Skip to content
Carlore
  • Features
  • Pricing
  • Manual
  • Support
Legal documents
  1. Privacy Policy
  2. Terms of Service
  3. Subscription Terms
  4. Refund Policy
  5. Affiliate Disclosure
  6. Acceptable Use Policy
  7. Accessibility Statement
  8. Security and Vulnerability Disclosure
  9. Open-Source Licenses
  10. Cookie Statement
  11. Data Processing Summary
  12. Account Deletion
  13. Contact and Legal Details

All documents and earlier versions

LegalSecurity and Vulnerability Disclosure

Security and Vulnerability Disclosure

Version 2026-10-02 · Effective October 2, 2026

How we protect Carlore and your data, and how to report a security vulnerability to us safely.

Contents

  1. The short version
  2. 1. How we protect your data
  3. 2. Reporting a vulnerability
  4. 3. Scope
  5. 4. Rules of engagement
  6. 5. Safe harbor
  7. 6. What to expect from us
  8. 7. If you think your account is at risk
  9. 8. security.txt

The short version

  • Your garage is encrypted on your phone and never reaches our servers.
  • Found a security problem? Email security@carlore.app. We'll acknowledge it within three business days.
  • If you research in good faith and follow this policy, we won't take legal action against you.

1. How we protect your data

Your garage

  • Your garage lives on your phone, protected by the operating system's file encryption, with an optional Face ID or biometric app lock. Carlore offers the lock when you scan your first paper.
  • Before it's copied to your iCloud Drive or Google Drive, it's encrypted on your phone with AES-256-GCM, using a random 256-bit garage key. Each file is authenticated and bound to its name, so it can't be swapped or altered without detection. The only file stored unencrypted is a small manifest holding the garage's technical details and its wrapped keys, never your content.
  • The garage key never reaches us. On iPhone with iCloud Drive, it's kept in iCloud Keychain, which Apple end-to-end encrypts. With Google Drive, it's wrapped with a key derived from your passphrase using PBKDF2-HMAC-SHA256 at 600,000 iterations. Every garage also has a recovery code with 160 bits of randomness.
  • For backup and sync, Carlore asks Google only for access to its own hidden app folder in your Drive, and that access stays on your phone. Household sharing uses a separate encrypted file you choose with the system file picker, with access limited to that file. Our servers receive neither the file nor its passphrase.
  • Restores are staged and checked file by file before anything on your phone changes.
  • Carlore keeps your garage out of your phone's own backups: iCloud Backup and computer backups on iPhone, and Google's device backup on Android.
  • Paper numbers and costs are Owner only by default, and a privacy review shows exactly what a handover package or borrower guide will include before it's made. Anything marked Owner only is never included.
  • The Glovebox works offline. If you add its lock-screen widget or shortcut, only the details you marked "Show in Glovebox" are shown there without unlocking.

Lookups

  • VIN decoding and recall checks go from your phone directly to NHTSA over HTTPS, only when you ask for them. Manual lookup goes from your phone directly to manufacturers' sites over HTTPS, sends only the year, make and model, and runs only if you said yes. None of these pass through our servers.

Accounts and servers

  • An account created with an email and password can't be used until its email address is verified, and signing in with Apple or Google joins an existing account automatically only when both have the same verified email address.
  • Passwords are stored as salted scrypt hashes. Access tokens last 30 minutes; refresh tokens are stored as hashes, rotated on every use, and reusing an old one revokes every session.
  • Sign in with Apple and Google sign-in use single-use nonces, and identity tokens are verified against Apple's and Google's published keys.
  • Purchases are verified with Apple and Google on our servers.
  • Our API and website run on Cloudflare, with HTTPS enforced (HSTS), strict security headers and rate limits. Data is encrypted at rest, and especially sensitive tokens are encrypted again with our own key.
  • Diagnostics carry no account details and are scrubbed of identifying details, such as email addresses and long numbers, before they're stored. Our servers' own logs contain no IP addresses or request headers, and are kept for 7 days. Cloudflare's invocation logs for our servers and its email message previews are turned off.
  • The admin console sits behind Cloudflare Access and requires separate staff accounts with roles, lockouts after failed sign-ins and an audit log. Staff can never see your garage.
  • The apps include no third-party analytics, advertising or tracking code.

2. Reporting a vulnerability

Email security@carlore.app. Please include:

  • a description of the issue and where it is;
  • the steps to reproduce it, with any proof-of-concept code, requests or screenshots;
  • what you think the impact is; and
  • how you'd like to be credited, if at all.

