Legal · Updated 2026-09-17

Privacy Policy

This revision applies to new users on publication. For existing users, material changes take effect on the date in our email notice, at least 14 days after that notice is sent.

This describes how Cellmetry processes personal data under the EU General Data Protection Regulation (GDPR) and Finnish data- protection law. It is written to be readable; the legal substance is binding all the same.

1. Controller

The data controller is Olli Ruokojoki, operating as Cellmetry (Finnish toiminimi / yksityinen elinkeinonharjoittaja, Y-tunnus 3619980-8), based in Oulu, Finland. For any data-protection matter, email [email protected]. We respond within 30 days, or sooner where the law requires.

2. What data we process

We process the following categories:

  • Account data: email, password hash (where used), role, creation and last-login timestamps. Registered accounts belong to individuals; the public demo uses a restricted, read-only session without registration. Fleet vehicles use a stable pseudonym such as “Tesla #XXXX”, or an optional public alias chosen by their owner. A public alias can identify you, so do not use personal details unless you intend to publish them. Your private vehicle name, account email and VIN are not part of the ordinary public Fleet display. Accounts are for adults: you must be 18 or older to hold one, and Cellmetry is not directed to children. If you sign in with Google or Apple instead of a password, we also store which provider you used and the account identifier it gives us.
  • Group data (when you create or join a Group to share vehicles with other people): the group name, slug, your role in the group (admin / contributor / viewer), the join timestamp, and which of your vehicles you have chosen to share into the group. Groups are an optional sharing overlay — your vehicles always belong to your own account, never to a group.
  • Vehicle data from Tesla Fleet API: the vehicle data covered by the single Tesla permission you grant us when you connect a car, which Tesla calls Vehicle Information (vehicle_device_data). Today that includes readings such as voltage, current, state-of-charge, pack and ambient temperature, cabin climate, odometer, gear, and charge port and session status. Those are examples, not a closed list: we read further signals from that same permission as we build new analyses, and anything outside it would need a new permission from you. Trip and charge sessions are derived from this stream. We do not collect location data (GPS, routes): location sits behind a separate Tesla permission (vehicle_location) that Cellmetry does not request, so your car has no way to tell us where it is.
  • Acknowledgement records: which terms you accepted at signup (Terms of Service, this Privacy Policy) and at each vehicle connection (Vehicle Data Use), the policy version at the time, timestamp, IP address, and user-agent. This is our audit trail of those acknowledgements.
  • Technical and security data: IP address at login, session tokens, diagnostic logs. Retained as described in Section 5.
  • Website visits: a counter of homepage visits and of the calls-to-action clicked there, with the country the request came from, the currency we showed you, and the marketing channel the visit arrived through. Each row carries a visitor identifier that is a one-way hash of the IP address and browser, rotated daily with a secret we hold: it counts a person once a day instead of once a click, and cannot be turned back into an IP address. No raw IP address or browser string is stored, no cookie is set for this, and nothing is shared with any advertising or analytics company. The signed-in dashboard is not measured this way. These rows are deleted after 90 days.
  • Billing data: handled by Stripe as a processor. Cellmetry does not store card numbers; we hold the Stripe customer ID and invoice metadata.

3. Why we process it (purposes and legal basis)

  • Providing the service (running your dashboard, ingesting telemetry, rendering charts): legal basis is performance of the contract between you and Cellmetry (Article 6(1)(b) GDPR).
  • Email about your account (verifying your address, resetting a password, a connection that needs re-authorising, a trial ending, a failed payment): performance of the contract and, for the security ones, our legitimate interest in protecting your account (Article 6(1)(b), (f)). These are not marketing and cannot be unsubscribed from while you hold an account, because they are how we tell you that something about your own service needs attention.
  • Occasional news about Cellmetry sent to customers and people on a trial, such as a price change or a significant new capability: our legitimate interest in telling our own users about our own service (Article 6(1)(f)). Finnish law allows this to an existing customer relationship for our own similar service, provided you can decline it, which you can do in three places: a box on the signup form when we first take your address, a switch under Preferences in your settings, and the unsubscribe link at the foot of every such message. Refusing is permanent and absolute: an objection under Article 21(2), covering this whole category and surviving your account. It does not affect the account email above. We do not send this to people who are not customers, and we never pass your address to anyone else to market to you.
  • Fleet comparisons: we use vehicle readings, period summaries and derived statistics for community comparisons. These include per-car views under stable pseudonyms or optional public aliases, as well as aggregates. Pseudonymous vehicle data remains personal data where it can be linked to a person; we do not treat it as anonymous simply because a name is hidden. Providing comparisons within the service is based on performance of our contract (Article 6(1)(b)).
  • Public Fleet and demo: visitors can view Fleet comparisons without an account, including through the read-only demo. The purpose is to let people explore EV performance and evaluate Cellmetry using real data. Our legal basis for this public presentation is legitimate interests (Article 6(1)(f)), subject to necessity and balancing against your rights. You can object by emailing [email protected]. Public information may be copied or linked with information from elsewhere; pseudonyms do not guarantee that a vehicle or driver cannot be recognised.
  • Groups: you choose which vehicles to share. Private groups allow their members to see shared vehicle details; public groups expose the limited community view. Group sharing is based on providing the sharing feature you request (Article 6(1)(b)). You can remove a vehicle from a group at any time.
  • Public showcase: the founder's BattMobile is deliberately shared with its detailed dashboard, including trip and charging history. A showcase requires its owner's specific permission (Article 6(1)(a)); connecting an ordinary vehicle does not make it a showcase. Permission can be withdrawn by contacting [email protected]. Owners must have authority to share data relating to other drivers.
  • Security, fraud prevention, platform integrity: legal basis is our legitimate interest (Article 6(1)(f)).
  • Measuring how the website is found and used: counting homepage visits and the clicks on its calls-to-action, so we know whether anyone arrives and whether the page works. Legal basis is our legitimate interest in running and improving our own site (Article 6(1)(f)), balanced by keeping the measurement to a daily one-way hash with no raw IP address, no cookie, and no third-party analytics provider. You can object by emailing [email protected].
  • Billing and legal/accounting obligations: legal basis is performance of the contract and legal obligation (Article 6(1)(b), (c)).

