Privacy Policy
Version 2.1 — Effective 1 September 2026
This Privacy Policy explains how RedMechs Intelligence OÜ ("noMech", "we", "us", "our") collects, uses, shares, and protects your personal data when you use the noMech mobile application (the "App"), the website at nomech.app (the "Website"), and related services (together, the "Service").
We keep it simple: we collect what we need to run an AI-powered vehicle assistant, we do not sell your personal data, and we do not use it for third-party advertising.
1. Who we are
The data controller responsible for your personal data is:
RedMechs Intelligence OÜ Harju maakond, Tallinn, Kesklinna linnaosa, Narva mnt 5, 10117, Estonia Email: contact@redmechs.com
We are an Estonian company. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
2. What this Policy covers
This Policy applies to the App (iOS and Android), the Website, and any communication you have with us (for example, support emails). It does not cover processing carried out by third parties acting as independent controllers under their own privacy policies — for example, Apple and Google when they handle your App Store or Google Play purchase, operate your device, or manage your Apple/Google account. Section 7 explains who acts as our processor and who acts independently.
3. Personal data we collect
3.1 Data you give us
- Account data. You sign in with Apple or Google. We receive your name, email address (or Apple's private relay email if you choose to hide yours), and a unique account identifier. We never see or store a password for you.
- Vehicle data. The vehicle details you enter: year, make, model, current mileage, and your unit preference (miles/kilometers). If we introduce VIN entry or scanning in a future update, we will also process your VIN; a VIN can identify a specific vehicle and, combined with your account, may constitute personal data — we will treat it as such.
- Content you create. Messages you send to the AI Mechanic chat (including symptom descriptions), service history entries, service costs you log, mileage updates, and feedback or ratings you submit on AI responses.
- Purchase and billing data (web purchases). If you subscribe on the Website, we act as the seller and process your order details: subscription plan, transaction history, billing country, and tax/VAT location evidence. Card payments are processed by Stripe; we never receive or store your full payment card number.
- Support communications. The contents of emails or messages you send us, and the contact details you use to send them.
What you must provide. Account data and vehicle data are necessary to enter into and perform our contract with you — without them we cannot create your account or provide vehicle-specific answers. All other data (chat messages, service history, analytics choices) is optional; not providing it only limits the features that depend on it.
3.2 Data collected automatically
- Device and technical data. Device model, operating system version, app version, language, time zone, IP address, and crash/diagnostic logs.
- Usage data (with your consent). Screens viewed, features used, taps and interaction events, and session information. In the App we use session replay to understand usability problems; text you type and sensitive fields are masked and are not visible in replays. See Section 13 for how consent works and how to change your choice.
- Website data. Pages visited, referrer, approximate location derived from IP address, and cookie identifiers (see Section 13).
3.3 Data from third parties
- Sign-in providers. Apple and Google send us the profile data described above when you authorize sign-in.
- App stores and payment infrastructure. Apple, Google, and our subscription platform (RevenueCat) send us subscription status, product identifiers, and pseudonymous transaction identifiers.
3.4 Data we do NOT collect
We do not collect precise GPS location, contacts, photos (the current App has no image input), health data, or advertising identifiers for ad targeting.
4. How we use your data
We use personal data to:
- Provide the Service — create and maintain your account, store your vehicle profile and service history, calculate maintenance schedules and your vehicle Health Score, and deliver AI Mechanic responses that reference your specific vehicle;
- Process subscriptions — manage free-tier limits, entitlements, purchases, renewals, refunds, and tax obligations for web purchases;
- Send notifications — service-due reminders (if you enable them) and important account, security, or service messages;
- Provide support — respond to your requests and troubleshoot problems;
- Improve and secure the Service — analyze usage (with your consent), fix crashes and usability issues, prevent fraud and abuse, and enforce our Terms of Use;
- Comply with law — accounting, tax, and other legal obligations.
