Voltmoss logo Voltmoss
Home Privacy Terms

Legal

Privacy Policy

Effective date: 3 September 2026

Terms of Use

Privacy Policy

Voltmoss is a companion app for a connected car. It is a client for a j5-ev-dashboard telemetry server that you host yourself. This policy explains what the app keeps on your phone, where your car's data travels, and the one thing we (the developer) do receive: anonymous usage analytics and crash reports, which you can switch off at any time.

In short: there is no Voltmoss account and no Voltmoss backend. Your car's telemetry goes only to the server address you type in. We never receive your number plate, VIN, server address, location, photos or passwords.

1. Who we are

Voltmoss is developed and published by Anders Cheow ("we", "us"). Voltmoss is an independent project and is not affiliated with, endorsed by or connected to any car manufacturer or their connected-car services. Questions about this policy: ll123mg@gmail.com.

2. What the app stores on your device

Everything below stays on your phone and is deleted when you delete the app.

  • Your server's address and display preferences — theme, language, plate/VIN masking, distance chart style, petrol-price comparison, service reminder, control remaps and the analytics switch — in the app's local preferences.
  • Your dashboard password — only if you choose "Remember on this device", and then only in the iOS Keychain or Android Keystore. It is never written to plain preferences and never leaves your device except to sign in to the server address you entered.
  • A session cookie (sid) issued by your own server after you sign in, kept on the device and shared with the app's home-screen widgets through the platform's protected storage (App Group Keychain on iOS, an encrypted Keystore blob on Android) so the widgets can refresh while the app is closed.
  • A car photo, if you choose one from your photo library. The cropped photo is kept on the device and, if you ask it to, uploaded to your own server — nowhere else.
  • A widget snapshot — the last battery, range and charging figures, so your home-screen widgets have something to show. It lives in the app's protected storage on the device.

3. Where your car's data goes

  • Your own dashboard server. Every telemetry request, remote command, route and place lookup, and charging-station search goes to the server address you typed in. What that server does with the data is under your control — see the j5-ev-dashboard project.
  • Carto (map tiles). The Trips tab's maps load basemap tiles from basemaps.cartocdn.com. Like any web request, a tile request exposes your IP address and the map area being viewed to Carto. See Carto's privacy policy.
  • Google Fonts. On first run the app downloads its typefaces from Google Fonts and caches them on the device. The request exposes your IP address to Google. See Google's privacy policy.
  • Google Maps (optional). "Open in Google Maps" and "Directions" hand a route or a station's coordinates to the Google Maps app or website on your device. Nothing is sent until you tap.
  • Google Firebase. Anonymous usage analytics and crash reports, described in the next section. This is the only data that reaches us.

4. Analytics and crash reporting

The app uses Google Analytics for Firebase and Firebase Crashlytics, both provided by Google LLC, so we can see which features are used, whether they work, and why the app crashed. Collection is on by default and you can turn it off in Settings → Privacy → Share usage analytics; the switch covers analytics and crash reports together, and takes effect immediately.

What is collected

  • Device and app information — device model, operating-system version, app version, app language, time zone, and an approximate country or region derived by Google from your IP address (the IP address itself is not stored in Analytics reports).
  • A pseudonymous app-instance identifier generated by Firebase on installation. It is not tied to your name, e-mail, phone number or any account, and it is reset when you reinstall the app.
  • Usage events — for example that a tab was opened, a remote command was sent and whether it succeeded, a trip was planned and how many charge stops it needed, an explainer sheet was opened, or a setting was changed. Events carry only the context needed to understand them: the kind of server (demo, Railway or self-hosted), the car's state (charging, driving, parked, offline), a battery percentage, a distance in kilometres, a stop count, a duration, a success flag, the type of error.
  • Crash and error reports — the stack trace of a crash or an unexpected server error, the device and app details above, and a short trail of the preceding events so the crash can be reproduced.

What is never collected

No event, property or crash report ever contains your number plate, VIN, server address or hostname, dashboard or CarLinko passwords, session cookie, GPS coordinates, place names or addresses you search for, the photo of your car, or the raw response from your server. Analytics data is never used for advertising: the app tells Firebase that advertising storage, ad user data and ad personalisation are all denied, regardless of the analytics switch.

Retention and legal basis

Event-level Analytics data is retained by Google for 2 months and aggregated reports for 14 months; Crashlytics reports are retained for 90 days. Google processes this data on our behalf under the Firebase Data Processing Terms; see also Privacy and Security in Firebase. Where a legal basis is required, we rely on your consent (the switch is yours) and on our legitimate interest in keeping the app working. Debug builds of the app never send anything.

5. Location

Location permission is requested only when you tap "My location" in the Trips tab's nearby charging-station browser, and only to centre the map and sort stations by distance. Your location is sent to your own server as the search origin; it is not stored by the app and not shared with anyone else, including our analytics. The feature is optional — the tab works without the permission.

6. Demo mode

Typing demo as the server address activates a built-in, entirely on-device demo server with fictional sample data. Demo mode makes no requests to any server. Usage analytics still apply in demo mode (marked as demo), unless you switch them off.

7. Security

Passwords live only in the platform keychain or keystore. The session cookie shared with widgets is stored in the App Group Keychain on iOS and in an AES-GCM blob protected by the Android Keystore, excluded from backups. Connections to your server use whatever scheme you enter; we recommend https.

8. Children

Voltmoss is a vehicle utility and is not directed at children under 13. We do not knowingly collect information from children.

9. Your choices and rights

  • Turn analytics off at any time in Settings → Privacy. The choice is stored on the device and honoured on every launch.
  • Delete everything on the device by deleting the app. Data on your own server is yours to manage there.
  • Ask us about the analytics data associated with your app instance. Because the identifier is pseudonymous, we will need the app-instance ID from your device to find it; e-mail ll123mg@gmail.com and we will explain how.
  • Depending on where you live you may have rights to access, correct, delete or restrict the processing of your personal data, and to complain to a supervisory authority.

10. Changes and contact

We will update this page when the app's data practices change and update the effective date above. Material changes will also be mentioned in the app's release notes. Questions: ll123mg@gmail.com.

© 2026 Voltmoss. An independent project, not affiliated with any car maker.
Privacy Policy Terms of Use ll123mg@gmail.com