Privacy policy
AdminShark is a life-admin tracker made by AdminShark (adminshark.app). It is built around one principle: your data is yours. Your records live on your device and we never collect them. There are no accounts and no sign-in. This policy explains what that means in practice and, just as importantly, describes honestly the few places where something does leave your phone: the optional Contact tag, purchases, feedback you choose to send, and your phone's own backup.
The short version
- Your records (vehicles, dates, policies, documents, photos, diary) never leave your device unless you export them yourself.
- There are no accounts, no ads and no analytics. We do not track you and we do not sell anything to anyone.
- If you set up a Contact tag, a small amount of data does go to a server we run: a random tag id, a notification token, and messages that are encrypted so that only your phone can read them.
- You can delete all of it, and we tell you exactly how, below.
What stays on your device
Everything you enter is stored in an encrypted database on your device only: vehicles, renewal dates, insurance details, warranties, subscriptions, costs, notes, service records, documents, IDs, investments and your diary. We cannot see any of it, and neither can anyone else without access to your unlocked phone. The app opens behind Face ID, your fingerprint or your device passcode, and the database is encrypted at rest under a key your recovery phrase protects. We have no copy of that key, so there is nothing we could hand over even if we were asked.
Photos and documents
You can attach photos to items, for example a service invoice or a warranty receipt. They are copied into the app's private storage and encrypted at rest with the same key as the rest of your data. They are never uploaded and never shared by the app. They are decrypted in memory only while you are looking at them.
Backups you export
You can export your data as a single backup file at any time. Backups are created only when you ask for one, they are encrypted, and only your recovery phrase can open them. The file is handed to you through your device's standard share or save options. Where you put it (your phone, your own cloud drive, your own iCloud folder, an email to yourself) is entirely your choice. We never receive a copy and we could not read one if we did. Restoring is equally local: the app reads the file you select and nothing more. The same is true of a vehicle file you share with a buyer: it is a file you create and send yourself, and it never passes through us.
Device backups (Google / Apple)
Separately from the app, your phone has its own built-in backup system: Google Backup on Android (to your Google Account, via Google Drive) and iCloud Backup on Apple devices. If you have this switched on, your operating system may include AdminShark's data in that backup, alongside your other apps. This is your own personal backup, stored in your own Google or Apple cloud account and protected under their terms. We are not involved: we never receive it, never see it, and cannot access it. You can review or turn it off in your device settings (on Android: Settings > Google > Backup; on iOS: Settings > your name > iCloud), and the in-app export above works regardless of that setting.
Reminders
Renewal reminders are scheduled locally on your device using its built-in notification system. Nothing about them is sent anywhere, no server is involved in deciding when they fire, and you can turn notifications off at any time in your device settings. The one kind of notification that does come from a server is a Contact tag alert, described next.
Contact tag (optional, Premium)
The Contact tag is an optional Premium feature. You print a QR sticker for your car, and someone who needs to reach you (blocking a driveway, lights left on, an alarm going) can scan it and send you a message without ever learning your phone number. This is the one part of AdminShark that uses a server we run, at tag.adminshark.app. If you never set up a tag, none of this section applies to you and nothing in it is collected.
When you create a tag, the app registers it with our relay. The relay stores, for that tag only:
- A random tag id. It is not derived from you, your phone or your vehicle.
- A one-way hash of the tag's secret, so the relay can check that a request really came from your app. The secret itself is never sent to us and never stored.
- Your device's push notification token, so we can alert you when someone scans the sticker, plus which platform it is for (Apple or Google).
- Your tag settings: whether it is on or paused, which reasons you accept, and whether you allow a call-back number.
- An expiry date for your Premium entitlement, and timestamps for when the tag was created and last updated.
It does not store your name, your phone number, your email, your number plate, your location, your IP address, or anything at all from your AdminShark records. There is no account attached to a tag.
