fiddle
Legal

Privacy Policy

Effective September 22, 2026

This version takes effect on September 22, 2026. Until then, the version effective August 8, 2026 continues to apply. What changed is set out in Section 3 — fiddle now states plainly that fitment outcomes are pooled across owners, and that aggregate analytics will reach retailers and manufacturers — a feed that is not built yet — while your personal information never does. As Section 8 requires, notice is given ahead of the date: this page is published now, and the search home and the sign-in screen both link to it.

Added August 26, 2026 — this part applies now, not in September. fiddle has started using Google Analytics to measure how the site is used, and it sets cookies of its own. That is a change to what the currently effective policy says about cookies and trackers, so it is written down here on the day it starts rather than held back to the September version. Section 1 sets out exactly what it collects, and Section 5 says how to refuse it.

This policy explains what information fiddle (operated by Buster Studios — "we," "us") collects, how we use it, and the choices you have. The short version: your garage is yours, most of your data stays on your device unless you sign in to sync it or choose to publish it, we don't sell your information, and we don't run ads.

Two things travel outward — one today, one when we build it — and Section 3 spells out both. Fitment data — which parts fit which cars — is pooled today from what owners log and shown to other owners, because that pool is the thing that makes the search engine worth using. Aggregate analytics about what people search for and price against will go to retailers, so they can put discounts where the demand actually is and hear what owners say about their products; that feed is not built yet, and we are disclosing it before it starts rather than after. Neither one carries your personal information, and we do not share your personal information with retailers, manufacturers or advertisers. One third party does see that a visit happened — the analytics tag described in Section 1 — and what it gets is the visit, never your account.

1. What we collect

Account information

When you create an account we collect your email address and name, plus a password (stored only as a salted hash) for email accounts. If you sign in with Google, Discord, or Apple, we receive your name, email, and an account identifier from that provider — we never see your password for those services, and we request only basic profile scopes.

Your garage and build data

The cars you add, the mods/service/track sessions you log, part numbers, notes, costs, and fitment reports live on your device. When you're signed in, this data syncs to your account on our servers so it survives a lost phone and follows you between devices. Costs and private records sync with your account but are never published unless you switch them on.

Fitment reports and part activity

fiddle is a parts search engine, and it learns from being used. When you record that a part fits your car — or that it didn't — log a part to a build, correct a fitment note, or stage a part you're weighing up, we record the part, the vehicle it was matched against, and the outcome. We also record what you search for and which results you open. This is the raw material for both of the things described in Section 3: the fit verdicts other owners see today, and the aggregate demand picture retailers will see once that feed is built.

Photos and camera

The camera is used for one thing: identifying parts and documenting your build. When you scan a part, the photo (or a cropped region of it) is sent to our servers and processed by our AI provider to identify what it shows; part detection also runs on-device. Build photos you add stay on your device unless you publish your build page with photos enabled — published photos pass automated content screening first. We don't scan your camera roll and only receive images you deliberately capture or select.

Optional information

A zip code, if you provide one, is used to show events and parts near you. A public username, if you set one, appears on your published pages and event lists.

What we deliberately collect little of

We use a session cookie to keep you signed in, and since August 26, 2026 we also run Google Analytics (GA4), which sets cookies of its own to count visits and show us which parts of the site actually get used. What it receives is the pages you open, the address that sent you here, your device, browser and language, an approximate location worked out from your IP address, and a random identifier for this browser. It does not receive your name, your email, your garage, or anything you have logged, and we do not connect it to your account.

What we still do not do: we run no advertising or remarketing tags, we do not use analytics to build advertising audiences, we do not fingerprint, and we do not collect your precise location. The retailer analytics described in Section 3 are a separate thing entirely — built from what you do inside fiddle, not bought from anyone and not taken from trackers that follow you around other sites.

2. How we use information

3. When information is shared

With other owners — fitment data

Fitment is pooled, and that is deliberate. When you record that a part fits your car — or that it didn't clear, didn't line up, or needed a different bracket — that outcome joins fiddle's shared fitment data and is shown to other owners researching the same part on the same chassis. It is what turns "the catalog says it fits" into "fourteen owners of your chassis run this, and two report it fouls a big-brake kit." Every owner's answer makes the next owner's answer better; that exchange is the service.

What travels is the part, the vehicle it was fitted to, and the result. Your name, email and account are not attached. A pooled fitment report is anonymous — the exception being one you separately chose to publish on your build page, which carries your username because publishing is what you asked it to do.

With retailers and manufacturers — aggregate analytics (not yet running)

This is not happening yet. No analytics of any kind currently go to a retailer or a manufacturer. We are describing it here before we build it, so that nobody learns about it after the fact.

When it exists, we will share aggregate, de-identified analytics with retailers and parts manufacturers: how many people searched a category, which chassis are driving demand for a part, how a part's asking price compares to what shoppers actually moved on, and what fitment outcomes owners reported against it. We will do it for two reasons, both of which point back at you — so retailers can place discounts and cost savings where owners are genuinely shopping instead of guessing, and so manufacturers get honest product feedback about what fits badly, fails early, or ships with the wrong hardware, and can fix it.

These will be counts and trends across many people. No personal information will reach a retailer or a manufacturer — not your name, email, account, zip code, garage, or the identity of any individual searcher. A retailer will not be able to learn from us that you searched for anything.

Publicly, when you publish

A published build page — owner name, car, and whatever your share toggles allow (log, sessions, staged items, maintenance, numbers, photos) — is visible to anyone with the link. Unpublishing removes the page, its gallery, its followers, and its entries in community feeds and search.

The remaining cases

We do not sell your personal information, we do not hand it to advertisers to target you, and we do not and will not hand it to retailers. Whatever eventually leaves fiddle for a retailer will be a number, not a person. The one automatic exception to "nothing leaves" is the analytics tag in Section 1, which measures the visit rather than the visitor.

4. Where your data lives, and for how long

Local data lives in your browser or app storage on your device. Synced and published data is stored with our hosting provider in the United States. We keep synced data while your account is active; published content until you unpublish it; and routine backups for a limited period after deletion.

5. Your choices

6. Children

fiddle is not directed to children under 13, and we don't knowingly collect their information. If you believe a child under 13 has an account, contact us and we'll delete it.

7. Security

All traffic is encrypted in transit (HTTPS). Passwords are stored only as salted hashes. Published-page edit rights are protected by per-page keys. No system is perfectly secure, so use a strong, unique password.

8. Changes and contact

If we materially change this policy, we'll give notice in the app or by email before the change takes effect. Questions or requests: hello@fiddle.diy.

fiddle · Terms of Service · back to the app