The short version: COROAD is built as a local-first vehicle ledger. Your vehicles, fuel logs, expense records, odometer readings, station notes, photos, and analytics stay on your device unless you choose to export, share, back up, restore, or otherwise move that information yourself. COROAD does not use advertising SDKs, does not sell your data, does not run cloud analytics, and does not require an account for the Phase 01 launch build.
1. Who We Are
COROAD is a mobile application developed and operated by iSHARATH Labs, India ("we", "us", "our"). COROAD helps users maintain a vehicle ledger for refuelling, odometer readings, expenses, station records, ownership costs, and related local insights.
This Privacy Policy applies to the COROAD and COROAD FE Android applications unless a later edition-specific policy is published. COROAD FE is the Founder's Edition of COROAD and is intended for a limited founder user cohort.
For the Phase 01 launch build, the app is designed to work without a COROAD account and without any COROAD-operated cloud backend.
2. Applicable Law
COROAD is operated from India and is primarily governed by Indian law, including the Digital Personal Data Protection Act 2023 and the Information Technology Act 2000 where applicable.
If you use COROAD outside India, local privacy, consumer, and digital service laws may also apply. We aim to operate COROAD using privacy principles that are familiar across major privacy frameworks, including data minimisation, purpose limitation, transparency, user control, security, and retention control.
COROAD currently stores app data on your own device. If future COROAD editions add cloud sync, account login, remote backup, online scanner processing, advertising, or cloud analytics, this Privacy Policy will be updated before those features are launched.
3. What Data You May Store in COROAD
COROAD stores the information you enter or generate while using the app. Depending on how you use the app, this may include:
Vehicle details: vehicle names, categories, fuel or energy type, engine or battery details, tank capacity, usage profile, and configuration details.
Fuel and energy logs: odometer readings, fuel quantity, cost per unit, total bill, currency, fuel tier, full-tank status, date and time, and notes.
Expense and maintenance records: service, repair, accessory, document, insurance, tax, or other ownership cost records you choose to add.
Station and location records: station names, manually entered locations, optional GPS-derived coordinates, and station metadata saved by you.
Photos and attachments: optional vehicle images and any local attachments supported by the app.
Preferences: app settings, selected units, display preferences, local unlock state, and local entitlement state.
Local analytics: insights calculated from your own vehicle and ledger data, such as economy, cost, range, confidence labels, and forecasts.
Backup files: encrypted COROAD backup files generated only when you choose to create an export.
4. What COROAD Does Not Collect for the Phase 01 Launch Build
COROAD does not create a COROAD account.
COROAD does not require an email address, phone number, username, or password for a COROAD service.
COROAD does not send your vehicle ledger to iSHARATH Labs servers.
COROAD does not include Firebase, Supabase, AWS, Google Cloud, advertising, crash reporting, or third-party behavioural analytics SDKs in the launch build.
COROAD does not collect biometric data. Device unlock is handled by the Android operating system.
COROAD does not access contacts, call logs, SMS, or microphone data.
COROAD does not perform background location tracking.
COROAD does not use fuel pump or odometer photo OCR at launch. If an offline smart scanner is added in a future version, this Policy will be updated before that feature is released.
5. Device Permissions
COROAD requests only permissions needed for the app features you choose to use.
Biometric or device credential unlock: Used to protect access to the app on your device. COROAD receives only the result of Android's authentication flow. It does not receive or store fingerprints, face data, PINs, passwords, or biometric templates.
Location: Used only when you choose satellite tagging for a refuelling entry or station. COROAD takes a one-time foreground snapshot and stores the resulting coordinates or station label locally. You can deny location permission and enter locations manually.
Camera and gallery: Used when you choose to add or replace a vehicle photo. Photos remain local unless you export, share, or back up data that includes them.
Files and sharing: Used when you choose to import an encrypted backup, export an encrypted backup, or share a CSV, XLSX, PDF, or backup file through Android's share sheet.
6. How We Use Data
For the Phase 01 launch build, data is used locally on your device to:
Display your vehicles, refuel logs, expense logs, and station records.
Calculate local insights, charts, forecasts, confidence labels, and ownership metrics.
Validate entries and reduce duplicate or implausible logs.
Generate exports and encrypted backups when you request them.
