Privacy
What we store about you
This covers the account you hold with us. It is short because we collect very little.
Your account
When you sign up we store your name and email address. If you set a password we store a one-way hash of it, never the password itself. If you sign in with Google we store the account identifier Google gives us so we can recognise you next time — we do not receive or store your Google password, and we ask Google for nothing beyond your name, email address and profile picture.
We use your email address to send you the things an account needs: address verification, password resets, and notices about your subscription. We do not sell it and we do not send marketing you did not ask for.
Your API usage
Every API call is logged against your account: the endpoint, the time, the response status, and the API token used. That is how rate limits, your usage dashboard and abuse detection work. Logs are kept for a rolling window and then discarded.
Payments
Subscriptions are handled by Stripe. Your card details go to Stripe directly and never touch our servers — we hold only the customer and subscription identifiers Stripe gives us back, plus the plan you are on.
Who else processes it
- Stripe — payments and subscription billing.
- Resend — sending account email.
- DigitalOcean — the servers and database, hosted in the EU.
- Cloudflare — DNS and edge caching in front of the API.
- Google — if you choose to sign in with Google, and Google Analytics for counting website visits.
Nobody else. We do not run advertising trackers on this site.
The website uses Google Analytics to count visits: which pages are read, which sites
and searches bring visitors, and roughly which country they are in. It sets the cookies
_ga and _ga_* so a returning visitor is not counted twice, and
keeps them for up to two years. Google Analytics does not store IP addresses, and what we
see are aggregate reports that are never linked to your account. It runs on the website
only, never on the API. A content blocker or
Google's opt-out add-on
stops it.
Race results are a separate thing
The race data this API serves — athlete names, finish times, splits, divisions — is published publicly by race organisers and their timing partners. It is not collected from you, it is not linked to your account, and deleting your account does not change it. If you are an athlete who wants a result changed or removed, that is a request for the organiser who published it, not for us.
Deleting your account
You can delete your account yourself from your profile page. That removes your account record and your API tokens. Billing records that we are required to keep for accounting stay with Stripe.
You can also ask us for a copy of what we hold about you, or ask us to correct it. Email [email protected] and we will sort it out.
Last updated September 2026.