Legal
Privacy policy
Effective date: August 5, 2026
This policy describes how Fixiom (the mobile app) and fixiom.ai (this website) handle information. Fixiom is operated by Fixiom LLC, a Vermont (USA) limited liability company. Fixiom is built around a simple idea: we ask for as little as possible. There is no account, no email address, and no advertising — and your conversations live on your device, not in a cloud profile.
The short version
- No account, no email, no name. The app creates a random anonymous identifier so your credits and purchases work. That identifier contains nothing about who you are.
- Your chats are stored on your device. Conversations, diagnostic records, and settings live in the app's local storage. Our servers process messages to generate answers, but do not keep a per-user conversation history.
- No ads, no ad partners, no selling of data. We do not sell or share personal information for advertising, and there are no third-party advertising or social-media trackers in the app or on this site.
- You can walk away clean. Uninstalling removes on-device data; a short email deletes the little that exists server-side. See Data deletion.
Information we handle, and why
Anonymous identifier
On first launch the app creates a random anonymous ID (via our authentication provider). It exists so the free credit allowance, purchases, and abuse protection can work without an account. It is not linked to your name, email, phone number, or any advertising identifier — with one opt-in exception: if you choose to include an email address when sending in-app feedback, that email is stored with your feedback submission (see "Feedback you send" below). You can see the ID yourself as the Support ID under Settings → About.
What you send in a conversation
When you use the AI features, your messages — plus the context needed to answer them (vehicle year/make/model or VIN if provided, trouble codes, summarized OBD2 readings, and any photo you attach) — are sent to our servers and processed by our AI provider to generate the reply. This processing is transient: we don't build a server-side profile of your conversations. Some commonly asked questions and their answers may be cached server-side to improve speed; those cache entries are keyed by the question itself and are not linked to your ID.
Vehicle and OBD2 data
Live sensor data from an OBD2 adapter is read and displayed locally on your phone. During an AI diagnosis, compact summaries (for example, averaged sensor values around a captured event, or a list of trouble codes) are sent to our servers so the AI can reason over them. We also receive anonymous product telemetry on the same random ID, retained for about 90 days: whether an adapter connected successfully, adapter model and error category (to improve compatibility); when the app could not match a sensor name the AI asked for, which records the vehicle's year, make, and model plus the signal name (so we can fix the gap); and the fact that a store review prompt was shown. No conversation content and no VIN are included.
Photos and voice
A photo is only sent when you attach one, is processed to answer you, and is not stored on our servers. Voice dictation is performed by your phone's operating system speech service — only the resulting text reaches us. Read-aloud in the natural voice sends the reply text to our speech provider to synthesize audio.
Feedback you send
The app has a "Send feedback" form (Settings → About). When you submit it, we store your written feedback together with the app version, platform, plan tier, and your anonymous ID so we can investigate and fix what you report. An email address is optional and used only to reply to your feedback — never for marketing, and never shared. The form states exactly what is attached before you send.
Purchases
Payments are processed entirely by Apple's App Store or Google Play — we never see your card details. Our purchase-management provider (RevenueCat) and our servers receive store receipts and entitlement status tied to your anonymous ID so your plan and credits activate.
Usage and cost accounting
We record how many AI credits your anonymous ID has used each month, and the corresponding processing cost, to enforce plan limits. This is a running total, not a log of what you asked.
How you found us (Android install source)
On Android, the first time the app runs it reads the Google Play install referrer — a short tag Google Play attaches when an install came from a link or an ad (for example, "came from fixiom.ai" or an ad campaign's identifiers). We store that tag with your anonymous ID so we can tell which channels bring people to Fixiom. It is read once per install, contains no personal information and no advertising identifier, is never shared, and is deleted with your other records if you delete your data. iOS has no equivalent — nothing like this is read there.
Network and security data
Like nearly every online service, our servers see the IP address of incoming requests and use it for rate limiting and abuse prevention (including a salted, one-way daily hash retained for about 30 days). Standard short-lived server logs exist at our hosting provider. Our servers also report their own errors (server stack traces — not conversation content, and nothing collected from your device) to our error-reporting service.
This website
fixiom.ai is a static site served via Cloudflare. It sets no advertising cookies. We use Cloudflare Web Analytics — a cookie-free, privacy-first measurement of page views and referrers by our hosting provider — with no cross-site tracking and no advertising identifiers.
Service providers
We use a small set of processors to run Fixiom, each receiving only what its job requires:
- Anthropic — AI processing of conversation content (including any attached photos) and its integrated web search. Processed under commercial API terms; not used to train AI models.
- Supabase — database and anonymous authentication.
- Railway — server hosting.
- RevenueCat — purchase and subscription management (receipts, entitlement status).
- Apple / Google — payment processing and app distribution, under their own privacy policies.
- Cartesia — natural-voice audio synthesis (receives reply text only, when you use read-aloud).
- Brave Search — diagram image search (receives the vehicle/diagram query only).
- NHTSA (a U.S. government service) — recall lookups by year/make/model.
- Sentry — error and crash reporting, in two scopes: our servers' own errors, and crash reports from the app itself (device model, OS version, app version, and the technical crash trace — no conversation content, no vehicle data, and not linked to your identity). Crash reports exist so we can find and fix app crashes; they are never used for advertising or tracking.
- Cloudflare — website hosting and network services, and Cloudflare Turnstile: an invisible bot-detection check that runs once when the app creates its anonymous account, so automated abuse can't drain the free tier. Turnstile evaluates technical signals from the device's request; it does not track you across sites. See Cloudflare's Turnstile Privacy Addendum.
- Expo (EAS) — app build and update delivery: serves the app's over-the-air updates to your device.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Data retention
- Conversations and records: on your device, under your control.
- Usage/credit counters and purchase entitlements: kept while your anonymous ID remains active.
- Connection telemetry: ~90 days. Abuse-prevention IP hashes: ~30 days. Server logs: short-lived per our hosting provider's defaults.
- Feedback submissions (including an optional reply email): kept until reviewed and resolved; deleted on request like any other record tied to your anonymous ID.
Your choices and rights
- Use it without identifying yourself. That's the default and only mode — we couldn't tie your usage to your identity without your help.
- Permissions are optional. Camera (VIN scanning, photos), microphone (dictation), and Bluetooth (OBD2) are each requested only when you use that feature, and the app works without them.
- Deletion. Uninstalling the app deletes on-device data. To delete server-side records tied to your anonymous ID, follow Data deletion.
- Depending on where you live, you may have legal rights to access or delete personal information. Since we hold almost nothing, requests are usually quick — email us and we'll help.
Children
Fixiom is not directed to children under 13, and we do not knowingly collect personal information from them.
Where processing happens
Fixiom is offered in the United States, and data is processed on servers in the United States.
Changes
If this policy changes materially, we'll update this page and its effective date. Continued use after a change means the updated policy applies.
Contact
Privacy questions or requests: [email protected]. Including your Support ID (Settings → About) lets us act on account-specific requests.
