BimmerInspect privacy notice
Privacy Policy
This policy explains how BimmerInspect handles vehicle diagnostic data, app telemetry, crash reporting, purchases, security checks, and information stored on your device.
1. Summary
BimmerInspect is a vehicle inspection application. It connects to a compatible BMW diagnostic adapter, reads information from vehicle control units, sends inspection data to BimmerInspect servers when needed to identify the vehicle and build a report, and stores report information locally so you can review it in the app.
No advertising business
We do not sell personal data, use advertising SDKs, or build advertising profiles from your vehicle data.
Vehicle data is central
A VIN, ECU information, mileage, diagnostic measurements, and fault codes may be processed to create inspection reports.
Optional sharing controls
App improvement analytics, diagnostic insights, and normalized vehicle statistics are three independent choices. Each is optional and off by default.
Important: a vehicle identification number (VIN), diagnostic trouble codes, mileage, and other vehicle data can be personal data in some jurisdictions when linked to you, your device, or your vehicle. We treat that data carefully and use it only for the purposes described in this policy.
2. Scope
This policy applies to the BimmerInspect mobile app, BimmerInspect vehicle inspection and report services, AI-assisted report summaries, report delivery services, purchase unlock flows, support communications, crash reporting, optional analytics, diagnostic insight sharing, optional normalized vehicle statistics, and this privacy page.
This policy does not replace the privacy policies of Apple, Google, Firebase, Cloudflare, payment processors, your mobile operating system, your vehicle manufacturer, your diagnostic adapter manufacturer, or your network provider. Those services may process information independently under their own terms when you use their platforms.
BimmerInspect does not require you to create a conventional account with a name, email address, or password. The app instead uses a device-bound security identity and pseudonymous installation identifiers to protect backend access, recover sessions, validate purchases, and improve reliability.
3. Data We Collect
The data collected depends on how you use the app, what adapter you connect, what vehicle information is available from the vehicle, which reports you create, which purchases you make, and which optional sharing settings you enable.
| Category | Examples | Purpose | Typical Location |
|---|---|---|---|
| Vehicle identity | VIN, platform code, ECU addresses, ECU variant identifiers, vehicle characteristics, engine cylinder count, displayed mileage. | Identify the vehicle, request the correct diagnostic bundle, run supported checks, and build an inspection report. | Device, BimmerInspect backend, encrypted bundle/report caches. |
| Inspection measurements | Signal codes, decoded values, ECU addresses, measurement timestamps, diagnostic trouble codes, fault status, fault mileage, fault timestamps, snapshot history. | Generate report findings, explain vehicle condition, and preserve report history. | Device and BimmerInspect backend when you run an inspection. |
| AI-assisted report summaries | Selected report findings and structured vehicle-condition evidence. Model input excludes VIN, report ID, and account, device, installation, adapter, payment, session, or diagnostic-upload identifiers, as well as raw vehicle communications. | Draft an English, German, or Russian summary for the inspection report you request. This is required report-service processing, not optional analytics. | BimmerInspect backend and Google Cloud's Gemini service in the United States multi-region. |
| Adapter and network data | Bluetooth device name or identifier, MAC address where exposed by the platform, RSSI, pairing state, Wi-Fi SSID/BSSID, local IP address, adapter IP and port, DoIP discovery responses. | Find, connect to, and maintain communication with diagnostic adapters. | Mostly on device; limited diagnostic metadata may be included in optional diagnostic insights. |
| Device and security data | Hashed installation ID, platform, app version, device public key, attestation evidence, signed challenges, access tokens, refresh tokens, session secret, IP address in server logs. | Protect backend APIs, prevent abuse, keep sessions secure, and diagnose service problems. | Device secure storage, BimmerInspect backend, security providers. |
| Optional app improvement analytics | Limited app-use and performance information, such as screen and feature use, app and platform version, connection and report outcomes, consent state, and broad vehicle details including connection type, vehicle platform, engine or fuel type, mileage range, and control-unit count. | Understand which parts of the app work well, find product friction, and prioritize app fixes when you enable this setting. | Firebase Analytics when app improvement analytics is enabled. |
