Privacy Policy
Last updated: September 7, 2026
HeyDrive is operated by CoolApps s.r.o. Contact: [email protected].
Connecting your Tesla account
HeyDrive does not ask for or see your Tesla username or password. You sign in directly on Tesla’s website using Tesla’s official OAuth authorization flow and choose which permissions to grant. Tesla access and refresh tokens remain server-side. They are never sent to the frontend or stored in browser cookies.
Vehicle data and its use
We process vehicle data to provide your garage, saved snapshots and the updates you request. Depending on your permissions and availability through Tesla Fleet API, this may include vehicle name, VIN, model and configuration, status and connectivity, battery level and range, charging, climate, lock state, odometer, location and other vehicle data needed for supported features. Not every field is available for every vehicle.
Location and live updates
GPS coordinates come from Tesla Fleet API. During an explicit successful live refresh, coordinates may be sent server-side to Geoapify to obtain a readable address (reverse geocoding). Coordinates and address results are cached to avoid repeated lookups for the same approximate location. If address lookup is unavailable, the GPS snapshot can still be used.
Opening HeyDrive, viewing saved data, choosing a vehicle and syncing identity do not wake your vehicle or trigger reverse geocoding. A live wake occurs only when you explicitly request a live refresh, or use a future enabled command that requires it. Vehicle commands are not available in the current beta.
Sessions, cookies and security
Session and token data are held server-side. In the HTTPS service, session cookies use Secure, HttpOnly and SameSite protections. Cookies identify your session; they do not contain Tesla access or refresh tokens. HeyDrive does not add analytics or advertising tracking cookies.
We use reasonable technical security measures to protect access and data. No system can guarantee absolute security.
Storage and retention
The beta uses temporary server-side session and snapshot storage. Data may expire or be cleared when the backend restarts, so HeyDrive is not a permanent vehicle history or backup service. Revoking authorization stops future authorized access; it does not itself guarantee that previously cached information has already been erased. Contact us for deletion requests.
Third-party services
- Tesla: account authorization and vehicle data through Tesla Fleet API. Tesla Privacy Notice.
- Cloudflare: delivery and security infrastructure, which may process connection information such as IP addresses and request metadata. Cloudflare Privacy Policy.
- Geoapify: reverse geocoding of coordinates during an explicit live refresh. Geoapify Privacy Policy.
These providers process data according to their roles and applicable policies. We do not sell user data.
Your choices and requests
You can stop using HeyDrive and revoke its access through your Tesla account authorization settings. See Tesla’s instructions for managing third-party access. Contact [email protected] about your data or to request access, correction or deletion. Depending on applicable law, you may also have rights to restriction, objection, portability and to complain to a data protection authority.
Beta service and policy updates
HeyDrive is in beta. Features and this policy may change. We will publish revisions here with an updated date.