
- Security reports: security@rbzilla.com — the address published in our security.txt and in our Terms of Service
- Support: support@kaijumechanic.com
- Website: https://www.kaijumechanic.com
- Mailing Address: RB ZILLA LLC, 116 E Main St, Suite 201, Rock Hill, SC 29730
Submit a Privacy Request (DSAR)
To exercise your data subject rights (access, deletion, correction, portability, opt-out), please use our dedicated intake form: https://www.kaijumechanic.com/privacy/data-request
Store orders are handled by the store, not by this form. For a request about an order you placed at shop.kaijumechanic.com, contact contact@support.shop.kaijumechanic.com. This form and the address below do not reach store order data; see Section 7.2.
You may also email your request directly to privacy@kaijumechanic.com. We respond to verifiable GDPR requests within one month of receipt. This period may be extended by up to two additional months where necessary, taking into account the complexity and number of requests; we will inform you of any such extension within one month of receipt, together with the reasons for the delay (GDPR Art. 12(3)). We respond to verifiable U.S. state privacy requests within 45 days of receipt, extendable once by a further 45 days where permitted, as required by applicable law.