| Optional diagnostic insights | Automotive and diagnostic-communication information, such as app and diagnostic version, connection type, vehicle configuration, engine, fuel and transmission type, exact displayed mileage, control-unit information, diagnostic readings, communication errors, response timing, and limited samples of communication between the app and vehicle. | Improve diagnostic accuracy, investigate vehicle and control-unit compatibility, and support more vehicle models when you enable this setting. | Device during collection, then BimmerInspect backend and Google Cloud Firestore when diagnostic insights are enabled. |
| Optional normalized vehicle statistics | Selected vehicle information, such as vehicle configuration, exact mileage, exact inspection date and time, diagnostic measurements, control-unit types, and fault codes. | Research aggregate platform and generation reliability, mileage at first observation, and fault-code prevalence when you enable this setting. | BimmerInspect backend and Google Cloud Firestore when vehicle statistics are enabled. |
| Essential reliability and security diagnostics | Redacted crash reports, redacted stack traces and error messages, support code, startup attempt ID, request ID, failure category, platform, app version, package name, runtime environment, backend host, hashed installation ID, last screen, connection state, transport type, consent state, server request metadata, IP address in server logs, and redacted operational log entries. Diagnostic crash context is only attached when diagnostic insights are enabled. | Detect crashes, understand startup and server-reachability failures, protect the service, prevent abuse, diagnose backend failures, and keep core app functions reliable. | Firebase Crashlytics, BimmerInspect backend, and infrastructure logs where needed for reliability, security, and operation. |
| Purchase data | Report ID, product ID, platform, purchase token or receipt verification data, store response containing the device-bound purchase binding, entitlement state, paid or refunded timestamp. | Verify payment and the store-confirmed device binding, unlock paid reports, prevent duplicate or fraudulent unlocks, and process refunds. | Device, Apple or Google, BimmerInspect backend. |
| Support communications | Sender email address and the message and attachments you choose to send. | Provide support, handle privacy requests, investigate compatibility, and locate reports or purchases when needed. | BimmerInspect and its email provider. |
Data we do not intentionally collect
Outside support communications that you initiate, BimmerInspect does not intentionally collect your name, email address, phone number, postal address, payment card number, contacts, photos, camera data, microphone data, calendar data, advertising ID, or precise GPS location. A support email may contain the sender address and any information or attachments you choose to include.
4. Vehicle and Inspection Data
To perform a meaningful inspection, BimmerInspect needs to read diagnostic information from the vehicle. Depending on the vehicle, adapter, and inspection flow, the app may collect and process the following information.
- Vehicle identification data
- VIN, platform code, ECU list, ECU diagnostic addresses, ECU variant identifiers, vehicle characteristics exposed by the diagnostic bundle, engine cylinder count, and displayed mileage.
- Inspection session data
- Inspection start and end timestamps, app version, diagnostic definition version, capability execution status, skipped capability reasons, and the list of ECUs scanned for diagnostic trouble codes.
- Measurements and findings input
- ECU address, signal code, decoded value, capture timestamp, diagnostic trouble code, fault status, fault mileage, fault date/time, occurrence count, healing counter, and snapshot history where available.
When you identify a vehicle, the app may send the VIN, ECU references, and platform code to BimmerInspect servers to receive the correct encrypted diagnostic bundle. When you run an inspection and do not cancel it, the app sends an inspection request so the backend can build the report.
The inspection request body is encrypted by the app before it is sent. The request envelope still includes the VIN and inspection start timestamp in plaintext so the backend can authenticate, route, and decrypt the request correctly. All network communication is sent over HTTPS.
The backend stores Firestore report records that include VIN, pseudonymous device and session identifiers, vehicle context, report details, entitlement data, and generated summaries. Raw inspection objects stored in Google Cloud Storage are scheduled for lifecycle deletion after 30 days and may then remain recoverable through Google Cloud Storage soft delete for up to 7 additional days. Firestore report records remain until administrative pruning or verified deletion; no fixed automatic deletion period is guaranteed. This required report processing is separate from the optional vehicle-statistics dataset, which does not store VIN or account, device, adapter, payment, report, or session identifiers.
