Privacy Policy
The short version: ButterLaps runs entirely in your browser. Your activity files are never uploaded, stored, or seen by us. There are no accounts, no cookies, and no tracking across sites.
1. Who we are
ButterLaps is a browser-based tool for editing lap boundaries in .fit activity files, operated by an individual developer ("we", "us"). For anything privacy-related, contact us at [email protected].
2. Your activity files
Files you open in ButterLaps are processed entirely on your device, in your browser. They are never transmitted to us or to any third party. There is no backend that could receive them. When you close the tab, the file is gone from memory; exported files are saved directly to your device by your browser.
If you contact us for support and choose to share a file to help diagnose an issue, that is a deliberate step you take outside the app – for example by attaching it to an email. It is entirely optional and your own decision. Files shared this way are used solely to investigate the reported issue and are deleted once resolved.
3. Data stored on your device
ButterLaps uses your browser's local storage to remember a small number of preferences – for example your theme (light/dark/system), preferred units (km/mi), and, if applicable, your license key and free-tier usage counter. This data stays in your browser, is not sent to us, and you can clear it at any time through your browser settings.
4. Purchases
If you buy a license, the payment is handled by our payment processor acting as the merchant of record. The processor collects the information needed to complete the purchase (such as your email address, payment details, and billing country) under its own privacy policy – we never see your payment details.
When a purchase completes, our license validation service receives and stores the following data from the payment processor: your email address, the issued license key, an order identifier, your billing country, the purchase amount and currency, and a mode flag (indicating whether the purchase was a test or a live transaction). This data is stored in Cloudflare's KV service and is used solely to validate and manage your license. Your name and payment details are not stored by us. We keep this data for as long as your license is valid, so we can continue to validate it; it is deleted on request or once it is no longer needed. If a license is revoked, a minimal record of that revocation is kept – Section 8 explains what stays and why.
When you unlock the app with a license key, the key (together with the purchase email) is sent to our license validation service to confirm it is genuine. Nothing about your activity files is included in that request.
5. Analytics
We use Cloudflare Web Analytics, a privacy-focused, cookieless analytics service, to understand aggregate usage – for example roughly how many people load the app. This kind of analytics does not use cookies, does not identify you personally, and does not track you across other websites. We also record a small set of anonymous in-app events – for example that a file was loaded or exported, or that the licence prompt was shown – along with a coarse size band of the activity based on its number of laps. These events are processed by our own service (Cloudflare Workers Analytics Engine), carry no cookies and no identifier that follows you across visits, and are used only to understand how the tool is used and to size the free tier. The contents of your activity files are never part of any analytics event.
6. Cookies
ButterLaps sets no cookies. Our payment processor may set cookies on its own checkout pages, governed by its own policy.
7. Sharing and selling
We do not sell, rent, or share personal data with anyone, full stop.
To run the service, we rely on a small number of trusted third-party providers who process data on our behalf: Cloudflare (which hosts the site, stores license data in its KV service, and provides cookieless Web Analytics) and our payment processor (the merchant of record for purchases). These providers act as service providers under their own data-protection terms and safeguards – they are not given your data to use for their own purposes, and this is not a sale or sharing of personal data. Because these providers operate globally, they may process data on servers located outside your country.
8. Your rights
Depending on where you live (for example under the GDPR), you may have rights to access, correct, or delete personal data we hold about you. The personal data we hold is limited to purchase-related information described in Section 4 (email, license key, order identifier, billing country, amount, currency). To exercise these rights, email us at [email protected] and we will respond promptly.
How to request erasure. Email [email protected] from the address you used to buy the license, or include the license key or the order identifier so we can find the right record – those are the only things we hold that connect a record to you. We reply within 30 days, and usually within a few days. Before deleting anything we will tell you what will go, because erasure has a cost worth knowing about: the purchase record is what our validation service checks, so deleting it ends the license it represents. The app will re-lock on your next page load, and we cannot restore it afterwards. If a refund is also owed, ask for it first – once the record is gone we can no longer issue one from our side.
One exception: revoked licenses. If a license has been revoked – for example after a chargeback, or a refund granted where the license was being misused – we keep a minimal record that the revocation happened. That record is the only thing stopping the revoked license being re-created and used again, so we retain it for fraud prevention, on the basis of our legitimate interest in protecting the service against abuse. When you request erasure we strip the personal data out of it – your email address and the order and transaction identifiers – and keep only the license key and the dates. What remains identifies a revoked license, not a person.
Data held by our payment processor as merchant of record – including your name and payment details, which we never see – is covered by that processor's own privacy policy and its own legal record-keeping duties. We can pass a request on, but that record is not ours to delete.
9. Changes to this policy
If we change this policy, we will update this page and the effective date above. Material changes will be noted in the app's changelog.