← Home ·
TACHKA Privacy Policy
Last updated: 2026-08-07
This Privacy Policy explains how Росляков Анатолий Николаевич (Roslyakov Anatoliy Nikolaevich) (referred to as "TACHKA," "we," "us," or "our") collects, uses, stores, and protects information when you use the TACHKA mobile application and related services.
TACHKA is a vehicle expense tracker and AI assistant for car owners. It helps you record expenses, view in-app statistics, chat with an AI consultant about your vehicle, and scan receipts. TACHKA is not a bank, payment service, lender, broker, investment platform, tax advisor, or financial advisor. We do not process, hold, transfer, or move user funds.
By using TACHKA, you acknowledge that you have read this Privacy Policy. Where consent is required for optional processing, we request it separately.
1. Information We Collect
1.1 Account Information
- Email address
- First and last name
- Hashed password (stored on the server; we never store plain-text passwords)
- Internal user/account identifier
- Telegram identifier and authentication proof when you sign in with or link Telegram
- Email verification address, one-time code record, status, and expiry time
We do not collect a phone number as part of registration.
1.2 Vehicle and App Data You Provide
- Vehicle profile: make, model, year, engine, transmission, power, mileage, region
- Expense records: category, amount, date, optional liters and notes
- "Memory" facts about a vehicle (for example maintenance notes, diagnostics, preferences)
- Chat messages you send to the AI assistant and assistant replies
- Custom categories you create
- App and server settings: theme, brand color, language, currency, distance and volume units, onboarding state
- Receipt photos you choose to scan (processed in memory; see section 5)
1.3 AI, OCR, and Voice Input
- Text chat: your question and recent dialogue context are sent to our backend and then to our AI provider (see section 5).
- Receipt OCR: a photo you select is uploaded to our server, converted to text on the server, and the extracted text (not the image) is sent to our AI provider to fill expense fields. The original photo is not stored in our database.
- Voice input: if you use voice, audio is processed by your device operating system (Apple or Google speech recognition). Only the recognized text is sent to our API. We do not receive or store raw audio recordings.
1.4 Usage Limits
TACHKA runs in Unlimited mode: there are no paid subscription tiers. Fair-use limits apply to AI-heavy features:
- up to 100 AI chat requests per day;
- up to 5 receipt scans per day.
We also store daily usage counters for these features and companion progress points for in-app gamification. Actual limits may vary and can be adjusted on the server for stability or abuse prevention; the app shows applicable limits where relevant.
1.5 Device and Technical Data
- Network connectivity status (online/offline) on the device, used only to enable offline cache behavior
- HTTP request metadata on our servers: method, URL path, response status, request duration
- IP address may appear in standard server or hosting logs
- Operational AI/OCR metrics linked to internal user and vehicle IDs: model, character/token counts, result counts, timings, status, and confidence; not full message or receipt text
1.6 What We Do Not Collect
TACHKA does not use third-party product analytics SDKs (such as Firebase Analytics, Amplitude, Mixpanel, or similar). We do not use dedicated crash-reporting SDKs (such as Sentry or Crashlytics). We do not request or collect:
- precise or coarse location / GPS;
- push notification tokens;
- contacts or address book;
- biometric data;
- SMS or call logs;
- advertising identifiers for cross-app tracking.
The in-app "Analytics" screen shows statistics about your vehicle expenses calculated from data you entered. It is not third-party behavioral tracking.
2. How We Use Information
We use data to:
- create and secure accounts and issue access tokens;
- store and sync your vehicles, expenses, memory facts, and chat history;
- provide AI chat and receipt scanning features;
- enforce fair-use limits in Unlimited mode (AI requests and receipt scans);
- calculate in-app expense statistics and export;
- maintain offline cache on your device when network is unavailable;
- operate, secure, and troubleshoot the service;
- prevent abuse and comply with legal obligations.
We do not sell personal data.
