GearOS Privacy Policy (Plain English)
This is the human-friendly version of our privacy policy. It explains what we collect, why we collect it, and what choices you have. If you want the most formal version, use the "MaintenanceFreak Privacy Policy (Formal)" document.
This policy covers MaintenanceFreak LLC ("we") and these services:
What we collect
Stuff you give us
When you create an account or use the product, you may give us:
- Account info
- Email, username, password, name, phone number
- Personal vs business account type, business name (if you enter it)
- Subscription and billing admin
- Which plan you are on, limits and usage, and billing workflow info
- If you enter an EIN for a business plan, we store it in encrypted form. We generally only show the last four digits in the app.
- Garages and teams
- Garage names and addresses
- Invitations (we send invites by email) and membership roles
- Your maintenance world
- Assets you add (make, model, year, notes, and identifiers like VIN or serial number)
- Maintenance tasks, due dates, priorities, time logs, parts used, and attachments
- Parts, tools, inventory movements, and related notes
- Documents and files
- Document details (title, tags, category, expiration, what it is linked to)
- The files themselves (PDFs, images, and other uploads)
- Messages to us
- Support requests or feedback (subject, body, and anything you include)
Stuff we collect automatically
When you use the service, our systems also see:
- Basic request info
- IP address, user-agent, device or browser type, and timestamps
- This is normal for any web or app service and is needed for security and reliability.
- Security and operations telemetry
- Logs and security events that help us prevent abuse, enforce rate limits, and debug problems.
- We also keep operational metrics (for example, counts of logins, errors, permission denials, and feature usage). Some internal processes briefly use identifiers in memory (like user IDs) to dedupe active-user counts, but what we emit is typically aggregated by tier or platform.
- Location info (only when relevant)
- If you type in an address, we store it.
- Some features may use location permission (like biasing an address search or showing monitoring maps). You control this in your browser or device settings.
Uploads, images, and moderation
We support uploads like avatars, asset photos, documents, and evidence attachments.
- Where uploads go
- Uploads are stored in cloud storage (AWS S3) using presigned upload links.
- For images (avatars and asset photos), we store the original and also a thumbnail to make the app load faster.
- Deleting uploads
- If the product shows a delete button for an upload, you can delete it anytime. Like most systems, it can take some time for deletion to fully disappear from redundancy systems and backups.
- Image safety checks
- We run safety checks on image uploads.
- If an image is flagged as inappropriate, we deny the upload and do not keep the image.
- We may keep a small log entry that the upload was rejected (for example, your account ID, time, and a reason code) to help prevent abuse.
Who we share data with (and why)
We do not sell your personal info for money. We share data only when it helps run the service, when you ask us to, or when the law requires it.
Service providers we use
Depending on what you do in the product, some data is processed by providers like:
- AWS (Amazon Web Services) for hosting, storage (S3), and message queuing (SQS)
- Stripe for subscriptions and payments (we do not get your full card number)
- Apple App Store and Google Play for subscriptions purchased in the mobile apps
- SendGrid and Amazon SES to send emails (verification, password reset, invites, and service notices)
- Push notifications
- Apple Push Notification service (APNs)
- Firebase Cloud Messaging (FCM)
- Maps and places
- Google Places for address autocomplete and place details (your query text goes to Google, and it returns place info like address and coordinates)
- OpenStreetMap tile servers for map tiles. When maps load, those servers receive your IP address and tile coordinates.
- X (formerly Twitter) OAuth, if you choose to sign in that way
We also load some page assets from third-party domains (for example, Google Fonts) on certain pages, which means your browser will connect to those domains to fetch assets.
Other people you work with
If you are part of a shared garage, team, or business account, other authorized members can see the things you share in that workspace (assets, tasks, documents) based on roles and permissions.
Public or link-based features
A few features are meant to be shareable:
- Public profile: If you turn on public profile settings, you can make some profile fields or selected documents visible publicly.
- Attestation: Some attestation pages are accessible by token or code. Anyone with the token or code can access that flow, so treat those like a secret link.
Cookies and storage on your device
We use minimal cookies and storage, mainly for login and security.
- Web app
- Uses secure, HTTP-only cookies to manage sign-in sessions and token refresh.
- Uses anti-forgery token controls (for example, OAuth state/verification and CSRF protection).
- Web access and refresh tokens are not stored in browser local storage.
- Mobile app
- Stores auth tokens in secure storage (Keychain on iOS, Keystore on Android).
- Stores certain BLE-related keys and install identifiers in secure storage.
- If you download a document in the app, it may be saved to your device storage.
How long we keep data
We keep data as long as we need it to run the service, keep it secure, and comply with the law.
A few specifics from how the product works today:
- Refresh token lifecycle metadata is kept and cleaned up based on configurable retention settings.
- Certain security replay-prevention records are kept only for a limited time (TTL).
- Attestation records are designed to be immutable once written. Access tokens or codes can expire, but the record may be kept for integrity and fraud prevention.
- Deleting an asset can remove links to documents, but it might not delete the documents themselves automatically. If you want a document gone, delete the document too (where the product supports it).
- If you use full account deletion, we remove account and linked consumer subscription data from active systems. The subscription ends immediately, and remaining prepaid time is forfeited except where required by law.
Your choices and rights
What you can do from inside the product (depending on the feature):
- Update your profile info and public profile visibility settings
- Delete selected data categories (
Profile, Assets, Maintenance, Documents, Parts, Tools) while keeping account/subscription login context active - Delete assets, asset images, documents, folders, and profile images
- Cancel garage invites
- Remove multi-factor authentication factors (where supported)
- Delete your full account (account data is permanently removed from active systems, your subscription is terminated immediately, and remaining prepaid time is forfeited except where required by law)
What you can request from us (subject to law and practical limits):
- A copy of your personal data
- Fix incorrect info
- Delete data (some records must be kept for security, integrity, or legal reasons)
- Export certain data (where feasible)
If you do not see a self-service option (for example, selective deletion, full account deletion, or export), contact us.
Contact us
MaintenanceFreak LLC
Attn: Privacy
2045 W Grand Ave Ste B
PMB 157913
Chicago, IL 60612-1577
Support: contact@gearos.io
Privacy: legal@maintenancefreak.com