Effective date: September 8, 2026

1. Introduction

LapBrain LLC ("LapBrain", "we", "us", "our") operates the LapBrain telemetry analysis platform. This Privacy Policy explains what information we collect, how we use it, and your choices regarding your data.

2. Information We Collect

Information you provide

  • Account information. Email address and password when you create an account.
  • Legal acceptance records. When you create an account, and again whenever we publish an updated Terms of Service or Privacy Policy and you accept it, we record which version of each document you agreed to and when you agreed. We keep this record so we can show what you were asked to agree to, and so we can tell whether you still need to review an updated document. It is part of your account data: it is included in the copy we provide if you exercise the access or export rights in Section 7, and it is deleted with your account as described in Section 6.
  • Display username. An optional, self-chosen username. Setting one is not required to use LapBrain. If you do set a username, it doubles as your display name and is visible to riders you connect with through the social features described in Section 4 (for example, mutually-accepted friends and riders you consent to compare with). It is never shown to other riders unless you opt into one of those features.
  • Age eligibility record. Creating an account requires you to confirm that you are at least 18. We store the date and time of that confirmation with your account so we can enforce and evidence the Service's age requirement.
  • Social connections. If you use LapBrain's optional social features, we store your friend requests, mutually accepted friendships, invite codes, blocks, and sharing choices. We do not read or upload the contacts from your phone or address book.
  • Subscription and purchase information. If you subscribe to paid features, we store the billing provider, product, subscription status, renewal or expiration dates, cancellation/refund/revocation status, and provider transaction or subscription identifiers needed to validate and manage your access. App Store and Google Play purchases are processed by Apple or Google; they do not give us your full payment-card details. If we later offer direct web billing, payment-card details will be handled by our payment processor rather than stored by LapBrain.
  • Telemetry data. Data logger files you upload, including AiM XRK/XRZ, MoTeC LD, and VBO exports from RaceBox or compatible software. These contain motorcycle and rider performance data such as GPS coordinates, speed, acceleration, lean angle, throttle position, and lap times.
  • Telemetry from a connected device. If you choose to connect your own RaceBox GPS data logger, LapBrain uses Bluetooth Low Energy solely to connect to that data logger and read its session telemetry, the same kind of motorcycle and rider performance data described above (GPS coordinates, speed, acceleration, lap times), which is then uploaded to the Service in the same way as an uploaded file. This device sync is optional: the core upload-and-debrief workflow does not require Bluetooth, and you can use LapBrain fully without connecting any device. We use Bluetooth only to communicate with your own data logger; the Bluetooth scan that finds nearby data loggers is flagged so that the operating system does not derive your location from scan results, and we do not use Bluetooth scanning to determine your location.
  • Data logger identifiers. When you sync sessions directly from a data logger (a RaceBox over Bluetooth, or an AiM Solo 2 or Solo 2 DL over its own WiFi from the mobile app), we also collect the data logger's hardware serial number along with the synced session. We use the serial to recognize which device recorded a session and to avoid importing the same session more than once (de-duplication).
  • Your bikes. If you add bikes to your garage, we store the bike details you enter, such as a name you choose and, optionally, the make, model, and year. This lets LapBrain keep per-bike personal bests and comparisons separate.
  • Coaching context. If you tell LapBrain about your current coaching situation (for example, a track school or a coaching program), we store the context you select and an optional free-text note. The note is entirely yours to fill in and is used only to give your coaching context. Please do not enter other people's personal details in this note. For instance, avoid putting a coach's full name or contact information there.
  • Support and contact messages. If you contact us (through an in-app support ticket or the contact form on this help site), we receive the content you send. For the help-site contact form this includes the name, email address, and message you provide; for in-app support tickets it includes the message text and the account it was sent from. We use this to respond to and resolve your request.
  • Preferences. Display settings such as unit preferences (imperial/metric).

Information collected automatically

  • Usage data (in-product analytics). After you sign in, we collect limited in-product analytics about how LapBrain is used, such as screen and route names, feature usage events, related LapBrain session IDs, app-session IDs, platform, app version, data logger type, and small structured metadata like reason codes or first-time-setup step identifiers. This is linked to your account. We use this to understand product adoption, identify friction, and improve the Service. "Usage data" means how you use the app. It is not your "Telemetry data" above, which is the riding data from your data logger. Usage data never includes your lap recordings; the two are different things, and the control below applies only to usage data. You can turn this off at any time in Settings → Privacy → "Share usage data to help improve LapBrain". Turning it off stops collection for your account going forward and does not affect your access to the Service. See Section 10 for the lawful basis and the related right to object.
  • Automated error and crash reports. When the LapBrain web or native app encounters a runtime error or panic, the app sends us a structured error report so we can diagnose and fix the underlying bug. Each report includes the error type, the error message (truncated), a bounded stack trace, the screen/route the error happened on, the platform and app version, and an app-session ID. Reports are persisted on your device before sending and may be delivered later if you are offline at the time of the failure. Some reports are sent without an account identifier (for example, when the error happens during sign-in or before you are signed in), and in that case we record only a date-scoped hash of your IP address for short-term rate-limit and abuse controls. The hash incorporates the current UTC date, so its value changes each day.
  • Technical information. Browser type, operating system, device type, and similar compatibility/debugging information.
  • Age-assurance signal. On our mobile apps, and only to help enforce our 18-or-older requirement (see Section 9 and the Terms of Service), at app launch we ask the platform's age-assurance service (Google Play Age Signals on Android, or Apple's Declared Age Range on iOS) whether you meet the 18 age gate, where the platform supports it. The platform may return a coarse age range, but we read and keep only a single coarse category (essentially whether you are over 18, under 18, or have declined to share), and we never receive or store your birth date or exact age. If you decline, or the platform provides no signal, we rely on the age confirmation you gave when you signed up.
  • App Store app identity. On iOS, after you sign in, Apple provides the app with a cryptographically signed app-transaction record even if you have not bought a subscription. It contains an identifier that Apple assigns to the combination of your Apple Account and the LapBrain app, plus information identifying the app and App Store environment. We send that signed record to LapBrain to verify it, immediately discard the raw record, and retain only a one-way hash of the identifier, the environment, its association with your LapBrain account, and when that association was first and last seen. We use this record only to associate an Apple consent-withdrawal notice with the correct LapBrain account and suspend access when required. It is not used as proof of your age, for advertising, or for tracking. Apple does not provide us with your Apple Account email address, name, or payment-card details through this record. The retained account association is deleted when you delete your LapBrain account.

What usage data does not include

Our usage data collection is designed to be minimal. It does not include:

  • raw rider telemetry streams such as GPS traces, lap channels, sector timeseries, or uploaded file contents
  • uploaded filenames copied into analytics events
  • free-form notes, support messages, search text, or arbitrary URLs
  • session replay, screen recording, or blanket clickstream capture
  • third-party advertising identifiers, third-party analytics pixels, or third-party tracking cookies

Usage data is collected by us alone and is sent only to LapBrain services.

What automated error and crash reports do not include

Error and crash reports are similarly scoped. They do not include:

  • raw rider telemetry, GPS traces, channel data, or any uploaded file contents
  • uploaded filenames or session contents
  • account email, username, password, bearer tokens, or session cookies
  • free-form notes, support messages, search text, or rider-entered text
  • arbitrary URLs (we record the semantic screen/route name only, never the full URL with its query string or fragment)
  • third-party crash reporters or external SDKs (error reports are sent only to LapBrain services)

3. How We Use Your Information

We use the information we collect to:

  • Provide the Service. Process your telemetry data, generate analysis, deliver coaching suggestions, and maintain the paid-feature access tied to your subscription or account grants.
  • Improve the Service. Understand usage patterns, identify product friction, fix bugs, validate onboarding/help flows, and develop new features.
  • Understand how the app is used. Measure feature adoption and core rider journeys, such as upload, debrief, analysis, corner-detail, and cross-session workflows.
  • Communicate with you. Send account-related notifications (e.g., password resets).
  • Ensure security. Detect and prevent unauthorized access or abuse.

4. Information Sharing

We do not sell, rent, or share your personal information with third parties for their marketing purposes.

We also do not send usage data to third-party analytics providers, advertising networks, or social-media tracking tools.

We may share information only in these limited circumstances:

  • Service providers. We use infrastructure providers (cloud hosting, email delivery) that process data on our behalf under strict confidentiality obligations.
  • Map and satellite imagery provider. When you view a track map, your device requests map and satellite image tiles directly from our maps provider, MapTiler. To serve those tiles, MapTiler receives your device's IP address and the map-tile parameters your device requests (such as the map area and zoom level). MapTiler does not receive your LapBrain account details or your rider telemetry. Your device only makes these requests when you open a view that shows a map.
  • Billing providers. If you subscribe through Apple App Store or Google Play, those providers process your purchase and provide us with subscription status information needed to validate access. If you make a refund request for an App Store subscription and separately agree in the app, LapBrain tells Apple that the subscription service was delivered, that information about its functionality was provided, and asks Apple to grant a prorated refund. Apple uses that information to decide the refund, and the agreement applies only to that request. On iOS, Apple also provides the signed app-identity record described in Section 2 after sign-in, whether or not you subscribe. If we later offer direct web billing, our payment processor will process the payment and provide us with the information needed to manage the subscription.
  • Legal requirements. We may disclose information if required by law, regulation, or valid legal process.
  • Business transfers. In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

Sharing with other riders

LapBrain includes optional social features that let you share data with other riders. These are the only ways your data becomes visible to another rider, and you control them.

Friends. You can connect with another rider as a friend. A friendship requires both riders to accept (there is no one-sided following) and it is established through an invite link or code you choose to share. Once you are friends:

  • What a friend can see: the sessions you share with friends, including the detailed lap data for those sessions (precise GPS racing-line traces; speed, throttle, brake, and lean traces; lap and sector times and deltas; turn-by-turn metrics) together with your chosen display username.
  • What a friend cannot see: your account email, your private rider notes and setup profiles, your full session list (only the sessions you share), your other friendships, or any field marked rider-private.

Sharing is on by default for new sessions, and you can opt out. For riders you have accepted as friends, new sessions are shared with those friends by default. This is opt-out: you can change the account-level default so future sessions are not shared, and you can override sharing for any individual session. Turning sharing off, at the account level or per session, takes effect immediately, and your friends' cached views are removed on their next visit.

Named-rider comparison (opt-in). Separately, you can opt in to named-rider comparison. This is off unless you turn it on. When enabled, eligible riders in the same track and bike-class context can select you as a comparison reference and see your display name together with summary comparisons and overlays based on your personal-best laps. It does not expose your raw lap traces; that deeper access comes only from friend sharing described above.

Turning off sharing and revoking access. You stay in control:

  • Change your account-level sharing default, or the per-session share setting, in Settings at any time.
  • Unfriend a rider (from either side) to end friend-level access; your data stops being visible to them going forward.
  • Block a rider to remove any existing friendship and prevent future requests.
  • Turn off named-rider comparison in Settings to stop appearing as a selectable comparison reference.

Revoking one friendship never affects any other friend's access. Sharing is managed per rider and per session.

5. Data Storage and Security

  • Your data is stored on servers in the United States.
  • We use encryption in transit (TLS) and at rest to protect your data.
  • We implement access controls and audit logging to prevent unauthorized access.
  • No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

6. Data Retention

  • We retain your account data and uploaded rider telemetry for as long as your account is active, unless a shorter retention period is required by law or an operational policy.
  • Raw usage data events are retained for up to 180 days.
  • Derived aggregate product usage counters are retained for up to 25 months.
  • Raw automated error and crash reports are retained for up to 90 days. Aggregate error signatures (a deduplicated record of "this error has been seen N times") are retained indefinitely so we can recognise recurring or returning bugs across releases; these aggregates are not keyed to your account.
  • The IP hash used only to rate-limit anonymous error reports incorporates the current UTC date, so the value derived from a given IP address changes every day. The underlying secret is retained, so this is not irreversible anonymization. We use it solely for abuse prevention and rate-limiting, never to identify or track you, and these hashes are retained for at most 90 days.
  • You can delete your account at any time from within the app (Settings → Delete Account) or by contacting us. When you do, we will delete your personal information, uploaded rider telemetry, account-keyed usage data, and account-keyed error reports within 30 days.
  • We may retain de-identified aggregated data that does not identify you for analytical purposes.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete your account and associated data (you can also do this yourself at any time in Settings → Account → Delete Account)
  • Export your data in a portable format
  • Object to certain processing of your data (for usage data you can do this yourself at any time in Settings → Privacy → "Share usage data to help improve LapBrain"; see Section 10)

To exercise these rights, contact us at [email protected].

8. Cookies and Local Storage

The web application uses browser local storage to maintain your session, preferences, and a short-lived outbox of pending error reports for delivery once you are online. We do not use third-party tracking cookies, advertising cookies, or third-party analytics cookies. Usage data and error reports go directly to LapBrain services and to no one else.

9. Children's Privacy

The Service is available only to users 18 or older (see the Terms of Service eligibility section) and is not directed at anyone under 18. We do not knowingly collect personal information from anyone under 18. If we learn that an account holder is under 18, we will close the account and delete its data. If you believe someone under 18 has provided us with personal information, contact us and we will delete it.

10. International Users

Your data is stored and processed in the United States. If you are accessing the Service from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

If you are located in the European Economic Area (EEA), United Kingdom, Switzerland, California, or another jurisdiction that grants additional privacy rights, you may have rights beyond those listed in Section 7, including the right to lodge a complaint with your local data protection authority. To exercise any data rights, contact us at [email protected] and we will respond within 30 days.

Lawful basis (EEA/UK)

If you are in the EEA or the UK, we rely on the following lawful bases under the GDPR (and the UK GDPR) for the processing described in this policy:

  • Performance of a contract for the processing needed to provide the Service to you: your account, your uploaded telemetry, and the analysis we produce from it.
  • Legitimate interests for usage data (Section 2, "Usage data (in-product analytics)") and for automated error and crash reports. Our legitimate interest is understanding how LapBrain is actually used and diagnosing faults, so that we can fix, maintain, and improve the Service. This usage data is linked to your account. We consider this processing to be limited in scope and low in impact: we collect it ourselves rather than through third parties, we do not sell or share it with advertisers, we do not use it for advertising, profiling that produces legal or similarly significant effects, or automated decision-making about you, and it excludes your raw telemetry streams, GPS traces, uploaded file contents, and free-form text, as described in Section 2.
  • Consent where we ask for it specifically, and legal obligation where we are required to retain or disclose information by law.

How to object. Where we rely on legitimate interests, you have the right to object to that processing (the Section 7 "Object" right). For usage data you can exercise that right yourself, at any time, in Settings → Privacy → "Share usage data to help improve LapBrain". Turning it off stops collection of usage data (how you use the app, not your riding data) for your account going forward; it does not require contacting us and does not affect your access to the Service. Automated error and crash reports are a separate category and are not covered by that setting. To object to those, or to any other processing described above, contact us at [email protected].

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service. Your continued use after changes are posted constitutes acceptance.

12. Contact

If you have questions about this Privacy Policy or LapBrain LLC's handling of personal information, contact us at [email protected].