LEGAL
Privacy Policy
Last updated: April 2026
1. What We Collect
- Vehicle information submitted through the diagnostic form (year, make, model, mileage). This is not personal data.
- Contact form submissions (name, email, message). Collected only when users voluntarily submit the contact form.
- IP addresses. Used for rate limiting only, not stored long-term.
- Usage analytics via Vercel Analytics. Anonymous, no cookies, no personally identifiable information.
2. What We Do Not Collect
- We do not require user accounts or registration
- We do not collect payment information
- We do not use tracking cookies
- We do not collect vehicle identification numbers (VINs) or license plates
- We do not collect location data
3. How We Use Data
- Vehicle data is used to generate AI reports and is cached anonymously (by vehicle specs, not by user) to improve performance
- Contact form data is used solely to respond to inquiries
- IP addresses are used for rate limiting to prevent abuse and are not stored permanently
4. Third-Party Services
VehicleMD uses the following third-party services to operate:
- Anthropic Claude API - Vehicle data is sent to Anthropic's API to generate reports. Subject to Anthropic's privacy policy.
- NHTSA API - Vehicle data is sent to the U.S. government's NHTSA API to retrieve recall and complaint data. This is a public government API.
- Supabase - Anonymous vehicle report data is cached in a PostgreSQL database hosted by Supabase. See Supabase's privacy policy.
- Google reCAPTCHA v3 - Used on the contact form to prevent spam. Collects behavioral data per Google's privacy policy.
- Vercel - Hosts the application and provides anonymous analytics. See Vercel's privacy policy.
- Resend - Processes contact form email delivery. See Resend's privacy policy.
5. Data Retention
- Cached vehicle reports are retained for 30 days
- Contact form emails are retained indefinitely for correspondence purposes
- No user accounts or profiles are created
6. Children's Privacy
VehicleMD is not directed at children under 13. We do not knowingly collect information from children.
7. California Residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights regarding the personal information VehicleMD may collect about you. This section describes those rights and how to exercise them.
Subject to certain limitations, you have the right to (a) know what personal information we have collected about you and how it is used and shared, (b) request deletion of personal information we have collected from you, (c) request correction of inaccurate personal information, (d) opt out of the sale or sharing of personal information, and (e) not be discriminated against for exercising any of these rights.
VehicleMD does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We do not knowingly sell or share the personal information of any consumer, including anyone under 16 years of age.
To exercise any of these rights, contact us at or through our contact form. We will respond within the timeframes required by applicable law. Because VehicleMD does not require accounts and collects minimal information, verification of a rights request may rely on information you supply in your request (such as the email address used when submitting a contact form).
8. Colorado Residents
If you are a Colorado resident, you may have rights under the Colorado Privacy Act regarding your personal data. Contact us at for any privacy-related requests.
9. AI Disclosure
VehicleMD uses artificial intelligence to generate vehicle health reports and power the chat assistant. All AI-generated content is labeled as such. We do not use AI to make automated decisions about individuals. The third-party AI provider used to process this data is named in the Third-Party Services section above.
10. Changes
We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes.
11. Contact
For privacy-related questions, reach out at .