# Privacy Policy

What Racing collects, why, where it is processed and how long it is kept. It describes what the product does today and the principles we commit to with design-partner teams.

## Who we are

Apex Scout Racing is a product of FunnySoft, the trade name of João Paulo Santos, a sole proprietor based in Leiria, Portugal. The full details are in the controller box above and in the business information at the foot of every page.

We have two roles. We are the controller for website visits, contact messages and the account data of invited users. For the content your team adds to the Racing app, such as notes, comparisons, diagnoses and test plans, we are a processor and act on your team's behalf.

Questions about this policy go to the [contact page](https://apexscout.racing/contact) or to hello@apexscout.app.

## What we collect

### Website visits

Anonymous page views, clicks on Request access and sent contact forms, as described in [Analytics and your opt-out](#analytics). Our hosting provider also receives your IP address and browser details with each request.

### Contact messages

Your name, email address, topic and message, plus your organisation and role if you give them. A message sent from the app also carries your account ID.

### Account data

Your name, email address, a hash of your password, your two-factor secret and recovery codes if you turn two-factor on, and a random analytics ID. Your invitation and access grant are stored with the account.

### Workspace content

The laps you include, the context you enter for each run, the diagnoses you request and your saved test plan. Context means free-text notes of up to 2000 characters, fuel, tyre pressures, anti-roll bar positions and camber. Every workspace today uses one synthetic Jerez session. You cannot upload telemetry yet.

### Security data

The IP address or account ID behind each request, held for a minute or an hour to limit request rates. Sign-in, password reset and the contact form also run a Cloudflare Turnstile check, which sends Cloudflare a token and your IP address.

## Purposes and lawful bases

Why we process each kind of data.

| Purpose | Data | Lawful basis |
| --- | --- | --- |
| Run your account and workspace | Account data and workspace content | Contract: the early access terms. For team content we follow your team's instructions as its processor. |
| Generate the analysis you request | Workspace content, sent to OpenAI | Contract. Nothing is sent until you request a diagnosis. |
| Answer contact messages and access requests | Contact messages | Steps you ask for before an agreement. Otherwise our legitimate interest in replying to you. |
| Keep Racing secure and working | Security data, logs and monitoring | Legitimate interest in preventing abuse and fixing faults |
| Count website visits | Anonymous analytics events | Legitimate interest, with an [opt-out](#opt-out) |
| Learn which app steps invitees use | App events under a random analytics ID | Legitimate interest in evaluating early access |

## AI analysis

When you request a diagnosis, the Racing API sends OpenAI the evidence snapshot for your comparison. It holds the synthetic lap and channel values you selected and the context for each run, including your free-text notes.

We call the OpenAI API with response storage turned off. OpenAI does not train its models on API data by default. It may still keep requests and responses for up to 30 days to detect abuse, and then deletes them.

The output is advisory. It offers observations, driving and setup hypotheses and one next test, each tied to the evidence it cites, and it can be wrong. Engineering judgment and safety decisions stay with you and your team. Racing makes no automated decision with legal or similarly significant effect on you.

Keep personal data about other people out of your notes.

## Processors

These providers process data for us, each under the safeguard listed. Racing's API, database and cache run in Frankfurt.

Who processes data for Racing.

| Processor | Purpose | Region | Safeguard |
| --- | --- | --- | --- |
| Laravel Cloud | Racing API, database, cache and queues | EU Central, Frankfurt | Laravel data processing agreement and the EU-US Data Privacy Framework |
| Vercel | Hosting for this website and the Racing app | Frankfurt, fra1 | Vercel data processing addendum with Standard Contractual Clauses, and the EU-US Data Privacy Framework |
| OpenAI | The AI analysis you request | United States | Standard Contractual Clauses in the OpenAI data processing addendum, with OpenAI Ireland Ltd |
| PostHog | Anonymous website analytics and app events | EU, Frankfurt | PostHog data processing agreement with Standard Contractual Clauses, and the EU-US Data Privacy Framework |
| Resend | Delivers contact messages to our mailbox | Sends from Ireland; keeps message logs in the United States | Resend data processing addendum with Standard Contractual Clauses, and the EU-US Data Privacy Framework |
| Cloudflare | Turnstile bot check | Cloudflare's global network | Cloudflare customer data processing addendum: the EU-US Data Privacy Framework, with Standard Contractual Clauses as fallback |
| Laravel Nightwatch | Error and performance monitoring of the Racing API | EU, Frankfurt | Laravel data processing agreement and the EU-US Data Privacy Framework |
| Google Workspace | Holds the messages we receive at hello@apexscout.app | Google's data centres, worldwide | Google Cloud data processing addendum: the EU-US Data Privacy Framework, with Standard Contractual Clauses as fallback |

Cloudflare also uses the signals from the bot check to improve Turnstile. For that use it is a separate controller under its own privacy policy.

## Transfers outside the EU

Racing stores its data in the EU, in Frankfurt. The AI analysis leaves the EU: when you request a diagnosis, the request goes to OpenAI in the United States. That transfer relies on the Standard Contractual Clauses in OpenAI's data processing addendum.

Two other providers keep data outside the EU. Resend keeps the logs of the emails that deliver contact messages in the United States for 30 days, and our mailbox runs on Google Workspace. Their safeguards are listed in the processors table.

## Retention

How long each kind of data is kept.

| Data | Kept for | Deleted by |
| --- | --- | --- |
| Account and workspace content | Until you delete your account | You, from the account page in the app |
| Contact messages sent from the app | 12 months | Daily automatic pruning, or deleting your account |
| Contact messages sent from this website | 12 months | Daily automatic pruning, or a request to us |
| Copies in our mailbox | 12 months, as our practice | Us |
| Failed email deliveries | 30 days | Automatic pruning |
| Requests sent to OpenAI | Up to 30 days at OpenAI | OpenAI, automatically |
| Sessions, password reset links and app tokens | 120 minutes, 60 minutes and 30 days | Expiry |
| Rate-limit counters | One minute, or one hour for contact | Expiry |
| Website analytics events | 7 years | PostHog, the fixed retention on our plan |
| App analytics events | 7 years | PostHog, the fixed retention on our plan. Deleting your account unlinks them from you. |
| Email delivery logs at Resend | 30 days | Resend, automatically |
| Logs, monitoring and backups | Logs 7 days, monitoring up to 90 days, database backups up to 30 days | Laravel Cloud and Nightwatch, automatically |

Deleting your account deletes the account, your comparisons, notes, diagnoses and test plans, the contact messages you sent from the app, any of their emails still waiting to be sent, and your analytics ID. Past app events stay in PostHog under that random ID, which nothing links to you any more.

## Design-partner principles

We are shaping the 2027 season roadmap with a small number of design-partner teams. These principles govern that work and apply to every team.

1. Team data stays the team's.
2. Apex Scout owns the software, the models and their weights.
3. No training across teams and no shared model. A team's model learns from that team's data only.
4. A team that leaves gets an export of its data, and then we delete it.
5. Generic features enter the product for everyone. Team-specific know-how stays with the team.

Today no telemetry is uploaded and we train no models on your data.

## Your rights

You can ask to access, correct, export or delete your personal data, or to restrict its processing. You can object to processing based on legitimate interest.

Delete your account yourself from the account page in the app. For an export or any other request, write to us through the [contact page](https://apexscout.racing/contact) or at hello@apexscout.app. We reply within one month.

Where your team is the controller for its content, we pass your request to the team and help it answer.

You can complain to the CNPD, the Portuguese data protection authority, at [cnpd.pt](https://www.cnpd.pt), or to the authority where you live or work.

## Changes to this policy

We change this policy when the processing changes, and update the date at the top. If a change affects invited users, we tell them by email before it applies.

## Analytics and your opt-out

This website sends anonymous page views, clicks on Request access and sent contact forms to PostHog in the EU. Each event carries only the page path without its query, the event name, the button clicked and the contact topic. The site sets no cookies and writes nothing to your browser's storage unless you opt out.

PostHog tells visits apart with a hash of your IP address and user agent, salted daily on its server. PostHog does not keep that hash and builds no profile of you. Our lawful basis is legitimate interest.

The Racing app sends five events from our server to PostHog: comparison opened, diagnosis requested, test plan saved, contact sent and account deleted. They carry a random analytics ID, never your name, email or notes.

To opt out of website analytics, use the control below. It stores one flag in this browser and stops every analytics request from it, on every page and after a reload.