Preski Labs
Privacy

How TrackLab handles your data

This notice describes the current TrackLab BMX web and iPhone/iPad app behavior. TrackLab combines Wattbike telemetry, mapped tracks, training history, multiplayer rooms, and optional AI commentary.

Last updated September 6, 2026
Your controlsPhotos, location, microphone, commentary, and ghost analytics have feature-level choices.
Account syncSigned-in profiles and training records are stored so they remain available across devices.
Portable sessionsDownload individual sessions as JSON or CSV, or a selected day as a Numbers/Excel workbook.

Data TrackLab handles

Account and profile information

Account records include your name, email address, password credential, membership level, and sign-in session. Passwords are stored by the TrackLab server as salted password hashes, not as readable passwords. You may add a rider photo. Studio and Club Connect features can also store rider names, nicknames, photos, club relationships, and invite status. Beta access records include your account identifier, connection allowance, activation and expiration dates, and revocation/audit status. During open public beta enrollment, signing in automatically creates this temporary access record without a purchase.

A signed-in user who asks to claim a bike-shop listing supplies the shop identity, their relationship to the business, a business email or phone number or documentation note, and the request's review status. Claim evidence and claimant/reviewer identities remain private to the requester and authorized TrackLab reviewers even after a decision. An approved listing publicly shows only a claimed-and-verified badge.

Friends, handles, and safety information

TrackLab assigns an account handle for the Friends feature. If you choose to appear in rider discovery, signed-in users can find your public handle and display name and may send you a friend request. TrackLab stores friend connections, pending and answered requests, invite-link status, blocks, removals of default connections, and safety reports so the service can operate the network and enforce your choices.

Wattbike and training information

TrackLab processes nearby Wattbike identifiers and names, saved bike assignments, connection state, and available measurements such as cadence, power, speed, and battery information. During a session, it can derive rollout distance, timing, reaction, splits, race position, pedal-zone results, finish order, personal records, ghost replays, and training history. Straight Sprint settings and Explore distance, duration, grade, and elevation can also be included in saved sessions.

Watt and power measurements are private rider records. They remain available in the individual rider's own training history and downloads. When a rider has claimed their Club Connect profile, power from training explicitly attributed to that claimed profile is also available to that club's authenticated owner in the private Results view. Power is never published to public leaderboards, ghosts, demo views, multiplayer participants, or public/shared exports. During club training, current live watts may also appear on the authenticated club owner’s optional Club Live Monitor and on a local monitor directly connected to the bikes.

Optional Apple Watch heart rate

If you choose to connect Apple Watch heart rate, the TrackLab Watch app asks through Apple Health for permission to read heart-rate samples and to save the indoor-cycling workout that you start. TrackLab receives the beats-per-minute value, the time Apple Watch measured it, and technical sequence and delivery times needed to prevent duplicate or stale readings. Heart rate is used only as a private fitness and training metric; TrackLab does not use it to diagnose, treat, or provide medical advice.

Choosing to save heart rate to TrackLab sends those samples to the signed-in rider's TrackLab account so they can be aligned with active riding time, pauses, pedal zones, and session results. Heart rate is excluded from public leaderboards, ghosts, Friends, multiplayer, AI commentary, advertising, and marketing. TrackLab does not sell heart-rate data or disclose it to advertisers or data brokers. A rider can continue using every training mode without granting Apple Health access.

Watch Connect can remember a rider's approved TrackLab app installation so later training days do not require another invite or setup code. TrackLab stores a random, revocable installation identifier for this purpose, not the Apple Watch serial number or a hardware advertising identifier. The rider still presses Watch Connect on the paired iPhone to start each visible four-hour connection. That connection can cover multiple TrackLab programs and bike reconnects, and it ends automatically after four hours unless the rider ends it sooner.

Maps, routes, and location

TrackLab stores selected tracks, custom routes, mapped ride lines, split routes, pedal zones, camera preferences, and recent Explore routes. If you tap Use my current location, the app requests a one-time device location to choose the route origin. Explore progress is driven by bike input rather than continuous device GPS. Developer-published track mappings and custom mapped tracks are designed to be visible to other TrackLab users.

