Legal · Torkmark for Android
Privacy policy.
This describes what the Torkmark Android app records, what leaves your phone, and what is done with it. It is written to be read, not to be survived.
In a breath
The short version.
A summary, for reading standing up. The full policy below is the authority, and it is what governs.
Read the full policy below, or ask a question through support. Deleting your account and everything under it is one email.
1. Scope
This policy covers the Torkmark Android app and this website. Torkmark builds vehicle telemetry and versioned build-manifest software. The app connects to an adapter plugged into your vehicle, records the sensor readings the vehicle exposes, and keeps a build record on your phone.
The app is in alpha and is in closed testing on Google Play. The behaviour described here is the behaviour of the current build; if it changes before launch, this page changes with it and the effective date moves.
Torkmark is operated by its builder as a sole proprietorship in Washington State, United States. That sole proprietorship is the entity responsible for the data described here, and Washington law governs this policy.
2. What is collected
Four kinds of data, and it is worth separating them because they behave very differently.
Account
- Google sign-inYou sign in with a Google account through Google's own account chooser. Torkmark receives the account's email address, display name, and a unique account identifier from Firebase Authentication. Torkmark never sees or stores your Google password.
- Session credentialsSign-in state is held by Firebase Authentication on the device. The app writes no access token to its own storage; each upload mints a short-lived token at the moment it is needed.
- Tester enrolmentDuring closed testing the server checks whether your account is on the tester list before accepting data. That check is made against your account identifier.
On your phone only
The following is written to the app's private storage on your device and is not uploaded:
- Vehicle profiles and settingsThe vehicle labels you create, which one is selected, your adapter's Bluetooth address and connection mode, your alert thresholds, your unit preference, theme, and dashboard layout choices. One exception, stated here so the two sections cannot be read as contradicting each other: the label of the vehicle you are recording rides with each uploaded reading, as section 4 describes.
- Build manifestsEvery committed version of your build record: the modification name, category, install date, odometer reading, cost, and note — whichever of those you chose to enter.
- Drive summariesA compact summary of each completed capture, kept so past drives can be compared later.
- Diagnostic trouble codesCodes read from the vehicle are decoded and displayed on the device. They are not part of the upload.
Sent from your phone
- Telemetry observationsEach reading is sent as: the vehicle label you chose, the manifest version in force, the signal name, the value, the unit, and the time your device recorded it. Nothing else is in the message. Section 4 covers this in detail.
Not collected
- No locationThe app does not collect or transmit your location. Its Bluetooth scanning permission is declared to Android with the
neverForLocationflag, and the legacy location permission it declares applies only to Android 11 and earlier, where the operating system required it in order to scan for a Bluetooth adapter at all. - No VINThe app does not read your vehicle identification number. The vehicle label used in the record is one you type in.
- No advertising, no third-party analyticsThe app contains no advertising software and no third-party analytics or crash-reporting software. There is no behavioural profile of you, because nothing in the app builds one.
- No contacts, photos, microphone, or cameraThe app requests none of these permissions.
The “join the test” button on this site is an ordinary mailto: link. There is no form, no field and no script that sends anything: it opens your own mail app, and nothing reaches Torkmark until you press send in that app.
This site is hosted on Google Firebase Hosting, which records standard access logs under Google's terms. Torkmark adds nothing to them. The pages themselves carry no analytics script, no advertising script, and no cookie. They load no external fonts, scripts or stylesheets: every file a page needs is served from torkmark.com itself.
3. Why it is used
- To keep your data yoursYour account identifier is what separates your observations from everyone else's. It is stamped on every reading by the server, from the credential on the request, so a reading cannot be filed under an account that did not record it.
- To run the productStoring your readings so a before-drive recorded in March can be compared against an after-drive recorded in May.
- To gate closed testingConfirming your account is enrolled as a tester.
- To answer youIf you email support, that message and your reply address are used to answer you.
Your telemetry is not used to advertise to you, is not sold, and is not shared with insurers, dealers, employers, or data brokers. If that ever changes it would be a change to this policy, announced under section 11 — not a quiet reinterpretation of this one.
4. Telemetry and vehicle identifiers
This is the section that matters most, so it is specific.
A capture is a drive. While it runs, the app asks your vehicle which standard signals it supports and polls only those. The standard set includes coolant temperature, intake air temperature, ambient air temperature, engine load, throttle position, engine speed, vehicle speed, short and long fuel trims, and control module voltage. Which of them exist depends on your vehicle and adapter.
Every reading is sent as a separate message containing six items: the vehicle label, the manifest version, the signal name, the numeric value, the unit, and the observation time from your device's clock. On arrival the server adds two more: your account identifier, taken from the credential on the request, and the time it received the reading.
The vehicle label is yours to choose. It is a free-text field. If you type a plate number, a VIN, or your name into it, that string travels with every reading and is stored. If you type green jeep, that is what is stored. Torkmark cannot tell the difference, so the choice is genuinely yours.
Speed data
Vehicle speed is one of the standard signals, recorded with a timestamp. It is not paired with any location, so it does not describe where you drove — but it is a record of how fast the vehicle was moving and when. It is stated plainly here rather than buried, because a reader entitled to know that should not have to infer it.
When the phone is offline
Readings that cannot be sent are held on your device and sent later. The buffer is capped; past that cap the oldest readings are dropped rather than the newest. Buffered readings are bound to the account that recorded them and cannot be uploaded under a different account, including if you switch accounts before they are sent.
