dminshark

Privacy policy

Effective 31 August 2026 · adminshark.app

AdminShark is a life-admin tracker made by AdminShark (adminshark.app). It is built around one principle: your data is yours. Your records live on your device and we never collect them. There are no accounts and no sign-in. This policy explains what that means in practice and, just as importantly, describes honestly the few places where something does leave your phone: the optional Contact tag, purchases, feedback you choose to send, and your phone's own backup.

The short version

What stays on your device

Everything you enter is stored in an encrypted database on your device only: vehicles, renewal dates, insurance details, warranties, subscriptions, costs, notes, service records, documents, IDs, investments and your diary. We cannot see any of it, and neither can anyone else without access to your unlocked phone. The app opens behind Face ID, your fingerprint or your device passcode, and the database is encrypted at rest under a key your recovery phrase protects. We have no copy of that key, so there is nothing we could hand over even if we were asked.

Photos and documents

You can attach photos to items, for example a service invoice or a warranty receipt. They are copied into the app's private storage and encrypted at rest with the same key as the rest of your data. They are never uploaded and never shared by the app. They are decrypted in memory only while you are looking at them.

Backups you export

You can export your data as a single backup file at any time. Backups are created only when you ask for one, they are encrypted, and only your recovery phrase can open them. The file is handed to you through your device's standard share or save options. Where you put it (your phone, your own cloud drive, your own iCloud folder, an email to yourself) is entirely your choice. We never receive a copy and we could not read one if we did. Restoring is equally local: the app reads the file you select and nothing more. The same is true of a vehicle file you share with a buyer: it is a file you create and send yourself, and it never passes through us.

Device backups (Google / Apple)

Separately from the app, your phone has its own built-in backup system: Google Backup on Android (to your Google Account, via Google Drive) and iCloud Backup on Apple devices. If you have this switched on, your operating system may include AdminShark's data in that backup, alongside your other apps. This is your own personal backup, stored in your own Google or Apple cloud account and protected under their terms. We are not involved: we never receive it, never see it, and cannot access it. You can review or turn it off in your device settings (on Android: Settings > Google > Backup; on iOS: Settings > your name > iCloud), and the in-app export above works regardless of that setting.

Reminders

Renewal reminders are scheduled locally on your device using its built-in notification system. Nothing about them is sent anywhere, no server is involved in deciding when they fire, and you can turn notifications off at any time in your device settings. The one kind of notification that does come from a server is a Contact tag alert, described next.

Contact tag (optional, Premium)

The Contact tag is an optional Premium feature. You print a QR sticker for your car, and someone who needs to reach you (blocking a driveway, lights left on, an alarm going) can scan it and send you a message without ever learning your phone number. This is the one part of AdminShark that uses a server we run, at tag.adminshark.app. If you never set up a tag, none of this section applies to you and nothing in it is collected.

When you create a tag, the app registers it with our relay. The relay stores, for that tag only:

It does not store your name, your phone number, your email, your number plate, your location, your IP address, or anything at all from your AdminShark records. There is no account attached to a tag.

When someone scans your sticker and writes to you, their message is encrypted in their browser before it is sent, using a key that exists only on your sticker and in your app. The relay receives ciphertext and stores it as ciphertext. It cannot read a single word, and neither can we. The key needed to open it is on your phone. Alongside the encrypted message, the relay stores a message id, the time, and the two-letter country the scan came from, which is why your app can say "Scanned in NZ". If the two of you keep talking, the relay also records when each side last opened the conversation, so the page can show "Delivered" and "Seen". That is the full extent of what we can see: that a message exists, how big it is, when it arrived, which country it came from, and whether it has been opened.

To alert you, the relay sends a push notification through Apple (APNs) on iPhone or Google (Firebase Cloud Messaging) on Android. The notification carries the encrypted message, the tag id, the time and the country. Apple and Google act as the delivery pipe and cannot read the message either. On iPhone the visible text is fixed wording that says someone contacted you about your car; on Android nothing visible is sent at all, and your phone builds the notification locally.

Because the tag is a Premium feature, when you register a tag the app sends our relay the anonymous purchase identifier that RevenueCat generated for your install, so the relay can ask RevenueCat whether your Premium entitlement is live. That identifier is random and per-install: it is not your name, your email, your device id or an advertising id, and the app has no account to attach it to. The relay does not store it. It keeps only the resulting expiry date, and holds a hashed copy in memory for ten minutes so it does not have to ask again on every request.

