Hardpark

Privacy Policy

Last updated 12 August 2026

Hardpark has no account, no sign-in, no email address and no password. You never tell us your name. To render your car, your photo does have to leave your device and reach an image model — so this policy is mostly about that one journey: what is stripped out of the photo before it goes, who touches it, how long anything survives, and what we keep afterwards. For most of what we keep, that is numbers rather than pictures — the one exception is a rendered image itself, briefly, and it is explained in its own section below.

The photo, step by step

This is the part that matters, so it is written out in order rather than summarised.

The result of all of this is the strongest claim in this policy and the one we are most confident in: no copy of your original photograph is ever stored off your device. Not on our server, not at the image provider, and not in any backup of your phone. The one copy that does persist is the resized, location-stripped one described in the first step above, it lives on your phone only, and it is there so the app remembers your car. The finished render — the picture Hardpark generates — is a separate thing, described next, and it does leave your device for a while.

The render, and how long it lasts

What happens to the finished render — your car with the mods applied — depends on which quality tier made it. Both are described here rather than smoothed into one sentence, because they behave differently.

Standard-tier renders are held on fal's content network, locked so anonymous requests cannot read them, for 24 hours, then permanently deleted. We ask for that lifetime explicitly on every single request; it is not a default we are hoping holds. Our own server never stores a copy of a standard-tier render — it fetches the locked image from fal each time you view or share one, and passes the bytes straight through without keeping them.

Premium-tier renders work differently. The image model Hardpark uses for premium hands the finished image's bytes back to us directly, rather than hosting them at an address the way the standard model does. That means our own server briefly holds a copy of the rendered image itself — the same database row that tracks the render holds the picture, not just a pointer to one. An automatic cleanup job clears it out on a nightly schedule: in practice that is usually close to 24 hours after the render was made, and it is never later than 48 hours from when the render was created, which is the outside bound the once-a-day schedule sets.

Either way, the app never receives an address it could leak: images are fetched or read through Hardpark's own server, which checks that the render belongs to the device asking for it. When you share a render, the app hands over the image itself rather than a link, so nobody ends up passing around a live URL that points at a picture of your house.

The lifetime above is how long the render survives off your device — on fal's servers, or briefly on ours. It is a deliberate balance, not a technical maximum: long enough that a phone which died overnight can still collect the render in the morning, and short enough that the window in which anything can go wrong is a day or two rather than forever. Once it expires there, it is gone from both places and we cannot bring it back. It is a separate question from whether a copy already made it onto your own phone — the next section covers that.

Your build gallery

Every render you complete is also added to a build gallery inside the app — a history of your past builds, separate from the render's own temporary lifetime described above. The gallery lives only on your phone. It is a folder in Hardpark's own storage (Application Support/Hardpark/Gallery/), never uploaded anywhere and never read by our server or anyone else. Each entry records which mods you picked, which car and category it was for, and — for as long as the render itself hasn't expired and you had it open — the image. Like the car photos described above, the gallery folder is marked so that iCloud and iTunes/Finder backups skip it, and on iOS its files are encrypted at rest by the device the same way the car photo is.

The gallery has no expiry of its own — entries stay until you remove them. You can clear the whole thing at once from Settings: Clear build history deletes every entry from the phone immediately. It is a separate control from Forget my car and Delete my data, deliberately: your build history, your car photos and your server record are three different things, and clearing one does not touch the other two. Uninstalling Hardpark removes the gallery along with everything else the app stores.

What we actually keep

Mostly numbers, tied to a device rather than a person — with one exception, described in the render section above: a premium-tier render's own image bytes sit in our database temporarily, until the nightly cleanup clears them. Everything else below is exactly that — numbers:

Outside of a premium render's temporary window, none of these hold, or can be turned back into, a picture of your car.

Rate-limit counters, and IP addresses

Requests are counted so that no single source can exhaust the service for everyone else. A counter is one row: a subject, which request it counts, a time window, and a number.

There are two kinds of subject, because a request may arrive before there is any identity to attach it to. Before that point — when the app first asks our server for a session — the counter is keyed on the network address the request came from, shortened to its network prefix if it is IPv6. Afterwards it is keyed on the pseudonymous identifier described in the section above, not on the address. Both kinds are deleted automatically by a scheduled job, within about 25 hours.

We do not use IP addresses to build a profile, we do not link them to renders, and we do not look up where they are.

Purchases

Browsing Hardpark costs nothing. Categories, subcategories, your car garage and your build gallery are all free to look at, with no subscription and no account. A paywall is shown once, right after onboarding, and you can close it and go straight to the app. What actually costs money is generating a render: that always spends a credit, and reaching zero credits is what brings a paywall or a purchase screen back, honestly, at the moment you try to spend one you don't have.

Two different things can be bought, and they are not the same purchase:

Prices and renewal terms for both are shown on their own screens, pulled live from the App Store for your country, never hardcoded here.

Anything you buy in Hardpark is sold and billed by Apple through the App Store. We never see your payment details — not your card number, not your billing address, not your name. Apple processes the transaction and tells the app only what was bought and whether it is still valid. Subscriptions renew automatically until cancelled; manage or cancel yours any time in Settings → [your name] → Subscriptions on your iPhone. A Restore Purchases button on the paywall recovers an active subscription on a new device or after a reinstall.

Hardpark uses RevenueCat to check and record subscription status. RevenueCat receives the same anonymous, App-Attest-derived identifier described above — not your Apple ID, name or email — plus your purchase information: which product, whether it renewed, whether it lapsed. It does not receive your photos or your renders; those never touch the billing path. See Apple's privacy policy and RevenueCat's privacy policy for how each of them handles what they receive.

Tracking, analytics and advertising

Hardpark contains no analytics SDK, no attribution or advertising library, and no crash reporter. It does not use the advertising identifier, and it will never show you the App Tracking Transparency prompt, because it has nothing to ask permission to track. How often you open the app, how long you spend in it, and what you tap are not recorded or sent anywhere. The one third-party SDK the app ships is RevenueCat, described in "Purchases" above — it exists solely to verify subscription purchases, and does not do analytics, advertising or tracking on Hardpark's behalf.

Who else is involved

That is the complete list. There are no advertising networks and no data brokers.

Deleting things — stated honestly

Some of this is bounded by a third party, and we would rather say so than promise erasure we cannot perform. Both controls live in the app's Settings — Forget my car for the photo on your phone, Delete my data for everything on our server — and the email address at the bottom of this page does the same job if you would rather write to us.

Children

Hardpark is not directed at children and is not intended for anyone under 13. We do not knowingly collect information from children.

Your rights

Under the GDPR, the UK GDPR and the CCPA you have rights to access, correct, export and erase personal data held about you. Hardpark holds no name, email address or account, so the data associated with your device is what is described above, and the deletion section says exactly what can and cannot be removed. We have never sold or shared personal information, and we do not sell or share it now.

Changes

If this policy changes, the date at the top changes with it and the previous version is superseded. A change that introduces a new recipient of your data — an analytics provider, a new model vendor, a billing service — will be published here before it ships, not after.

Contact

Questions about this policy, or a request about your data: gokhan.tosun1995@gmail.com.