Cookie Statement
carlore.app sets no cookies of its own and uses no analytics; this statement explains the strictly necessary security checks our hosting provider may run.
The short version
- carlore.app sets no cookies of its own, stores nothing in your browser, and has no analytics, no ads and no tracking.
- Cloudflare, which delivers and protects our site, may set a strictly necessary security cookie if it needs to check for automated traffic.
- Our admin console, which isn't public, uses Cloudflare Access session cookies for our team.
- Because none of this is used to track you, we don't show a cookie banner.
1. Our website
Our website, carlore.app, includes our home page, the user manual, our legal pages, support, the account deletion page, and the pages that finish an email verification or a password reset. It hosts nothing you make in Carlore. It:
- sets no cookies of its own, and doesn't use your browser's local storage or similar technologies;
- doesn't use analytics, advertising, social media or other third-party tracking scripts; and
- serves its fonts, images and scripts itself, so opening our pages doesn't contact other companies' servers.
The verification and password reset links carry their code after the "#", which browsers don't send to servers. The pages send it to our servers only when you confirm, then clear it from the address bar, and keep nothing in your browser.
2. Security cookies set by Cloudflare
Our site is delivered and protected by Cloudflare. If traffic looks automated, or during an attack, Cloudflare may ask your browser to pass a quick check. If it does, it sets a strictly necessary cookie called cf_clearance, which remembers that your browser passed, so you aren't asked again straight away. It usually lasts 30 minutes. If we turn on more of Cloudflare's bot protection, Cloudflare may also set similar short-lived security cookies, such as __cf_bm, which helps tell people from bots and expires after 30 minutes.
These cookies are used only for security. They aren't used to track you across websites or for advertising. See Cloudflare's cookie policy for details.
3. The admin console
Our admin console, at admin.carlore.app, is used only by the Carlore team. It's protected by Cloudflare Access, which sets session cookies (such as CF_Authorization) after an authorized team member signs in. It isn't open to the public, and these cookies are never set when you visit carlore.app.
4. The apps
The Carlore apps don't use cookies to track you, and contain no third-party analytics, advertising or tracking software. Their connections to our servers don't use cookies. Their lookups at NHTSA and manufacturers' sites go straight from your phone to those sites, under their own policies.
- When you open a link from the app, such as a recall on nhtsa.gov or a manual in its publisher's viewer, it opens in your browser, where that site may set its own cookies under its own policy.
- When you sign in with Google on iPhone, or connect Google Drive, Google's sign-in page opens in a secure browser window, where Google may use its own cookies (for example, to remember that you're already signed in to Google) under Google's privacy policy. We don't receive those cookies.
5. Your choices
Because the only cookies on carlore.app are strictly necessary for security, we don't show a cookie banner. You can block or delete cookies in your browser's settings at any time. If you block Cloudflare's security cookies, you may see extra checks.
Our website works the same whether or not your browser sends a "Do Not Track" or Global Privacy Control signal, because it doesn't track you either way. Our Privacy Policy explains how we treat these signals.
6. Changes and contact
If we ever change how cookies are used on carlore.app, we'll update this statement first, and ask for your consent where the law requires it. Questions: privacy@carlore.app. Our Privacy Policy has more about how we handle personal information.