Please keep the details confidential until we've fixed the issue (see section 5), and don't include anyone else's personal information in your report beyond what's necessary to show the problem. Reports in English are preferred.

3. Scope

In scope:

  • the Carlore app for iPhone, latest version from the App Store;
  • the Carlore app for Android, latest version from Google Play;
  • api.carlore.app;
  • carlore.app; and
  • the garage encryption, backup and sync design, and the privacy review for handover packages and borrower guides, as implemented in the apps.

Out of scope for testing without our written permission:

  • the admin console (admin.carlore.app) and its sign-in pages. If you notice a problem there, please report it, but don't test it;
  • staging and test environments;
  • Cloudflare, Apple, Google, NHTSA, manufacturers' websites and other third-party services, including iCloud Drive and Google Drive. Please report issues in them to those providers.

Not accepted as vulnerabilities:

  • denial-of-service or load testing, spam, social engineering, phishing, or physical attacks;
  • reports from automated scanners without a demonstrated, exploitable impact;
  • missing security headers, cookie flags or email authentication records (SPF, DKIM, DMARC) without a demonstrated exploit;
  • clickjacking on pages without sensitive actions, self-XSS, and CSV injection without a demonstrated impact;
  • software version disclosure, or descriptive error messages without sensitive data;
  • rate-limit observations without a demonstrated impact;
  • attacks that need a jailbroken or rooted device, physical access to an unlocked phone, or an already compromised Apple, Google or email account;
  • the details someone chose to show in the Glovebox being visible on their lock screen. That's how the Glovebox is designed to work; and
  • a handover package, borrower guide, paper copy or export being readable by whoever it was sent to. They're files the owner sends on purpose.

4. Rules of engagement

  • Only test with accounts and data you own. You can create a few test accounts by hand; don't create accounts automatically.
  • Don't access, change, delete or keep other people's data. If you come across it, stop, don't share it, and tell us.
  • Don't degrade the Service for others. Keep automated requests to no more than five per second, and stop if you notice any impact.
  • Don't send automated or excessive requests to NHTSA or manufacturers' sites through Carlore.
  • Don't try to guess, enumerate or brute-force codes or accounts; demonstrate issues with your own.
  • Don't use social engineering, phishing or physical access.
  • Give us reasonable time to fix an issue before you disclose it.
  • Follow the law. Don't ask for payment in exchange for not disclosing a problem.

5. Safe harbor

If you make a good-faith effort to follow this policy while researching and reporting a vulnerability:

  • we consider your research authorized, and we won't pursue or support legal action against you, or report you to law enforcement, for it;
  • we waive the parts of our Terms of Service and Acceptable Use Policy that would otherwise restrict your research (such as the restrictions on reverse engineering), to the extent needed for research within this policy; and
  • if a third party takes legal action against you for research that followed this policy, we'll make it known that you acted in line with it.

This safe harbor doesn't bind third parties such as Apple, Google, Cloudflare, NHTSA or manufacturers. If you're unsure whether something is allowed, ask us first at security@carlore.app.

We ask that you give us 90 days, or until the issue is fixed if that's sooner, before you publish details. We're happy to coordinate disclosure with you.

6. What to expect from us

  • We'll acknowledge your report within three business days.
  • We'll give you an initial assessment within ten business days, and keep you updated at least every 14 days until the issue is resolved.
  • We aim to fix critical issues within 7 days, high-severity issues within 30 days, and others within 90 days.
  • We'll tell you when the issue is fixed and, with your permission, thank you by name in our release notes or on this page.

We don't currently run a paid bug bounty.

7. If you think your account is at risk

Change your password, sign out everywhere from your signed-in devices in Settings, then tell us at support@carlore.app. If you think someone knows your passphrase or recovery code, change the passphrase or create a new recovery code in Settings › Sync & backup. We will never ask for your password, passphrase or recovery code.

8. security.txt

Our contact details for security researchers are also published at carlore.app/.well-known/security.txt.

Carlore

Every car’s story, kept.

The owner’s manual and record vault for every vehicle you own, on iPhone and Android. No ads. No tracking. Ever.

Carlore

  • Features
  • Privacy by design
  • Pricing
  • User manual
  • Support

Legal

  • Privacy Policy
  • Terms of Service
  • Subscription Terms
  • Refund Policy
  • Affiliate Disclosure
  • Cookie Statement
  • Security
  • Delete your account
  • All legal documents

Contact

  • support@carlore.app
  • privacy@carlore.app
  • security@carlore.app
  • hello@carlore.app

© 2026 Carlore

This site sets no cookies of its own.