Dashivra - Car Widgets

Privacy

Dashivra - Car Widgets privacy policy

What this app collects, why it collects it, and what you can ask us to delete.

This policy explains what the Dashivra - Car Widgets app ("Dashivra", "we") does with information on iPhone, iPad and Android, what leaves your device, why, who receives it, how long it is kept and how you can delete it. Dashivra has no ads, does not sell your information and does not track you across other companies' apps or websites. It does not use the advertising identifier on either platform.

What stays on your device

Most of what you put into Dashivra is stored only on your device and never sent to us:

  • your vehicles (including plate and photo), maintenance items, service log and fuel or charge log
  • parking spots, including their precise location, notes, level and photos
  • Drive Mode trips (start and end time, distance, moving time and average speed; the precise location used to measure them is neither stored nor sent)
  • your widget designs and background images, and the history of your AI results
  • your answers to the welcome questions
  • the music shown in Now Playing (title, artist, album, artwork and playback state)

Widgets read a copy of this information inside your device. On Android, notification access is used only to find the active media session of the app you play music from; Dashivra does not read, store or send the content of your notifications.

On Android, Dashivra turns off Android backup and device-to-device transfer for its data, so none of it is copied to your Google Account or to a new phone; a reinstall or a new phone starts empty. On iPhone and iPad, app data is included in your own iCloud or computer backup if you use one, as for every app.

What leaves your device and why

  • Anonymous app identity. There is no sign-up. When you first open the app, Google Firebase creates an anonymous identifier, and the app creates a random install ID and a signing key kept in your device's secure key storage. The app registers the install ID, the public part of the key, the platform and the app version with our server, which gives back a support code. App attestation (Apple App Attest or DeviceCheck, Google Play Integrity) through Firebase App Check confirms requests come from the genuine app. We use these to secure requests, prevent abuse and let you delete your data.
  • Subscription verification. When you buy or restore Dashivra Pro, the app sends the store's transaction proof (the signed App Store transaction or the Google Play purchase token) and the product to our server, which checks it with Apple or Google and records the product, its state, its expiry and a reference to the transaction (Apple's original transaction ID, or a fingerprint of the Google Play token). Payment details stay with Apple or Google.
  • AI tools. When you use an AI tool, what you send goes to our server and, through the OpenRouter service, to the AI model that creates your result: your prompt or question (with the last few turns of an assistant conversation), the vehicle details, habits or fuel entries the tool needs, and a photo when you choose one (a dashboard warning light, or your car or interior for the Dash Designer). Our server removes photo metadata, such as location, before passing a photo on. Text and photo requests are routed only to model endpoints that do not retain them; a Widget Art prompt goes to an image model under its provider's terms. Our server keeps the text of each AI result for 30 days, then deletes it and keeps only a fingerprint so a report about that result can still be checked. We do not store your photos.
  • Reports. When you report an AI result, we receive the reason, your optional note and the result's fingerprint, and we review it.
  • Daily allowances and abuse prevention. To show and enforce each AI tool's daily allowance and to stop abuse, our server counts requests per install and uses your IP address to limit request rates.
  • Weather. To show local weather, the app sends your location rounded to about 1 km to our server, which asks MET Norway for the forecast for that rounded area without any identifier and caches it for other requests in the same area.
  • Lyrics. When you open the lyrics panel, the app sends the current song's title, artist, album and length to our server. Our server looks the song up in LRCLIB (lrclib.net), a free public lyrics database whose entries are shared by its community, and sends LRCLIB only the song's title, artist, album and length. LRCLIB never receives your IP address, install ID or any other identifier; it sees only our server. To avoid repeating the same lookups, our server keeps a short cache of song lookups (found lyrics for up to 6 hours, songs without lyrics for up to 1 hour); it holds only song information and lyrics, never who asked. The app keeps lyrics only while the panel shows them.
  • Analytics and crash reports. Google Analytics for Firebase records which screens and features are used, and it also automatically records App Store and Google Play in-app purchase events (such as the product, price, currency and transaction identifier). It estimates your approximate region from your IP address. Firebase Crashlytics records crash reports and diagnostics; error messages from the app's own code are cleaned of identifiers, coordinates and anything you typed before they are sent. We use both to fix problems and improve the app. They use app-instance identifiers, are never used for advertising, and are not combined with your install ID or support code.
  • Welcome and subscription screens. These screens load from our website, dashivra.site, with your device language and platform. Like any website, it receives your IP address to deliver the pages. Your answers to the welcome questions stay on your device.
  • Links you open. When you tap Directions for a parking spot, open a song in Apple Music or YouTube Music, or tap View on LRCLIB under lyrics, Dashivra hands the location, the song name or the song's LRCLIB page to that app or website. What it does next is covered by its own privacy policy.

Who receives it

We use these service providers only to run the app: Google Firebase (anonymous authentication, App Check, Analytics and Crashlytics), OpenRouter and the AI model providers it routes to, Apple and Google for subscription verification, MET Norway for weather forecasts (rounded location only), LRCLIB for lyrics (the song's title, artist, album and length only, sent by our server without any identifier), and the hosting and network providers that carry traffic to our server and website. We do not sell or share your information with anyone else, except when the law requires it. Our servers and these providers may process information in countries other than yours.

How long we keep it

  • AI result text: 30 days, then only its fingerprint remains.
  • Daily allowance counters: up to 3 days. IP-based rate limits: up to 1 day. AI request records used to prevent abuse (with the anonymous Firebase identifier and IP address) and records of which request signatures were already used: up to 2 days.
  • Cached weather: until the forecast expires, then at most 1 more day; it is stored by area, not by user.
  • Cached song lookups for lyrics: up to 6 hours (up to 1 hour when no lyrics were found), in our server's memory only; they are stored by song, not by user.
  • Your install record, subscription records and report notes: until you delete your data.
  • Web deletion requests: the support code you enter is erased 30 days after the request is processed; a record that the request was received and processed, without the code, remains.
  • Crash reports: 90 days in Firebase Crashlytics. Analytics: according to our Google Analytics retention setting.

Deleting your data

  • In the app: Settings > Delete all my data removes everything on your device (database, photos and files, widget data, reminders, the signing key and the install ID) and deletes your install's records on our server, including its stored AI results, usage counts and subscription records. It also deletes the anonymous Firebase account, resets the Analytics data and identifier kept on your device and resets the Crashlytics identifiers, so later use starts under new identifiers that are not linked to the old ones.
  • On the web: if you no longer have the app, enter your support code (Settings > Support code) at the data deletion page. This removes the same server records. It cannot reach your phone, so the data on the phone and its anonymous Firebase sign-in are removed only by Delete all my data in the app.

After deletion we keep only what is needed to prevent abuse and to honour the request: a marker that stops the deleted install from registering again (its account fingerprint and public key are removed after 30 days), reports about AI results without your install ID or note, the short-lived abuse-prevention records listed above (up to 2 days), and, for a web request, the support code for 30 days after it is processed. Analytics events and crash reports already sent stay in Firebase for the periods above, no longer linked to your device. Deleting your data does not cancel a subscription; manage it in your Apple Account or Google Play subscription settings.

Your choices

Location, camera, photos, music and notification access are optional. You can refuse or turn them off in your device settings at any time; the features that need them explain why and stop working until you allow access again. You can also choose not to use the AI tools, weather or lyrics.

Children

Dashivra is made for drivers and is not directed to children. We do not knowingly collect information from children.

Questions and requests

For questions about privacy, or to ask for access to or deletion of your information, write to us through the support page. We will update this policy when the app's data practices change.