← Back to top
Privacy Policy
Last updated: September 12, 2026
RC Pit Spec ("the App") is an application provided by KG App Lab ("the Operator"). The Operator respects user privacy and handles information in accordance with this policy.
1. Information We Collect
- Anonymous identifier: An anonymous UID automatically generated per device. We do not collect personally identifiable information such as name or email address. The anonymous UID is stored on our server for poster identification, plan management, and abuse prevention.
- Setting data: The RC car configuration entered by the user. As a rule this is stored on the device and not sent to our server, except when the user chooses to share it via the Pit as described below (for what is sent to Google by the AI features, see below).
- Shared data (Pit posts): Only when the user chooses to share via the "Pit" feature, the following are stored on our server: machine name, partial setting values, course name, environment information (temperature, surface, grip, etc.), and the language setting at the time of posting. If photos are attached to a post, those images are also stored on our server (Firebase Cloud Storage) and are publicly viewable by anyone who can browse the Pit. On the posting screen, photos already registered for that machine are attached by default. Each one can be removed before posting, and removed photos are not sent. The poster's anonymous UID is also stored, used for post deletion and to address inappropriate content. Users may optionally enter a public handle name at the time of posting (displayed as "Anonymous" if left blank). The entered handle name is stored only for the post in question and is not linked to any cross-device profile.
- Machine support requests: Only when the user selects "Request" on the confirmation screen shown after adding a machine that is not in the list, the machine name entered, an identifier for that machine within the App, how the machine was added (whether the user searched by name or opened it directly from the list), the time of the request, and the App version and language setting are stored on our server (Firestore) together with the sender's anonymous UID. This data is used solely to decide which machines the App will officially support in the future. Sending is optional, and the machine has already been added either way. The setting values and photos for the added machine are not sent. This request cannot be withdrawn from within the App, so deletion is handled through the request process in Section 6. Please do not enter personally identifiable information in the machine name.
- AI feature inputs and outputs: "AI conversation", "AI diagnosis", and "AI analysis of running logs" all send information about the machine in question to Google (Gemini API): the chassis name (for machines you added yourself, the name you gave it), the current setting values (excluding items we do not pass to the AI; including the display names and units of custom items), the environment settings (air temperature, humidity, track temperature, indoor/outdoor, surface, grip, and track condition), the driver note entered on the setup screen, and parts catalog information for that machine. The driver note is a free-text field, so please do not enter personally identifiable information in it.
- AI conversation: In addition to the common information above, the user's messages, the personality prompt of the selected AI partner character, a summary generated from past conversations (long-term memory), and a summary of recent running logs (including the circuit names and notes entered) are sent to generate responses. The long-term memory is produced by having the AI summarize past conversations and is stored on the device only. This summarization runs automatically when the App starts (once enough conversation has accumulated, or enough time has passed since the last summary); the conversation text so far, the previous summary, and the list of names of your registered machines are sent to Google for it. Only when building this long-term memory, email addresses, phone numbers, postal codes, credit card numbers, and My Number (the Japanese national ID) are masked — as far as they can be detected by pattern matching — in the conversation text passed to the summarizer and in its output. Ordinary message sending is not masked. Conversation history is stored on-device in a local SQLite database, retaining up to 100 conversations per machine; older ones are automatically deleted when this limit is exceeded. Except when sent as an "AI error report" described below, conversation history is never persistently stored on our server (Firestore, etc.), and it is removed when the App is uninstalled.
- AI diagnosis: Only the common information above is sent to obtain an evaluation (nothing additional). Diagnosis results are stored on the device only and not sent to our server (they are deleted when the App is uninstalled).
- AI analysis of running logs: Only when the user runs an analysis on a running log, then in addition to the common information above, that log (the date, the circuit name entered, best lap, lap count, surface, grip, air temperature, track temperature, and any notes entered), a comparison and statistics against previous runs at the same circuit, the setting changes since the previous run, and the currently installed parts are sent to obtain the analysis. The circuit name and notes are free-text fields, so please do not enter personally identifiable information in them. Results are stored on the device only and, except when sent as an "AI error report" described below, are not sent to our server.
- Per Google's API terms of service, the data sent is not used to train AI models.
- AI error reports: Only when the user reports an AI message as incorrect, the text of that AI message, the user's own preceding message that prompted it, any setting change the AI proposed in the same exchange (the item, the values before and after, and what the user did with it), the chassis type, the setting information at that time (within the same scope as a Pit post), which feature the report came from (AI conversation or running-log AI analysis), the selected AI partner, an optional reason and free-text note entered by the user, the time of the report, an identifier for the report, and the App version and language setting are stored on our server (Firestore) together with the reporter's anonymous UID. This data is used solely to improve the quality of AI responses. A report can be withdrawn within the App until a reason is selected; after that, deletion is handled through the request process in Section 6. Please do not enter personally identifiable information in the free-text field.
- Setup item error reports: Only when the user reports a setup screen item as incorrect, the chassis type, the item in question, the reason selected (such as a wrong item name, an incorrect range of values, or a wrong illustration), any text optionally entered when "Other" is selected, the file name of the illustration shown on screen at the time of the report, and the App version and language setting are stored on our server (Firestore) together with the reporter's anonymous UID. This data is used solely to correct errors in the setup items and illustrations the App displays; the values the user has set are not sent. This type of report cannot be withdrawn from within the App, so deletion is handled through the request process in Section 6. Please do not enter personally identifiable information in the free-text field.
