Teslr
PrivacyTermsSupport

Your data / kept minimal

Privacy Policy

Effective and last updated August 4, 2026

What this policy covers

This policy explains how Teslr handles information when you visit teslr.club, connect a Tesla account, use the Teslr API or skill, or request support. Teslr is designed to retain as little vehicle and account information as practical.

Information Teslr processes

  • Direct Tesla connections. Tesla OAuth access and refresh tokens, granted scopes, token expiration times, Fleet region, and connection timestamps are stored so Teslr can serve your requests. OAuth tokens are encrypted at rest. Teslr stores only a one-way hash of the Teslr connection token issued to you and a keyed one-way hash of Tesla's account subject so a reconnect does not create a different fair-use identity.
  • Vehicle and energy data. State, location, history, charging, driver, invitation, and energy information is requested only when needed to answer or perform your request. Teslr does not intentionally persist provider response bodies, trip histories, precise locations, VINs, plates, or command payloads in its application database or operational logs.
  • Response minimization. Teslr removes person names, contact fields, user-defined energy-site labels, addresses, coordinates, and other precise-location values from API responses by default. A user-defined vehicle name is returned to the authenticated assistant as target-resolution context so a request such as “open Carla's trunk” can select the correct vehicle. The Teslr skill instructs the assistant to repeat that name only when the user asks for it or uses it to identify the vehicle in the same request. Uninspectable maps, invoices, and other binary responses fail closed. An authenticated caller may request other personal data for one explicitly authorized private response; this exception must not be used on a public timeline or in a shared conversation.
  • Tessie compatibility. If you use a Tessie token, Teslr forwards it only for the current request and does not store it.
  • Place search. When you ask for a nearby destination, Teslr sends a rounded search origin and your place query to fixed OpenStreetMap search services. Teslr does not send your credential, VIN, vehicle name, or exact origin to those services.
  • Security and fair-use information. Teslr may retain one-way hashes derived from a connection token, stable Tesla account, or network address plus timestamped request categories and counters for abuse prevention, fair-use limits, and cost measurement. General security counters expire within seven days; beta fair-use events are eligible for deletion within 35 days.
  • Privacy-preserving usage analytics. When beta analytics are enabled, Teslr stores UTC daily aggregate counts for completed Tesla connections, successful, failed, and uncertain requests, provider, safe operation category, and total response time. It also stores short-lived, separately keyed one-way markers to count active Tesla and Tessie connections, connected accounts that have not yet made a Teslr request, vehicles served, and energy sites without retaining a raw provider token, vehicle identifier, VIN, account identity, location, request body, or provider response. Tessie usage counts toward these aggregates even though Tessie requests do not consume Teslr fair-use events.
  • Infrastructure request metadata. Hosting and security providers may process a network address, user agent, timestamp, request method, and request URL for delivery, abuse prevention, and troubleshooting under their own retention policies. A request URL can include an opaque Teslr resource id, a user-supplied place-search term, or Tesla's short-lived OAuth callback parameters. Teslr does not intentionally place an authorization header, provider token, exact vehicle coordinates, command body, or provider response body in an application log.
  • Beta fair use. Teslr stores pseudonymous, timestamped categories for broad routes and actual Tesla Data, Command, and Wake requests, plus temporary cooldown or manual-access status. These use the keyed Tesla-account hash described above rather than a VIN, email, raw account subject, or vehicle as the owner. No location, destination, command body, or provider response is stored in fair-use events. Dormant service-credit records may be retained for reconciliation and a possible future paid service, but are not charged during the free beta.
  • Essential cookies. Teslr uses a short-lived, secure OAuth state cookie during Tesla connection. Infrastructure providers may set essential security or bot-protection cookies.

How information is used

Teslr uses information to authenticate your connection, retrieve requested data, send commands you authorize, protect the service, prevent abuse, troubleshoot generic service failures, and comply with applicable law. Teslr does not sell personal information or use vehicle data for advertising.

Service providers and disclosures

Information is processed by Tesla or Tessie when you choose that connection, by OpenAI Sites and Cloudflare for hosting and security, and by OpenStreetMap services only for requested place searches. Teslr may disclose information when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards.

Retention and deletion

Direct Tesla credentials remain until you disconnect Teslr, the credentials expire, or retention is otherwise required by law. One-use OAuth state expires after ten minutes. Security counters are short-lived. Analytics subject markers expire after 35 days; daily aggregate counters may be retained to measure adoption, reliability, and provider mix over time. Teslr application logs are limited to generic failure and service-health metadata. Infrastructure request logs are controlled by the hosting and security providers described above.

Credit ledger and promotional-grant records may be retained for accounting, replay prevention, security, dispute handling, and legal compliance. Disconnecting a provider credential does not automatically erase those pseudonymous billing records.

To delete a direct connection, privately ask your AI assistant to “disconnect Tesla from Teslr,” confirm the request, and removeTESLR_FLEET_TOKEN from its secure settings. You may also remove Teslr from Tesla's third-party app access. For Tessie, remove TESSIE_API_TOKEN and revoke or rotate it through Tessie.

Security

Teslr uses HTTPS, encrypted Tesla credentials, hashed connection tokens, fixed provider allowlists, non-cached API responses, and a secret-authenticated command signer. No system is perfectly secure. If you believe a token was exposed, follow the steps on the support page immediately.

Your choices and contact

You may disconnect at any time and may ask about access, correction, or deletion rights available under applicable law. Contact @TeslrBot on X without posting a token, account linkage, VIN, plate, account identity, or vehicle location. Teslr is not intended for children under 18. Material policy updates will be posted here with a revised date.

Teslr is independent software and is not affiliated with, endorsed by, or sponsored by Tesla, Bankr, Robinhood, Tessie, X, or any other company referenced here. All trademarks belong to their respective owners.

@TeslrBot