/mytesla.io

Privacy policy

What we collect, why, who we share it with, how long we keep it, and your rights.

Last updated: 2026-09-12

1. Who we are

mytesla.io (the "Service") is operated by Embay, LLC and is contactable at support@mytesla.io. (When you connect your Tesla, our app appears as "Embay, LLC" on Tesla's authorization screen — that's us.) This policy explains what personal data we collect about you when you use the Service, why we collect it, how long we keep it, and the rights you have over it.

2. What we collect

Account data — your email address (required for login via one-time code); an optional display name if you set one; the date your account was created. Stored in Cloudflare's infrastructure.

  • Legal basis: Contract — we need this to provide the Service to you.

Tesla connection data — when you connect your Tesla account, Tesla issues us an OAuth access token and refresh token. We store these tokens encrypted at Cloudflare. We do not receive or store your Tesla account password. We also record the Tesla account identifier that Tesla includes in those tokens (an opaque ID, not your Tesla email), so we can tell when the same Tesla login is connected to more than one mytesla.io account.

  • Legal basis: Contract; legitimate interest (keeping the free trial to one per person).

Vehicle identifiers - the VIN of each car on your connected Tesla account. We keep that list so we can act on a specific car when you ask us for help (for example, clearing a cached setting for one vehicle). We also keep a keyed, one-way hash of each VIN (not the VIN itself), and use it only to spot the same car being connected to more than one mytesla.io account. When two accounts share a Tesla login or a car, our team is alerted to review it; nothing is blocked automatically, and many shared cars are simply two drivers in one household.

  • Legal basis: Legitimate interest (supporting your account; preventing abuse of the free trial).

Vehicle data (transient) — when your AI assistant asks for your car's status or sends a command, we fetch live data from the Tesla Fleet API (battery level, location, climate, etc.) and return it to the assistant. We do not store this data on our servers by default. The exceptions are the vehicle identifiers described above, and the quality-of-service data each MCP tool call produces, which we record to improve our service: which tool was called, whether it succeeded, and how long it took. The vehicle data itself is not in that log.

  • Legal basis: Contract.

Billing data — when you subscribe or buy a top-up, Stripe processes the payment. We store your Stripe customer ID and a record of subscription/invoice events (not your card number — Stripe holds that). See Stripe's own privacy policy for how they handle payment data: https://stripe.com/privacy.

  • Legal basis: Contract + legal obligation (tax/accounting records).

Usage logs — for every MCP tool call, we record: your user ID, the tool name, whether it succeeded or errored, the latency, and the credits consumed. We use these to compute your credit balance, diagnose errors, and aggregate overall service health.

  • Legal basis: Legitimate interest (operating and improving the Service).

Bug reports — if your AI assistant asks you whether you want to report a failed command as a bug and you say yes, we record the tool that failed, the error message, your own description (if you provide one), and your AI assistant's summary.

  • Legal basis: Legitimate interest + your consent at the point of filing.

Request metadata — IP address, browser user-agent, and request timestamps for a short window to support rate limiting and debugging. Typically purged within 30 days.

  • Legal basis: Legitimate interest (security, abuse prevention).

Approximate location - when you sign in or open your dashboard in a browser, our edge provider (Cloudflare) tells us where your IP address appears to be: continent, country, region and region code, city, postal code, US metro area code, timezone, whether the country is in the EU, and coordinates we round to roughly 1 km (IP geolocation is city-grade at best - it usually points at your metro area, not your street). We keep the most recent snapshot on your account and refresh it as you come back, so it reflects where you are now rather than where you first signed up. We use it in aggregate to understand where our users are, and for support context (like knowing your timezone). It is never captured from AI-assistant traffic (that would locate the AI provider's datacenter, not you), it is never used to make decisions about your account or to gate any feature, it is included in your data export, and it is erased when you delete your account.

  • Legal basis: Legitimate interest (understanding our market, support).

Email we send you, and a record of it: besides account emails (sign-in codes, verification, receipts, replies to your support messages), we send a small number of onboarding and usage emails: a welcome message when you sign up, occasional prompts if you've set up an account but haven't connected your car or your AI assistant yet, or if your connection has gone quiet for a few weeks, and - if you took the free trial and have unused credits about to lapse - one heads-up a few days before they expire that names the paid plans. There is no newsletter, no promotional campaign, and nothing is sent to a mailing list. Each one is triggered by the state of your own account.

For each email we record who it went to, which type it was, whether it sent, and whether it was opened or its link clicked. Open tracking is a 1x1 image and is unreliable by design: Apple Mail and Gmail routinely load it whether or not a human read anything, so we treat it as a rough signal, not proof you read an email.

Every onboarding or usage email carries a one-click unsubscribe, and opting out stops that whole category immediately. Account and billing emails are not affected by that choice, because skipping those would only hurt you.

  • Legal basis: Contract (account emails); Legitimate interest (helping you actually set up and use the Service you signed up for), with an unconditional opt-out.

Attribution data — when you arrive at our marketing site via a link or ad, we record a first-touch attribution cookie (mt_attr) on .mytesla.io containing the referral source, medium, campaign, any ad click identifiers (e.g. utm_*, gclid), and the referring page. We read it once when you create an account to record which channel you came from. It's a first-party cookie, set without consent only outside the EEA/UK/Switzerland; within those regions it is set only after you accept the cookie banner.