We do not sell your personal data, share it with data brokers, or use it for third-party advertising. We do not make automated decisions about you that produce legal or similarly significant effects.
5. The AI Mechanic and your data
The AI Mechanic is an artificial-intelligence chat assistant. When you send a message, we transmit your message together with your vehicle context (year, make, model, mileage, unit preference, and a snapshot of your open maintenance items) to our AI provider — OpenAI — to generate a response.
- Under our agreement with this provider, your conversations are not used to train its models.
- The provider may retain API data for abuse monitoring — typically for up to 30 days — after which it is deleted, in line with its API terms.
- Please do not include sensitive personal information (for example, health or financial details) in chat messages — the chat only needs vehicle symptoms.
- AI responses are generated automatically and are informational only; see our Terms of Use for the related disclaimers.
6. Legal bases for processing (EEA users)
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating your account; storing vehicle data, chats, and service history; generating AI responses; processing subscriptions and web billing | Contract (Art. 6(1)(b)) — needed to provide the Service you signed up for |
| Product analytics and session replay (App and Website) | Consent (Art. 6(1)(a)) — collected via the in-App prompt and the Website cookie banner; you can withdraw it at any time (Section 13) |
| Crash diagnostics; device and technical data needed to deliver and secure the Service | Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) in a stable, secure Service |
| Service-due reminders and other optional notifications | Consent (Art. 6(1)(a)) — you enable them and can turn them off at any time |
| Important account, security, or service messages | Contract (Art. 6(1)(b)) or legitimate interests (Art. 6(1)(f)) in keeping you informed about the service you use |
| Security, fraud prevention, enforcing our terms | Legitimate interests (Art. 6(1)(f)) in keeping the Service safe |
| Tax, accounting, and responding to lawful requests | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms.
Your right to object. Where we process your personal data based on legitimate interests, you have the right to object at any time, on grounds relating to your particular situation, by emailing contact@redmechs.com. We will stop the processing unless we have compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed for legal claims.
7. Who we share data with
Service providers (processors). These companies process personal data on our behalf and on our instructions, under data-processing agreements:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Backend platform and database (account, vehicle, chat, and service data) | EU/US |
| OpenAI | AI response generation | US |
| RevenueCat | Subscription management across App Store, Google Play, and web billing | US |
| Stripe | Payment processing for web subscriptions | US/EU |
| PostHog | Product analytics and masked session replay | EU/US |
| Google Analytics; push delivery (Firebase Cloud Messaging) | US | |
| Vercel | Website hosting | US/EU |
Independent controllers. Some parties process your data for their own purposes under their own privacy policies: Apple and Google when you sign in with your Apple/Google account, purchase through the App Store or Google Play, or when they operate your device's operating system and app-store account; and Stripe for its own payment-fraud prevention and regulatory compliance.
We may also disclose personal data if required by law or valid legal process, to protect the rights, safety, or property of noMech or others, or as part of a merger, acquisition, or sale of assets (in which case this Policy will continue to apply to your data, and we will notify you of any change of controller).
8. International data transfers
We are based in Estonia and store primary data in the EU where possible. Some of the providers above process data in the United States or other countries outside the EEA. Where personal data leaves the EEA, we rely on safeguards recognized under GDPR: the European Commission's Standard Contractual Clauses, an adequacy decision (including the EU–US Data Privacy Framework for certified providers), and supplementary measures where appropriate. You can request a copy of the relevant safeguards (for example, the Standard Contractual Clauses we rely on) at contact@redmechs.com.
9. Data retention
- Account and content data (vehicle profile, chats, service history): kept while your account is active. If you delete your account, we delete this data within 30 days; residual copies in encrypted backups are purged within 90 days.
- Inactive accounts: if you have not signed in for 24 months, we may delete your account and data after notifying the email on file.
- Transaction and accounting records: kept up to 7 years as required by Estonian accounting and tax law.