The server-side data format contains an optional field for location context. No part of the Android app fills it in, and no reading sent by the app carries it. It is named here because it exists in the format rather than because it is in use.
The field is kept rather than deleted because it is reserved for a capability that has not been built: matching drives by location — elevation, or recognizing the same route by where it was driven. The comparisons the product makes today work from what the sensors reported, not from where the vehicle was; this field would add the where. If that ships it will be opt-in and off by default, and this page will describe it before it collects anything. Until then the field stays empty.
5. Storage and retention
Uploaded readings are stored in Google BigQuery, in infrastructure Torkmark operates on Google Cloud. Each stored row carries your account identifier, and access to the table is restricted by that identifier so that a query run for one account cannot return another account's rows.
Your build manifests and drive summaries stay on your phone. Uninstalling the app removes them, and there is currently no server-side copy to restore them from.
- Telemetry retentionUploaded readings are kept for as long as your account exists and are deleted when the account is deleted. There is no separate expiry clock. One alpha caveat, stated plainly: data recorded during alpha may be reset before launch, and you will be told before that happens.
- Account retentionSign-in records are deleted within 30 days of account deletion.
- Support email retentionSupport correspondence is kept as ordinary email while it is still relevant, and deleted on request.
- Storage regionThe United States. The service that receives readings and the table that stores them both sit in Google Cloud's us-west1 region, in Oregon. Uploaded telemetry does not leave the United States; the processors named in section 6 handle account, store and email data under their own listed terms.
- BackupsThere are no independent backup copies today; the live datastore is the only copy. If backups are introduced, deletion will propagate to them at rotation, and this section will say so before they exist.
None of those periods is an estimate. If any of them changes, this section changes with it and the effective date at the top moves.
7. Security
- Credentials are short-livedThe app stores no long-lived upload credential. Each upload mints a fresh, short-lived token, so nothing recoverable from the app's storage grants access to your data.
- Identity comes from the credential, never the payloadThe server stamps every reading with the account identifier proven by the request's credential, ignoring any account named in the data itself. A message cannot claim to belong to someone else.
- Buffered data stays bound to its accountReadings held on the device while offline are tied to the account that recorded them, structurally, so a later sign-in as someone else cannot pick them up.
- Row-level access controlStored readings are separated by account identifier at the database level.
- TransportThe app talks to the server over HTTPS.
No system is beyond compromise, and this one is in alpha. If a breach affects your data, you will be notified without undue delay, and the target is within 72 hours of the breach being confirmed.
8. Your choices and deletion
- Not capturingNothing is recorded from your vehicle unless you start a capture. The app is not a background tracker; capture runs as a visible foreground service with a notification while it is on.
- Choosing what the label saysSection 4 — the vehicle label is free text you control, and the most direct privacy choice in the app.
- Signing outSigning out drops the session on the device. Readings already uploaded are unaffected.
- UninstallingRemoves the app's on-device data, including your manifests and drive summaries. Uploaded readings are not removed by uninstalling.
- Deleting uploaded data — email support@torkmark.com with the subject "Delete my account" from the address on the account; the full procedure is documented at /support/#delete-account. Deletion removes the account record and any telemetry uploaded under it, and is confirmed by reply within 30 days. Nothing is retained afterwards: there are no independent backup copies for deleted data to survive in, and if that ever changes, section 5 says so before it does.
- Exporting your dataYour build manifest can be exported from the app today. That export is the manifest only, by design. A full export of uploaded telemetry is a commitment for after alpha, not a promise being made for launch.
9. Children
Torkmark is a tool for people who work on vehicles and is not directed at children. You must be at least 16 to hold an account. An account identified as belonging to someone younger is deleted; if you know of one, write to support@torkmark.com and it will be handled the same way as any other deletion.
10. Regional rights
Depending on where you live you may have rights to access, correct, delete, or port your data, or to object to certain processing.
- How to exercise themEmail support@torkmark.com from the address on the account. That match is the identity check; no document or photograph is asked for. Requests are answered within 30 days.
- European Economic Area and United KingdomTorkmark is currently available in the United States only. The EEA and UK regimes will be addressed before the app is made available there, and this section will be written for them before that happens rather than after.
- California and other United States state regimesTorkmark does not sell personal information and does not share it for cross-context advertising, as those terms are defined in the California statutes. The rights route is the one above; there is no separate form to fill in.
- ElsewhereThe same route: email the support address from the address on the account.
11. Changes to this policy
When this policy changes, the effective date at the top changes and the current text replaces the old one on this page. Prior versions are published alongside this page from the first revision onward, so any change can be read against the text it replaced. The previous version is at /privacy/2026-08-27/. A material change is also emailed to the address on your account.
A product built on the premise that history should not be quietly rewritten ought to hold its own policy to the same standard. That is why the old versions stay published instead of disappearing at each revision.
12. Contact
Privacy questions go to support@torkmark.com. Say that the question is about privacy in the subject line and it will be routed accordingly.
Do not include your full VIN, your plate, or any account password in an email. Nothing about a privacy question requires them.
- Postal addressNo postal address is published during closed testing. Postal contact is available on request through the support address.
- Data protection contactThe same support address, with "Privacy" in the subject line. There is no separately named officer, and none is required at this size and under these regimes.