The public Global Bike Shop Directory displays a browsable world map and loads public bike-shop listings for the visible area after you pan or zoom to a useful city or regional view. You can also enter a city, ZIP code, or address, or request a one-time device location, to move the map there. TrackLab sends the visible map bounds and zoom level—or the selected nearby-search point and radius—to the OpenStreetMap directory service. Those map bounds and search points are not saved to your TrackLab account; directory results may be held briefly in an in-memory service cache to improve reliability.

Rooms, messages, and optional microphone audio

Multiplayer features handle display names, room membership, invites, challenges, race state, and room messages. Voice chat is off by default. If a room racer enables it, TrackLab requests microphone access and sends live audio to the other room racers through real-time connections. The current implementation processes connection-signaling messages but does not create stored voice recordings.

An explicitly accepted friend who is currently online can send a short-lived request to talk live. The request contains no custom message, expires automatically, and reveals the private audio room only after the invited friend chooses Join. Friend live audio is microphone-off by default, is limited to the two connected friends, is not recorded, and does not create a message history or inbox.

Optional app notifications

In the iPhone or iPad app, you can choose notifications for live-audio invitations, friend requests, new friend connections, and shared tracks. TrackLab sends Apple Push Notification service an opaque device token and stores a random app-installation identifier and credential so Apple can deliver the choices enabled for your signed-in personal account. Notification payloads contain a notification type and opaque identifier, not workout, heart-rate, microphone, message, or payment data.

Technical information

TrackLab servers process network information such as IP address, request timing, browser or app capabilities, and error or service-health information to deliver the service, enforce rate limits, diagnose failures, and protect accounts. Local device or browser storage keeps settings, remembered bike identifiers, camera layouts, and short-lived working data.

How data is used

  • Authenticate accounts and synchronize account, club, rider, route, and training data.
  • Connect up to four Wattbikes and run BMX races, straight sprints, and Explore rides.
  • Create results, non-power leaderboards, records, ghosts, calendar history, and downloadable reports.
  • Provide rider discovery, friend requests, secure friend invitations, suggestions, blocks, and safety reporting.
  • Operate private rooms, room chat, short-lived friend live-audio alerts, optional voice, challenges, and live race state.
  • Deliver optional account-chosen app alerts through Apple Push Notification service.
  • Load maps, resolve route locations, calculate routes and elevation, and show track information.
  • Find nearby bike shops and connect a selected shop to nearby BMX tracks in the public directory.
  • Generate optional pre-race and live commentary from current race context.
  • Process memberships, prevent misuse, monitor reliability, and troubleshoot the service.

When data is shared

  • Friends and rider discovery: if you opt in to discovery, other signed-in users can see your public handle and display name in search or relevant suggestions. An accepted friend connection is visible to both accounts, and ordinary connected friends can see an optional account profile photo. TrackLab adds the verified Preski Ranch club account and TrackLab founder as default connections; a rider may see those verified accounts' photos, but the default connection does not share the rider's photo back. You can remove or block either connection. Explicitly accepted friends can see whether the other account is currently online. Verified club and founder accounts may also show their own public online status through an auto-added connection. An auto-added official connection cannot see an ordinary rider's online presence unless that rider explicitly accepts the connection. Friendship by itself does not share private workout history, private pedal-zone analytics, live device location, or current training activity. An explicitly accepted online friend can send a short-lived live-audio alert containing their public display identity; you can decline it without opening the room. Information can still be shared through a separate action or feature you choose, such as joining a room, publishing an eligible ghost, or training through Club Connect.
  • Friend invitation links: you can create an expiring, single-use link or QR code and send it through a service of your choice. The link contains a random invitation token rather than your email address. A signed-in rider who opens a valid link becomes connected to the inviter, so invitation links should be sent only to the intended rider.
  • Other TrackLab users: room participants can see rider display names, photos, live positions, and results. Public leaderboards and ghost replays can display rider identity and race performance, excluding watts and power. Detailed non-power ghost zone analytics are shared only when that option is enabled.
  • Clubs: a claimed Club Connect athlete can choose “Training at” a club to associate the saved session with that club. The club owner may optionally open Club Live Monitor; when open, TrackLab also shares the athlete's selected program, live status, course progress, track or destination, cadence, speed, and current live watts with that owner. While the athlete is actively sharing a Club Live session, the owner can also view a temporary, read-only image of the visible TrackLab activity screen. Screen sharing does not capture the device camera, microphone, taps, notifications, other apps, or content outside TrackLab. Frames expire and are deleted when Club Live sharing ends. Saved power history remains private to the athlete and, for training attributed to a claimed Club Connect profile, that club's authenticated owner. Live or saved watts are not published to public leaderboards, shared ghosts, multiplayer participants, or public/shared exports. The rest of the read-only live feed expires automatically after the athlete leaves club training or stops transmitting.
  • Apple Watch heart rate and clubs: saving private heart rate to a rider account does not give a club access to it. A rider can separately approve a trusted Watch Connect enrollment for one specific club and claimed rider account. The rider then starts each four-hour studio connection with one explicit press on the paired iPhone. Sharing current heart rate is a separate optional choice; sharing saved session summaries also requires the rider's explicit approval. Friendship, verified default connections, Club Connect membership, name selection, and bike assignment alone never grant heart-rate access. The rider can forget the trusted enrollment, and the rider or club owner can disconnect studio sharing without deleting the athlete's club membership. Raw and between-effort samples remain private.
  • Apple Push Notification service: if you enable app notifications, TrackLab provides Apple an opaque device token and a minimal alert for delivery to this app installation. Opening an alert causes TrackLab to securely refetch current Friends information for the active account; the alert itself cannot accept an invitation, join live audio, or enable the microphone.
  • Google mapping services: map tiles, places, route endpoints, route geometry, Street View, and elevation requests are handled by the Google mapping services used by the feature.
  • OpenStreetMap: the Global Bike Shop Directory sends the visible map bounds and zoom level, or chosen nearby-search coordinates and radius, to OpenStreetMap's Overpass service and displays public shop listing data under the ODbL. Choosing a shop's map, directions, or Street View action opens Google Maps.
  • OpenAI: when AI commentary is enabled, limited race context—including supplied rider display names and live race facts—can be sent to generate commentary and speech.
  • Apple App Store: Wattbike connection subscriptions in the iPhone and iPad app are purchased through Apple. Apple processes payment details; TrackLab receives signed transaction and entitlement information needed to verify the subscription and unlock its connection capacity across devices. TrackLab does not receive raw payment-card numbers from Apple.
  • Hosting and database providers: TrackLab uses hosted application and database infrastructure to deliver and store cloud-backed features.
  • Safety and moderation: blocking removes the friend connection and pending requests and prevents the blocked pair from reconnecting while the block remains. A safety report stores the reported account, category, available details, and review status for TrackLab safety review and moderation. The reported rider is not told who submitted the report.

External services process data under their own terms and privacy notices. Opening a landmark website, Google Maps or another external link takes you to that provider.

Your controls

  • Profile photos are optional and can be replaced from profile or rider controls.
  • You can choose whether your account appears in rider search and friend suggestions.
  • You can approve or decline ordinary friend requests, remove friends, and block or report an account.
  • Verified club and founder connections are added by default, but each can be removed or blocked.
  • Current location is requested only after you choose the current-location action. Explore and bike-shop search both offer a typed-location alternative when you do not want to grant device location.
  • Room and friend-live microphone access starts only after you explicitly turn voice on.
  • App notification permission is requested only after you choose Enable notifications. You can select alert types in TrackLab Settings and can turn notification access off later in iOS Settings.
  • Race commentary and ambient track sound each have an on/off control.
  • Ghost replay analytics have a separate sharing choice.
  • Individual training sessions can be exported as JSON or CSV, and the selected day's non-health spreadsheet can be downloaded as a Numbers/Excel workbook (.xlsx) from the account calendar.
  • Apple Watch heart rate is optional. After one-time setup, you press Watch Connect on the paired iPhone to start a visible four-hour connection, can end it early from TrackLab, and can use TrackLab without it. You can change Apple Health permission later in the system Health or Settings app.
  • Revoking Apple Health access stops future collection but does not automatically erase heart-rate samples already saved to TrackLab. Heart rate remains visible in the rider's private session history and is deliberately excluded from generic session JSON/CSV, the standard selected-day workbook, and public or club exports. A signed-in rider can deliberately download a separate private Numbers/Excel workbook containing heart-rate summaries alongside their session and zone metrics; that workbook does not include raw heart-rate samples. Deleting the TrackLab account also deletes its saved heart-rate records. Contact support for a separate verified raw health-data export or a heart-rate-only deletion.
  • You can sign out to end the current browser or app session.