Reports may be stored locally in the app and retrieved from the backend by report ID. Full paid report details, including generated summaries, may be cached on the device in encrypted form for faster access.
To draft an AI-assisted report summary, the BimmerInspect backend sends selected report findings and structured vehicle-condition evidence to Google Cloud's Gemini service in the United States multi-region. The model input excludes VIN, report ID, account, device, installation, adapter, payment, session, and diagnostic-upload identifiers, and raw vehicle communications. Gemini drafts summaries in English, German, or Russian; the generated summary is cached with the report. This is required processing for the report service, not optional analytics, and does not mean that all report content is sent to the model.
5. Adapter and Network Data
BimmerInspect supports Bluetooth, BLE, Wi-Fi, and Ethernet/DoIP diagnostic adapters. To discover and connect to those adapters, the app may process adapter and local network information.
- Bluetooth and BLE: device name, platform device identifier, MAC address where available, RSSI, pairing state, scan status, and connection status.
- Wi-Fi adapters: current SSID, BSSID, local IP address, adapter IP address, adapter port, and connectivity state.
- Ethernet and DoIP: local network discovery responses, IP address, port, adapter identifiers, and vehicle discovery details if included by the response.
Android and iOS may require Bluetooth, local network, Wi-Fi, or location-related permissions for these adapter functions. BimmerInspect uses those permissions to connect to diagnostic hardware and detect the adapter network. The app does not use these permissions for advertising, continuous location tracking, or background GPS tracking.
6. Telemetry and Diagnostics
BimmerInspect provides three independent optional controls: app improvement analytics, diagnostic insights, and normalized vehicle statistics. All three are off by default, and you can change each choice separately in the app settings. Processing needed to create a report you request, including AI-assisted summary drafting, and essential reliability and security diagnostics are separate from these optional choices and may still occur where needed to provide the report, keep the app working, diagnose failures, and protect the service.
App improvement analytics
When enabled, Firebase Analytics may collect limited information about app use and performance, such as screen and feature use, app and platform version, consent state, connection outcomes, report generation, and whether supported diagnostic checks complete successfully.
Where available, app improvement analytics may include broad vehicle details such as connection type, vehicle platform, engine or fuel type, mileage range, and control-unit count. These analytics do not include VIN, exact mileage, report content, raw vehicle communications, purchase details, Wi-Fi network names, MAC addresses, or IP addresses.
Diagnostic insights
When enabled, BimmerInspect may perform additional supported diagnostic checks after an inspection while the vehicle remains connected. The app sends the resulting information to BimmerInspect over HTTPS in an encrypted form. This processing is used to improve diagnostic accuracy, investigate vehicle and control-unit compatibility, and support more vehicles.
The information can include app and diagnostic version, time of collection, connection type, vehicle configuration, engine, fuel and transmission type, exact displayed mileage, control-unit information, diagnostic readings, communication errors, response timing, and limited samples of communication between the app and vehicle.
The diagnostic information does not contain VIN or identifiers for an account, device, app installation, adapter, payment, report, or session. Known identifying content is excluded. Diagnostic readings and communication samples can still be specific to the inspected vehicle, so this is detailed pseudonymous vehicle data rather than anonymous analytics. Disabling the setting stops future diagnostic-insights collection but does not immediately delete information already sent.
AI-assisted report summaries
AI-assisted summary drafting is part of the report service rather than an optional analytics setting. The backend sends only selected report findings and structured vehicle-condition evidence to Google Cloud Gemini, with the identifier and raw-communication exclusions described in Section 4, and caches the generated summary with the report.
Vehicle statistics
When you separately enable vehicle statistics, BimmerInspect may create a pseudonymous record containing selected vehicle information such as vehicle configuration, exact mileage, exact inspection date and time, diagnostic measurements, control-unit types, and fault codes. The purposes are aggregate platform and generation reliability research, mileage-at-first-observation analysis, and fault-code prevalence. The dataset is not sold and is not used for advertising, cross-context tracking, or public per-car lookup.
