Privacy policy

Last updated 26 August 2026

This is a plain-English summary of how AutoUnmask handles your data. It’s written to be genuinely accurate about what the product does today, not a template. Have a lawyer review it before launch — this isn’t legal advice.

What we collect

When you check a listing: the listing text or screenshot you give us, any photos you upload, the asking price, and the listing’s location. If you create an account: your email address and, if you choose to add them, your display name, state, and postcode. We also collect ordinary usage data (pages visited, checks run) via PostHog.

What we strip before we store anything

Every uploaded image has its EXIF metadata removed before storage. Personal information that lands in a screenshot — names, phone numbers, faces, house numbers, number plates — is detected and masked before the image is stored or shown in a share card. Plates are treated as personal information for display purposes, even though we use them internally to look up the vehicle.

Anonymised market data

The price, year, kilometres, and location of every listing checked — not who checked it — feeds an aggregated dataset of private-market car prices (market_comps in our systems). This is retained indefinitely and is not linked back to the account or session that submitted it. This is what lets AutoUnmask tell you whether a price is fair; without it, the product doesn’t work.

How long we keep things

  • Account data: for as long as your account exists, plus 30 days after deletion, for fraud/abuse prevention.
  • Listing content and uploaded photos: 12 months from your last check on that listing, then deleted.
  • Anonymised price data: retained indefinitely (see above — it’s no longer personal information once anonymised).
  • Analytics events: 24 months.

What we never do

We don’t sell your data. We don’t use your uploads to train or fine-tune any model. We don’t share your uploads with anyone beyond the model provider (Anthropic) needed to process your check, under their standard API data-handling terms.

Deleting your data

You can request deletion of your account and associated listing data by emailing us — see Terms for contact details. Honestly: as of this version, deletion is a manual process we run on request, not yet a self-serve button in the product. Building real self-serve deletion is on the roadmap; this page will be updated the day it ships, and until then every request is actioned by a human within 30 days.

Questions

If something here doesn’t match what the product actually does, that’s a bug in this page — tell us and we’ll fix it.

AutoUnmask