Teslr
ConnectPrivacyTermsSupport

Your data / kept minimal

Privacy Policy

Effective and last updated August 21, 2026

What this policy covers

This policy explains how Teslr handles information when you visit teslr.club, connect a Tesla account, use the Teslr API or skill, or request support. Teslr is designed to retain as little vehicle and account information as practical.

Information Teslr processes

  • Linked X, Tesla, and Tessie accounts. For the recommended @TeslrBot connection, Teslr verifies your public X username and profile image, stores a keyed one-way marker derived from your X account identity, and links it to the vehicle provider you choose. Tesla OAuth access and refresh tokens, granted scopes, expiration times, Fleet region, and connection timestamps are stored so Teslr can serve your requests. If you submit a Tessie access token, Teslr stores that token so @TeslrBot can use your Tessie account. Tesla OAuth tokens and Tessie access tokens are encrypted at rest. Teslr does not retain the X OAuth access token, and this flow does not give you a Teslr token to copy or manage.
  • Bankr and direct API compatibility. If you use the compatible private-token connection, Teslr issues a one-time connection token for you to store in your assistant's secure settings. Teslr stores only a one-way hash of that token. For both connection methods, Teslr stores a keyed one-way hash of Tesla's account subject so reconnecting retains the same private account identity.
  • Vehicle and energy data. State, location, history, charging, driver, invitation, and energy information is requested only when needed to answer or perform your request. Teslr does not intentionally persist provider response bodies, trip histories, precise locations, VINs, plates, or command payloads in its application database or operational logs.
  • Response minimization. Teslr removes person names, contact fields, user-defined energy-site labels, addresses, coordinates, and other precise-location values from API responses by default. A user-defined vehicle name is returned to the authenticated assistant as target-resolution context so a request such as “open Carla's trunk” can select the correct vehicle. The Teslr skill instructs the assistant to repeat that name only when the user asks for it or uses it to identify the vehicle in the same request. Uninspectable maps, invoices, and other binary responses fail closed. An authenticated caller may request other personal data for one explicitly authorized private response; this exception must not be used on a public timeline or in a shared conversation.
  • Tessie compatibility. If you use a Tessie token, through Bankr or the API, Teslr forwards it only for the current request and does not store it. If you add a Tessie token from the signed-in X connection page, Teslr validates it with Tessie and stores an encrypted copy plus a one-way token hash in its application database, bound to the keyed marker for that X account. It is decrypted only in process memory for that account's requests and is deleted when you remove Tessie or unlink the X account. Teslr does not receive your Tessie password.
  • Place search. When you ask for a nearby destination, Teslr sends a rounded search origin and your place query to fixed OpenStreetMap search services. Teslr does not send your credential, VIN, vehicle name, or exact origin to those services.
  • Security information. Teslr may retain one-way hashes derived from a linked X account, compatibility connection token, stable Tesla account, or network address plus timestamped request categories and counters for abuse prevention, reliability analytics, and cost measurement. General security counters expire within seven days. Historical beta measurement events are eligible for deletion within 35 days.
  • Privacy-preserving usage analytics. When beta analytics are enabled, Teslr stores UTC daily aggregate counts for completed Tesla connections, successful, failed, and uncertain requests, provider, safe operation category, and total response time. It also stores short-lived, separately keyed one-way markers to count active Tesla and Tessie connections, connected accounts that have not yet made a Teslr request, vehicles served, and energy sites without retaining a raw provider token, vehicle identifier, VIN, account identity, location, request body, or provider response. Tessie usage counts toward these aggregates.
  • Private X account activity records. While an X account has completed X linking and a Tesla or Tessie vehicle connection, and production analytics are enabled, Teslr keeps the verified public X username, a keyed one-way account marker, lifetime counts, and daily X-versus- Bankr counts of successful, failed, or uncertain requests by broad operation category. Direct-Tesla Bankr activity is associated with an X account only when the Tesla account maps to exactly one active X link; ambiguous shared-account activity is not assigned to either user. These private records let the operator measure account-level usage and may support eligibility records for a future promotion if one is offered. They do not contain post text, reply text, command parameters, destinations, vehicle identifiers, wallet addresses, or provider response data, and they are not exposed through a public endpoint.
  • Public X conversation context. When you reply to @TeslrBot, Teslr may retrieve the newest post and a bounded chain of its public reply ancestors and send their text and public author identifiers to OpenAI Codex to understand conversational follow-ups such as “me too” or an omitted noun. This context is used to plan that reply and is not added to Teslr's private account-level analytics record. A different author's account link, authorization, or vehicle does not transfer through conversation history.
  • Infrastructure request metadata. Hosting and security providers may process a network address, user agent, timestamp, request method, and request URL for delivery, abuse prevention, and troubleshooting under their own retention policies. A request URL can include an opaque Teslr resource id, a user-supplied place-search term, or Tesla's short-lived OAuth callback parameters. Teslr does not intentionally place an authorization header, provider token, exact vehicle coordinates, command body, or provider response body in an application log.
  • Dormant beta measurement. Account-level fair-use measurement and enforcement are disabled for the open beta. Historical pseudonymous measurement events and dormant service-credit records may be retained for reconciliation and a possible future reviewed service model, but are not charged during the free beta.
  • Essential cookies. Teslr uses short-lived, secure OAuth state cookies during X and Tesla connection and a secure, HTTP-only management-session cookie after X sign-in. Infrastructure providers may set essential security or bot-protection cookies.