- Analytics data: kept in identifiable form for no longer than 24 months, then deleted or aggregated.
- Support correspondence: kept up to 24 months after the issue is closed.
10. Your rights
Depending on where you live, you have the right to:
- Access the personal data we hold about you and receive a copy;
- Correct inaccurate or incomplete data;
- Delete your data ("right to be forgotten");
- Port your data to another service in a structured, machine-readable format;
- Restrict certain processing;
- Object to processing based on legitimate interests (see the highlighted notice in Section 6);
- Withdraw consent at any time, without affecting processing that happened before withdrawal;
- Complain to a supervisory authority.
To exercise any of these rights, email contact@redmechs.com. We respond within one month (GDPR) or the period required by your local law. We may need to verify your identity first — usually by confirming control of the email linked to your account.
EEA users may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or the supervisory authority of their own country. Philippine residents have rights of access, correction, erasure, and data portability under the Data Privacy Act of 2012 (RA 10173) and may lodge complaints with the National Privacy Commission (privacy.gov.ph). California residents have equivalent rights of access, deletion, correction, and non-discrimination under the CCPA/CPRA; we do not sell or share personal information as defined by that law.
11. Deleting your account and data
You can delete your account at any time:
- In the App: Profile → Settings → Delete Account;
- On the web: visit nomech.app/delete-account and follow the steps; or
- By email: send a request to contact@redmechs.com from your account email — or, if you have lost access to that email, after we verify your identity another way.
Deleting the App from your device does not delete your account or cancel a subscription. Deletion removes your account data as described in Section 9; records we must keep by law (for example, payment records) are retained only as long as the law requires.
12. Security
We protect your data with encryption in transit (TLS 1.2+), encryption at rest for our databases and backups, role-based access controls, row-level security on user data, and multi-factor authentication for administrative access. No system is perfectly secure; if we discover a personal data breach that risks your rights, we will notify the supervisory authority within 72 hours and affected users without undue delay, as GDPR requires.
13. Analytics, cookies, and similar technologies
In the App. We ask for your consent before enabling analytics and session replay. If you decline, the App works normally and only the data needed to provide and secure the Service (Section 3.1 and the device and technical data in Section 3.2) and crash diagnostics are processed. You can change your choice at any time in the App under Settings → Privacy.
On the Website. We use:
- Essential cookies — needed for the site to function (no consent required);
- Analytics cookies — set only after you consent via the cookie banner. You can withdraw consent at any time through the "Cookie settings" link in the Website footer.
| Cookie / storage | Provider | Purpose | Duration |
|---|---|---|---|
| Session/security cookies | noMech | Sign-in state, security, load balancing | Session |
| Cookie-consent record | noMech | Remembers your banner choice | 12 months |
_ga, _ga_* | Google Analytics | Visitor and session statistics | Up to 24 months |
ph_* | PostHog | Product analytics | Up to 12 months |
We do not use advertising or cross-site tracking cookies.
14. Notifications
- Service-due reminders and other optional notifications are sent only if you enable them, and you can turn them off at any time in the App's Settings or your device settings.
- Important account, security, or service messages (for example, confirmation of a purchase, a security alert, or notice of changes to these documents) may be sent to your account email or shown in the App as part of providing the Service.
- We do not send marketing push notifications without a separate opt-in.
15. Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child under 16 has provided us personal data, contact us at contact@redmechs.com and we will delete it.
16. Changes to this Policy
We may update this Policy as the Service evolves. For material changes we will notify you at least 14 days before they take effect — in the App, on the Website, or by email — and update the version number and effective date above. Where a change concerns processing based on your consent, we will ask for your consent again rather than assume it.
17. Contact
RedMechs Intelligence OÜ Harju maakond, Tallinn, Kesklinna linnaosa, Narva mnt 5, 10117, Estonia contact@redmechs.com
We aim to answer privacy inquiries within 7 days.