Restore your COROAD ledger from an encrypted backup when you choose to import one.
Remember local settings such as preferred units, currencies, and display choices.
We do not use your data for advertising, external profiling, cross-app tracking, data brokerage, or sale to third parties.
7. Local Storage and Backups
COROAD stores app data in local storage controlled by your device operating system. If you delete the app or clear app data, your local COROAD data may be deleted unless you previously exported a backup.
When you choose to export a COROAD backup, the app creates an encrypted .ninkabeee file. The backup is encrypted using a password you choose. COROAD cannot recover this password for you. If you forget the password, the encrypted backup may not be recoverable.
Once a backup, CSV, XLSX, PDF, screenshot, or other export is handed to another app through Android sharing, storage, messaging, email, or cloud services, that destination app or service controls the copy you sent there. You should review the privacy practices of any app or service you choose for sharing or storage.
8. Data Sharing and Third Parties
COROAD does not automatically share your vehicle ledger with iSHARATH Labs or any third party. Data leaves COROAD only when you initiate an action such as export, share, backup, restore, screenshot, or manual transfer.
For the launch build, COROAD relies on standard Android and Flutter platform services and app-store distribution infrastructure. The following third-party flows may apply:
Google Play: Distributes the app and may process install, update, crash, purchase, and device data according to Google's own policies.
Android share sheet and destination apps: Used only when you choose to share or save an export.
Device operating system services: Used for biometric or device credential authentication, camera/gallery selection, file selection, and location permission prompts.
COROAD does not sell, rent, or trade your data.
9. Payments and Entitlements
COROAD FE is intended to provide lifetime COROAD IQ access to the approved founder cohort. COROAD FE itself does not process payment data in the launch build.
Regular COROAD editions may use Google Play Billing for one-time purchases or subscriptions. If billing is enabled in a future public COROAD edition, payment processing will be handled by Google Play. COROAD does not receive or store your full card number, bank account details, or payment credentials.
10. Government and Legal Requests
For the Phase 01 build, iSHARATH Labs does not operate a cloud database containing your local vehicle ledger. If we receive a legal request, we can only provide information we actually possess, such as support correspondence you sent to us or app-store or developer records available to us.
We will evaluate legal requests before responding and will not voluntarily disclose user information without valid legal process where required by law.
11. Data Retention and Deletion
Local app data remains on your device until you delete entries, clear app data, uninstall COROAD, reset your device, or import or restore over existing data.
Encrypted backups remain wherever you choose to save or share them until you delete those copies.
Exports such as CSV, XLSX, and PDF files remain wherever you save or share them until you delete those copies.
Support emails and legal correspondence may be retained as needed to respond to your request, maintain records, prevent abuse, or comply with law.
12. Your Choices and Rights
You control most COROAD data directly on your device. You may:
Add, edit, or delete vehicle and ledger entries in the app.
Deny location permission and use manual tagging instead.
Choose whether to add photos or attachments.
Choose whether to export, share, or back up your data.
Delete local data by using in-app deletion flows, clearing app data, or uninstalling the app.
Contact us for privacy questions, complaints, or requests involving information we hold outside your device, such as support emails.
COROAD uses a local-first security model. Relevant measures include:
No release internet permission in the Android manifest for the Phase 01 launch build.
Optional device biometric or credential unlock handled by Android.
Encrypted backup exports using modern authenticated encryption.
Password rules for backup creation.
Local validation and confirmation screens before saving entries.
No advertising or third-party behavioural analytics SDKs in the Phase 01 launch build.
No device or app is completely secure. You are responsible for keeping your device lock, backup password, exported files, and destination storage accounts safe.
14. Children and Age Requirements
COROAD is intended for adults who maintain vehicle and fuel records. It is not directed to children. You should use COROAD only if you are at least 18 years old or the age of majority in your jurisdiction, whichever is higher.
If you believe a child has sent personal information to us through support or other contact channels, email us and we will take appropriate action.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When material changes affect how COROAD handles data, we will update the effective date and, where appropriate, provide notice through the app, app-store listing, or other reasonable means.
If future COROAD versions add account login, cloud sync, online scanner processing, advertising, remote analytics, or cloud backups, this Policy must be updated before those features are launched.
16. Contact and Grievance Officer
For privacy questions, rights requests, and grievances: