Two years after I began investigating connected-vehicle privacy. A new study finds that automakers’ privacy policies have grown longer, more complicated and further beyond the reading level of many Americans.
A note of appreciation and full credit: This special report is based primarily on extensive original research by All About Cookies, whose team examined the current privacy policies of 14 major automakers. The study was written by Steph Trejos and Josh Koebert and edited by Kalleigh Lane. Their work made this CarPro update possible, and I sincerely thank them for allowing consumers to see—in plain numbers—how difficult automakers make it to understand what happens to our personal information.
In March 2024, I began a series of reports under a simple but disturbing question: “Is Your Car Spying on You?”
What began with reports of driving information reaching insurance companies quickly grew into something much larger. Over the following months, I examined the collection of location information, acceleration and braking data, app activity, personal contacts and other information. We covered GM’s decision to stop sharing OnStar Smart Driver data with LexisNexis and Verisk, the potential danger connected-car technology can pose to domestic-abuse victims, Mozilla’s troubling evaluation of automotive privacy and calls by two U.S. senators for federal action.
At the time, I called some of these practices deplorable. More than two years later, I still do.
The latest All About Cookies study does not simply ask what information automakers say they may collect. It asks an equally important question: Can an ordinary customer realistically understand the privacy policy supposedly explaining it?
For many consumers, the answer appears to be no.
The Fine Print Is Going in the Wrong Direction
All About Cookies analyzed 18 privacy documents from 14 major automakers. Four companies publish separate policies covering connected vehicles or in-car services, so those documents were graded individually.
Researchers copied the policies into the Hemingway Editor, which calculated reading levels, sentence counts and document lengths. Reading times were measured with a separate readability tool. The policies examined were the most recent versions available as of July 2026.
GET THIS: The average automaker’s primary privacy policy contained 8,422 words, required approximately 42 minutes to read and demanded a 13th-grade reading level—the equivalent of a college freshman.
The study’s 2024 analysis found an average of 7,505 words and a 12th-grade reading level. All About Cookies calculates that the average primary policy has grown roughly 12% longer in two years. In other words, as vehicles become more complicated, the documents explaining their data practices are becoming more complicated, too.

Even the easiest policy in the study—the combined notice covering Chrysler, Jeep, Dodge and Ram—requires a ninth-grade reading level. All About Cookies notes that the average American reads at approximately a seventh- or eighth-grade level.
That means every automaker examined wrote its privacy policy above the reading level of the average consumer.
Ford had the longest single document at 18,588 words. Kia was the wordiest company overall, with a 14,631-word general policy and a separate 10,942-word Kia Connect policy. Together, they total 25,573 words—longer than some well-known books.
Apparently, somewhere between selecting a paint color and signing the finance papers, buyers are expected to squeeze in a little light reading roughly the length of a novella.
What the Policies Say Companies May Collect
Length alone is not the biggest concern. It is what consumers may discover if they make it through the legal language.
According to All About Cookies examination, Ford’s policy covers entertainment information including radio presets, volume and the titles, artists and genres played in the vehicle. BMW’s policy addresses calendar events, contacts, notifications and 3-D surround-view images. GM says Super Cruise may record when its system determines that a driver is distracted or drowsy.
Honda’s policy describes inferences involving such characteristics as behavior, attitudes, intelligence, abilities and aptitudes. Kia lists genetic information and citizenship status among sensitive information categories. Nissan’s policy includes religious affiliation and national origin and says Nissan holds exclusive rights to certain carbon credits generated through an electric vehicle’s charging data.
Tesla describes collecting a mathematical representation of a customer’s face for automated identity verification during purchasing, financing and delivery. Toyota has an “AI Research” category that allows customer data to be used to train and fine-tune artificial-intelligence models. Mercedes-Benz also says information may be used to train, test and refine AI models and algorithms.
Mazda’s connected-vehicle policy says driving information such as speed, acceleration, steering and braking is transmitted at the end of a trip when the ignition is turned off. All About Cookies also found language indicating that Mazda’s data collection does not necessarily stop when the vehicle is sold or a lease ends.
Hyundai’s policy says vehicle location may be used to assist Hyundai Capital America with repossession in delinquency cases, regardless of a customer’s location-data settings. Volkswagen’s DriveView program shares driving behavior and GPS information with named insurance companies for up to 20 days or 20 trips.
These disclosures do not necessarily mean every listed category is collected from every driver, on every trip, in every model. A general privacy policy may cover websites, financing, dealerships, mobile apps and connected services in addition to information generated inside the vehicle. Readability scores also do not establish that an automaker has violated a law.
They do, however, show what companies say they may collect, use, infer or share—and how difficult it can be for customers to understand the bargain they are making.
Why Readability Matters
A privacy policy is supposed to provide notice. But notice is not especially meaningful when it takes 42 minutes and a college education to decipher it.
Most people encounter these agreements while creating an app account, setting up connected services or taking delivery of a new vehicle. After negotiating, signing documents, moving personal belongings and learning a new infotainment system, almost nobody stops to study another 8,000 words of legal language.
That makes the “I agree” button less like informed permission and more like the digital equivalent of “Just show me where to initial so I can go home.”
This is not a theoretical concern. In January 2026, the Federal Trade Commission finalized an order settling allegations that GM and OnStar collected, used and sold precise geolocation and driving-behavior information without adequately notifying consumers or obtaining informed consent. The data included hard braking, speeding and late-night driving and could be used by consumer reporting agencies and insurers.
Under the order, GM and OnStar are prohibited for five years from disclosing certain information to consumer reporting agencies. They must obtain affirmative consent for specified collection and uses and provide consumers with greater access to and control over their data. GM did not admit or deny the allegations beyond what was required by the settlement.
That enforcement action grew out of the same issue CarPro began warning readers about in 2024: A vehicle can quietly become a rolling data source, and the consequences may not become visible until an insurance premium rises or some other decision is made.
What You Can Do Now
First, find the privacy and data-sharing settings in both your vehicle and its mobile app. Look specifically for driver scores, driving feedback, insurance connections, personalized advertising and third-party sharing. Do not automatically accept every permission simply because the screen makes “Agree” the easiest button to press.
If you pair a phone, consider whether the vehicle truly needs your contacts, messages, calendar and complete address book. Convenience has value, but access should be intentional.
You can also enter your VIN at VehiclePrivacyReport.com for a summary of the data practices associated with your vehicle. Treat it as a starting point, then visit the automaker’s privacy-request page to ask what information it maintains and what choices are available where you live.
Before selling, trading, returning or renting a vehicle, delete saved destinations, Home and Work addresses, contacts, call histories, text messages, Bluetooth connections, user profiles and garage-door codes. Sign out of apps, disconnect the vehicle from your manufacturer account and perform the proper factory reset. Remove toll tags and paperwork, too. A trade-in should include your old floor mats—not a digital autobiography.
The Bottom Line
The new All About Cookies research confirms that the privacy issue I began investigating in 2024 has not disappeared. Privacy policies are getting longer, the average reading level has risen, and the information described reaches far beyond engine diagnostics and maintenance reminders.
Connected technology can provide navigation, emergency assistance, remote starting, theft recovery and important safety features. I am not suggesting we give all of that up. I am saying consumers deserve a clear explanation of what is collected, why it is collected, who receives it and how to say no without losing unrelated features.
If an automaker can explain a 500-horsepower engine or hands-free driving system in a 30-second commercial, it ought to be able to explain what it does with our personal information without requiring a college degree and a free afternoon.
Your car may still be spying on you. The least it can do is tell you—in language you can understand.