A signed-in user can open My Profile, choose Delete Account, reenter the current password, and confirm permanent deletion in the app. Deleting a TrackLab account does not cancel an Apple subscription; manage or cancel that subscription with Apple first if you do not want it to renew. TrackLab retains only a one-way pseudonymous Apple transaction-lineage proof after deletion, without the deleted profile ID, email, or name. A user with the same active Apple subscription may deliberately use Restore Purchases after creating a new TrackLab account. Contact support to request access, correction, a partial deletion, or help with an account-specific request.

Storage, retention, and security

Signed-in cloud data is stored in TrackLab's application database. Some preferences and remembered device information remain in local browser or app storage. A same-site, HTTP-only session cookie is used for web authentication. Production connections use HTTPS, and passwords are processed with a salted password-hashing function.

TrackLab keeps account and training records so they remain available across devices and sessions until the account is deleted. Temporary records, expired authentication sessions, and local data can have different lifetimes. TrackLab may retain limited records when required for safety, security, fraud prevention, dispute resolution, or legal obligations. No internet service or storage method can guarantee absolute security.

Saved heart-rate samples are stored in the authenticated rider's private heart-rate stream. TrackLab links only the exact active-time portions of that stream to a completed training session; samples measured between short studio efforts remain private to the rider and are not included in the club's saved-session view. Heart-rate records currently follow the general account-retention policy above rather than a separate automatic deletion schedule. They are transmitted over encrypted connections, and TrackLab does not store personal health information in iCloud. Deleting the TrackLab account also deletes its saved heart-rate records. A rider may contact support for an export or a heart-rate-only deletion request. Ending an Apple Watch workout or revoking Apple Health permission does not by itself delete a previously synchronized TrackLab record.

The app keeps its random notification installation identifier and credential in the iOS Keychain using device-only storage. TrackLab removes the server registration during normal sign-out and does not register personal push alerts in Club Tablet kiosk mode. Apple may retain delivery information under its own terms.

Friend connections are deleted when either account removes the connection. TrackLab retains a suppression record after a verified default connection is removed or blocked so that connection is not silently added again. Blocks remain until the blocking account removes them. Answered requests, claimed or expired invite records, and safety reports may be retained for network integrity, abuse prevention, moderation, and legal obligations. An account-deletion request also covers the account's social graph, subject to records that TrackLab must retain for safety, security, dispute, or legal reasons.

Club and youth use

Family profiles let a signed-in parent or guardian create a separate managed athlete profile without giving the child an email address or password. An existing account must approve an invitation before its profile and training activity, including cycling power, can be viewed by the requesting parent. Either account can remove that viewing permission. A parent can separately issue a one-use, 15-minute child-phone setup link for a managed child. Redeeming it creates a child-only signed-in session under that child’s profile; it does not sign the child into the parent’s account. Parents can revoke child-phone sessions from Family. Treat setup links as private credentials. Family viewing does not grant account sign-in, billing access, friend or message access, live location, or Apple Watch heart-rate access.

TrackLab includes studio riders and Club Connect, but the current build does not independently verify a rider's age. When a rider is a minor, the club, studio, parent, or guardian is responsible for using the service only with the authorization and supervision required in their location. Do not upload a minor's photo or create a claimed account for a minor without appropriate permission.

Friend discovery, invitations, and connection controls do not independently verify a rider's age. A parent or guardian should supervise a minor's discovery setting, friend requests, shared invitations, live-audio invitations and microphone use, blocks, and reports.

Apple Watch heart rate and any live studio sharing must not be enabled for a minor without the permission and supervision required from their parent or guardian. A coach, club owner, friendship, or bike assignment cannot substitute for that authorization.

Questions or data requests

Email preskiranch@gmail.com with “TrackLab BMX Privacy” in the subject. Include the account email involved, but do not send your password, payment-card details, API keys, or Bluetooth credentials.

This notice may be updated as TrackLab changes. The date at the top identifies the version currently published with the service.