Last updated 4 October 2026
Lapbar is a roller coaster logging app run by Patrick Darmody, an individual developer. This page describes the kinds of information Lapbar handles and the commitments that go with them. Those commitments are meant to outlast any particular version of the app.
This box is the part that changes. When one of these switches on, this box and the date at the top change with it, in the same release.
Since 30 August 2026 the app records a short list of things that happen in it: that a sign-in code was asked for, that one worked, that a profile was made, how far you got through the welcome steps, that the log screen was opened, that a ride was logged, that a wait time was reported, that an invite or a link was shared, and — once sponsorship is switched on — that a sponsored spot was shown or tapped. Nothing else.
Each record holds the event name, the time, your account id, whether you are on iPhone or Android, the app version, and a few counters — whether a ride was rated, how many people were tagged, whether you said which row you sat in. No free text, no coaster names, no email addresses. The rule we hold ourselves to is that this table should be safe to hand someone as a spreadsheet.
It exists to answer questions the rest of the database cannot: how many people open the log screen without saving anything, how many reach the username step and stop. Only Patrick can read it. It is not shared with anyone and there is no third-party analytics service in the app.
An email address, which is how you sign in — Lapbar has no passwords, it emails you a code. Plus the profile you choose: username, display name, bio, home park. Your email address is never shown to anyone.
Rides you log, ratings, written reviews, your favorite parks and coasters, and answers to questions about a ride — what restraint it uses, how long you queued, which row you sat in, how it rode that day. Who you rode with: another rider's username, or a name you type in for someone who is not on Lapbar. Places you ate and, if you say, what you paid. Where you like to sit on a train. Lapbar is a public log by design — assume everything in this category is visible to anyone using the app. Private-visibility settings may exist in future; until this page says so, they do not.
Photos. Since 31 August 2026 you can attach a photo to a review, and choose a profile picture. Every photo is held until a person has looked at it — until then only you can see it. Once approved it is public. You must not upload pictures of people who have not agreed to appear, or anything you do not have the right to share. A reported photo is hidden immediately while a person looks at it. Lapbar asks for your camera or photo library only when you choose to add a photo, and takes only the one you pick. The coaster and park photographs throughout the app come from Wikimedia Commons under free licenses and are not from users.
People you block and reports you file. Reports are private: the person reported is never told who reported them. That is a commitment, not an implementation detail.
Only if you send one: a suggested coaster, or a claim that you represent a park — which includes the work email address you provide for verification.
If you allow notifications, your phone gives Lapbar a token that addresses it, stored against your account so a follow, a reply or a reminder reaches you. Turning notifications off in your phone's settings stops them; signing out removes the token. Lapbar may also send one email reminder if you start setting up a profile and leave it empty.
Lapbar uses a third-party service to record crashes, and may later use one to understand which parts of the app get used. Such a service receives technical information — the error and where it happened, your device model, operating system and app version — and an account identifier that is a random ID rather than your email or name.
Crash reporting has been on since 21 August 2026, through Sentry. It is set up deliberately narrowly: no IP address is recorded, your account is identified only by a random ID, and the addresses of pages you loaded have their details stripped before being stored. Lapbar does not record your screen and does not track how long you spend anywhere.
They are never used for advertising, and never joined to anything outside Lapbar. The box above says whether any of this is currently active.
These are commitments rather than a description of the current build:
Lapbar relies on a small number of services to run. Each gets only what its job requires:
| Role | Currently |
|---|---|
| Database, sign-in and photo storage | Supabase (United States) |
| Delivering notifications to your phone | Expo (United States), then Apple or Google |
| Sending email — your sign-in code, and the one setup reminder | Resend — receives your email address and the message, nothing else |
| App distribution | Apple, under Apple's own terms |
| Crash reporting | Sentry — receives the error, your device model and OS, the app version, and a random account id. Never your email. |
| Product analytics | None active — see the box above |
That right-hand column is a snapshot and will change as the app grows; the roles are the durable part. Coaster photographs come from Wikimedia Commons under free licenses — a one-way fetch that sends nothing about you.
Profile → Delete my account. It removes your profile, every lap you have logged, your ratings and reviews, immediately and permanently. It cannot be undone and it cannot be recovered afterwards. Aggregate counts that cannot identify you — such as how many people say a coaster has a lap bar — may remain. Copies in our encrypted backups are deleted on a rolling schedule within 13 months and are only used to recover from a disaster.
You can see everything Lapbar holds about you inside the app, change it by editing it, and erase it by deleting your account. If you are in the UK, EU or California you have statutory rights of access, correction, erasure and portability; email [email protected] and they will be honored. Information is processed to provide a service you asked for, and on a legitimate interest in keeping the app safe.
Lapbar is for people aged 13 and over. It is not directed at children, and accounts believed to belong to under-13s are deleted. If you believe a child has created an account, email [email protected].
Until you delete them. There is no scheduled deletion of active accounts. Blocks and reports last as long as your account, because they are what stops the same problem recurring.
Every table enforces row-level security, so the database itself refuses to hand your information to someone else's session rather than trusting the app to ask correctly. Sign-in uses single-use codes, so there are no passwords to leak. No system is perfectly secure, and this is a small independent app rather than a company with a security team — weigh that when deciding what to post.
The commitments above are meant to be stable. The box at the top, and the right-hand column of the processor table, change as features ship — in the same release as the change itself, never after it. The version and date at the top move every time. Material changes will also be surfaced in the app.
Patrick Darmody — [email protected]