Legal · Updated 2026-09-17
This revision applies to new users on publication. For existing users, material changes take effect on the date in our email notice, at least 14 days after that notice is sent.
This describes how Cellmetry processes personal data under the EU General Data Protection Regulation (GDPR) and Finnish data- protection law. It is written to be readable; the legal substance is binding all the same.
The data controller is Olli Ruokojoki, operating as Cellmetry (Finnish toiminimi / yksityinen elinkeinonharjoittaja, Y-tunnus 3619980-8), based in Oulu, Finland. For any data-protection matter, email [email protected]. We respond within 30 days, or sooner where the law requires.
We process the following categories:
We do not sell personal data. Public Fleet and showcase views are available to anyone on the internet without an account. Private group members receive the details you share with that group. We also use the following service providers, with processing agreements where they act as our processors:
Data may be disclosed to public authorities where required by law and proportionate (for example, a lawful court order).
Account and vehicle history are retained while you use the service, including during subscription pauses. Account deletion removes your account and its ownership links, but does not automatically erase every retained vehicle record. Specifics:
Under GDPR you have the right to:
To exercise any of these, email [email protected] from the address on your account. We may ask for additional proof of identity before acting and will respond within 30 days of receiving a verified request.
The primary storage and processing is inside the EU. Transfers to Tesla, Inc. occur when we fetch telemetry on your behalf; these are covered by Standard Contractual Clauses and are a necessary part of the service you requested. Stripe transfers, when applicable, rely on its EU entity and contractual safeguards. Email delivery via Resend (transactional emails to you, and operator alerts about you to Cellmetry) is processed within the EU under Resend's EU data-residency option, so no transfer outside the EEA is involved for those messages. Sentry events are processed in Sentry's EU region.
Three providers are US-based. Cloudflare serves cellmetry.com from its network and stores our encrypted backups; Apple carries push notifications to the iOS app and, if you use it, Sign in with Apple; Google handles “Continue with Google”. Each relies on Standard Contractual Clauses, and additionally on the EU–US Data Privacy Framework where that provider is certified under it. Only Cloudflare is unavoidable, and what it processes is connection data plus, because it terminates the connection's encryption, the content of the requests and responses themselves; the backups it stores are separately encrypted by us before upload, so those it holds as ciphertext. Signing in with an email address and password keeps Google out of it, and staying off the iOS app keeps Apple's push service out of it, though an unanswered TestFlight invitation still means Apple has been told your address.
Data in transit is protected by TLS. Data at rest lives in a PostgreSQL database on EU-hosted servers, with production access limited to Cellmetry's operators. Passwords are hashed with bcrypt and session tokens are signed JWTs. Tesla refresh tokens are additionally encrypted at the column level with AES-256-GCM under a key held in the deployment environment, so a database-only compromise yields ciphertext rather than usable credentials.
We may update this policy. Material changes will be announced by email at least 14 days before they take effect. Older versions remain available on request.
For questions, data-protection requests, or complaints, email [email protected].