Privacy Policy
Last updated: 2026
Quick Summary
- ✓ We collect only what is needed to run tire analysis and accounts
- ✓ Tire photos may be stored to show history, PDF reports, and improve the service
- ✓ Part of pre-checks (Stage 0) runs in your browser; deep analysis runs on our servers
- ✓ We do not sell your personal data
- ✓ You can request access, correction, or deletion of your data
- ✓ Designed with GDPR and 152-FZ principles in mind
1. Information We Collect
Account information
When you register, we collect your email address, hashed password, optional display name, plan type, and scan usage counters. Passwords are stored only as bcrypt hashes, never in plain text.
Tire images
When you upload a tire photo, the image is sent to our servers for analysis. Compressed copies (for example WebP) may be saved under our uploads storage and linked to your scan record so you can view history and download PDF reports. Guest (non-registered) scans may also create a server-side record with the image path for abuse prevention, operations, and quality control.
Scan results and diagnostics
For each analysis we may store technical and diagnostic fields such as wear class, confidence scores, estimated tread depth and depth ranges, tread health index (THI), work remaining, model alignment / conflict status, bounding-box coordinates, TWI marker counts, processing time, model version, timestamps, and optional image content hash for deduplication and security.
Guest and usage data
For rate limiting and security we may store IP-derived identifiers, user-agent strings, request timestamps, and anonymous scan counters. Registered accounts also track monthly (or plan-based) scan usage.
API keys (if enabled)
If you use API access, we store API key identifiers, names, usage counts, and activity metadata needed to authenticate and limit requests.
2. How Analysis Works (Client and Server)
On-device pre-check (Stage 0)
Before a full server analysis, your browser may run a lightweight on-device model (ONNX Runtime Web) to reject non-tire images or obvious critical defects. That step processes image data locally in the browser session. Model files may be downloaded and cached by your browser like other static assets.
Server-side deep analysis
If the pre-check passes, the image is uploaded to our API. Our servers run computer-vision models (region of interest, depth estimation, wear signals, TWI indicators) and a fusion / safety layer that produces the depth range, tread life index, and related metrics shown in the product UI.
PDF diagnostic reports
Registered users may generate a PDF summary of a scan (condition, depth information, tread life, selected technical fields, and disclaimer). PDF generation can use the stored image and scan metadata. Guest users may be asked to create an account to unlock PDF download and personal history.
3. Cookies and Local Storage
We use cookies and browser storage for authentication, preferences, and legal acknowledgements:
| Name | Purpose | Duration |
|---|---|---|
| auth-token / session cookie | Signed-in session (httpOnly cookie where applicable) | Session / up to 7 days |
| theme | Dark / light preference | Up to 1 year |
| scantire-cookie-consent | Cookie banner choice | Up to 1 year |
| scantire-disclaimer-accepted | Product disclaimer / safety notice acceptance | Up to 1 year |
Your browser may also cache static assets (scripts, WASM, ONNX model files) under normal browser caching rules.
4. How We Use Your Data
- • Service delivery: run tire analysis, show results, history, and PDF reports
- • Accounts and plans: authentication, scan limits, billing-ready plan flags
- • Security and fair use: rate limits, abuse prevention, audit of anonymous and registered activity
- • Quality and model improvement: we may use scans and metadata (including images) to debug errors, calibrate outputs, and improve model accuracy; where feasible we minimise direct identifiers
- • Support: respond to privacy or product requests you send us
- • Legal compliance: retain records when required by law or to establish / defend legal claims
5. Sharing and Processors
We do not sell personal data. We may use infrastructure providers (hosting, database, email, optional payment processors) strictly to operate the service. Those providers process data under their own terms and security controls.
We do not embed third-party advertising trackers as part of the core product experience described in this policy.
6. Retention
- • Account data: kept while your account remains active and for a reasonable period afterward if needed for security or legal reasons
- • Scan images and results: kept to provide history/PDF and operations; may be deleted when you delete a scan or account, or after internal retention windows
- • Guest / IP rate-limit records: kept only as long as needed for abuse prevention (typically short rolling windows)
- • Logs: server logs may include IPs and errors for a limited operational period
7. Your Rights
Depending on your jurisdiction (including GDPR and 152-FZ concepts), you may have rights to:
- • Access a copy of personal data we hold about you
- • Rectify inaccurate data
- • Erase account and associated scans where applicable
- • Portability of machine-readable export where applicable
- • Object / restrict certain processing
- • Withdraw consent where processing is consent-based (e.g. optional emails)
Use in-app Settings / account controls where available, or email scantireai@gmail.com.
8. Security
- • HTTPS for data in transit
- • Password hashing (bcrypt)
- • Access-controlled server and database hosting
- • Session cookies designed for authenticated areas of the app
- • Operational monitoring and dependency updates on a best-effort basis
No method of transmission or storage is 100% secure. Please use a strong unique password and protect your device.
9. AI Outputs and Photos You Upload
Analysis results are automated estimates. They may be wrong or incomplete. Do not rely solely on Scan Tire AI for safety-critical decisions. See our in-app disclaimer and Terms for liability limits.
Only upload images you have the right to use. Avoid uploading photos that contain unnecessary personal data (faces, documents, license plates) when possible; if such data appears, it may be processed as part of the image file.
10. International Users and Children
The service may be hosted and operated from infrastructure that is not in your country. By using the service you understand that data may be processed in the locations of our hosting providers.
The service is not directed at children under 16 (or the minimum age required in your country). We do not knowingly collect data from children.
11. Changes and Contact
We may update this Privacy Policy as the product evolves (for example new PDF, API, or storage features). The “Last updated” year at the top will change when we publish material revisions. Continued use after an update means you accept the revised policy where permitted by law.
Privacy contact: scantireai@gmail.com
Website: https://scantire.com