/mytesla.io

Privacy policy

What we collect, why, who we share it with, how long we keep it, and your rights.

Last updated: 2026-06-26

1. Who we are

mytesla.io (the "Service") is operated by Embay, LLC and is contactable at support@mytesla.io. (When you connect your Tesla, our app appears as "Embay, LLC" on Tesla's authorization screen — that's us.) This policy explains what personal data we collect about you when you use the Service, why we collect it, how long we keep it, and the rights you have over it.

2. What we collect

Account data — your email address (required for login via one-time code); an optional display name if you set one; the date your account was created. Stored in Cloudflare's infrastructure.

  • Legal basis: Contract — we need this to provide the Service to you.

Tesla connection data — when you connect your Tesla account, Tesla issues us an OAuth access token and refresh token. We store these tokens encrypted at Cloudflare. We do not receive or store your Tesla account password.

  • Legal basis: Contract.

Vehicle data (transient) — when your AI assistant asks for your car's status or sends a command, we fetch live data from the Tesla Fleet API (battery level, location, climate, etc.) and return it to the assistant. We do not store this data on our servers by default. The single exception is that each MCP tool call produces quality-of-service data we record to improve our service: which tool was called, whether it succeeded, and how long it took — the vehicle data itself is not in that log.

  • Legal basis: Contract.

Billing data — when you subscribe or buy a top-up, Stripe processes the payment. We store your Stripe customer ID and a record of subscription/invoice events (not your card number — Stripe holds that). See Stripe's own privacy policy for how they handle payment data: https://stripe.com/privacy.

  • Legal basis: Contract + legal obligation (tax/accounting records).

Usage logs — for every MCP tool call, we record: your user ID, the tool name, whether it succeeded or errored, the latency, and the credits consumed. We use these to compute your credit balance, diagnose errors, and aggregate overall service health.

  • Legal basis: Legitimate interest (operating and improving the Service).

Bug reports — if your AI assistant asks you whether you want to report a failed command as a bug and you say yes, we record the tool that failed, the error message, your own description (if you provide one), and your AI assistant's summary.

  • Legal basis: Legitimate interest + your consent at the point of filing.

Request metadata — IP address, browser user-agent, and request timestamps for a short window to support rate limiting and debugging. Typically purged within 30 days.

  • Legal basis: Legitimate interest (security, abuse prevention).

Attribution data — when you arrive at our marketing site via a link or ad, we record a first-touch attribution cookie (mt_attr) on .mytesla.io containing the referral source, medium, campaign, any ad click identifiers (e.g. utm_*, gclid), and the referring page. We read it once when you create an account to record which channel you came from. It's a first-party cookie, set without consent only outside the EEA/UK/Switzerland; within those regions it is set only after you accept the cookie banner.

  • Legal basis: Legitimate interest (understanding which channels work) — consent within the EEA/UK/Switzerland.

3. What we DO NOT collect

  • We don't track you across other websites — no third-party advertising cookies, and no analytics at all on the signed-in app/portal at mcp.mytesla.io. (Our public marketing site, mytesla.io, uses Google Analytics, which sets analytics cookies only after you accept the cookie banner — see "Who we share with" below — and Cloudflare Web Analytics, which is cookieless and collects no personal data.)
  • We don't read or store your Tesla's charge history, drive history, or navigation history beyond the single live snapshot requested by a tool call.
  • We don't sell your data to anyone. Ever.
  • We don't train AI models on your conversations, tool calls, vehicle data, or bug reports.

4. Who we share with

We share data only with the third parties required to run the Service:

Provider What they get Why
Cloudflare All of the above, as our hosting provider We run our service on Cloudflare
Stripe Your email, Stripe customer ID, billing events Payment processing
Cloudflare Email Your email + the one-time code we send you Transactional email delivery
Tesla Your Tesla-issued OAuth token (on each request) Live vehicle data and commands
Google Analytics Anonymous usage events on the marketing site, only after you accept the cookie banner Understand how the marketing site is used

We do not share personal data with anyone else unless compelled by valid legal process or a court order. If that happens we'll notify you unless the order forbids it.

5. How long we keep it

  • Account data: as long as you have an account. Deleted within 30 days of account closure.
  • Tesla tokens: until you disconnect, or until they expire.
  • Tool-call logs: 12 months rolling — older rows are deleted.
  • Financial events (invoices, payments): 7 years, because accounting rules.
  • Bug reports: 12 months after the status becomes "fixed", "duplicate", or "invalid".
  • Request metadata logs: 30 days.

6. Your rights

Depending on where you live, you have some or all of these rights:

  • Access — get a copy of your data. You can self-serve from Account → Download my data on the dashboard. The download is a summary: profile, current subscription and credit balance, billing events with Stripe invoice IDs (so you can reconcile with your receipts), usage totals by category and by day, bug reports you've filed, and waitlist entries. Individual per-call records are aggregated into daily totals rather than itemised.
  • Correction — fix anything inaccurate.
  • Deletion — ask us to remove your account. You can self-serve at Account → Delete my account. Email, display name, Tesla connection tokens, and active sessions are erased immediately. Your anonymised usage, billing, and bug-report history is retained for aggregate business analytics, tax / accounting, and to keep the bug tracker useful — but it's no longer linked to you personally, and we cannot recover the deleted identity. Active subscriptions cancel at the end of the current billing period per our billing policy.
  • Portability — the self-serve export above is structured JSON, machine-readable.
  • Object / restrict — tell us to stop or limit certain processing, if possible to do so.
  • Withdraw consent — for anything based on consent, you can withdraw at any time.

Email support@mytesla.io with any request the self-serve flows don't cover. We'll respond within 30 days.

7. Security

  • All traffic is HTTPS-only.
  • Passwords don't exist — we use one-time email codes instead.
  • Tesla tokens and Stripe secrets are stored encrypted at rest.
  • Session cookies are HttpOnly, Secure, and SameSite=Lax.
  • Rate limits on login and signup block brute-force attempts.

If we ever suffer a breach that affects your data, we'll notify you within 72 hours as required by law.

8. Children

The Service isn't directed at anyone under 18 and we don't knowingly collect data from them. If you believe we have data on a child, email us and we'll delete it.

9. International transfers

We operate on Cloudflare's global network; your data may be processed in any region Cloudflare operates. Cloudflare's data processing agreement covers cross-border transfers.

10. Changes to this policy

If we make material changes (new data types, new providers, longer retention), we'll email you at the address on your account at least 14 days before the change takes effect.

11. Contact

Questions? Complaints? Data requests?

Email: support@mytesla.io

← Back to home