When someone scans your sticker and writes to you, their message is encrypted in their browser before it is sent, using a key that exists only on your sticker and in your app. The relay receives ciphertext and stores it as ciphertext. It cannot read a single word, and neither can we. The key needed to open it is on your phone. Alongside the encrypted message, the relay stores a message id, the time, and the two-letter country the scan came from, which is why your app can say "Scanned in NZ". If the two of you keep talking, the relay also records when each side last opened the conversation, so the page can show "Delivered" and "Seen". That is the full extent of what we can see: that a message exists, how big it is, when it arrived, which country it came from, and whether it has been opened.
To alert you, the relay sends a push notification through Apple (APNs) on iPhone or Google (Firebase Cloud Messaging) on Android. The notification carries the encrypted message, the tag id, the time and the country. Apple and Google act as the delivery pipe and cannot read the message either. On iPhone the visible text is fixed wording that says someone contacted you about your car; on Android nothing visible is sent at all, and your phone builds the notification locally.
Because the tag is a Premium feature, when you register a tag the app sends our relay the anonymous purchase identifier that RevenueCat generated for your install, so the relay can ask RevenueCat whether your Premium entitlement is live. That identifier is random and per-install: it is not your name, your email, your device id or an advertising id, and the app has no account to attach it to. The relay does not store it. It keeps only the resulting expiry date, and holds a hashed copy in memory for ten minutes so it does not have to ask again on every request.
Our relay sits behind Cloudflare, and is hosted on Railway. As with any web server, the request logs of those services record the internet address a request came from. We do not put IP addresses in our own database and we do not use them to build a profile: they are used to rate-limit abuse and then they age out with the hosting provider's log retention.
How long Contact tag data is kept
- A one-off scan message: up to 7 days, and we keep at most the 50 most recent per tag.
- A back-and-forth conversation: 24 hours. After that the conversation, every message in it and the read receipts are deleted. A conversation is capped at 50 messages.
- A short-lived fingerprint of each message, used to spot the same message being sent twice: 24 hours.
- A deleted tag id: kept for 30 days as a blocked id, and nothing else. This stops someone who finds your discarded sticker from claiming that id.
One honest caveat: these limits are applied whenever a tag is next used, rather than by a clock running in the background. On a tag nobody is using, a record may sit a little past its window before the next request clears it.
If you scanned someone's sticker
This section is for you if you are not an AdminShark user and you have just scanned a sticker on a car. You do not need an account, an app or a phone number to use that page.
- Your message is not readable by us. It is encrypted in your browser, for the owner's phone only, before it is sent. We store it as ciphertext and pass it on. We cannot read it and neither can Apple or Google, who only carry it.
- What our server sees. Your internet address, because every web request has one. It reaches us through Cloudflare, which also tells us the country you are in. The country is shown to the owner as "Scanned in" that country. Your internet address is not stored in our database: it is used to rate-limit abuse and appears in ordinary hosting request logs, which age out.
- The bot check. The page uses Cloudflare Turnstile to keep automated abuse off the owner's sticker. As part of that check your internet address is passed to Cloudflare. Turnstile is a privacy-preserving alternative to a CAPTCHA and does not track you across sites.
- What is stored in your browser. If you want a reply, the page creates a throwaway key pair and a conversation token and keeps them in your browser's local storage, along with the text of your own messages so the page can show them back to you. That is the only way a reply can be delivered to you and only to you. None of it is a cookie, none of it is sent to us in readable form (the conversation token only ever travels as a one-way hash), and it is all specific to that one sticker. You can clear it any time by clearing site data for tag.adminshark.app.
- No tracking. The page sets no cookies, runs no analytics, loads no advertising and no third-party trackers. The only outside thing it loads is the Cloudflare bot check.
- How long it lasts. A conversation and everything in it, including your message, is deleted after 24 hours. A one-way message is deleted after at most 7 days.
