// Privacy Policy
Privacy Policy
What Apex Copilot does and doesn't collect — in plain language.
Apex Copilot (“the app”) is a telemetry companion for the game Forza Horizon, published by Kirill Shirinkin (“we,” “us”). This policy explains exactly what data the app handles, what stays on your device, and the limited usage analytics we collect to fix bugs and improve the app. We’ve tried to keep it specific and honest rather than vague and legalistic.
The short version: the app needs no account to do anything it does on your device. The telemetry stream from your console or PC, and the races you record, stay on your device unless you choose to publish a lap to Apex Cloud — an optional, separate service with its own sign‑in. Nothing is uploaded until you ask for it. Besides that, the only data that leaves your device is limited usage analytics that are not tied to your real‑world identity and are never used for advertising.
Who handles your data
The app is published and operated by Kirill Shirinkin. For any privacy question, email kirill@hey.com.
Data that stays on your device
Most of what the app does never leaves your phone or tablet:
- Live telemetry. Apex Copilot listens on your local Wi‑Fi network for the one‑way “Data Out” stream that Forza Horizon sends from your Xbox or PC. This is an inbound connection on your own network. The app uses your local‑network access only to receive this stream; it does not send the stream anywhere.
- Your race log. Completed runs — lap times, sectors, a decimated route trace, speed and input samples, the car used — are saved in the app’s own storage on your device. Deleting a run, or deleting the app, removes them. They are uploaded only if you publish that lap (see Apex Cloud below).
- Full‑rate telemetry capture. The app also keeps every telemetry packet of each race you drive — a much more detailed recording, including engine RPM, per‑tyre temperature and slip, and suspension travel. It is subject to a storage limit you choose, deleting a race deletes its capture, and you can clear all of it at any time from the Connection screen. You can switch it off entirely in Connection ▸ DATA ▸ FULL‑RATE CAPTURE. It is uploaded only alongside a lap you publish, and never on its own.
- Preferences. A few settings (such as your speed and temperature units) are stored locally on the device.
None of the above is transmitted anywhere unless you publish a lap.
Exporting your data
You can export recorded telemetry from the app as a .zip file. You choose where it goes
through the iOS share sheet; the app does not upload it anywhere. The file includes a random,
account‑free identifier for your app installation, so that a future version of Apex Copilot could
recognise several exports as coming from the same install. It is not linked to your name, Apple
ID, or the usage analytics described below — but because it is the same identifier in every export
from that install, keep it in mind if you publish exported files somewhere public.
Apex Cloud (optional)
Apex Cloud is a separate, optional service. If you never sign in, the app never contacts it and nothing on this page’s list of on‑device data goes anywhere. Everything the app does on your device works the same either way.
Signing in
Signing in uses Sign in with Apple, and we request no scopes — not your name, not your email, not even Apple’s relay address. What we receive is the opaque, app‑specific identifier Apple issues for you, which cannot be used to contact you or to identify you outside this app.
Your account holds: that identifier, the driver name you choose, your avatar, and — if you upload one — a profile photo. Location data is removed from any photo you upload before it is stored.
What is uploaded, and when
A lap leaves your device only when you publish it: either by choosing to share it, or by turning on auto‑publish, which is off by default and asks you to confirm once before it starts. Nothing is uploaded in the background before that.
When you publish a lap we receive:
- the recorded lap itself — position, speed, throttle, brake, steering, gear over the lap, the lap time and distance, the car, its class and performance index, and when you drove it;
- the full‑rate capture for that lap, if the app has one, sent shortly afterwards. This is what allows a lap to be checked against the physics of the car and marked as verified;
- the app version and the platform.
We do not receive laps you did not publish, your telemetry stream as you drive, or anything at all from the app’s other screens.
What is public
A published lap becomes a public page on this site, listed in the feed and on that race’s leaderboard, under your driver name and avatar. That is the purpose of publishing, so treat it the way you would any public post. Anyone can view these pages without an account.
We do not publish the app‑installation identifier that appears in exported files, and we do not publish your Apple identifier.
Deleting things
- Delete your account in Connection ▸ ACCOUNT ▸ DELETE. Your driver name, your photo and every lap you have published are deleted, and their pages stop resolving — a deleted page returns “gone” rather than simply disappearing, so search engines drop it. Your entries leave every leaderboard, and every device signed in to the account is signed out. Deletion is final: signing in with Apple again starts a new account rather than reopening the deleted one. The underlying rows and stored telemetry are erased within 30 days; the delay is ours, for recovering from a fault, and does not put your account back within reach.
- Sign out at any time in Connection ▸ ACCOUNT. Signing out removes the credential from your device and leaves every race on your device untouched.
- Turn Apex Cloud off in Connection ▸ DATA ▸ APEX CLOUD to remove it from the app entirely.
- To take down a single published lap while keeping your account, email kirill@hey.com and we will remove it.
Where it runs
Apex Cloud runs on Cloudflare (Workers, D1, R2), acting as our processor. Published laps and their telemetry are stored there. See How long it’s kept below.