2.1 Legal Bases
Depending on applicable law, we process data to perform our contract with you (accounts and requested app features), to comply with law, with your consent for optional permissions or processing where required, and for legitimate interests such as service security, abuse prevention, diagnostics, and reliability. You may withdraw consent for optional processing through device settings or by no longer using the feature; this does not affect earlier lawful processing.
3. Data Stored on Your Device
| Storage | What is stored |
|---|---|
| Secure storage | Access token (JWT), token type, login timestamp, token expiry metadata |
| App preferences | Theme, language, brand color, onboarding flags, and other non-secret settings |
| Offline cache | Cached vehicle list, memory facts, and chat history per vehicle when offline |
Receipt photos are kept only temporarily while you select and upload them; they are not written to permanent local app storage as part of normal operation.
4. Data Stored on Our Servers
Account and app data are stored in a PostgreSQL database hosted in RU / Timeweb Cloud. Main data categories:
| Category | Examples |
|---|---|
| Account | Email, name, password hash, user ID, timestamps |
| Authentication | Telegram ID/link state; email verification code hash or record, status, and expiry |
| Vehicles | Make, model, year, engine, transmission, power, mileage, region, active flag |
| Expenses | Category, amount, liters, date, notes, vehicle link |
| Memory facts | Category and text associated with a vehicle |
| Chat | Message role, text, confirmation flags, structured action metadata |
| Usage counters | Daily AI request and receipt scan counts |
| Companion | Points and action history for in-app gamification |
| Configuration | Runtime feature limits (for example daily AI/OCR caps) |
| Operational metrics | Internal user/vehicle IDs, model, counts, timings, confidence, and status for AI/OCR operations |
Not stored on servers: original receipt image files, raw microphone audio.
5. AI and OCR Processing
TACHKA uses DeepSeek (DeepSeek API) as the large language model provider for:
- AI chat: vehicle profile, memory facts, up to three recent dialogue turns (truncated), the current date anchor, and your question;
- Receipt parsing: text extracted from a receipt (up to about 2,500 characters), not the photo itself.
Receipt text recognition (OCR) runs on our own server using PaddleOCR. Model files may be downloaded from Hugging Face during server setup or updates; user photos are not sent to Hugging Face.
AI responses may include suggested memory updates or expense entries. These are applied only after you confirm them in the app.
OCR responses may include a short preview of recognized text (about 280 characters) for your review; the full receipt image is not retained.
We do not use your content to train a TACHKA-owned model. DeepSeek's processing, retention, caching, and any model-improvement use are governed by its Open Platform terms and privacy policy. Do not submit unnecessary sensitive data or third-party personal data to AI features.
6. Third-Party Providers
| Provider / category | Purpose | Data potentially processed |
|---|---|---|
| Timeweb Cloud (hosting / database) | Run API, store account and app data | All server-side data listed in section 4; request metadata and IP in hosting logs |
| DeepSeek API | AI chat and receipt field extraction | Prompts containing vehicle data, memory facts, chat context, receipt text, and your messages |
| Resend | Deliver verification and service email | Email address, message subject/content, delivery metadata |
| Telegram | Sign-in, account linking, Mini App operation, and optional support chat | Telegram identifier and signed authentication data; support messages you choose to send |
| Yandex Mail | Receive and respond to support/privacy requests | Your email address and message contents |
| Hugging Face | Download OCR model weights to our server | No user content; infrastructure/model files only |
| Apple / Google (device OS) | Speech-to-text when you use voice input | Audio may be processed on-device or by the OS provider according to device settings and provider terms; we receive text only |
| External browser (via link) | Open support, privacy, or terms pages | Standard web browsing data to the opened site |
Provider privacy pages:
- DeepSeek — https://www.deepseek.com/privacy
- Timeweb Cloud — https://timeweb.cloud/
- Hugging Face — https://huggingface.co/privacy
- Resend — https://resend.com/legal/privacy-policy
- Telegram — https://telegram.org/privacy
We do not currently integrate third-party product analytics, crash reporting, or push notification services.
