Effective date: 15 August 2026 Last updated: 15 August 2026
This policy explains what Dexlin ("we", "us") collects when you use Pokicar, why we collect it, who else sees it, and what you can tell us to do about it.
Pokicar is a car-spotting and collection app: you photograph a car, an automated system identifies it, and it is added to your collection with a rarity tier and a score.
It applies to Pokicar only. Our other apps each have their own policy — see all policies. The website itself collects almost nothing, and the cookie notice covers that separately.
What Pokicar uses, at a glance
| Account required | Yes — email and password, or Google/Apple sign-in |
| Camera | Yes, to photograph cars |
| Photo library | Optional, to pick existing photos and to save photos back |
| Location | Optional, while in use only. Never in the background |
| AI processing | Yes — photos are sent to Google Gemini for identification, as described in §2.4 |
| Advertising | Optional rewarded video only, to earn extra identifications |
| Subscription | Yes — monthly or annual, via the App Store or Google Play |
| Shared with other users | Your display name, profile photo, and any spot you set to Friends or Everyone. Every spot has its own controls for whether the photo, the exact location and the time are shared. New spots default to keeping exact location private |
| Minimum age | 13+ |
1. Who is responsible for your data
Dexlin Av. del Mediterráneo, Loc 4, 29670 Marbella, Málaga, Spain [email protected]
For EU and UK users, we are the data controller for the personal data described here. We are not required to appoint a Data Protection Officer; the contact address above reaches the person responsible.
2. What we collect
We collect only what Pokicar needs to work. Everything below is something the app actually uses.
2.1 Information you give us
| Data | Why | Required? |
|---|---|---|
| Email address | To create and secure your account, and to reset your password | Yes, for an account |
| Password | Authentication. Stored only as a salted hash by Firebase Authentication — we never see or store your plaintext password | Yes, for email sign-in |
| Display name | Shown next to your activity to other users | Yes |
| Profile photo | Shown next to your activity, if you set one | Optional |
| City and country | Shown on your profile and used for regional features | Optional |
| Photos you capture or upload | The core function of the app — see §2.4 for how photos are processed | Depends on feature |
| Content you post | Comments, reactions and similar contributions | Optional |
| Support correspondence | To answer you | Optional |
2.2 Information collected automatically
| Data | Why |
|---|---|
| Approximate or precise location, only while the app is open and only if you grant permission | To record where an item was captured and to distinguish a genuinely new capture from a repeat. Never collected in the background |
| Device and app diagnostics — device model, OS version, app version, crash traces | To diagnose faults and keep the app stable |
| Usage events — screens opened, features used | To understand which features earn their place |
| Advertising identifier (IDFA on iOS, AAID on Android) | Only for the optional rewarded-ad feature, and on iOS only if you allow tracking when asked. See §6 |
| IP address | Inherent to any internet request; used for security, abuse prevention and coarse region |
2.3 Information we create about you
Account state such as level, score, streaks, achievements, subscription status and usage allowances. This is generated by our servers from your activity. You cannot edit it directly, and neither can anyone else — that is a deliberate security property, not an inconvenience.
2.4 Photographs and AI processing
This is the part most people care about, so it is stated plainly.
When you capture or upload a photo for identification:
- The photo is uploaded to our storage, in a folder only your account can write to.
- The photo is sent to Google's Gemini API for automated analysis, to identify the subject and return structured details about it.
- The result and the photo are saved to your account.
We do not use your photos to train any AI model, and Google does not use data submitted through the paid Gemini API to train its models. We do not sell your photos and we do not publish them anywhere you have not chosen to publish them.
Photos may contain more than their subject — faces, number plates, house fronts, street signs. Please consider that before you capture and, in particular, before you set a capture to public. You can delete any photo at any time, and you control per-item what is shared.
2.5 What we deliberately do not collect
- We do not collect your contacts, calendar, microphone, health data or browsing history.
- We do not track your location in the background or when the app is closed.
- We do not build advertising profiles about you, and we do not sell or rent personal data to anyone. We have never done so.
- We do not store payment card details. Purchases are handled entirely by Apple or Google — see §5.
3. Why we are allowed to use it (EU/UK legal bases)
| Purpose | Legal basis |
|---|---|
| Creating and running your account; delivering the features you asked for | Performance of a contract |
| Keeping the service secure, preventing fraud and abuse, protecting the integrity of scores and rankings | Legitimate interests |
| Diagnostics and crash reporting | Legitimate interests |
| Location capture | Consent — via the operating system permission prompt |
| Personalised advertising and the advertising identifier | Consent — via the OS prompt and our consent form |
| Responding to legal obligations | Legal obligation |
Where we rely on consent you may withdraw it at any time, in the app's settings or in your device's system settings. Withdrawing consent does not affect processing that already happened.
