Privacy Policy
This policy explains how the current version of FuelLog handles user data.
Data stored by the app
FuelLog is a vehicle logbook app. It may store locally on the user's device:
- vehicle data such as vehicle name, fuel type, odometer value, inspection dates, motorway vignette dates and service intervals;
- fill-up records, including date, fuel amount, price, currency and odometer value;
- costs, service records, notes, statistics and maintenance history;
- photos of receipts, odometers, fuel prices or service documents;
- app settings, active vehicle, entitlement cache, Cloud Backup state and user-created local backups.
Most app content is stored locally on the user's device by default.
Photos and OCR
The app may use the camera to take photos of receipts, odometers or fuel price boards. Photos are stored in the app's internal storage.
Text recognition from photos is processed locally on the device using Google ML Kit. In the current version, receipt, odometer and fuel price photos are not uploaded to the FuelLog backend for OCR.
Voice input
The app may use the microphone for optional voice entry of fuel or expense data. Speech recognition is provided by the phone's system service. Depending on the device and settings, the system speech provider may use online processing.
FuelLog does not store audio and does not send audio to its own backend. Only text or values confirmed by the user are stored in the form.
Google sign-in and backend
Google sign-in is optional. If the user signs in with Google, the app sends a Google ID token to the FuelLog backend to verify the account and manage account features.
The backend may process:
- email address and name from the Google account, if returned during sign-in;
- random device identifier, backend access token and user access token;
- plan, credits, entitlement information and account deletion request status;
- Cloud Backup data and metadata if the user enables the feature.
The backend is used for device registration, Google sign-in, entitlement checks, PRO features, Cloud Backup, account status and account deletion requests.
Backups, Cloud Backup and exports
The app allows the user to create a portable ZIP backup. This manual backup may contain local app database data and photos stored by the app. The user chooses where to save or share the backup.
Cloud Backup is an optional PRO feature available after Google sign-in. It stores database history on the FuelLog backend, such as vehicles, fill-ups, expenses, service records, inspections and motorway vignette records. In the current version, Cloud Backup does not upload physical receipt, odometer, fuel price or attachment photos.
The backup is encrypted on the device before it is sent (AES-256-GCM) using a key stored exclusively via Google Blockstore. The FuelLog backend only stores the encrypted data and has no access to the encryption key. Restoring a backup reliably works today on the same device that created it; restoring on a brand-new device after signing in with the same Google account is not yet guaranteed in every case.
If Android system backup or device transfer is enabled, the operating system may back up the app database, settings and app-owned photos according to Android backup rules and the user's settings.
PDF, CSV and other exports may contain sensitive information, costs, service history or photos. The user is responsible for how exported files are handled.
Analytics, diagnostics and crash reporting
FuelLog uses Firebase/Google services for basic analytics, diagnostics, installations, session information and crash reporting. These services may process technical data such as app installation identifiers, Advertising ID or similar resettable identifiers, device model, operating system version, app version, usage time, basic app events, crash information, stack traces and diagnostics needed to fix bugs.
We use this data for app operation, stability measurement, bug fixing, security and quality improvement. We do not use advertising SDKs and we do not sell personal data.
Firebase Analytics only runs with your consent. On first launch (or when updating to a version with this feature, if you have not given consent yet) a dialog asks whether you agree to anonymous usage-analytics collection. Consent is optional, the app works identically either way, and you can change your choice anytime in Settings → Legal and account. Firebase Crashlytics is not affected by this consent and provides crash diagnostics and stability data for all users.
Who data may be made available to
- the user in the app;
- the FuelLog backend for Google sign-in, device registration, Cloud Backup, entitlement checks or account deletion;
- Google Sign-In and the system speech recognition service if the user uses the relevant feature;
- Google/Firebase services for analytics, diagnostics, crash reporting and technical operation;
- infrastructure providers required to operate the backend;
- public authorities where required by law.
Legal basis
- provision of the app and its features;
- legitimate interest in security, abuse prevention, entitlement management, diagnostics and technical support;
- consent, where an optional feature relies on consent;
- compliance with legal obligations, where applicable.
Subscriptions and payments
FuelLog PRO is sold as a subscription through Google Play. Payments are processed solely by Google Play as the payment provider. Card numbers and other payment details never reach us and we do not store them.
When you purchase, Google Play gives us a purchase confirmation. From it we store the purchase identifier, the product identifier and the subscription state (active, in grace period, cancelled, refunded). The purchase identifier is stored encrypted. We need this data to verify that the subscription really exists, to protect against abuse and to manage access to PRO features.
The purchase is linked to your account through a one-way fingerprint (HMAC) derived from the account identifier using a server-side secret. Your identity cannot be recovered from that fingerprint.
Price, billing period and renewal terms are shown in Google Play before you confirm the purchase. The subscription renews automatically until you cancel it. You can cancel at any time in Google Play under Payments and subscriptions. After cancelling, PRO stays active until the end of the period you already paid for.
When you request account deletion, we stop the automatic renewal of your subscription and verify the result with Google Play. The paid period runs out and no money is refunded; refunds are decided solely by Google under its own rules. Purchase records are retained as long as required for accounting and tax purposes and for dispute resolution, including after account deletion; they are kept without a link to the deleted identity.
If you delete your account and create a new one while your subscription is still running, the remaining entitlement may be restored.
Retention and deletion
Local data remains on the user's device until the user deletes it, clears app data or uninstalls the app. Files exported outside the app must be deleted separately by the user.
Cloud Backup and backend data linked to the account are deleted as part of the account deletion process unless there is a legal, security or operational reason for limited retention. Account deletion is first performed as a soft-delete with a 48-hour protection period to prevent accidental data loss.
The account and data deletion process is described on the Account and data deletion page.
App permissions
- Camera: taking photos of receipts, odometers or fuel price boards.
- Microphone: optional voice entry of form data.
- Internet: Google sign-in, device registration, Cloud Backup, Firebase diagnostics, entitlement checks and account deletion requests.
- Notifications: service, inspection and other reminders.
User rights
Users may request access, correction, deletion, restriction of processing, data portability or object to processing under applicable law. Send requests to privacy@fuellog.eu.
Controller and contact
The data controller is the operator and publisher of the FuelLog app:
Tomáš Navrátil
Holandská 13
571 01 Moravská Třebová
Czech Republic
For privacy, support and GDPR requests, use:
- Support: support@fuellog.eu
- Privacy and GDPR: privacy@fuellog.eu
Changes
This policy may be updated when new features, payments, Cloud Backup changes, diagnostics changes or legal requirements change.
This page was last updated on 30 August 2026.