  • Legal basis: Legitimate interest (understanding which channels work) — consent within the EEA/UK/Switzerland.

3. What we DO NOT collect

  • We don't track you across other websites — no third-party advertising cookies, and no analytics at all on the signed-in app/portal at mcp.mytesla.io. (Our public marketing site, mytesla.io, uses Google Analytics, which sets analytics cookies only after you accept the cookie banner — see "Who we share with" below — and Cloudflare Web Analytics, which is cookieless and collects no personal data.)
  • We don't read or store your Tesla's charge history, drive history, or navigation history beyond the single live snapshot requested by a tool call.
  • We don't sell your data to anyone. Ever.
  • We don't train AI models on your conversations, tool calls, vehicle data, or bug reports.

4. Who we share with

We share data only with the third parties required to run the Service:

Provider What they get Why
Cloudflare All of the above, as our hosting provider We run our service on Cloudflare
Stripe Your email, Stripe customer ID, billing events Payment processing
Cloudflare Email Your email address and the contents of emails we send you Delivering account, support and onboarding email
GitHub An encrypted-at-rest copy of our database in a weekly backup, kept 90 days Disaster recovery
Tesla Your Tesla-issued OAuth token (on each request) Live vehicle data and commands
Google Analytics Anonymous usage events on the marketing site, only after you accept the cookie banner Understand how the marketing site is used

We do not share personal data with anyone else unless compelled by valid legal process or a court order. If that happens we'll notify you unless the order forbids it.

5. How long we keep it

  • Account data: as long as you have an account. Deleted within 30 days of account closure.
  • Tesla tokens: until you disconnect, or until they expire.
  • Tesla account identifier: kept with your Tesla connection, and removed when you disconnect or delete your account.
  • Vehicle identifiers: the VIN list is kept for up to 12 months after we last see a change to it; the VIN hashes, and any record that another account shares your Tesla login or car, are kept while your account exists, including after you disconnect your Tesla, so the check still works if the same car is connected elsewhere. All of it is erased when you delete your account.
  • Tool-call logs: 12 months rolling — older rows are deleted.
  • Financial events (invoices, payments): 7 years, because accounting rules.
  • Bug reports: 12 months after the status becomes "fixed", "duplicate", or "invalid".
  • Request metadata logs: 30 days.
  • Approximate location snapshot: most recent only - each refresh overwrites the last, so there is no location history. Erased on account deletion.
  • Backups: a weekly snapshot of the database, kept 90 days, then deleted automatically. Deleting your account removes your data from the live database immediately; copies inside existing backups age out within that window, or we can purge them sooner on request.
  • Email send records (which type was sent, when, whether it was opened or clicked): kept as a delivery log. On account deletion your email preferences, including your unsubscribe token, are deleted outright, and these records keep only the internal account identifier, which by then resolves to an anonymised account, not to you.

6. Your rights

Depending on where you live, you have some or all of these rights:

  • Access — get a copy of your data. You can self-serve from Account → Download my data on the dashboard. The download is a summary: profile, the approximate-location snapshot described above, current subscription and credit balance, your Tesla account identifier and VINs, how many other accounts we have found sharing either, billing events with Stripe invoice IDs (so you can reconcile with your receipts), usage totals by category and by day, bug reports you've filed, and waitlist entries. Individual per-call records are aggregated into daily totals rather than itemised.
  • Correction — fix anything inaccurate.
  • Deletion — ask us to remove your account. You can self-serve at Account → Delete my account. Email, display name, Tesla connection tokens, vehicle identifiers, and your location snapshot are erased immediately, and the device you deleted from is signed out. Sign-in sessions on any other device are not individually revocable (they are signed cookies, not server records) and expire on their own within 14 days; nothing they can reach is still linked to you. Your anonymised usage, billing, and bug-report history is retained for aggregate business analytics, tax / accounting, and to keep the bug tracker useful — but it's no longer linked to you personally, and we cannot recover the deleted identity. Active subscriptions cancel at the end of the current billing period per our billing policy.
  • Portability — the self-serve export above is structured JSON, machine-readable.
  • Object / restrict — tell us to stop or limit certain processing, if possible to do so.
  • Withdraw consent — for anything based on consent, you can withdraw at any time.

Email support@mytesla.io with any request the self-serve flows don't cover. We'll respond within 30 days.

7. Security

  • All traffic is HTTPS-only.
  • Passwords don't exist — we use one-time email codes instead.
  • Tesla tokens and Stripe secrets are stored encrypted at rest.
  • Session cookies are HttpOnly, Secure, and SameSite=Lax.
  • Rate limits on login and signup block brute-force attempts.

If we ever suffer a breach that affects your data, we'll notify you within 72 hours as required by law.

8. Children

The Service isn't directed at anyone under 18 and we don't knowingly collect data from them. If you believe we have data on a child, email us and we'll delete it.

9. International transfers

We operate on Cloudflare's global network; your data may be processed in any region Cloudflare operates. Cloudflare's data processing agreement covers cross-border transfers.

10. Changes to this policy

If we make material changes (new data types, new providers, longer retention), we'll email you at the address on your account at least 14 days before the change takes effect.

11. Contact

Questions? Complaints? Data requests?

Email: support@mytesla.io

← Back to home