The backend normalizes the VIN and derives a keyed HMAC-SHA-256 pseudonym. The HMAC secret remains only on the backend. If a later requested report supplies the same VIN, the backend can derive the same pseudonym and link observations for that vehicle. For this reason, the dataset is pseudonymous, not anonymous. It does not store VIN, account, device, adapter, payment, report, or session identifiers, and neither the app nor the user receives the pseudonym.
BimmerInspect backend services process this optional dataset and Google Cloud Firestore stores it. There is no public per-car access. Turning the vehicle-statistics choice off or withdrawing consent stops future statistics processing, but it does not automatically erase statistics already collected. The current dataset has no fixed automatic expiry and is retained while needed for the consented research purposes or until a valid deletion request is completed, subject only to legal and security obligations.
Essential reliability diagnostics
BimmerInspect uses a required structured operational log lane that is separate from optional Firebase Analytics and optional diagnostic insights. It is needed for app operation, startup and server-reachability checks, attestation and security handling, purchase unlock and recovery, report open, fetch, cache, and decode failures, and inspection submission failures.
These records can include human-readable fields such as event type, message, severity, timestamp, support code, startup attempt ID, client operation ID, app profile, platform, package name, version and build, backend host, request path template instead of raw URL, request ID, HTTP status or backend error code, phase, outcome, reason, duration, error type, coarse connection type, counts, and inspection, report-open, or purchase attempt IDs. App or backend records may also include hashed installation ID, telemetry or diagnostic session IDs, backend report ID, pseudonymous device ID, diagnostic upload batch ID, VIN hash, purchase-token hash, request metadata, and server IP address. These records are not used for advertising, cross-app tracking, or product analytics.
Crash reports and operational logs
BimmerInspect uses Firebase Crashlytics and internal logging for necessary reliability, security, and operational processing. This is separate from optional app improvement analytics and diagnostic insights. Crash reports may include redacted stack traces and error messages, platform, app version, hashed installation ID, last screen, connection state, transport type, and consent state. Diagnostic crash context such as adapter context, vehicle context, capability ID, ECU address, and negative response code is attached only when diagnostic insights are enabled.
Operational records do not intentionally include raw VIN, raw purchase tokens, authentication credentials, or raw diagnostic payloads. App-generated events also avoid request or response bodies, authorization headers, SSID, BSSID, MAC address, IP address, file paths, typed user input, and raw payment details. Server and infrastructure logs may contain IP address and similar metadata as ordinary server-side request information.
7. Local Storage
BimmerInspect stores information on your device so the app can work reliably, remember settings, protect sessions, show reports, and recover from temporary network failures.
- Settings: language, consent choices, unit preferences, selected adapter details, and other app preferences.
- Install and device-bound identifiers: an installation ID used in hashed form for telemetry and crash reporting, and a device-bound purchase binding derived one-way from the app's device public key for use with the app store.
- Security material: refresh tokens, session secret, and device-bound key material stored through platform secure storage such as Keychain, Secure Enclave, Android Keystore, and encrypted shared preferences where available.
- Vehicle cache: recently identified vehicle metadata and ECU variant data to speed up repeated inspections. The current implementation caps the vehicle cache at 10 vehicles, treats ECU variant data as fresh for 7 days, and can refresh vehicle characteristics when the app version changes.
- Reports: report metadata, summary snapshots, full report details where available, and user-created PDF report files.
- Offline queues: unsent operational log events, cloud log entries, and pending purchase verification records until they can be delivered or confirmed. Firebase Analytics events and diagnostic-insights batches are not stored in these persistent offline queues.
Uninstalling the app generally removes app-local data, subject to the behavior of your operating system, device backup settings, and app store purchase records. Deleting a local report in the app removes that local copy, but it may not automatically delete backend records needed for report delivery, fraud prevention, or legal compliance.
