Fuel Sniper · Last updated 23 August 2026
This page describes how Fuel Sniper is built and what protects the small amount of data it holds. It is deliberately specific, including about what these measures do not cover.
Fuel Sniper has no accounts, no passwords and no payment details. There is no credential to steal, no password database to breach, and no billing record to expose. Almost everything the app knows about you — your vehicles, your fill-up history, your favourites, your settings — is held on your own phone and never sent to us. The safest data is the data we never collect, and that is the primary control here, not an afterthought.
Every request between the app, the website and our server uses HTTPS with TLS. There is no unencrypted fallback. The website is served over HTTPS with HSTS.
Server-side records — alert registrations and shared fill-up prices — are stored in Cloudflare Workers KV, which encrypts data at rest. Price data itself is public information from government schemes and is cached at Cloudflare's edge.
Every API key for the government fuel feeds, Google Maps Platform and Open Charge Map is held as a server-side secret in our Cloudflare Worker. None of them ship inside the app. This was a deliberate migration: earlier builds carried feed credentials in the client bundle, where anyone can extract them, and those licences are server-to-server. The app now knows only the address of our own API and nothing about which providers sit behind it.
We collect the least that makes a feature work, and we discard it on a schedule: alert registrations last only while alerts are on, shared prices are discarded after about a week, and the daily price history we keep for trend charts contains no user data at all. The retention table in our Privacy Policy is the authoritative version.
| Provider | Role | What they hold |
|---|---|---|
| Cloudflare | Hosting, edge cache, storage | Alert registrations, shared prices, request logs |
| Expo | Push notification delivery | Push tokens and message contents |
| Google Maps Platform | Routing, geocoding, place search | Route endpoints and search text, at request time |
| Open Charge Map | EV charger data | Map centre coordinates, at request time |
| Apple | App distribution | Whatever the App Store holds about your purchase or download |
Fuel Sniper requests location only while you are using it. It does not request background or "always" location, and it does not read your contacts, photos, microphone, camera or health data.
If we become aware of unauthorised access to personal information we hold, we will assess it and, where it is likely to result in serious harm, notify affected users and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.
If you find a security problem in Fuel Sniper, please email support@fuelsniper.com.au with enough detail to reproduce it. Please give us a reasonable chance to fix it before publishing, and please do not access, modify or delete data belonging to anyone else while investigating. We will not pursue action against good-faith research that follows this.
Fuel Sniper is a small independent product. We do not hold SOC 2, ISO 27001 or any comparable certification, and we do not run a 24/7 security operations centre. What we do have is a system with very little worth stealing in it, and honest documentation of what that little is.