Premium purchases
AdminShark is free for your first 4 assets. If you upgrade to Premium (a monthly subscription or a one-off lifetime purchase), the payment is processed entirely by Apple's App Store or Google Play under their terms. We never see or store your payment details. To recognise your purchase across reinstalls, the app uses RevenueCat, a purchase-management service, which receives a randomly generated, anonymous app identifier and your purchase history for this app. It receives no name, no email and none of your records. You can read how RevenueCat handles this in the RevenueCat privacy policy. If you use the Contact tag, that same anonymous identifier is sent to our relay to verify your entitlement, as described above.
Feedback
Settings includes an optional "Send feedback" option. It does nothing unless you tap it and write a message. If you send a bug report or feature request, the text you write is sent to us so we can read and act on it, along with basic device information (your platform, OS version and the app version) if you leave that toggle on. It carries no account or identity information, because the app has none, and we do not link it to you. The message travels through a small relay we run on Cloudflare and is delivered to us in Slack. Nothing else from the app goes with it.
This website
adminshark.app is a static site served through Cloudflare. It sets no cookies on its public pages, runs no analytics, and loads no third-party scripts or fonts. As with any website, Cloudflare handles the request and its standard security and request logs apply.
The confidential investor area at /investors is different, because it has a form. If you request access, we store the name and work email you type, the domain of that email, the country Cloudflare reports for your request, and a short extract of your browser's user-agent string, so we know who asked and can follow up. We send you a single-use link by email through Resend, our email delivery provider. Signing in sets one HttpOnly cookie so the deck stays open in your browser, and the deck itself is watermarked with your email address. We record when you first and last opened it and a rough count of visits. We keep those records until we no longer need them, and you can ask us to delete yours at any time by emailing [email protected]. We do not add you to a mailing list and we do not pass your details to anyone else.
No advertising
AdminShark shows no ads and contains no advertising SDK. It does not request, use or share any advertising identifier, and there is no tracking permission prompt because there is nothing to track. Earlier versions of the app were ad-supported; advertising was removed in July 2026 and the ad code was deleted with it.
Who else is involved
- Apple and Google: they process your purchase, and if you use a Contact tag they deliver the notification. They carry the encrypted message and cannot read it.
- RevenueCat: checks whether your Premium purchase is live, from an anonymous identifier.
- Cloudflare: serves this website, sits in front of the Contact tag relay, and runs the bot check on the scan page.
- Railway: hosts the Contact tag relay.
- Slack: where feedback you send is delivered to us.
- Resend: sends the investor-access email, if you request one.
That is the complete list. We do not sell your data, we do not share it for advertising, and there is no analytics, crash reporting or tracking SDK in the app.
Deleting your data
On your device: deleting an item removes it from the local database. Settings has a "Delete all data" option that wipes every record, document and diary entry in one action. Uninstalling the app removes the database and all attached files. Any backup you exported stays wherever you saved it, under your control, until you delete it.
Your Contact tag, if you have one: open the app, go to the tag and choose Delete tag. This tells our relay to delete the tag record, the push notification token, the hashed secret and every message and conversation held for it. Only the blocked tag id remains, for 30 days, so nobody can claim your old sticker. Regenerate tag does the same and then issues you a fresh tag and sticker, which retires the printed one immediately.
Two things to know about the order you do this in. Deleting your tag needs an internet connection, because it is a request to our relay. And "Delete all data" clears your device but does not by itself remove the tag from our relay, so if you want everything gone, delete the tag first. If you have already wiped the app or uninstalled it and your tag is still registered, email us at [email protected] with the tag id from your printed sticker and we will delete it for you.
Purchase records held by RevenueCat, and anything held by Apple or Google about your purchase, are governed by their own policies. Email us and we will pass on a deletion request for our side of it.
Children
AdminShark is a general-audience app for managing vehicles, insurance and other adult life admin. It is not directed at children, and we knowingly hold no personal information about anyone, of any age.
Changes to this policy
If we change this policy we will post the updated version on this page with a new effective date. Material changes will also be noted in the app's release notes. This version was updated for AdminShark 1.6.0, which introduced the Contact tag.
Governing law and contact
This policy is governed by the laws of New Zealand, including the Privacy Act 2020. If you have any questions about it, or about how AdminShark handles your information, email us at [email protected].