Usage analytics we collect
To understand which features are used and to find and fix bugs, the app sends limited,
aggregate product‑analytics events to PostHog, an analytics service. We use PostHog’s
EU cloud (eu.i.posthog.com), so this data is processed and stored in the European Union.
This analytics collection is on by default in the App Store version of the app.
What an analytics event contains:
- Automatic device/app context added by the analytics SDK: app version and build, operating system version, device model, language and region, and a persistent random identifier generated on the device (a PostHog “distinct ID”). This identifier ties together the events from one device over time, but it is not your name, email, phone number, or Apple ID, and we never connect it to your real‑world identity. Because of this device‑level identifier, the data is best described as pseudonymous rather than fully anonymous.
- What you did, in non‑identifying terms — for example: that a race run was recorded, the car class and performance index, a run’s total distance and total time; that a replay or video clip was created and with which options; that a screen or sector was opened; counts such as how many tracks you’ve raced. Only these summary values go to analytics — the full route trace and the speed and input samples for a run are never sent to analytics at all (they leave your device only if you publish that lap, as described above). A few setup events include limited technical context such as the network port and the device’s local (private) Wi‑Fi IP address shown on the Connection screen (used to configure Forza’s Data Out).
- Names you type for your own races. If you rename or merge events in the Race Log, the name you assign is included with those events — and, because it becomes that race’s label, it may also appear with later analytics events about the same race (for example when you open a replay or a comparison).
- Your device’s public IP address is seen by the analytics provider when events are sent and may be used to derive approximate (country/region‑level) location; it is not used to identify you.
What we do not collect or do:
- No names, emails, or contact details. Signing in to Apex Cloud uses Sign in with Apple and we request no scopes at all — we never receive your name or your email address, real or relayed.
- No precise location, no contacts, no photos, no microphone or camera.
- No advertising. No ad networks, no advertising identifier (IDFA), no data brokers.
- No cross‑app or cross‑website tracking. We do not link your activity with data from other companies for advertising. Under Apple’s definition, the app does not “track” you.
- Your telemetry and race traces are never sent to analytics. The analytics events describe that you used a feature, not the underlying driving data. (Publishing a lap to Apex Cloud is a separate, deliberate action described below, and does not go through analytics.)
Why we collect it (legal basis)
We process this limited, pseudonymous usage data for our legitimate interest in understanding how the app is used, fixing crashes and bugs, and improving features. Because the data is not linked to your identity, it is not used to make decisions about you as an individual.
How long it’s kept
- On‑device data (your race log, full‑rate captures and preferences) stays until you delete it or remove the app. Full‑rate captures are also dropped oldest‑first once they pass the storage limit you set.
- Published laps are kept for as long as they are published. Delete your account and they stop resolving immediately, and everything behind them — the lap, its telemetry in storage, and your profile — is erased within 30 days.
- Analytics data is retained by our analytics provider for a limited period under their retention policy and then aggregated or deleted. See PostHog’s documentation at posthog.com/privacy for details on how they process data as our processor.
Your choices and rights
- You can delete recorded races individually in the Race Log, or remove all on‑device data by deleting the app from your device.
- You can delete your Apex Cloud account from inside the app, at any time, in Connection ▸ ACCOUNT ▸ DELETE. No email, and no request to us, is needed.
- You can publish nothing at all — sharing is never automatic unless you switch auto‑publish on yourself, and Apex Cloud can be turned off completely in Connection ▸ DATA.
- You can turn analytics off at any time in Connection ▸ DATA ▸ ANALYTICS. When it is off the analytics SDK is never started, so nothing is sent — not even an app‑opened event.
- Deleting the app also stops all analytics collection going forward.
- Because the analytics data is pseudonymous — keyed to a random per‑device identifier, not to your name — we may not be able to connect a request to your specific records unless you can supply that identifier. If you have a concern, email kirill@hey.com and we’ll do our best to help.
- Depending on where you live (for example, the EU/EEA, the UK, or California), you may have rights to access, correct, or delete personal data and to object to processing. To exercise any such right, contact us at the address above.
Children
Apex Copilot is not directed to children under 13 and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will address it.
Third‑party services
Two third‑party services receive data from the app:
- PostHog (EU cloud), our processor for the usage analytics described above.
- Cloudflare, our processor for Apex Cloud — but only if you sign in and publish something.
Sign in with Apple is operated by Apple; we request no scopes and receive no personal details through it. The app integrates no advertising SDKs, no other social logins, and no other trackers. Downloading the app and its updates is handled by Apple under Apple’s Privacy Policy.
Changes to this policy
If we change what the app collects, we’ll update this page and the “last updated” date above. Material changes will be reflected here before they take effect.
Contact
Questions about privacy? Email kirill@hey.com.
Apex Copilot is an unofficial companion app and is not affiliated with, sponsored by, or endorsed by Microsoft, Turn 10 Studios, or Playground Games.