How information is used

Teslr uses information to authenticate your connection, retrieve requested data, send commands you authorize, protect the service, prevent abuse, measure linked-account activity, determine or administer promotion eligibility if a promotion is offered, troubleshoot generic service failures, and comply with applicable law. Teslr does not sell personal information or use vehicle data for advertising.

Service providers and disclosures

Information is processed by Tesla or Tessie when you choose that connection, by OpenAI Sites and Cloudflare for hosting and security, by OpenAI Codex for @TeslrBot response planning, and by OpenStreetMap services only for requested place searches. Teslr may disclose information when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards.

Retention and deletion

Direct Tesla credentials and any Tessie token added for X remain until you disconnect or unlink them, the credentials expire, or retention is otherwise required by law. One-use OAuth state expires after ten minutes. Security counters are short-lived. Analytics subject markers expire after 35 days; daily aggregate counters may be retained to measure adoption, reliability, and provider mix over time. Teslr application logs are limited to generic failure and service-health metadata. While an X reply or command confirmation is unfinished, owner-only local recovery state may temporarily contain the source post and public author fields. It is removed after completion or confirmation expiry; failed reply recovery state is removed within 24 hours. Completed local events retain only operational post/reply identifiers and outcomes, not post text or display names. Infrastructure request logs are controlled by the hosting and security providers described above. Private X account activity records remain only while the X account is linked and are deleted when that account is unlinked; an X-only sign-in that never completes a vehicle-provider connection is excluded from this account-activity ledger. Anonymous daily aggregate counters may remain afterward.

Credit ledger and promotional-grant records may be retained for accounting, replay prevention, security, dispute handling, and legal compliance. Disconnecting a provider credential does not automatically erase those pseudonymous billing records.

For the recommended @TeslrBot connection, unlink from Teslr's connection page and confirm with the same X identity. This removes the X account's Tesla pairing, encrypted Tesla authorization, encrypted X-linked Tessie token, management session, and private account-level activity record. You may separately remove Teslr's virtual key from each vehicle and remove Teslr from Tesla's third-party app access.

For the Bankr-compatible connection, privately ask your AI assistant to “disconnect Tesla from Teslr,” confirm the request, and removeTESLR_FLEET_TOKEN from its secure settings. For Tessie, remove TESSIE_API_TOKEN and revoke or rotate it through Tessie.

Security

Teslr uses HTTPS, encrypted stored provider credentials, protected account markers, hashed compatibility tokens, fixed provider allowlists, non-cached API responses, and a secret-authenticated command signer. No system is perfectly secure. If you believe an account link or compatibility token was compromised, follow the steps on the support page immediately.

Your choices and contact

You may disconnect at any time and may ask about access, correction, or deletion rights available under applicable law. Contact @TeslrBot on X without posting a token, account linkage, VIN, plate, account identity, or vehicle location. Teslr is not intended for children under 18. Material policy updates will be posted here with a revised date.

Teslr is independent software and is not affiliated with, endorsed by, or sponsored by Tesla, Bankr, Robinhood, Tessie, X, or any other company referenced here. All trademarks belong to their respective owners.

@TeslrBot