Version 3 — 21 August 2026
Lapbar is a roller coaster logging app run by Patrick Darmody, an individual developer. This page describes the kinds of information Lapbar handles and the commitments that go with them. Those commitments are meant to outlast any particular version of the app.
This box is the part that changes. When one of these switches on, this box and the date at the top change with it, in the same release.
An email address, which is how you sign in — Lapbar has no passwords, it emails you a code. Plus the profile you choose: username, display name, bio, home park. Your email address is never shown to anyone.
Rides you log, ratings, written reviews, photos, your favourite parks and coasters, and answers to questions about a ride such as what restraint it uses. Lapbar is a public log by design — assume everything in this category is visible to anyone using the app. Private-visibility settings may exist in future; until this page says so, they do not.
People you block and reports you file. Reports are private: the person reported is never told who reported them. That is a commitment, not an implementation detail.
Only if you send one: a suggested coaster, or a claim that you represent a park — which includes the work email address you provide for verification.
Lapbar uses a third-party service to record crashes, and may later use one to understand which parts of the app get used. Such a service receives technical information — the error and where it happened, your device model, operating system and app version — and an account identifier that is a random ID rather than your email or name.
Crash reporting has been on since 21 August 2026, through Sentry. It is set up deliberately narrowly: no IP address is recorded, your account is identified only by a random ID, and the addresses of pages you loaded have their details stripped before being stored. Lapbar does not record your screen and does not track how long you spend anywhere.
They are never used for advertising, and never joined to anything outside Lapbar. The box above says whether any of this is currently active.
These are commitments rather than a description of the current build:
Lapbar relies on a small number of services to run. Each gets only what its job requires:
| Role | Currently |
|---|---|
| Database, sign-in and photo storage | Supabase (United States) |
| Sending your sign-in code | Resend — receives your email address and nothing else |
| App distribution | Apple, under Apple's own terms |
| Crash reporting | Sentry — receives the error, your device model and OS, the app version, and a random account id. Never your email. |
| Product analytics | None active — see the box above |
That right-hand column is a snapshot and will change as the app grows; the roles are the durable part. Coaster photographs come from Wikimedia Commons under free licences — a one-way fetch that sends nothing about you.
Profile → Delete my account. It removes your profile, every lap you have logged, your ratings, reviews and photos, immediately and permanently. It cannot be undone and it cannot be recovered afterwards. Aggregate counts that cannot identify you — such as how many people say a coaster has a lap bar — may remain.
You can see everything Lapbar holds about you inside the app, change it by editing it, and erase it by deleting your account. If you are in the UK, EU or California you have statutory rights of access, correction, erasure and portability; email [email protected] and they will be honoured. Information is processed to provide a service you asked for, and on a legitimate interest in keeping the app safe.
Lapbar is for people aged 13 and over. It is not directed at children, and accounts believed to belong to under-13s are deleted. If you believe a child has created an account, email [email protected].
Until you delete them. There is no scheduled deletion of active accounts. Blocks and reports last as long as your account, because they are what stops the same problem recurring.
Every table enforces row-level security, so the database itself refuses to hand your information to someone else's session rather than trusting the app to ask correctly. Sign-in uses single-use codes, so there are no passwords to leak. No system is perfectly secure, and this is a small independent app rather than a company with a security team — weigh that when deciding what to post.
The commitments above are meant to be stable. The box at the top, and the right-hand column of the processor table, change as features ship — in the same release as the change itself, never after it. The version and date at the top move every time. Material changes will also be surfaced in the app.
Patrick Darmody — [email protected]