- Usage data: To enforce plan quotas, the remaining AI ticket count, the per-plan limit, current plan type, and contract cycle start/reset dates are stored on our server. On the free plan, usage counts are stored on the device only and are not sent to our server.
- Subscription information: Subscription status from Apple App Store / Google Play Store is synchronized via RevenueCat to manage plan validity. The App's anonymous UID is provided to RevenueCat as the App User ID for synchronization. Payment information such as credit card numbers is not handled by the App; it is processed directly by Apple / Google.
- Push notification information: Only when the user opts in to receive notifications about new Pit posts, the push notification registration token and the user's selected list of chassis-type subscriptions are managed by the notification delivery service (Google). Our server does not retain the subscription token. Notification permission can be revoked at any time via the device OS settings.
- Crash reports and usage analytics: To fix bugs and improve features, we collect crash information, device information, and aggregated usage events. No personally identifiable information, including the anonymous UID, is associated with this data.
- Abuse detection information: If abuse is detected, the Operator may flag the corresponding anonymous UID on the server side and apply feature restrictions.
2. Information We Do Not Collect
- Personally identifiable information such as name, address, phone number, or email address
- Device data such as location or contacts
- Regarding the camera and photos: images taken or selected for machines and parts, and the camera feed used for lap measurement, are processed and stored entirely on the device and never sent to our server (the only images stored on our server are those attached to a Pit post, as described in Section 1). Photo selection receives one user-chosen image at a time; we never read the photo library as a whole
- Payment information (handled directly by Apple / Google)
- Additional identifiers such as device fingerprints or hashed IP addresses
3. Purpose of Use
- Storing, displaying, and sharing setting data
- Providing AI diagnosis and AI conversation features
- Plan quota management and subscription management
- Detecting and preventing abuse
- Collecting crash and error information for product improvement
- Improving features and optimizing UI based on aggregated usage
- Deciding which machines the App will support and expanding the catalog
4. Sharing with Third Parties
We share the minimum necessary information with the following external services:
- Google (Firebase services / Gemini API / AdMob): Authentication, data storage, AI response generation, push notifications, crash reports, usage analytics, abuse prevention, advertising
- RevenueCat: Subscription management
- Apple / Google: In-app purchase processing (each store's payment platform)
Other than the above, we do not share information with third parties unless required by law.
Cross-border data transfers: Both Google and RevenueCat are headquartered in the United States. By using the App, data may be processed overseas, including in the United States, through these providers.
Privacy policies of each service:
5. Data Storage
Data stored in Firebase (Firestore / Cloud Functions / Cloud Storage) is managed in Japan (Tokyo region). AI response generation (Gemini API) is processed in regions designated by Google. Data on the device is removed when the App is uninstalled.
6. Data Deletion / Disclosure Requests
Users may request disclosure, correction, deletion, or suspension of use of their data at any time. Please contact us at the address below. We will respond within 30 days of receipt. Upon request, the Operator will bulk-delete the server-stored data associated with that anonymous UID. Two exceptions apply: records needed for plan management (subscription information and usage data, which are required to provide plans and determine billing status) and abuse detection records kept to prevent repeat abuse.
Please include your anonymous UID in the request. Because the App holds no name or email address, we cannot identify your data without it. Sending the request from "Settings → Support → Request data deletion" inside the App fills in your anonymous UID automatically.
Handling of Pit posts: Posts published in the Pit can be deleted individually by long-pressing your own post in the Pit list and choosing "Delete". Posts remain on the server even after the App is uninstalled, so please delete them individually beforehand or contact us at the address above to request data deletion.
Retention: Data stored on our server (Firestore / Cloud Storage) against an anonymous UID is retained until the user deletes it within the App or requests deletion, except for the items excluded above. There is no mechanism that deletes it automatically after a set period; the abuse detection records described below are also removed manually as part of our operations. Crash reports and usage analytics (Section 1) expire according to the retention periods set by the respective Google services.
Retention period of abuse detection records: Flag information for anonymous UIDs detected as abusing the service is retained for approximately one year, after which it is removed if no further abuse is observed.
7. Advertising
Free users see ads delivered by Google AdMob. No ads are displayed while a paid plan (Basic / Pro) is active.
About personalized advertising: Ads delivered by AdMob may be personalized based on the device's advertising ID (IDFA / AAID), shared with the Google ad network (use of advertising IDs may include tracking). On iOS, the AppTrackingTransparency (ATT) permission dialog is shown at first launch, and tracking is performed only if the user grants permission. If permission is not granted, or if the advertising ID is reset / opted out of, non-personalized ads are shown. Advertising IDs can be managed via the device OS settings.
8. Affiliate Links
Purchase links in the parts catalog include Amazon Associates and Rakuten affiliate links. Purchases made through these links may result in affiliate revenue for the Operator.
9. Children's Privacy
This App is not intended for children under the age of 13. We do not knowingly collect personal information from anyone under 13.
10. Changes to This Policy
This policy may be changed without prior notice. Significant changes may be announced inside the App. Updated policies take effect once posted on this page.
11. Note for EU Residents (GDPR)
If you reside in the EU (European Economic Area), under the EU General Data Protection Regulation (GDPR) you have the right to access, rectify, erase, restrict the processing of, port, and object to the processing of your personal data, and the right not to be subject to automated decision-making. To exercise these rights, please contact us at the address listed in §6. The legal basis for data processing is the performance of a contract for the provision of the service.
12. Data Controller
The data controller for this App is KG App Lab. For inquiries regarding the controller's address and contact details, please email info@kgapplab.com.
13. Contact
For inquiries regarding this policy, please contact info@kgapplab.com.