AutoLens
Legal

Privacy Policy

Effective date: June 10, 2026

AutoLens (“AutoLens,” “we,” “our,” or “us,” operated by AutoLenStudios) provides the “AutoLens — Website to Marketplace” Chrome extension and the connected AutoLens web service. The extension helps dealers extract vehicle listing information from their own inventory websites, generate listing descriptions with AI, post listings to Facebook Marketplace, and sync that inventory to their AutoLens account. This Privacy Policy explains what information we collect, how we use it, where it is stored, how long it is kept, and with whom it is shared. It applies to the AutoLens — Website to Marketplace Chrome extension and to the AutoLens web service the extension connects to.

TopicWhere it is covered
Data collectionSection 1 — Information We Collect
Data use and handlingSection 2 — How We Use and Handle Information
Data storage and retentionSection 3 — Data Storage, Location, and Retention
Data sharingSection 4 — Data Sharing and Disclosure
Data securitySection 5 — Security
User rights and deletionSection 6 — Your Rights and Controls

1.Information We Collect

Account and authentication information. When you create an AutoLens account or sign in (from the extension or the web app), we collect your name, email address, dealership name, and password. Passwords are transmitted over HTTPS and stored only as salted bcrypt hashes — we never store or log plaintext passwords. After sign-in, a session token and your basic profile (name, email, dealership, and the contact phone number you provided, if any) are stored locally in the extension via Chrome’s storage API so you stay signed in.

Vehicle listing data (website content). When you activate the extension on an inventory webpage, AutoLens reads the visible vehicle listing details from that page: title, year, make, model, trim, VIN (if shown), price, mileage, description text, image URLs, and the dealership name, address, and contact details shown on the page. Extracted listings are held locally in the extension and, when you sign in or click sync/post, are also sent to your AutoLens account on our servers so your inventory is available in the AutoLens web dashboard.

Facebook Marketplace listing statistics. If you use the extension to post listings, it periodically reads the performance statistics of your own Marketplace listings (views, saves, shares, message counts) from your own Facebook seller dashboard, in your own Facebook session, and sends them to your AutoLens account so the dashboard can show how your listings are performing. This sync only covers your own listings’ aggregate counts — it does not read your Facebook messages, friends, feed, or any other Facebook content.

Locally stored data. The extension stores listing drafts, the posting queue, user preferences (for example price markup, default location), the session token, and sync timestamps locally in the browser via the Chrome storage API.

Chrome Web Store data-type categories. In the categories used by the Chrome Web Store’s privacy disclosures, the extension collects: personally identifiable information (name, email address, dealership name, and contact phone number you provide), authentication information (your password at sign-in, which is never stored in plaintext, and the resulting session token), and website content (the vehicle listing details you choose to extract, and the aggregate statistics of your own Facebook Marketplace listings).

Information we do not collect. The extension does not collect or transmit your web browsing history, the content of pages where you have not activated it (other than the Facebook pages described above), keystrokes, mouse movements, health information, precise geolocation, or payment card numbers (payments are handled by Stripe in the web app). The extension contains no third-party advertising, analytics, or tracking SDKs.

2.How We Use and Handle Information

We use the information described above solely to provide and improve AutoLens’s single, user-facing purpose: turning your dealership inventory into Facebook Marketplace listings and tracking them. Specifically:

  • Authenticate you and keep you signed in to your AutoLens account.
  • Populate listing drafts you can review and edit inside the extension.
  • Generate AI listing descriptions you request (the vehicle details for that listing are sent to our API, which calls Anthropic’s Claude API to write the text).
  • Pre-fill Facebook Marketplace’s listing form when you initiate a post, including appending your chosen contact phone number to the description.
  • Sync your extracted inventory and your listings’ Marketplace performance statistics to your AutoLens account so they appear in your dashboard.
  • Provide support, maintain security, and prevent abuse of the service.

AutoLens does not use collected data for advertising, audience building, user profiling, behavioral targeting, credit decisions, or any purpose unrelated to the single purpose above. We do not use your data to train machine-learning models.

3.Data Storage, Location, and Retention

On your device. Drafts, the posting queue, preferences, and your session token are stored locally via Chrome’s storage.local API, which is isolated to the extension and not accessible to websites. They persist until you sign out, clear them, or uninstall the extension.

On our servers. Your account profile, synced vehicle listings, and listing statistics are stored in the AutoLens database, hosted on Railway in the United States. All communication between the extension, the web app, and our API uses HTTPS/TLS encryption in transit.

Retention. Server-side data is retained while your account is active. If you delete your account (or ask us to — see “Your Rights and Controls”), we delete your account data, synced listings, and statistics, except where we must retain records to comply with legal obligations. Locally stored data is under your control at all times and is removed when you uninstall the extension.

4.Data Sharing and Disclosure

We do not sell, rent, or trade user data. We never transfer user data to advertisers, ad networks, data brokers, or resellers, and we never use or transfer it to serve personalized, re-targeted, or interest-based advertising, or to determine creditworthiness or for lending purposes.

User-initiated transfers to Facebook. When you choose to publish a listing to Facebook Marketplace, the listing content you have reviewed (vehicle details, photos, description, contact number) is submitted to facebook.com through your own Facebook session. This transfer happens only when you initiate a post and is subject to Meta’s Privacy Policy.