7. Server Logs
Our API logs each request's HTTP method, path, response status, and duration. These logs do not intentionally include request bodies, chat text, or JWT tokens. Separate operational logs for chat and OCR may include internal user/vehicle IDs, model, character/token and result counts, timing, status, and confidence, without full user message or receipt text.
8. Data Storage and Security
- Primary data region: RU / Timeweb Cloud
- HTTPS/TLS in transit between app and API
- Passwords stored as hashes only
- Restricted production access
- Reasonable technical and organizational safeguards
Authentication tokens are stored in OS-protected secure storage, not ordinary app preferences. AI requests to DeepSeek involve international processing as described in section 12.
No method of transmission or storage is absolutely secure.
9. Data Retention and Deletion
You may delete your account in the app or submit a web/email request at https://support.tachka.site/delete-account.html. Account deletion removes active account data and linked vehicles, expenses, memories, chats, counters, and settings, subject to data that must be retained by law or for security claims.
- In-app deletion: active database deletion starts when the confirmed request succeeds
- Manually verified email requests: target completion within 30 days
- Security/fraud logs: may be retained for up to 12 months when necessary
- Backups, if enabled: removed on the normal rotation cycle, no later than 90 days
- Email verification codes become invalid at expiry and are retained only as operationally necessary
Aggregated or anonymized data that can no longer identify you may be retained longer.
10. App Permissions
Permissions are requested only when a feature requires them. You can deny optional permissions; related features will not work.
Android
| Permission | Purpose | Required |
|---|---|---|
INTERNET | Connect to TACHKA API and AI-backed features | Yes |
RECORD_AUDIO | Voice input in chat | Optional |
BLUETOOTH, BLUETOOTH_ADMIN, BLUETOOTH_CONNECT | Microphone/headset access for voice input on some devices | Optional |
CAMERA | Take a photo of a receipt | Optional |
READ_MEDIA_IMAGES | Pick a receipt image from gallery (Android 13+) | Optional |
READ_EXTERNAL_STORAGE (API 32 and below) | Pick a receipt image from gallery on older Android versions | Optional |
iOS
| Permission | Purpose | Required |
|---|---|---|
Microphone (NSMicrophoneUsageDescription) | Voice input in chat | Optional |
Speech Recognition (NSSpeechRecognitionUsageDescription) | Convert speech to text using OS speech services | Optional |
Camera (NSCameraUsageDescription) | Take a photo of a receipt | Optional |
Photo Library (NSPhotoLibraryUsageDescription) | Choose a receipt image from gallery | Optional |
Not requested: location, push notifications, contacts, biometrics, files beyond photo access for receipts.
11. Your Privacy Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, port, restrict, or object to processing, and to withdraw consent where applicable.
Contact: s.tachka@yandex.ru
12. International Transfers
Primary storage and processing of account and app data occur in Russia (Timeweb Cloud). DeepSeek processes AI prompts through infrastructure that may be located in the People's Republic of China or other jurisdictions identified by DeepSeek. Resend and Telegram may process authentication, email, or support data in the jurisdictions where they operate. Where required, we rely on contractual arrangements, consent, or another lawful transfer mechanism and limit transferred data to what the requested feature needs.
13. Children's Privacy
TACHKA is intended for users aged 16 and older. This 16+ recommendation reflects the app's target audience of current and prospective drivers and car owners; it is not based on adult-only or otherwise harmful content. We do not knowingly seek personal data from users under 16. If you are 16 or 17, use the service only with authorization from a parent or legal guardian where applicable law requires it.
14. Policy Changes
We may update this policy and change the "Last updated" date. Material changes may be communicated in the app or by email where appropriate.
15. Contact
- Email: s.tachka@yandex.ru
- Support URL: https://support.tachka.site
- Privacy URL: https://support.tachka.site/privacy.html
- Account deletion: https://support.tachka.site/delete-account.html