8. Purchases
Paid report unlocks are handled through Apple App Store or Google Play in-app purchase systems. BimmerInspect does not receive or store your payment card number or bank details.
During a purchase, the app supplies Apple or Google with a device-bound binding. For verification, the app sends BimmerInspect the report ID, platform, product ID, and store verification token or receipt. The backend derives the expected binding from the authenticated device identity and checks it against the store response to prevent fraud, bind the purchase to that secured identity, and recover valid unlocks. The app does not send a separate device-bound purchase identifier directly to BimmerInspect.
The app may store pending purchase verification data locally until the backend confirms the unlock. It may also store entitlement state, such as whether a report is paid or refunded, so the app can show the correct report access state.
9. How We Use Data
We use the information described in this policy for the following purposes:
- To discover and connect to diagnostic adapters.
- To identify compatible vehicle diagnostic definitions and encrypted bundles.
- To run vehicle inspections and generate inspection reports.
- To use Google Cloud Gemini to draft an English, German, or Russian summary from selected report findings and structured vehicle-condition evidence.
- To store, retrieve, cache, display, export, and unlock reports.
- To verify purchases, process entitlement state, and prevent fraud.
- To protect backend services through device attestation, signed challenges, tokens, and abuse prevention.
- To diagnose crashes, startup failures, connection failures, backend errors, and compatibility issues.
- To improve app quality and diagnostic reliability where you have enabled optional sharing.
- To research aggregate platform and generation reliability, mileage at first observation, and DTC prevalence where you have enabled optional vehicle statistics.
- To answer support and privacy requests, investigate compatibility, and locate reports or purchases when needed.
- To comply with legal, tax, accounting, security, and app store obligations.
Legal bases where required
Where laws such as the GDPR require a legal basis, we rely on performance of a service you request for inspections, reports, AI-assisted report summaries, purchases, and requested support; legitimate interests for service protection, fraud prevention, crash diagnostics, operational reliability, compatibility investigation, and efficient support; consent for optional analytics, diagnostic insight sharing, and vehicle statistics; and legal obligations for records and privacy requests we must handle.
11. Security
BimmerInspect uses technical safeguards designed for the sensitivity of vehicle diagnostics and report data.
- Network communication with BimmerInspect services uses HTTPS.
- Inspection request bodies are encrypted by the app before submission, with the VIN and inspection start timestamp left in the authenticated request envelope.
- Diagnostic bundles are delivered encrypted and decrypted using a session secret.
- Full report cache files are encrypted locally.
- Refresh tokens and session secrets are stored using platform secure storage where available.
- Device-bound key material and attestation mechanisms, including Apple App Attest and Google Play Integrity, help protect API access.
- Optional app analytics use a hashed installation ID. Diagnostic-insights batches are separately encrypted and exclude the VIN and account, device, installation, adapter, payment, report and session identifiers.
- Optional vehicle statistics use a keyed HMAC-SHA-256 pseudonym derived by the backend from normalized VIN. The secret remains backend-only, and the resulting dataset is pseudonymous rather than anonymous.
No method of transmission or storage is perfectly secure. If we learn of a security incident that affects your data, we will respond as required by applicable law.
12. Retention
We keep data only for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law. Exact retention periods can depend on app version, backend configuration, legal requirements, and the type of record.
