Privacy Policy
Last updated: April 2026
About this policy
Mechanic Frank is operated by HeyJoe. We take your privacy seriously — especially given that you're uploading photos and details of a car you're considering buying. This policy explains clearly what we collect, what we do with it, and what we don't do.
This policy is written to comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
What we collect
We collect only what's necessary to deliver your report:
- Your email address — so we can deliver your completed report. We don't send marketing emails unless you explicitly opt in.
- Car listing photos and/or listing text — these are processed by our AI to generate your report. They are deleted after report generation is complete.
- Payment details — handled entirely by Stripe. We never see or store your card number. Stripe is PCI-DSS compliant.
Photos and listing data — the full story
We use OpenAI's GPT-4o model to analyse your listing. When we send your images to OpenAI for analysis, OpenAI processes them under their API data usage policy, which specifies that API inputs are not used to train OpenAI's models. You can review OpenAI's privacy policy at openai.com/privacy.
We do not sell, licence, trade, or share your listing data with any third party for any purpose other than AI processing to generate your report.
Cookies and analytics
We use a minimal analytics beacon to count page visits. This records anonymous visitor counts only — no personal data, no behavioural tracking, no cross-site tracking, no advertising profiles.
We do not use advertising cookies. We do not use Meta Pixel, Google Analytics, or any third-party behavioural tracking tools.
How we use your email
Your email address is collected when you purchase a report. We use it to:
- Deliver your completed report link
- Send transactional emails related to your purchase (e.g. receipt confirmation)
We do not add you to marketing lists without your consent. If you receive an unwanted email from us, contact us at heyjoe@polsia.app and we'll remove you immediately.
Data storage and security
Our servers are hosted in the United States via Render (render.com), with data in transit protected by TLS/HTTPS. Payment processing is handled by Stripe's PCI-DSS compliant infrastructure.
We retain your email address and report records (not the listing photos) to allow you to retrieve your completed report if needed. You can request deletion of your data at any time by contacting us.
Your rights under Australian Privacy law
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your personal information
- Complain if you believe your privacy has been breached
To exercise any of these rights, contact us at heyjoe@polsia.app. We will respond within a reasonable time, and no later than 30 days.
If you're not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Changes to this policy
We may update this policy from time to time. Any material changes will be noted with an updated date at the top of this page. Continued use of Mechanic Frank after a policy update constitutes acceptance of the updated terms.
Contact us
Questions about this privacy policy? We're happy to explain anything plainly.
Email us at heyjoe@polsia.app