Security and data
What we read, what we keep, and why the score holds.
BattGrade handles two kinds of data: what the app reads from the car, and the details an inspector enters for a customer. This page explains both in plain words. The privacy policy and the methodology give the full text.
In the car
The app only reads.
The app sends standard OBD2 requests (modes 01 and 09), manufacturer data reads (services 21 and 22) and one identification read that gives the VIN on some Hyundai and Kia models. It blocks any other request before it reaches the adapter.
- It does not write to the car
- It does not clear fault codes
- It does not reset any control unit
- It never writes to the adapter's stored configuration
What it reads, depending on the model
- The SoH reported by the battery management system, the charge level and, where available, energy and capacity
- Cell voltages and battery temperatures
- The insulation resistance of the high voltage system
- Lifetime energy counters and charge counts, where the car stores them
- The VIN, the odometer and the model year
What we keep
The data, and where it lives.
Test data
The readings, the result and the raw data of every test: each request sent to the car and each response. The server recomputes the score from this raw data.
Certificates
The public data of each certificate: the vehicle, the result, the readings, the inspector and their company. This is what the verification page shows.
Customer details
The customer's name, email and language, entered by the inspector to deliver the certificate. They are private and do not appear on the public page or in the public PDF.
Technical reports
When a test fails, or when the inspector reports a problem, the app sends a report: the communication with the car, the VIN, the readings, details of the adapter, the app and the phone, and any note. During the testing period, the app also sends these reports after successful tests, to help us improve the readings. We use these reports only to diagnose and fix problems.
Where
Our database runs on servers in the European Union, in Germany. Company logos printed on certificates are stored in Cloudflare R2. Connections to our servers and to the app are encrypted (HTTPS), and we do not sell personal data.
How long
How long we keep it.
- Technical reports
- Up to 12 months, then deleted.
- Certificates and their tests
- Kept so that verification keeps working. You can ask us at any time to export or delete personal data.
- Customer details
- They are not part of the signed data, so they can be deleted on request without breaking the certificate's verification.
- Website visits
- No cookies. Visits are counted in aggregate with Plausible, which we host ourselves.
Why the score holds
Nobody can type the score in.
The server recomputes the result
The app sends the raw data with each test. Our server runs the same decoding and scoring code, and the certificate is issued from the server's result. If the app's result or readings do not match, no certificate is issued.
A demo test cannot become a certificate
Tests run in the app's demo mode use synthetic data and can never become certificates.
Signed, and checked on every visit
Each certificate's public data is hashed with SHA-256 and signed with an ECDSA P-256 key. The verification page recomputes the hash and checks the signature every time it opens, and our public keys are published.
Customer data is not signed and not public
Customer details are not part of the signed data and never appear on the public page.
The VIN is partly hidden
On the public verification page, part of the VIN is hidden to protect the owner's privacy.
Nothing is edited after issue
A certificate cannot be changed once it is issued. A mistake is handled by revoking it, and the verification page then shows it as revoked.
The full text
Questions, answered.
No. It sends read-only diagnostic requests and blocks any other request before it reaches the adapter. It does not write to the car, clear fault codes or reset any control unit.
The inspector's company, in its test history, and BattGrade, which uses it to deliver the certificate. It does not appear on the public page, in the public PDF or in the signed data.
Our database runs on servers in the European Union, in Germany. Company logos printed on certificates are stored in Cloudflare R2.
Write to [email protected]. Customer details can be deleted without breaking a certificate's verification, because they are not part of the signed data. The GDPR page explains your rights.