Privacy Policy
Privacy Policy
Effective date: 2026-05-13
Last updated: 2026-07-13
Version: 1.1.2
TuneView is a product of LambdaWorx LLC. This policy explains what data we collect, how we use it, and what rights you have. We've written it in plain English on purpose — no legal maze.
Contact us any time: [email protected]
1. Who This Applies To
This policy covers everyone who uses TuneView: tuners (calibrators), review participants, and any organization (like a shop or team) that accesses TuneView through our platform or API.
2. What We Collect
2.1 Account Data
When you create an account we collect:
- Email address
- Display name
- Role (e.g., tuner, reviewer, org admin)
- Organization name and affiliation (if provided)
- Password hash (we never store plaintext passwords)
We use this to authenticate you, route work to the right people, and contact you about your account.
2.2 Uploaded Artifacts
When you upload content to TuneView we collect:
- Tune files — calibration files (e.g., .hpt, .e2s, vendor-specific formats)
- Datalogs — vehicle data logs associated with a tune or review
- Vehicle metadata — year, make, model, engine, platform
- Submission context — notes, mileage, modifications, review request details you attach
You own your files. Uploading does not transfer ownership. You grant LambdaWorx a license to store and process your uploaded artifacts for the purposes described in this policy. If we later decide to incorporate user uploads into AIE training, we will update this policy and give notice before doing so (see §4).
2.3 Review and Verdict Data
When a tune is reviewed on TuneView, we collect:
- Review requests and metadata
- Reviewer comments and annotations
- Review verdicts and ratings (pass/flag/fail, issue categories)
- Revision history and re-review outcomes
2.4 Usage and Log Data
We automatically collect:
- IP address and approximate location
- Browser type, OS, device
- Pages visited, features used, timestamps
- Error logs and crash reports
- API request logs (for API users)
2.5 Cookies and Analytics
We use:
- Session cookies — required for login and security
- Functional cookies — remember your preferences
- Analytics — first-party or privacy-respecting analytics to understand how the product is used (no behavioral ad tracking)
You can disable non-essential cookies in your browser. Session cookies are required for the service to work.
2.6 Mobile App Data
When you use the TuneView mobile app (iOS or Android) we additionally collect:
- Platform type (iOS or Android) — used to route push notifications to the correct service and to deliver platform-appropriate UI.
- Push notification token — an opaque device identifier issued by the OS (via Expo) so we can send you notifications about reviews, verdicts, and account activity. You can disable push notifications at any time in your device settings; doing so does not affect your TuneView account.
We do not collect contacts, photos, microphone, precise location, or any data outside the permissions the app explicitly requests.
3. How We Use Your Data
| Purpose | Data Used |
|---|---|
| Provide the TuneView service | All data in §2 |
| Authenticate and authorize users | Account data |
| Facilitate reviews and feedback | Uploaded artifacts, review data |
| Improve TuneView product features | Uploaded artifacts, review data, verdicts (used to diagnose bugs, improve UX, and inform feature priorities — not currently used to train AIE models, see §4) |
| Send transactional emails | Email address |
| Debug and fix issues | Log data, error reports |
| Comply with legal obligations | Any data as required |
We do not sell your data. We do not use your data for behavioral advertising.
4. The Active Intelligence Engine (AIE) — How Your Data Is Used for Training
The AIE is TuneView's AI system that learns from real-world tune and datalog data to improve platform intelligence — things like automated diagnostic signals, review assist features, and anomaly detection.
What gets used for AIE training:
- Uploaded tune files and datalogs
- Vehicle metadata associated with uploads
- Review verdicts and reviewer annotations
- Aggregate review outcomes
How we handle it:
- User-uploaded tune files and datalogs are stored securely with per-user access controls. Currently, user-uploaded data is not used to train AIE models — the AIE is trained on public knowledge sources (technical forums, documentation). If and when we incorporate user uploads into training, we will update this policy in advance.
5. Data Retention
| Data Type | Retention |
|---|---|
| Account data | Until account deletion + 90-day grace period |
| Uploaded tune files and datalogs | 2 years from last access, then deleted |
| Vehicle metadata | Same as uploaded artifacts |
| Review and verdict data | 2 years from review completion |
| Log and analytics data | 90 days rolling |
| Backups | 30 days |
| Push notification tokens | Until the app is uninstalled, the token is invalidated by the OS, or you delete your account |
When you delete your account, we delete your account data and uploaded artifacts.
6. Sharing and Subprocessors
We do not sell your data or share it with third parties for advertising. We use the following subprocessors to operate TuneView:
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel | Application hosting and edge delivery | USA |
| Supabase | Database and file storage for tune files and datalogs | USA |
| Anthropic | AI model inference for AIE features | USA |
| Resend | Transactional and notification emails | USA |
| Expo | Push notification token issuance and delivery routing for the mobile app | USA |
| Apple Push Notification service (APNs) | Push notification delivery to iOS devices | USA |
| Firebase Cloud Messaging (FCM) | Push notification delivery to Android devices | USA |
We will update this list when subprocessors change. If a subprocessor operates outside the USA we will call that out explicitly.
7. Security
Here is what we actually do — no puffery:
- Passwords are hashed (bcrypt or equivalent). We never store or transmit plaintext passwords.
- Data in transit is encrypted with TLS.
- Data at rest is encrypted at the storage layer.
- Access to production data is restricted to LambdaWorx engineers with a documented need.
- We do not have SOC 2 certification yet. We are a small team operating responsibly, not a certified enterprise.
- We will notify affected users promptly in the event of a data breach involving personal data.
8. Your Rights
You have the right to:
- Access your data — email [email protected] and we will export your account data and uploaded files within 30 days.
- Delete your account — from settings or by emailing us. We will delete your personal data and uploaded artifacts per the retention schedule in §5.
- Correct inaccurate account data — update it in settings or contact us.
- Port your data — we will export your tune files, datalogs, and review history in their original formats on request.
- Objectto specific uses — if you have a concern about how we're using your data, contact us. We will respond within 10 business days.
For California residents (CCPA): we do not sell personal information. You have the right to know, delete, and opt-out of sale (there is no sale to opt out of). Contact [email protected].
For EEA/UK residents (GDPR): our lawful basis for processing is legitimate interests (providing and improving the service) and contract performance. We are not currently established in the EEA; if you are in the EEA and have a concern, contact us and we will engage in good faith.
9. Children
TuneView is not intended for users under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact [email protected].
10. Changes to This Policy
When we make material changes, we will:
- Post the updated policy at tuneview.io/privacy
- Update the "Last updated" date at the top
- Notify users by email for changes that significantly affect their rights
Continued use of TuneView after changes take effect constitutes acceptance of the updated policy.
11. Contact
LambdaWorx LLC
Privacy contact: [email protected]
If you have a question, concern, or request related to this policy, email us. We respond to all privacy inquiries.