The short version
- Journal entries you create stay in the app's storage on your device. There is no RangeLendger account and no RangeLendger server that receives them.
- This website has no analytics, no advertising pixels, no cookies set by us and no third-party scripts or fonts.
- Personal and vehicle data is never sold, rented or shared for advertising.
- Any connection to a vehicle manufacturer's API is optional, authorised by you in the manufacturer's own sign-in screen, and revocable there.
- RangeLendger is an independent personal project. It is not affiliated with, endorsed by or sponsored by Tesla, Inc. or any other vehicle manufacturer.
1. Scope
This policy describes how personal information is handled by the RangeLendger website at rangelendger.org and by the RangeLendger iOS app (together, "RangeLendger"). RangeLendger is maintained by an individual developer as a personal, non-commercial project, referred to below as "we" or "the developer".
The iOS app is currently in private development and is not distributed publicly. If distribution ever changes, this policy will be updated before the app is made available and the "last updated" date above will change.
2. Data the app stores
RangeLendger exists to record information you choose to type in. Depending on the entry, that can include:
- Charging entries — date and time, start and end state of charge, energy added, cost, charging network or connector type, and a place name you enter.
- Trip entries — date, distance, duration, origin and destination as you describe them, temperature or weather notes, and energy used.
- Service and maintenance entries — date, odometer reading, work performed, cost, and free-text notes.
- Vehicle details — a nickname, model year and other reference values you enter to make calculations useful.
This information is written to the app's local database on your device. It is not transmitted to the developer, and there is no RangeLendger server, account system or cloud sync service that receives it. The developer cannot read your entries.
Location entries are text you type, such as a charger name. The app is not designed to collect continuous background location, and it does not build a movement history beyond the entries you deliberately create.
3. Data this website collects
This site is a set of static files. It does not use analytics, advertising pixels, tag managers, session recording, third-party fonts, embedded videos or social widgets. It does not set cookies, and it has no sign-in, comment form or newsletter.
The site is hosted on GitHub Pages. Like any web host, GitHub processes standard technical request data — such as IP address, browser user-agent, referring page and the URL requested — in order to deliver pages and protect the service against abuse. That processing is governed by GitHub's own privacy practices and is outside the developer's control. The developer does not receive per-visitor reports or visitor-level logs from GitHub Pages.
4. Optional vehicle manufacturer connections
RangeLendger is a manual journal and works without any connection to a vehicle. A future version may offer an optional connection to an official manufacturer owner API so that a reading such as odometer or state of charge can be filled in for you instead of typed.
If such a connection is ever offered, it will work as follows:
- It is opt-in. Nothing connects unless you start the process yourself.
- You sign in on the manufacturer's own authorisation screen. The app never sees or stores your manufacturer account password.
- You approve a specific, limited set of scopes, and the app requests no more than it needs to fill in journal fields.
- Access tokens are stored in the device keychain on your phone. They are not transmitted to the developer, because there is no developer-operated server to transmit them to.
- You can revoke access at any time in the manufacturer's own account settings, and disconnecting in the app deletes the stored tokens from your device.
- Data retrieved this way is stored the same way as anything you type: locally, on your device.
The page at /oauth/callback on this site is the registered redirect target for that future authorisation flow. It is a static page: it reports whether an authorisation succeeded or failed, and it stores nothing, logs nothing and holds no client secrets.
5. What is never done
- Personal information and vehicle data are never sold, rented or traded. The developer does not sell or share personal information as those terms are used in California privacy law, and has never done so.
- No advertising profiles are built, and there is no advertising in the app or on this site.
- No cross-app or cross-site tracking, and no identifiers are shared with data brokers or ad networks.
- Vehicle location, charge state or journal contents are not shared with third parties for their own purposes.
- Your entries are not used to train models or to compile aggregate datasets for anyone else.
6. Backups and device sync
Because your journal lives in the app's storage on your device, it is included in the device backups you already use — for example an encrypted local backup or an iCloud backup, depending on your own iOS settings. Those backups are handled by Apple under Apple's terms and privacy policy, not by the developer. You control whether the app is included in a backup through the usual iOS settings.
7. Retention and deletion
Because the developer never receives your journal, there is nothing on the developer's side to retain or delete. You control retention entirely:
- Delete an individual entry in the app to remove it from the local database.
- Delete the app from your device to remove its local database along with it.
- Remove any linked manufacturer authorisation in the manufacturer's account settings, and disconnect in the app to clear stored tokens.
- Remember that a device backup made earlier may still contain data until that backup is deleted or replaced.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, delete or restrict the use of your personal information, and to object to certain processing. RangeLendger is designed so that you can exercise those rights directly: the data is on your device, under your control, and you can view, edit, export or erase it without asking anyone's permission.
Where a right would normally be exercised through a request to a company, the practical answer here is that the developer holds no copy of your journal to produce, correct or delete. If you have a question about that, use the contact details below.
9. Children
RangeLendger is intended for adult vehicle owners. It is not directed to children, is not marketed to children, and does not knowingly collect personal information from children.
10. Security
The main security property of this design is that there is very little to attack: no accounts, no server-side database, no synchronisation endpoint and no credentials held by the developer. Your journal is protected by the operating system's app sandbox and by the device passcode, Face ID or Touch ID protections you have enabled.
This website is served over HTTPS. No system is perfectly secure, and no absolute guarantee of security can be given, but no personal data is deliberately collected here that could be exposed.
11. Changes to this policy
This policy may be updated if the app gains capabilities that change how data is handled — for example, if an optional manufacturer connection ships. Material changes will be reflected on this page with a new "last updated" date, and the previous behaviour will not be applied retroactively to data already on your device.
12. Contact
Questions about this policy, or about how RangeLendger handles data, can be sent to privacy@rangelendger.org.
RangeLendger is an independent personal project. It is not affiliated with, endorsed by or sponsored by Tesla, Inc. or any other vehicle manufacturer. See the terms for more detail.