4. Who we share data with

We do not sell personal data. Public Fleet and showcase views are available to anyone on the internet without an account. Private group members receive the details you share with that group. We also use the following service providers, with processing agreements where they act as our processors:

  • Hetzner Online GmbH (EU) — hosting provider for the application and database. Data stays in the EU.
  • Tesla, Inc. — source of the telemetry. You authorise the data flow to Cellmetry when you connect your Tesla account. Tesla also processes vehicle data as described in the Tesla Customer Privacy Notice, which applies to the data they hold.
  • Stripe Payments Europe Ltd. (Ireland) — payment processing for subscriptions. Stripe acts as an independent controller for parts of the payment flow it regulates.
  • Resend Brand, Inc. (processing in Ireland (EU) under Resend's EU data-residency option) — email delivery for four kinds of message: (1) account and security email, such as verifying your address at signup and resetting your password; (2) service and billing email about your own account, such as a Tesla connection that needs re-authorising, a trial ending, a failed payment, a referral reward, or a TestFlight invitation; (3) occasional news about Cellmetry itself sent to customers and people on a trial, such as the message announcing a price cut, each carrying an unsubscribe link that stops all of category 3 permanently; and (4) operator alerts to Cellmetry about events needing our attention, such as a vehicle whose onboarding is stuck. Messages in the first three carry your email address, the subject, and a body that says only what that message is about, which for account email is a one-use link. Operator alerts carry only the context needed to act on them: your account email and, when the alert concerns a specific car, its VIN, plus operational context such as how long ago the vehicle was added or which Tesla API error occurred. Two carry more. A subscription from a country we do not serve alerts us with the billing country and the country your card was issued in, which is the only payment-related detail that ever reaches email. Feedback you submit is forwarded with your message, the page you sent it from, your IP address and your browser string, so a bug report can be reproduced. No telemetry samples, passwords, card numbers or session tokens are ever sent.
  • Cloudflare, Inc. — DNS and the proxy every request to cellmetry.com passes through, for TLS termination, caching and protection against attacks. Cloudflare therefore processes connection data including your IP address, and tells our server which country a request came from so prices can be shown in your currency. Cloudflare also stores our nightly database backups (R2 object storage); those are encrypted before they leave our server, so Cloudflare holds ciphertext it cannot read.
  • Google Ireland Ltd. and Apple Inc., when you choose “Continue with Google” or “Sign in with Apple” — the sign-in happens on their page, and they tell us your email address and a stable account identifier so we can recognise you on your next visit. Signing in also tells them that you use Cellmetry. They act as controllers for the sign-in itself; email and password sign-in avoids them entirely.
  • Apple Inc. (App Store Connect), for the iOS beta. If you have opened Cellmetry on an iPhone or iPad but not installed the app, we may invite you to the TestFlight beta a few days after your first car is connected, and doing that registers your email address with Apple as a tester. It is an invitation, not an enrolment: nothing is installed on your device and you can ignore it. The invitation is email of the third kind above, so unsubscribing stops it, and you can ask us to remove you from the tester list at [email protected].
  • Apple Inc. (Apple Push Notification service), if you use the Cellmetry iOS app and allow notifications — the live drive, charge and Sentry Mode updates we send to your phone travel through Apple. The payload is the state of your own car (for example charging power or state of charge) addressed to a device token Apple issued for that install.
  • Functional Software, Inc. (Sentry) — error monitoring for the dashboard backend. When a server-side error occurs, an event is sent to Sentry containing the stack trace, the request path, and breadcrumbs describing the steps leading up to the failure. Before any event leaves the server, a scrubber removes session cookies, session tokens, Tesla refresh tokens, email addresses, and VINs from the payload. Cellmetry does not enable Sentry's automatic personal-data capture (IP addresses, cookies, request bodies), and Sentry session replay is not used. Cellmetry uses Sentry's EU region (Frankfurt, Germany); event data is processed and stored within the EU.

