A modern car and its companion app collect journey, vehicle and phone data, and pass some of it to third parties. You can reduce that flow by working through the car’s own settings, the app’s permissions and your legal data rights.
Gather what you need before you start
You will need physical access to the vehicle with the ignition on, since most in-car privacy menus are locked while driving. You also need the login for the manufacturer’s connected services account — usually the same account the companion app uses — and access to the email address it was registered with, because data requests are normally confirmed by email.
Have the vehicle identification number to hand. It is the key that links your car to your account, and most data requests will ask for it. Set aside an hour: the settings are spread across the car, the app, your phone’s operating system and the manufacturer’s website, and there is no single switch that covers all four.
Finally, know which country’s rules apply to you. Your leverage depends far more on where you live than on which car you drive.
Read the connected services agreement first
Before changing anything, find the connected services terms and the privacy notice for your vehicle brand. These are separate from the sales contract and are usually published on the manufacturer’s site rather than supplied with the car. They set out what categories of data the vehicle transmits, how long it is kept and which third parties receive it.
Two passages matter most. The first is the list of recipients, which typically covers analytics providers, advertising partners, insurers, roadside assistance firms and, under legal process, law enforcement. The second is the description of what happens if you withdraw consent, because some features stop working. Reading this first tells you which switches you can safely turn off and which ones will disable something you use.
Ars Technica reports that a study of connected car data sharing found the picture is still poor, and that drivers are exposed to a substantial number of trackers across both the vehicles and their companion apps. The precise findings of that study are not reproduced here.
Work through the in-car privacy menus
Start with the car itself, because settings made in the vehicle usually take precedence over those made in the app. On most infotainment systems the relevant menu sits under a heading such as privacy, data or connected services, often buried inside general settings.
Look for separate toggles rather than one master control. Common ones cover the sharing of driving behaviour data, location history, voice recordings, diagnostic telemetry and personalised marketing. Turn off anything you do not actively rely on. Driving behaviour and marketing toggles are the ones most worth disabling, because these are the categories most likely to be shared beyond the manufacturer.
Also delete the paired phone profiles you no longer use. When a phone connects over Bluetooth, the car may copy contacts, call logs and text messages into local storage, and those copies survive until removed. If the car is leased, shared or destined for resale, clear them before handing it on.
Cut the companion app’s permissions
The app is usually the leakier half of the pair. On both Android and iOS, open the operating system’s per-app permission screen rather than the app’s own settings, since that is the level the app cannot override.
Location is the permission to examine first. A car app rarely needs continuous background location to unlock doors or check charge level, so set it to “while using the app” or deny it outright and test whether the features you use still work. Do the same for microphone, contacts, calendar, nearby devices and physical activity. If something breaks, you can grant the permission back; nothing is lost by testing.
Then look at the app’s own account settings for analytics and personalisation options. Some manufacturers put a marketing consent switch there that does not appear in the car, and the two are not always synchronised.
Restrict tracking at the phone level
Permissions control what the app can read. They do not control what it sends to embedded third-party software development kits, which is where most trackers live. That is handled by your phone’s advertising controls.
On iOS, app tracking transparency lets you refuse an app permission to track you across other apps and websites, and you can switch it off globally for all apps. On Android, you can delete the advertising ID entirely, which replaces it with a string of zeros for every app on the device. Doing both removes the stable identifier that ties in-app activity to profiles built elsewhere.
This does not stop the app collecting data under your account. It makes that data harder to join to the rest of your online life, which is a meaningful reduction even though it is not a complete one.
Submit an access and deletion request
Settings only affect the future. To address data already collected, use the legal route. In the United Kingdom and the European Union, the UK GDPR and GDPR give you a right to request a copy of the personal data an organisation holds about you and, in many circumstances, to have it erased. Several US states, California among them, provide comparable access and deletion rights.
Send the request to the privacy contact named in the manufacturer’s privacy notice, not to customer service. State clearly that you are exercising your statutory rights, include the vehicle identification number and your account email, and ask specifically for the categories of data collected and the identities of third parties it has been disclosed to. That last question is often the most revealing part of the reply.
Keep the confirmation. If no substantive response arrives within the statutory deadline, you can escalate to your data protection authority or state attorney general.
Avoid the mistakes that undo the work
The most common error is assuming the app and the car hold the same settings. They frequently do not, and disabling sharing in one place can leave it enabled in the other. Check both.
The second is treating a software update as harmless. Major infotainment and app updates sometimes reset privacy toggles to their defaults or introduce new consent categories that default to on. Re-check after any significant update.
The third is overlooking used and rented vehicles. A car bought second-hand may still carry the previous keeper’s account, phone profiles and saved locations, and a hire car will keep yours unless you factory-reset the infotainment before returning it.
The fourth is relying on opting out of marketing alone. That usually stops advertising uses while leaving the underlying collection and onward sharing intact.
Recognise when this is the wrong approach
If the data sharing is contractual rather than optional, settings will not help. Usage-based insurance policies, subscription driver-assistance features and fleet or company car telematics depend on the transmission you would be switching off. Disabling it may breach the agreement or void a discount, and the honest options there are to accept the collection or change the product.
The same applies if you depend on remote unlocking, stolen vehicle tracking, emergency call functions or over-the-air updates. These need a live connection and, in some jurisdictions, emergency call systems are mandated and cannot be disabled at all.
If your concern is a specific safety risk rather than general privacy — a stalking situation, or a vehicle shared with someone you have separated from — this checklist is too slow and too partial. Seek specialist support and treat account ownership, not toggles, as the issue to resolve.
Frequently asked questions
Can I stop my car from sending data completely?
Usually not, and rarely without consequences. Many vehicles keep a cellular connection for safety-critical functions such as emergency calling, which is legally required in some regions and cannot be switched off. What you can normally disable is discretionary collection: marketing, personalisation, driving behaviour analytics and location history. Physically removing the modem or its aerial is possible on some models but tends to void warranties and disable safety features.
Does my car’s data get sold to insurers?
Manufacturers’ privacy notices commonly list insurers and data brokers among the categories of recipients, though practice varies by brand and jurisdiction and is often tied to consent given during setup. The only reliable way to find out for your own vehicle is to read the connected services notice and then submit a data access request asking specifically which third parties have received your data.
Will limiting app permissions break remote features?
Some of them, but fewer than people expect. Remote lock, climate control and charge status generally work without background location, contacts or microphone access. Features that genuinely need a permission are things such as finding your parked car or geofenced alerts. The safe method is to revoke permissions one at a time, use the app normally for a few days, and restore only what actually stops working.
What happens to my data when I sell the car?
It does not leave automatically. Paired phone profiles, saved destinations, garage door codes and call logs stay in the infotainment system, and your connected services account may remain linked to the vehicle identification number, giving you visibility over the new owner’s journeys. Perform a factory reset of the infotainment system and remove the vehicle from your online account before handing over the keys.
Sources and further reading
- Ars Technica — motoring and technology coverage reporting on a study of connected car data privacy and tracking in vehicles and their companion apps.
- Manufacturer connected services privacy notices — the primary documents setting out collected data categories, retention periods and third-party recipients for each brand.
- UK Information Commissioner’s Office and equivalent European data protection authorities — guidance on subject access and erasure requests.
- Apple and Google developer and support documentation — current behaviour of app tracking transparency and the Android advertising identifier.
Surfaced from the rss:arstechnica signal “connected car data study”. AI-assisted draft, editorially reviewed.