| Data | Retention Approach |
|---|---|
| Local settings and identifiers | Generally kept until you change settings, clear app data, or uninstall the app. Platform backups may behave differently depending on your device settings. |
| Vehicle cache | Kept locally to speed up repeated inspections, with caps and freshness checks. The current implementation limits the vehicle cache to 10 vehicles and treats ECU variant data as fresh for 7 days. |
| Encrypted report cache | Kept locally for faster report access and refreshed or evicted based on cache freshness. The current default freshness period for encrypted report cache entries is 24 hours. |
| Reports and PDFs | Kept locally until deleted in the app, removed by clearing app data, or removed by uninstall behavior. Raw inspection objects in Google Cloud Storage are scheduled for lifecycle deletion after 30 days and may then remain recoverable through Google Cloud Storage soft delete for up to 7 additional days. Firestore report records, including VIN, pseudonymous device and session identifiers, vehicle context, report details, entitlement data, and generated summaries, remain until administrative pruning or verified deletion; no fixed automatic deletion period is guaranteed. |
| Optional diagnostic insights | Detailed diagnostic-insights submissions and individual observations receive an expiration time 30 days after receipt and are then deleted by the Firestore TTL process; technical deletion may occur after that expiration time. Aggregate review counters that do not contain vehicle context or communication samples may be kept longer to track diagnostic-quality improvements. |
| Offline queues | Persistent operational-log queues are capped locally to avoid unbounded storage. Current caps are 500 required structured operational log entries and 200 existing cloud log entries. Pending purchase verification records are kept until they are confirmed, superseded, or no longer needed for recovery. |
| Purchase records | Kept as needed to verify unlocks, support refunds, prevent fraud, and comply with app store, tax, accounting, and legal obligations. |
| Crash, reliability, security, and server logs | Kept for operational reliability, security, fraud prevention, and legal compliance, then deleted or anonymized when no longer needed. |
| Optional vehicle statistics | The current pseudonymous dataset has no fixed automatic expiry. It is retained while needed for the consented research purposes or until a valid deletion request is completed, subject only to legal and security obligations. Turning the setting off stops future collection but does not automatically erase existing data. |
| Support communications | Kept while needed to answer the request, investigate compatibility, locate a report or purchase, maintain support history, or meet legal and security obligations, then deleted when no longer needed. |
To request deletion of backend records associated with your reports or device, email [email protected]. We may need information such as report ID, VIN, approximate inspection date, or purchase details to locate the relevant records, and we may retain certain records where required by law or needed for fraud prevention and security.
13. Your Choices and Rights
In-app choices
- You can independently decline optional app improvement analytics, diagnostic insight sharing, and normalized vehicle statistics. All three choices are off by default.
- You can change telemetry choices in settings. Disabling a choice stops future optional collection for that choice, but it does not automatically delete data already sent.
- You can delete local reports from the app where that feature is available.
- You can remove local app data by using your operating system's app storage controls or uninstalling the app.
Deleting vehicle statistics
Turning off vehicle statistics or withdrawing consent stops future statistics processing but does not automatically erase existing statistics. To request deletion, email [email protected] and provide the VIN plus the approximate inspection date. After verifying the request, BimmerInspect will use that information to locate and delete matching pseudonymous vehicle-statistics inspection records. The app and user are never given the backend pseudonym.
Privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, objection, or withdrawal of consent. You may also have the right to complain to a data protection authority.
Residents of certain U.S. states may have additional rights to know, access, correct, delete, or opt out of certain uses of personal information. BimmerInspect does not sell personal information and does not use personal information for cross-context behavioral advertising.
We will not discriminate against you for exercising privacy rights. To exercise a right, contact us using the address below. We may need to verify your request before acting on it.
14. Children
BimmerInspect is intended for vehicle owners, technicians, and other users old enough to connect a vehicle adapter and review inspection data. It is not directed to children. We do not knowingly collect personal data from children under the age required by applicable law. If you believe a child has provided personal data to BimmerInspect, contact us so we can review and delete it where required.
15. Changes
We may update this policy as BimmerInspect evolves, including when we add features, change service providers, modify retention practices, or update legal language. When we make material changes, we will update the effective date and provide notice as required by law.
16. Contact
For privacy questions, requests, or concerns, contact:
BimmerInspect Privacy
Sergiu Stirbet (StirbitLabs)
[email protected]
When you email support, BimmerInspect and its email provider process your sender address and the message and attachments you send to provide support, handle privacy requests, investigate compatibility, and locate reports or purchases when needed. Please include enough detail for us to understand your request, such as report ID, approximate inspection date, purchase platform, or the device involved. Do not send unnecessary sensitive information, diagnostic payloads, or payment information by email unless we specifically ask for it through a secure process.