Privacy policy
Shitbox Garage · Updated 8 September 2026
Operator and contact
Shitbox Garage is operated by Lluc Matas Pomar. For privacy questions, support or abuse reports, contact [email protected].
Information the app uses
Email/password and Google sign-in are handled through Auth0. The app receives an account identifier and, when provided, your name, email address and avatar URL. It does not receive your password.
We store the garages and memberships, invitations, car or motorbike projects, tasks, checklists, comments, parts and activity you create. Optional details include VIN, mileage, approximate prices, suppliers and uploaded photos, and image or purchase links. Members of the same garage can view and edit shared content.
Purposes and providers
This information supports sign-in, access control for private garages and shared project coordination. Railway hosts the services and PostgreSQL database. Cloudflare R2 stores uploaded photos in a private bucket. Auth0 handles authentication; Google is also involved if you choose that sign-in method. These providers may process IP addresses and technical logs to operate and protect their services.
Linked images are requested directly from their hosts. Opening a purchase link takes you to a third party with its own policy. Uploaded photos are validated, converted to metadata-free WebP, and displayed through short-lived private links. The app has no advertising, billing, advertising analytics or push-notification system. The developer reviews support requests and reports you send; include only the information needed.
Information on your device
The app stores language and other local preferences. It may retain a read-only copy of the last loaded garage, separated by identity and garage; this is cleared on logout or identity change. The native mobile app stores session credentials in device secure storage to keep you signed in. Logout clears the app's credential cache.
Retention and archiving
We store the version of the rules you accept and member blocks to protect private garages. Open requests remain until reviewed; resolved requests are automatically deleted after 90 days.
Archiving a project keeps it: it does not delete an account or its data. Shared content, including its photos, remains in its garage until it is deleted. Replaced photos and abandoned uploads are removed by daily cleanup. Garage deletion has a 30-day recovery window, followed by a daily purge of its data and photos. This is separate from account deletion.
Technical-log and backup retention depends on provider configuration. You can ask about the retention applicable to your account using the contact above. Avoid adding unnecessary sensitive information to shared comments or images.
Request account deletion
In the app, open Support and privacy and select Delete account and personal data. This signs you out and starts deletion from Auth0 and the database. If a provider fails, the request remains pending and retries. You can also request deletion by email without app access.
We remove your profile, authored comments, invitations, assignments and personal attribution. Garages with no other members are permanently deleted. Shared garages retain project, task and part structure with neutral labels, without text and links on records you created or your vehicle details. Ownership passes to the longest-standing remaining member and related activity is removed. Identify the location of personal information written by others so we can review and remove it.
For 30 days we retain a hash of the login identifier and the deletion time to reject old sessions. This record contains no name or email. Deleting Shitbox Garage does not delete your Google account.
You can request deletion of your Shitbox Garage account and associated personal data without reinstalling the app. Write from the email address you use to sign in and state that you want your account deleted. Do not send passwords or access codes.
Request deletion by emailLluc Matas Pomar will review the request and may ask you to verify your identity. The response will clarify how shared content and any information that must be retained will be handled. Sending a request or archiving a project does not mean deletion has been completed.
Your rights and support
Use the same contact to request access, correction or deletion of your information and exercise applicable data-protection rights. You may also complain to the Spanish Data Protection Agency.
Content and reports
Use garages to coordinate projects respectfully. Do not share illegal content, threats, harassment or someone else's personal information without authorization. To report content or a user, contact the email above with the garage, content and reason. The developer reviews reports and can permanently remove content. In Support and privacy you can report and block a member: you leave all garages shared with that person and future shared membership is prevented. Before contributing you must accept the content rules, which also prohibit sexual content, child exploitation, hate and scams. Archived content remains recoverable; archiving is not account deletion.