Our relay sits behind Cloudflare, and is hosted on Railway. As with any web server, the request logs of those services record the internet address a request came from. We do not put IP addresses in our own database and we do not use them to build a profile: they are used to rate-limit abuse and then they age out with the hosting provider's log retention.

How long Contact tag data is kept

One honest caveat: these limits are applied whenever a tag is next used, rather than by a clock running in the background. On a tag nobody is using, a record may sit a little past its window before the next request clears it.

If you scanned someone's sticker

This section is for you if you are not an AdminShark user and you have just scanned a sticker on a car. You do not need an account, an app or a phone number to use that page.

Premium purchases

AdminShark is free for your first 4 assets. If you upgrade to Premium (a monthly subscription or a one-off lifetime purchase), the payment is processed entirely by Apple's App Store or Google Play under their terms. We never see or store your payment details. To recognise your purchase across reinstalls, the app uses RevenueCat, a purchase-management service, which receives a randomly generated, anonymous app identifier and your purchase history for this app. It receives no name, no email and none of your records. You can read how RevenueCat handles this in the RevenueCat privacy policy. If you use the Contact tag, that same anonymous identifier is sent to our relay to verify your entitlement, as described above.

Feedback

Settings includes an optional "Send feedback" option. It does nothing unless you tap it and write a message. If you send a bug report or feature request, the text you write is sent to us so we can read and act on it, along with basic device information (your platform, OS version and the app version) if you leave that toggle on. It carries no account or identity information, because the app has none, and we do not link it to you. The message travels through a small relay we run on Cloudflare and is delivered to us in Slack. Nothing else from the app goes with it.

This website

adminshark.app is a static site served through Cloudflare. It sets no cookies on its public pages, runs no analytics, and loads no third-party scripts or fonts. As with any website, Cloudflare handles the request and its standard security and request logs apply.

The confidential investor area at /investors is different, because it has a form. If you request access, we store the name and work email you type, the domain of that email, the country Cloudflare reports for your request, and a short extract of your browser's user-agent string, so we know who asked and can follow up. We send you a single-use link by email through Resend, our email delivery provider. Signing in sets one HttpOnly cookie so the deck stays open in your browser, and the deck itself is watermarked with your email address. We record when you first and last opened it and a rough count of visits. We keep those records until we no longer need them, and you can ask us to delete yours at any time by emailing [email protected]. We do not add you to a mailing list and we do not pass your details to anyone else.

No advertising

AdminShark shows no ads and contains no advertising SDK. It does not request, use or share any advertising identifier, and there is no tracking permission prompt because there is nothing to track. Earlier versions of the app were ad-supported; advertising was removed in July 2026 and the ad code was deleted with it.

Who else is involved

That is the complete list. We do not sell your data, we do not share it for advertising, and there is no analytics, crash reporting or tracking SDK in the app.

Deleting your data

On your device: deleting an item removes it from the local database. Settings has a "Delete all data" option that wipes every record, document and diary entry in one action. Uninstalling the app removes the database and all attached files. Any backup you exported stays wherever you saved it, under your control, until you delete it.

Your Contact tag, if you have one: open the app, go to the tag and choose Delete tag. This tells our relay to delete the tag record, the push notification token, the hashed secret and every message and conversation held for it. Only the blocked tag id remains, for 30 days, so nobody can claim your old sticker. Regenerate tag does the same and then issues you a fresh tag and sticker, which retires the printed one immediately.

Two things to know about the order you do this in. Deleting your tag needs an internet connection, because it is a request to our relay. And "Delete all data" clears your device but does not by itself remove the tag from our relay, so if you want everything gone, delete the tag first. If you have already wiped the app or uninstalled it and your tag is still registered, email us at [email protected] with the tag id from your printed sticker and we will delete it for you.

Purchase records held by RevenueCat, and anything held by Apple or Google about your purchase, are governed by their own policies. Email us and we will pass on a deletion request for our side of it.

Children

AdminShark is a general-audience app for managing vehicles, insurance and other adult life admin. It is not directed at children, and we knowingly hold no personal information about anyone, of any age.

Changes to this policy

If we change this policy we will post the updated version on this page with a new effective date. Material changes will also be noted in the app's release notes. This version was updated for AdminShark 1.6.0, which introduced the Contact tag.

Governing law and contact

This policy is governed by the laws of New Zealand, including the Privacy Act 2020. If you have any questions about it, or about how AdminShark handles your information, email us at [email protected].