Legal
Privacy Policy
Short version: Veltor does not collect, store, or sell your personal data. Everything stays on your device. We do not run servers that hold your information.
1. Who we are
Veltor ("we", "us", "our") is a mobile application developed and published by Veltor App. Contact: privacy@veltorapp.com
2. Data we collect — and what we do not
Veltor is designed to be serverless and offline-first. We do not operate any cloud backend that stores your data.
The following data is processed entirely on your device and never transmitted to our servers:
- Location / GPS data (used for speed calculation and HUD display)
- Accelerometer and gyroscope readings (used for drive coaching and engine sound)
- Tesla API access tokens (stored in your device's secure keychain / encrypted storage)
- Tesla vehicle telemetry (speed, battery, gear, etc.) — fetched directly from Tesla's servers to your device
- Trip history and driving scores (stored locally in the app's private database)
- App preferences and settings
3. Tesla account and OAuth
If you connect a Tesla account, Veltor uses Tesla's official OAuth 2.0 + PKCE flow. This means:
- You sign in directly on Tesla's own website — Veltor never sees your Tesla password
- Tesla issues access tokens directly to your device
- Tokens are stored in your device's secure enclave (iOS Keychain / Android EncryptedSharedPreferences)
- Veltor communicates with the Tesla Fleet API directly from your device — no proxy server
- You can revoke access at any time via your Tesla account at tesla.com
The callback URL https://veltorapp.com/callback is a static redirect page hosted on GitHub Pages that immediately redirects to the Veltor app on your device. No data from this redirect is logged or stored.
4. Location data
Veltor requests "When In Use" location permission to provide GPS speed readings and HUD display. Location data is processed in real-time on your device and is never uploaded to any server.
If you grant "Always" location access, this enables speed tracking while the app is backgrounded. This data remains local to your device.
5. Analytics and crash reporting
The current version of Veltor does not include any third-party analytics SDK. If this changes in a future version, this policy will be updated and you will be notified in the app before any analytics are collected.
6. Advertising
The free tier of Veltor may display advertisements served by Google AdMob. Google's privacy policy applies to data collected by AdMob: policies.google.com/privacy
Upgrading to Veltor Pro removes all advertising.
7. In-app purchases
Purchases are processed by Apple (App Store) or Google (Google Play). We receive confirmation that a purchase was made, but we do not receive your payment card details. Purchase records are stored locally on your device.
8. Children's privacy
Veltor is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us at privacy@veltorapp.com.
9. Data retention and deletion
Since all data is stored locally on your device, you can delete all Veltor data at any time by uninstalling the app. Tesla tokens are stored in your device keychain and are also deleted on uninstall.
To revoke Tesla API access independently of uninstalling the app, go to Settings → Sign out of Tesla within the app, or visit your Tesla account security settings.
10. Your rights
Because we do not hold personal data on our servers, rights such as data access, rectification, and erasure are exercised directly on your device by using the app's built-in controls or uninstalling the app.
For any privacy concerns, contact us at privacy@veltorapp.com. We will respond within 30 days.
11. Changes to this policy
We may update this Privacy Policy as the app evolves. We will notify you of material changes via an in-app notice. Continued use of the app after changes constitutes acceptance of the revised policy.
12. Contact
Veltor App
privacy@veltorapp.com
veltorapp.com