Data may be disclosed to public authorities where required by law and proportionate (for example, a lawful court order).

5. How long we keep data

Account and vehicle history are retained while you use the service, including during subscription pauses. Account deletion removes your account and its ownership links, but does not automatically erase every retained vehicle record. Specifics:

  • While your subscription is active or paused: telemetry, account data, trips, charge sessions, and derived analytics are retained in full indefinitely. Pausing a subscription or letting it lapse does not delete your data — you can resume at any time with full history intact. Legal basis for retention during a pause is our legitimate interest in preserving your data so you can resume service, balanced against your right to object (Article 6(1)(f) GDPR).
  • When you delete your account from Settings: your account, email, password hash and acknowledgement records are deleted, and ownership links to vehicles are removed. Collection is stopped and the vehicles are removed from active community browsing. Historical telemetry and vehicle records are retained for statistics and comparison baselines without a fixed automatic deletion period. These records can still contain vehicle identifiers and names; they are not necessarily anonymous. GDPR rights continue to apply. Contact [email protected] to request erasure of retained personal data or to object to its use. Retention must have a valid legal basis and remains subject to those requests and applicable legal obligations. Account deletion cannot undo copies others previously made of publicly visible information.
  • Invoices and billing records: retained for 6 years as required by Finnish bookkeeping law (Kirjanpitolaki). These records are held by our payment processor Stripe under their own retention obligations; on account deletion we sever our local reference to your Stripe customer record but the invoice itself remains with Stripe for the statutory period. This is a legal obligation (Article 6(1)(c) GDPR) and overrides the erasure right for those specific records.
  • Acknowledgement records: retained for the life of the account, as audit evidence that you accepted the Terms, Privacy Policy, and Vehicle Data Use acknowledgement at the relevant moments. When you delete the account, these acknowledgement records are also erased. Retained vehicle records are described above.

6. Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you.
  • Request rectification if it is inaccurate.
  • Request erasure of data we hold about you, subject to overrides (for example, statutory retention of invoices).
  • Restrict or object to processing based on legitimate interest.
  • Receive an export of your personal data. We provide this on request by email — see below — and respond within 30 days. The export covers your account, vehicles, trips, charges, and consent records in JSON.
  • Withdraw any consent you have given; this does not affect the lawfulness of processing before the withdrawal.
  • Lodge a complaint with the Finnish Data Protection Ombudsman (tietosuojavaltuutettu.fi) if you believe your rights are not respected.

To exercise any of these, email [email protected] from the address on your account. We may ask for additional proof of identity before acting and will respond within 30 days of receiving a verified request.

7. International transfers

The primary storage and processing is inside the EU. Transfers to Tesla, Inc. occur when we fetch telemetry on your behalf; these are covered by Standard Contractual Clauses and are a necessary part of the service you requested. Stripe transfers, when applicable, rely on its EU entity and contractual safeguards. Email delivery via Resend (transactional emails to you, and operator alerts about you to Cellmetry) is processed within the EU under Resend's EU data-residency option, so no transfer outside the EEA is involved for those messages. Sentry events are processed in Sentry's EU region.

Three providers are US-based. Cloudflare serves cellmetry.com from its network and stores our encrypted backups; Apple carries push notifications to the iOS app and, if you use it, Sign in with Apple; Google handles “Continue with Google”. Each relies on Standard Contractual Clauses, and additionally on the EU–US Data Privacy Framework where that provider is certified under it. Only Cloudflare is unavoidable, and what it processes is connection data plus, because it terminates the connection's encryption, the content of the requests and responses themselves; the backups it stores are separately encrypted by us before upload, so those it holds as ciphertext. Signing in with an email address and password keeps Google out of it, and staying off the iOS app keeps Apple's push service out of it, though an unanswered TestFlight invitation still means Apple has been told your address.

8. Security

Data in transit is protected by TLS. Data at rest lives in a PostgreSQL database on EU-hosted servers, with production access limited to Cellmetry's operators. Passwords are hashed with bcrypt and session tokens are signed JWTs. Tesla refresh tokens are additionally encrypted at the column level with AES-256-GCM under a key held in the deployment environment, so a database-only compromise yields ciphertext rather than usable credentials.

9. Changes to this policy

We may update this policy. Material changes will be announced by email at least 14 days before they take effect. Older versions remain available on request.

10. Contact

For questions, data-protection requests, or complaints, email [email protected].

← Back to homepage