Privacy Policy
Carumi Privacy Policy
Last updated September 25, 2026
The short version
Carumi is local-first: your vehicle history stays on your iPhone, with optional private iCloud sync. There is no Lucernel account and no Lucernel server holding your records. We never sell data, show ads or track you. Only purchase status, anonymous analytics and crash reports reach our providers.
1. Who we are
- This policy covers Carumi, an iPhone app made by Lucernel LLC ("Lucernel", "we").
- For anything about your privacy, write to [email protected].
2. Data that stays with you
- Carumi is local-first: your vehicle history stays on your iPhone, with optional private iCloud sync. There is no Lucernel account and no Lucernel server holding your records.
- Vehicles, service records, mileage, maintenance schedules, deadlines, costs, documents, photos and reminders are stored on the device.
- Optional iCloud sync uses your private CloudKit database, which belongs to your Apple Account. Lucernel cannot read it.
- Home Screen widgets read a short summary that the app writes to a shared container on the same device.
- VIN capture and document text recognition run on the device with Apple Vision. Carumi does not use a paid VIN service and does not connect to vehicle history providers.
- Subscription status is handled by Apple and RevenueCat.
- Product analytics events and crash reports may be sent through PostHog. They describe how the app is used, such as a screen opened or a purchase completed, and never include the content of your records.
3. Data we or our providers receive
- Purchase and subscription status through Apple and RevenueCat.
- Product analytics events and crash reports through PostHog, without record content.
- Crash reports contain the technical trace of the crash, the app version, the iOS version and the device model.
- Analytics events carry an anonymous app identifier, the app version, locale and approximate country. They are not linked to your name or email.
- Emails you send to [email protected] or [email protected], with the address you write from.
4. How we use data
- To keep the service timeline, maintenance schedules, deadline reminders, cost charts, the Vehicle Passport PDF and exports.
- To manage access, purchases and Restore Purchases.
- To understand onboarding completion, feature reliability, purchases and stability.
- To answer support and privacy requests.
5. Permissions
- Camera: to scan a VIN or a document, on the device.
- Photos: to attach photos you choose.
- Notifications: for maintenance and deadline reminders.
- Each permission is asked for only when you use the feature that needs it. You can change it at any time in the Settings app of your iPhone.
6. Service providers
- Apple for App Store payments, iCloud/CloudKit sync when enabled, notifications and device services.
- RevenueCat for subscription status, restore and entitlement handling.
- PostHog for product analytics events and crash reports.
- Each provider handles data only to provide its service to us, under its data processing terms, and must protect it at least as this policy does. Apple is also bound by its own privacy policy for App Store, iCloud and device services.
7. What we never do
- We do not sell or rent personal data.
- We do not show ads, and we do not track you across other companies’ apps or websites.
- We do not share your records with anyone. We cannot read the data in your private iCloud.
8. How long we keep data
- Records stay on your device, and in your private iCloud when sync is on, until you delete them or the app.
- Apple, RevenueCat and PostHog keep their records according to their own retention settings.
- Purchase records are kept by Apple and RevenueCat for as long as they are needed to manage your subscription and to meet tax and accounting duties.
- Analytics events and crash reports are kept only as long as they help us understand how the app works, and are deleted on request.
- Support emails are kept while we handle your request and for a reasonable time after, then deleted.
9. Your choices and rights
- Carumi has no email-and-password account.
- Delete records inside the app, or delete the app to remove its data from the device. If iCloud sync is on, synced data can be removed from the iCloud settings of your device.
- For requests about subscription or analytics records held by providers, contact [email protected].
- You can withdraw consent at any time: turn off a permission in the Settings app, delete the app to stop all collection, or write to [email protected] and we will stop using and delete the data we or our providers hold about your installation.
- Depending on where you live, you can ask to access, correct, delete or receive a copy of your data, or object to its use. We answer within 30 days and never charge for it.
10. Children
Carumi is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has sent us data, write to [email protected] and we will delete it.
11. Security
Data on your device is protected by iOS and, when synced, by your Apple Account. Providers use encryption in transit. No system is perfectly secure, so we keep what we receive to the minimum.
12. Changes to this policy
When this policy changes, the date at the top changes too. Important changes are also announced in the app.
13. Contact
- Privacy questions and deletion requests: [email protected].
- Everything else: [email protected].








