Privacy

Last updated August 29, 2026

The short version

Kerbside is a small, independent tool. We collect the minimum needed to give you a fair price estimate and to see whether the product is useful. We don't sell your data and we don't run ads against it.

What you give us

  • Vehicle details — VIN or year/make/model/trim, mileage, ZIP, condition. Used to compute your estimate. VIN is decoded server-side via NHTSA and passed to Marketcheck to find comparable listings. Not stored against your account.
  • Email + password (if you sign in) — handled by Supabase Auth. Google sign-in only sees your email, name, and profile picture. We never see your Google password.
  • Sale outcomes you contribute — if you tell us what you actually paid, we store that with year/make/model/trim/ZIP and your user id (so you can amend it later). Displayed to other users only as anonymized aggregates, never with your identity, and only when at least three people have contributed for a given vehicle.

What we collect automatically

  • Product analytics via PostHog — page views and a handful of named events (estimate submitted, Deep AI Search clicked, sign-in started). We do not enable session recording, autocapture, or heatmaps. PostHog sets a cookie to keep your session id stable.
  • Rate-limit counters via Upstash Redis — your IP (or user id when signed in) and a rolling count of API calls to prevent abuse. Counters expire on their own within an hour.
  • Standard server logs — Vercel keeps request logs for a short window for security and debugging. We don't mine them.

Who else sees your data

We use third-party services to run Kerbside. Each one only receives the fields it needs:

  • Marketcheck (real listings and prices) — year/make/model/trim/ZIP/radius, or VIN.
  • NHTSA (recalls, safety, complaints, VIN decode) — year/make/model or VIN.
  • Brave Search (curated reviews + Reddit threads) — year/make/model/trim.
  • YouTube Data API (video reviews) — year/make/model/trim.
  • EPA fueleconomy.gov (MPG + fuel cost) — year/make/model/trim.
  • Anthropic (reviewer summary, common issues, sold-price extraction) — the review/thread text we already fetched.
  • Supabase (auth, sale outcomes storage) — email + your contributed sale outcomes.
  • PostHog (product analytics) — the events listed above.
  • Upstash Redis (rate limiting) — your IP or user id.
  • Vercel (hosting) — everything served through the site.

Your choices

  • Skip sign-in — the estimator and free-tier research work without an account.
  • Block analytics — a browser extension like uBlock Origin or PostHog's own opt-out will stop PostHog from firing. Kerbside works normally either way.
  • Delete your account or your contributions — email us at the address below. We'll delete your auth record and null out your sale outcomes within seven days.

Kids

Kerbside isn't designed for anyone under 13, and we don't knowingly collect data from them.

Changes

If we materially change what we collect, we'll update this page and note the date at the top. Small clarifications may go in without a notice.

Contact

Questions, corrections, or deletion requests: hello@kerbside.ai