4. Who else sees your data
We use a small number of service providers ("processors"). They act on our instructions and may not use your data for their own purposes, except where noted.
| Provider | What they handle | Their policy |
|---|---|---|
| Google Firebase (Authentication, Firestore, Cloud Storage, Cloud Functions) — Google Ireland Ltd / Google LLC | Account credentials, all app data, uploaded photos, server-side logic | firebase.google.com/support/privacy |
| Google Gemini API — Google | Automated analysis of photos you submit for identification | cloud.google.com/terms/cloud-privacy-notice |
| Google AdMob — Google | The optional rewarded-ad feature only. AdMob is an independent controller for advertising data | policies.google.com/technologies/ads |
| Apple | App distribution, and subscription purchase and receipt validation | apple.com/legal/privacy |
| Google Play | App distribution, and subscription purchase and receipt validation | policies.google.com/privacy |
Other users see only what you choose to make visible: your display name, profile photo, and any content you set to be shared. Privacy controls are per-item where the app provides them.
We will also disclose data where we are legally required to — a valid court order, for example — or where it is necessary to investigate abuse or protect someone's safety. We will tell you if that happens unless we are prohibited from doing so.
We do not sell personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under California law.
5. Payments and subscriptions
Subscriptions are purchased through the App Store or Google Play. We never see your card number, bank details or billing address. The store tells us only that a purchase was verified, which plan it was, and when it expires, so that we can unlock the right features. Manage or cancel a subscription in your App Store or Google Play account settings.
6. Advertising
Advertising is limited to an optional rewarded format: you choose to watch a short video in exchange for something in the app. We do not show banner or interstitial advertisements, and no advertisement blocks or interrupts core functionality.
- iOS: we ask for permission through Apple's App Tracking Transparency prompt. If you decline, ads still work, but they are non-personalised.
- EU/UK: we present a Google-certified consent form before serving personalised ads, and you can reopen it from the app's settings.
- You can reset or limit your advertising identifier in your device settings at any time.
7. Children
Pokicar is not directed at children under 13 (or under 14 in Spain, and up to 16 in some other EU countries, where a higher age applies), and we do not knowingly collect their personal data. If you believe a child has given us personal data, write to [email protected] and we will delete the account and its data promptly.
8. How long we keep it
- Account data: for as long as your account exists.
- After you delete your account: your profile, generated state, uploaded photos and content are deleted from our live systems immediately and automatically. Encrypted backups are overwritten on a rolling cycle of no more than 30 days.
- Diagnostic and crash data: retained in aggregated or truncated form for up to 14 months.
- Records we must keep by law (for example, transaction records for tax): retained for the period the law requires, and no longer.
9. Deleting your account
You can delete your account and all its data from inside the app, without emailing anyone and without visiting a website: open Settings → Delete account and confirm.
This is immediate and cannot be undone. It removes your profile, your generated state, everything you have captured or posted, and your uploaded photos. A subscription bought through a store is not cancelled by deleting your account — cancel it in your App Store or Google Play account, or it will keep renewing.
If you cannot reach the in-app option — because you have already uninstalled the app, lost the device, or cannot sign in — use the web route at https://dexlin.app/delete-account/, which explains exactly what is erased and what we are obliged to keep, or email [email protected] from your registered address. Either way we will action it within 30 days.
10. Your rights
Depending on where you live, you have some or all of the following rights. All of them are free to exercise, and we will respond within 30 days.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of anything inaccurate. Most of it is editable in the app.
- Erasure — deletion, as described in §9.
- Restriction and objection — including the right to object to processing based on legitimate interests.
- Portability — your data in a structured, machine-readable format.
- Withdraw consent — at any time, without affecting prior processing.
- No discrimination — we will not degrade your service for exercising any of these rights.
To exercise any of them, email [email protected]. We may need to confirm you control the account before we act.
EU and UK users may complain to a supervisory authority. Ours is the Spanish data protection agency, the Agencia Española de Protección de Datos (aepd.es) — and you may also complain to the authority where you live. We would rather you came to us first so we can put it right.
California users have the rights above under the CCPA/CPRA, and may designate an authorised agent to act for them. As stated in §4, we do not sell or share personal information.
11. International transfers
We are based in Spain, inside the EEA, so most processing stays within it. Some of our providers process data in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision — including the EU–US Data Privacy Framework — where one applies.
12. Security
Passwords are hashed by Firebase Authentication and never stored in readable form by us. Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to those who need it.
Security rules enforce, at the database level, that account state such as subscription status, allowances and scores can be written only by our server-side code — never by an app on a device, and never by another user. This is verified by an automated test suite that runs against the rules themselves.
No system is perfectly secure. If a breach affects your rights, we will notify you and the relevant regulator within the time limits the law sets (72 hours to the regulator, under the GDPR).
13. Changes to this policy
We will post any change here and update the date at the top. If a change materially affects your rights, we will tell you in the app or by email before it takes effect.
14. Contact
Questions, requests or complaints:
[email protected] Dexlin, Av. del Mediterráneo, Loc 4, 29670 Marbella, Málaga, Spain
Dexlin — this policy is provided in plain English on purpose. If anything here is unclear, ask us and we will explain it.