01
Overview
Marque is designed as a local-first application with optional accounts. You can use Marque in guest mode without registering.
Guest mode remains device-based. If you sign in, Marque provides basic cloud backup and synchronization for supported Garage and account data. This cloud backup is an account feature and is not restricted to a Marque+ subscription.
Some product state remains only on your device even when you are signed in. The categories of cloud-backed and device-local data are described below.
Marque does not currently provide friends, communities, a social graph, public profiles, or a global leaderboard.
Some features, including vehicle identification, analytics, crash reporting, and subscription management, use third-party services as described below.
02
Information We Process
Depending on how you use Marque, we may process the following categories of information:
- photos you choose to submit for vehicle identification;
- technical information required to process an identification request;
- optional account and authentication information, including your email address, authentication or provider identifiers, Supabase account UUID, session information needed to sign in or restore a session, display name, and avatar;
- cloud-backed Garage and account data for signed-in users;
- pseudonymous app and installation-related identifiers;
- app usage and interaction events;
- diagnostic and crash information;
- subscription and purchase status;
- device-local scan, reward, cache, Pending Spot, onboarding, and installation state.
Creating an account is optional. Marque supports Google Sign-In and passwordless email sign-in through Supabase Auth. Guest mode remains available without registration.
Account ownership is based on the authenticated Supabase user identity and UUID. Depending on the sign-in method you choose, Supabase and the selected authentication provider process the identifiers and session information needed to authenticate you and restore your session. Marque does not receive your Google password or an email account password.
The authenticated account identity is used for account functionality, cloud backup and restore, cross-device synchronization, and preservation of durable collection state. It may also provide the foundation for future account features if they are introduced; it is not currently used to provide friends, communities, a social graph, public profiles, or a global leaderboard.
For signed-in users, cloud-backed durable account state may include Garage collectible records, vehicle and card metadata required to restore collectibles, favorites, backed-up Garage display images, achievement unlock IDs, highest-rank floor, earned reward IDs, equipped frame, equipped title, equipped poster style, display name, and avatar.
03
Images and Vehicle Identification
Vehicle identification processing
When you choose to identify a vehicle, Marque processes the selected image for the purpose of recognizing the car.
Images may originate from:
- the device camera after you explicitly choose to take a photo; or
- a photo selected through the device’s system photo picker.
Marque sends a prepared version of the image through a Supabase Edge Function to Google Gemini for vehicle identification.
The Gemini API credential is held by the backend and is not embedded in the Marque mobile application.
Marque may generate a SHA-256 cryptographic hash of image content to support duplicate detection, replay protection, caching, and scan-economy safeguards. A cryptographic hash is not a copy of the image itself.
Marque does not store raw images, base64 image content, prompts, model responses, or raw IP addresses in its backend telemetry.
Successful identification results may be stored temporarily in bounded caches so that an identical image can reuse a previous successful result instead of causing another AI request.
Third-party providers involved in image processing may process information in accordance with their own privacy and security practices.
Garage cloud image backup
For signed-in users, a processed or display representation of a Garage image may be stored in private Supabase Storage for cloud backup and restore.
This Garage display-image backup is separate from the image processing used for Google Gemini vehicle identification. Marque does not upload the raw camera or gallery acquisition original as the Garage backup image.
04
Analytics
Marque uses PostHog EU to understand how the app is used and to improve product behavior, reliability, onboarding, identification flows, collection features, and monetization experiences.
Analytics may include events such as:
- app and feature usage;
- onboarding progress;
- identification attempts and outcomes;
- collection actions;
- scan-economy events;
- sharing actions;
- subscription-related interactions.
Where currently instrumented, analytics may also include account or cloud lifecycle events needed to understand those flows.
Marque’s analytics implementation is designed not to send:
- raw images;
- sensitive prompt or response content;
- passwords, authentication secrets, or session tokens;
- raw profile information intentionally provided as personally identifying data.
Analytics information may include pseudonymous technical identifiers and event metadata necessary to understand app usage.
05
Crash Reporting
Marque uses Sentry for crash and unexpected-error reporting.
Diagnostic information may include technical details such as:
- app version;
- device or operating-system information;
- error type;
- stack traces;
- technical context associated with a failure.
The current Marque configuration does not intentionally include screenshots or performance tracing as part of crash reporting.
Marque does not intentionally include raw personally identifying profile information in crash reports.
Crash reporting is used to diagnose defects, improve reliability, and maintain the security and stability of the app.
06
Purchases and Subscriptions
Marque offers optional Marque+ subscriptions.
Subscription purchases are processed through Google Play on Android. Marque also uses RevenueCat to manage subscription entitlement state and purchase-related integration.
Marque does not directly receive or store your full payment-card details.
Google Play and RevenueCat may process purchase-related information according to their respective privacy policies and service terms.
Marque may receive information necessary to determine whether a valid Marque+ entitlement is active, such as purchase status, product information, and entitlement state.
Marque+ entitlement is separate from eligibility for basic account-based cloud Garage backup and synchronization.
Deleting a Marque account does not automatically cancel a Google Play subscription. Google Play subscriptions must be managed or canceled separately through Google Play.
See Account Deletion for the separate account deletion process.
07
Local Storage
Marque stores substantial product data locally on your device. The following state remains device-local and is not included in cloud Garage backup:
- scan wallet and regeneration state;
- Spot Reserve state;
- rewarded history and limits;
- scan transactions;
- exact-image cache;
- Pending Spots and locally managed Pending Spot images;
- onboarding state;
- technical installation state;
- reward-presentation markers.
