Hardpark
Last updated 8 August 2026
Hardpark has no account, no sign-in, no email address and no password. You never tell us your name. To render your car, your photo does have to leave your device and reach an image model — so this policy is mostly about that one journey: what is stripped out of the photo before it goes, who touches it, how long anything survives, and what we keep afterwards (which is numbers, not pictures).
This is the part that matters, so it is written out in order rather than summarised.
The result of all of this is the strongest claim in this policy and the one we are most confident in: your original photograph is not stored anywhere, by anyone, at any point.
The rendered image — your car with the mods applied — is held on fal's content network for 24 hours, then permanently deleted. We ask for that lifetime explicitly on every single request; it is not a default we are hoping holds.
While it exists, the render is locked so that anonymous requests cannot read it. The app never receives its address: images are fetched through Hardpark's own server, which checks that the render belongs to the device asking for it. When you share a render, the app hands over the image itself rather than a link, so nobody ends up passing around a live URL that points at a picture of your house.
Twenty-four hours is a deliberate balance, not a technical maximum. It is long enough that a phone which died overnight can still collect the render in the morning, and short enough that the window in which anything can go wrong is a day rather than forever. If you want to keep a render, save it to your photo library — after 24 hours it is gone, and we cannot bring it back.
No images. What is stored in our database, tied to a device rather than a person:
None of these hold, or can be turned back into, a picture of your car.
When the app first asks our server for a session, that request is not yet attached to any identity, so it is rate-limited by network address — otherwise the free tier is a script's free tier rather than yours. The address (shortened to its network prefix if it is IPv6) is used as the key of a counter. Those counters are deleted automatically after about 25 hours by a scheduled job. We do not use IP addresses to build a profile, we do not link them to renders, and we do not look up where they are.
Anything you buy in Hardpark is sold and billed by Apple through the App Store. We never see your payment details — not your card number, not your billing address, not your name. Apple processes the transaction and tells the app only what was bought and whether it is still valid.
At the time of writing, no purchases have launched. When they do, Hardpark will use RevenueCat to check and record subscription status, and RevenueCat will receive the same anonymous app-generated identifier described above plus your purchase information — which product, whether it renewed, whether it lapsed. It will not receive your photos or your renders; those never touch the billing path. This policy will be updated before that ships, not after, and the date at the top will change with it. See Apple's privacy policy and RevenueCat's privacy policy for how each of them handles what they receive.
Hardpark contains no analytics SDK, no attribution or advertising library, no crash reporter, and no advertising. The app ships with no third-party code at all. It does not use the advertising identifier, and it will never show you the App Tracking Transparency prompt, because it has nothing to ask permission to track. How often you open the app, how long you spend in it, and what you tap are not recorded or sent anywhere.
That is the complete list. There are no advertising networks, no data brokers, and no analytics vendors, because there is no analytics.
Some of this is bounded by a third party, and we would rather say so than promise erasure we cannot perform.
Hardpark is not directed at children and is not intended for anyone under 13. We do not knowingly collect information from children.
Under the GDPR, the UK GDPR and the CCPA you have rights to access, correct, export and erase personal data held about you. Hardpark holds no name, email address or account, so the data associated with your device is what is described above, and the deletion section says exactly what can and cannot be removed. We have never sold or shared personal information, and we do not sell or share it now.
If this policy changes, the date at the top changes with it and the previous version is superseded. A change that introduces a new recipient of your data — an analytics provider, a new model vendor, a billing service — will be published here before it ships, not after.
Questions about this policy, or a request about your data: gokhan.tosun1995@gmail.com.