PRIVACY POLICY
Your data is used to provide your protection.
This page describes processing in the current version of SentinelMax. Optional features remain inactive until they are configured or authorized.
Controller and contact
The publisher of SentinelMax is responsible for the processing described here. For any question or request concerning your data, email contact@sentinelmax.fr.
Data we process
- Account and Tesla authorization: technical Tesla identifier, encrypted OAuth tokens, and granted permissions. SentinelMax does not receive your Tesla password.
- Vehicle: VIN, technical identifier, name, model, configuration, connectivity status, and capabilities.
- Security: preferences, relevant telemetry and status, supported events, requested actions, processing acknowledgements, and incident reports.
- Location: vehicle location and observations of iPhone presence only when a dependent feature is enabled and authorized. Presence observations are short-lived.
- Notifications: device push token, platform, and language.
- Subscription: product, transaction identifier, and status when server verification is used. Apple processes payment.
- Optional product analytics: limited usage events, without VIN, vehicle name, location, email, alert content, or command results.
Why we process it
This data is used to connect the requested account, display vehicles, receive and present available security signals, send selected notifications, perform explicitly requested actions, personalize protections, maintain service security, and provide support. Core features are performed at your request; iOS and Tesla permissions also depend on your choice.
Recipients and service providers
- Tesla: authentication, Fleet API, telemetry, and compatible commands.
- Apple: app distribution, in-app purchases, iOS notifications, and system permissions.
- Expo: technical delivery of push notifications.
- Hosting providers: server infrastructure, PostgreSQL, and Redis required for the service.
- PostHog: product analytics only if configured; session replay and IP geolocation are disabled in the app.
- Meta and TikTok: advertising attribution only if their SDKs are configured and after your Apple tracking consent. Events are limited to the acquisition journey and, where applicable, plan type.
SentinelMax does not sell your personal data. Sensitive Tesla data, VIN, location, and alert content are not sent to analytics or attribution tools by the app’s logic.
Cameras
The official Fleet API used by SentinelMax does not provide camera streams to the app. SentinelMax therefore does not collect vehicle video through this API.
Retention
SentinelMax sessions expire after 90 days. Mobile codes expire after 2 minutes and OAuth requests after 10 minutes. Presence observations normally expire after 5 minutes and are periodically purged. Other account data is retained while the account is active or for as long as required to provide the service and meet its obligations; the service does not define a shorter fixed period for security history.
Security and deletion
Tesla tokens are encrypted server-side, sessions are stored in hashed form, and client roles are denied direct access to application tables. You can delete your account in the app; associated records are deleted through cascading deletion. Technical backups may remain temporarily according to the hosting provider’s backup cycle.
Your rights
Depending on your circumstances, you may request access, correction, deletion, restriction, or portability of your data, and object to certain processing. Email contact@sentinelmax.fr. You may also lodge a complaint with the CNIL, the French data protection authority. You can withdraw permissions in iOS, revoke SentinelMax in Tesla, and decline advertising tracking without losing features that do not depend on it.
Independent app. SentinelMax is independent from Tesla, Inc. and is not endorsed or sponsored by Tesla.