A guest Garage is also device-local unless and until the user creates or connects an account through Marque’s account migration flow.
For guest mode, clearing application storage, resetting local data, or uninstalling Marque may permanently remove local-only information. For signed-in users, supported cloud-backed Garage data may be restored after reinstalling Marque and signing in again; device-local categories are not restored from cloud backup.
08
Data Retention
Marque retains information only for as long as reasonably necessary for the purposes described in this Policy, subject to the nature of the information and the systems involved.
Device-local data
Device-local application data generally remains on your device until one of the following occurs:
- you delete or reset the relevant data through Marque;
- you clear the application’s storage;
- you uninstall the application;
- the app removes data as part of its normal lifecycle.
Pending Spot images remain locally managed until they are deleted, converted through the normal identification flow, removed through an applicable reset action, or removed with the application’s local data.
Cloud account data
Cloud-backed account data is retained while the account and cloud functionality are used and until user deletion, account deletion, or other legitimate lifecycle cleanup. Completing the account deletion flow permanently deletes the account-owned cloud data described in the Data Deletion section.
Identification, cache, and operational data
Backend identification caches are bounded and use limited retention periods rather than permanent storage.
Third-party data
Analytics, diagnostic, subscription, and other data handled by third-party providers may be retained according to our service configuration and the applicable provider’s retention practices.
Legitimate retention exceptions
Limited information may be retained where reasonably necessary for security, fraud or abuse prevention, legal or regulatory compliance, dispute resolution, or protection of the service.
09
Data Deletion
Signed-in users can permanently delete their Marque account from within the app. Account deletion is deletion, not an account freeze or deactivation.
The deletion flow removes associated account-owned cloud data, including Garage cloud rows and collectible restore metadata, backed-up Garage display images, cloud progression and achievement unlocks, highest-rank floor, earned rewards, equipped frame, title and poster style, display name and avatar, and the associated Supabase Auth account.
Account deletion does not automatically cancel a Google Play subscription. Any active subscription must be managed or canceled separately through Google Play.
Device-local scan wallet and regeneration state, Spot Reserve, rewarded history and limits, scan transaction state, exact-image cache, Pending Spots and their locally managed images, onboarding state, technical installation state, and reward-presentation markers are not part of cloud account deletion. You may remove local Marque data using available in-app controls, by clearing application storage, or by uninstalling the app.
See the public Account Deletion page for in-app instructions and an outside-the-app request path. If you cannot access Marque, you may start an account deletion request by contacting marq.support@gmail.com.
We may need to verify account ownership before processing an external deletion request. Never send passwords, one-time passcodes (OTP codes), magic-link tokens, session tokens, or other authentication secrets by email.
Some pseudonymous analytics or diagnostic records may not be reasonably linkable to a specific account or individual.
Information controlled independently by third-party providers may also be subject to those providers’ own deletion procedures.
10
Sharing of Information
Marque does not sell your personal information.
Information may be shared with service providers only where necessary to operate the relevant features of the application.
Current service providers may include:
- Supabase — authentication, database, private Storage, Edge Functions and backend infrastructure, cloud Garage and account functionality, and vehicle-identification request handling;
- Google — Google Sign-In authentication when you choose that sign-in method;
- Google Gemini — AI-assisted vehicle identification;
- PostHog EU — product analytics;
- Sentry — crash and error reporting;
- Google Play — Android application distribution and purchase processing;
- RevenueCat — subscription and entitlement management.
We may also disclose information where required by law, legal process, or where reasonably necessary to protect users, Marque, or others from fraud, abuse, security threats, or unlawful activity.
11
Security
We use reasonable technical and organizational safeguards intended to protect information processed by Marque.
Examples include:
- keeping provider and backend secrets out of the Flutter mobile client;
- using authenticated Supabase Auth identity to establish account ownership;
- protecting account-owned database data with Row Level Security;
- using private, user-isolated Storage policies for backed-up Garage display images;
- using an authenticated trusted-backend path for account deletion;
- using backend-controlled access to vehicle-identification providers;
- technical rate limiting, provider-attempt, and backend cost controls;
- bounded request timeouts and caches;
- minimizing sensitive raw information in telemetry;
- using cryptographic hashing where appropriate for abuse and replay protection.
No method of electronic transmission or storage can be guaranteed to be completely secure, and we cannot guarantee absolute security.
12
Children
Marque is intended for users 13 years of age and older.
Marque is not intended for children under 13, and we do not knowingly seek to collect personal information from children under 13.
If we learn that information from a child under 13 has been collected in a manner that requires deletion, we will take reasonable steps to remove it.
A parent or guardian who believes that a child under 13 has provided information to Marque may contact us at: marq.support@gmail.com
13
International Processing
Marque and its service providers may process information in countries other than the country in which you live.
Where information is processed by third-party infrastructure or service providers, those providers may operate systems in multiple regions and jurisdictions.
Their handling of information is also governed by their applicable privacy and security terms.
14
Changes to This Privacy Policy
We may update this Privacy Policy when Marque’s features, service providers, legal requirements, or data practices change.
When we make material changes, we will update the Last updated date shown at the top of this page and provide additional notice where appropriate.
We encourage you to review this Privacy Policy periodically.
15
Contact
For privacy questions, requests, or concerns relating to Marque, contact: marq.support@gmail.com