Service providers (sub-processors). We share data with the following providers only as needed to operate AutoLens, under agreements that restrict their use of the data to providing services to us:

ProviderPurposeData involved
RailwayHosting of the AutoLens API and database (United States).All account and synced listing data described in this policy.
AnthropicAI text generation. When the user requests an AI-written listing description, the vehicle details for that listing are sent to the Claude API to generate the text.Vehicle listing details for the specific request. No account credentials.
Meta (Facebook)User-initiated listing publication and the user’s own listing statistics, through the user’s own Facebook session. Subject to Meta’s own Privacy Policy.The listing content the user chooses to post (vehicle details, photos, description, contact number).
VercelHosting of the AutoLens web application.Standard web request data when using the web dashboard.
StripeSubscription billing for paid AutoLens plans (handled in the web app, not the extension).Billing name, email, and payment details entered directly with Stripe.
SentryServer-side error monitoring so we can fix failures in the AutoLens service.Technical error context from our servers; not used for advertising or analytics.
Twilio / PostmarkSMS delivery and transactional email for AutoLens CRM accounts that enable those features (not used by the extension itself).Message content and recipient phone number / email for messages the account sends.

Legal compliance. We may disclose information if required to do so by law, subpoena, or other legal process, and only to the extent required.

Business transfers. If AutoLens is acquired, merged, or its assets transferred, user data may be transferred as part of that transaction. This Privacy Policy will continue to apply, and we will provide notice before user data becomes subject to a different privacy policy.

5.Security

All traffic between the extension, the web app, and our API is encrypted in transit with HTTPS/TLS. Passwords are stored only as salted bcrypt hashes. Access to production data is restricted to the founding team, and every state-changing operation on our servers is recorded in an audit log. Local extension storage is protected by the browser’s built-in isolation between extensions and websites. Keep Chrome and the AutoLens extension up to date to receive security patches.

6.Your Rights and Controls

You can, at any time:

  • Sign out of the extension, which removes your session token from the device.
  • Clear all AutoLens-stored local data through Chrome’s extension management page (chrome://extensions) or by uninstalling the extension.
  • Review and delete synced listings from your AutoLens dashboard.
  • Request a copy of your data, correction of inaccurate data, or deletion of your account and all associated server-side data by contacting us at the address in the “Contact” section. We respond within 30 days.
  • Disable individual host-website access from the extension’s permissions screen in Chrome.

These controls implement the rights of access, correction, deletion, and objection under applicable privacy laws, including Canada’s PIPEDA, Quebec’s Law 25, the GDPR, the UK GDPR, and the CCPA/CPRA.

7.Chrome Permissions

The AutoLens — Website to Marketplace extension uses the following Chrome permissions:

PermissionPurpose
activeTabLets the extension access the webpage the user is currently viewing, only after the user activates the extension, so listing details can be read from that page.
tabsLets the extension open and manage the Facebook Marketplace listing tab during a user-initiated posting run and identify which tab a user-initiated extraction came from.
scriptingLets the extension run its content scripts on the active page to read visible listing information the user has chosen to extract.
storageLets the extension save the signed-in session token, listing drafts, the posting queue, and user preferences locally in the browser.
alarmsSchedules the periodic background sync of the user’s own Facebook Marketplace listing statistics (at most every few hours).
Host permission: dealership websitesAllows AutoLens to read vehicle listing information from the inventory pages the user chooses to extract. The extension only reads a page when the user activates it there; it does not log or transmit general browsing activity.
Host permission: facebook.comAllows AutoLens to pre-fill the Facebook Marketplace listing form when the user clicks to post, and to read the performance statistics (views, saves, messages) of the user’s own Marketplace listings from the user’s own seller dashboard.
Host permission: AutoLens APIAllows the extension to communicate with the AutoLens service for sign-in, syncing the user’s extracted inventory to their AutoLens account, AI description generation, and listing statistics.

8.Compliance with Chrome Web Store Limited Use

AutoLens’s use and transfer of information received through the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:

  • We only use data to provide or improve the extension’s single, user-facing purpose.
  • We only transfer data as necessary to provide that purpose (to the service providers listed above), to comply with applicable law, to protect against abuse, or as part of a merger or acquisition with prior notice.
  • We do not use or transfer data for serving advertisements.
  • We do not use or transfer data to determine creditworthiness or for lending purposes.
  • We do not allow humans to read user data unless we have your affirmative agreement, it is necessary for security or support purposes, it is required to comply with applicable law, or the data is aggregated and used for internal operations.

9.Children's Privacy

AutoLens is intended for use by adults working with dealership inventory. It is not directed to children under 13, and we do not knowingly collect data from children. If you believe a child has used the extension and you wish to raise a concern, contact us using the details below.

10.Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to the extension, the service, applicable law, or industry guidance. When we make a material change, we will update the “Effective date” above and, where appropriate, surface a notice inside the extension or the web app. Continued use after an update constitutes acceptance of the revised policy.

11.Contact

If you have questions about this privacy policy, or want to exercise any of the rights described above, contact:

Zain Gaad, AutoLenStudios
zainazmat69@gmail.com

Privacy Policy — AutoLens