Privacy Policy

Last updated: August 5, 2026

Your Tesla — the questions we hear most

Why does Tesphase ask for “Vehicle Commands”?
Tesla puts waking your car in the same “Vehicle Commands” checkbox as unlock, remote start, trunk, and cameras — it can’t be split apart on their screen. Tesphase uses it for one thing: a Tesla sleeps most of the day and reports nothing over the API while asleep, so we wake it, read the battery and charge state, and let it go back to sleep. Charging itself — start, stop, and speed — comes from the separate “Vehicle Charging Management” permission.
Can Tesphase unlock, drive, track, or open my car?
No. Our system is built so it can only ever send charging and wake commands. A separate safeguard — a command firewall — sits in front of the component that signs commands to your car and rejects every other command (unlock, remote start, trunk, cameras, driver management) before it can reach your Tesla. This is enforced by how the system is built, not just a policy we promise. We also never request your vehicle’s location or your Tesla profile.
How do I turn it off?
You’re always in control. Remove Tesphase from your Tesla account’s third-party apps page anytime and command access stops immediately — no need to ask us.

Full detail is in “What we can and cannot do with your Tesla” below.

Summary

Tesphase exists to automatically charge your electric vehicle with excess solar power. To do that, we need three things from you: an account so you can log in, an OAuth connection to your solar system, and an OAuth connection to your EV. We do not sell your data. We do not show you ads. We do not share your data with third parties for marketing.

Data we collect

  • Account information. Your email address and a bcrypt-hashed password.
  • OAuth tokens. Access and refresh tokens for Enphase, Tesla, and other solar/EV providers you connect. Tokens are encrypted at rest using AES-256-GCM before being written to our database. They are never logged.
  • Energy telemetry. Solar production, home consumption, vehicle battery level, and charging amperage at roughly 8-minute intervals while your system is active. This data drives the charging decision engine.
  • Charging events. Start time, end time, kWh delivered, and the reason a charging session started or stopped.
  • Device push tokens. If you grant push notification permission in the mobile app, we store the Firebase Cloud Messaging token for your device so we can send charging alerts.

Data we do not collect

  • Location data of any kind. The mobile app does not request location permission.
  • Your contacts, calendar, photos, microphone, or camera.
  • Device identifiers for advertising (IDFA, AAID).
  • Browsing history outside the Tesphase app or website.

What we can and cannot do with your Tesla

Connecting your Tesla uses Tesla’s permission screen, which groups “wake” together with other commands under a single “Vehicle Commands” option. Tesphase uses that permission for exactly one purpose: waking your car so we can read its battery level and charging state (a sleeping Tesla reports nothing over the API). Charging itself — start, stop, and speed — comes from the separate “Vehicle Charging Management” permission.

Tesphase’s system is built so it can only ever send charging and wake commands to your car. A separate safeguard sits in front of the component that talks to your Tesla and rejects every other command — unlock, remote start, trunk, cameras, driver management — before it can reach your vehicle. This is enforced by how the system is built, not merely a policy we promise to follow. We never request your vehicle’s location or your Tesla profile.

You remain in control at all times: you can remove Tesphase’s access from your Tesla account’s third-party apps page whenever you like, and command access stops immediately.

Third parties that process your data

  • Tesla, Inc. — Fleet API. We exchange your OAuth tokens with Tesla to read vehicle state and send charging commands you have authorized.
  • Enphase Energy. Solar production and home consumption data from your Envoy gateway.
  • Neon, Inc. PostgreSQL database hosting in the AWS us-east-1 region.
  • Vercel Inc. Web application hosting (United States).
  • Railway Corp. Engine and worker hosting.
  • Resend — transactional email (charging alerts, account notifications).
  • Google Firebase — push notification delivery (mobile app only).

We do not share your data with any third party for advertising or marketing purposes.

How long we keep your data

Account information and OAuth tokens are kept as long as your account is active. Energy telemetry and charging events are retained for the lifetime of the account so you can see historical performance. When you delete your account, all associated data is permanently removed from our production database within seven days.

Your rights

You can request a copy of your data, correct inaccurate data, or delete your account at any time. Account deletion is available from Settings → Account inside the app, or by visiting our account deletion page without an account.

California residents have additional rights under the California Consumer Privacy Act (CCPA). Residents of the European Union have rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, port, and erase personal data, and to lodge a complaint with a supervisory authority.

Security

OAuth tokens are encrypted at rest with AES-256-GCM. All network traffic is TLS 1.2 or higher. Passwords are hashed with bcrypt. We do not log secrets or tokens. We follow the principle of least privilege when granting access to production data.

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you by email without undue delay and within the timeframe required by applicable law.

Children

Tesphase is not directed to children under 13, and we do not knowingly collect personal information from children.

Changes to this policy

We will post material changes to this page and update the “Last updated” date. Continued use of Tesphase after a change constitutes acceptance of the revised policy.

Contact

Questions about this policy, or requests to exercise your privacy rights, can be sent to info@tesphase.co.