Local by default
Opening the App does not upload the Garage. Vehicles, mileage, expenses, receipts and service history begin in app-private device storage.
Privacy by design
Drilore 1.1 keeps the core Garage local and does not require a personal profile. Online services receive only the information needed for the action the owner requests.
Opening the App does not upload the Garage. Vehicles, mileage, expenses, receipts and service history begin in app-private device storage.
No third-party advertising SDK, sale of Garage records, cross-app tracking or behavioural advertising profile is part of Drilore 1.1.
An online request is initiated by the owner, uses the minimum practical fields for that result and remains separate from the full Garage.
Backup, CSV export and Share Studio are deliberate actions. A preview and privacy choices belong before any future cloud or community share.
An important correction
Drilore is designed not to require profile details such as a name, birth date, contact list or advertising ID for the core Garage. That does not mean every vehicle record is automatically anonymous.
A Rego, VIN, vehicle photo, receipt, IP address or location can identify or relate to a person when combined with other information. The OAIC uses vehicle registration as an example of information whose status depends on context. Drilore therefore treats linkable vehicle data with personal-information care even when it does not ask for the owner’s name.
OAIC: what is personal information? →Current 1.1 data map
Infrastructure providers can process technical logs needed to deliver and protect a service. Exact provider, region and retention disclosures must be finalised in the formal policy before general public release.
Not required for local Garage
Your controls today
Access and correction. Current Garage data is visible and editable inside the App because it is stored on the device.
Portable backup. Export My Garage creates an encrypted Drilore file. You choose where to store it and keep the password separately. A CSV expense export is for review, not full restoration.
Deletion. Delete individual records in the App or remove the App data from the device. Copies you exported remain wherever you placed them and must be deleted there separately.
Permissions. Location is requested for a current nearby or weather action. Turning it off disables those location-dependent results without deleting the local Garage.
Analytics boundary
Version 1.1 does not continuously upload raw Garage records for product analytics. Future measurement should answer questions such as “did the fuel search return a result?” or “was backup completed?” without sending Rego, VIN, receipts, notes or exact coordinates as analytics fields.
Vehicle-level insights such as cost trends should be calculated on-device where practical. If an owner later chooses cloud analysis, the purpose, fields, region, retention and deletion path must be shown before consent.
Commerce test boundary
Closed by default. The commerce system has separate closed, test and live states. Test order and payment readiness is visible only to explicitly allowed testers, and public Checkout stays disabled until a later launch decision.
Separate transaction purpose. When Checkout is eventually enabled, Drilore Pty Ltd will need the customer details required to accept payment, deliver an order, provide support and meet accounting or consumer obligations. Those details belong to the commerce account and order — not to the local Garage.
Minimal product measurement. The commerce event schema accepts controlled event names, product or category references and coarse result counts. It does not accept Rego, VIN, receipt images, free-form Garage notes or exact vehicle location.
Owner-approved crossing. A completed order can create a pending receipt, warranty, service or replacement-reminder write-back. It does not enter a Garage until the owner approves the action.
Before future launch
Signing into one part of Drilore must not silently grant access to another. Each surface needs its own data boundary.
Separate opt-in, disclosed data region, encrypted transport and storage, tested restore, export and account deletion, backup-expiry rules and a documented recovery design.
A separate choice using minimal event names and coarse counts. Raw VIN, Rego, receipt images, notes and exact location must not be analytics properties.
A community identity and public posts stay separate from the private Garage. No vehicle record becomes a forum post without an explicit share action and preview.
The commerce foundation is being built in a closed test mode. Shopping, payment and delivery data have their own tables, retention and disclosure; they must not be combined with private Garage history for advertising.
Privacy standard
The OAIC’s 2026 APP guidance says collection should be relevant, minimal and not excessive. Its security guidance also addresses destroying or de-identifying personal information that is no longer needed.
This is the accurate product boundary for Drilore 1.1, not a substitute for the final legal privacy policy. Before general public release, Drilore must publish the operating entity, privacy contact, infrastructure providers, data regions, specific retention periods, complaint path and market-specific rights.
Last product-boundary review: 25 August 2026.