Lairo privacy policy
Last updated: 22 September 2026
Lairo is live telemetry for rowing. A phone in the boat records where the boat is and how fast it is going. Rowers see their split on the phone, and coaches of the same club follow the boats on a map. This policy explains what that means for your personal data. It is written to be read, not skimmed past, because the core of the service is continuous location data about identifiable people.
Who is responsible
- Controller: Lauri Pilpola, a private individual
- Contact: [email protected]
Your club is not the controller.
What we collect, and why
Your account
- Email address and name. Used to sign you in with a one-time link and to show who you are to your club.
- Club membership and role (athlete, coach or admin), and any training groups you join. Used to decide what you can see and do.
Outings
When a phone records an outing, it sends one sample per second:
- position (latitude and longitude), speed, the GPS accuracy estimates, and the time;
- stroke rate, calculated on the phone from its motion sensors (the raw sensor readings do not leave the phone);
- the boat class and the nickname typed on the phone.
An outing is linked to you when you claim it: automatically if you are signed in on the recording phone, or by choosing "This is me" on the coach map.
Why: showing the boat live to your coaches, and keeping a history of outings for training (splits, distances, pieces, comparisons over time).
Besides the database, the server writes the same samples to a raw file per outing, used to investigate errors in the figures. It holds the same data and follows the same retention and deletion rules.
Heart rate
Only if you connect a heart-rate strap in the app. The strap sends your heart rate to the phone over Bluetooth, and the phone sends it to us together with the outing. Heart rate is health data, a special category of personal data, and we process it only with your explicit consent. Before you connect a strap for the first time, the app asks for it on a screen of its own, which says that your heart rate will be stored with your outings and visible to the members of your club. We record when you agreed. Using Lairo without a strap is fully possible. You can withdraw your consent at any time in the app, which stops heart rate being sent, and you can ask us to delete the heart rate already stored.
We also store the strap's Bluetooth identifier, so that the app can reconnect to the right strap.
Sign-in and security
- Sign-in links and sessions are stored only as one-way hashes. A sign-in link expires after 15 minutes and a session after 30 days without use.
- A phone connected to a club with the club code gets a random connection key. We store only a one-way hash of it, which club it is for, and when it was created and last used. It is not linked to your account or stored with your outings. It stops working when the club removes the phone; tapping Remove in the app deletes the phone's copy.
- With a sign-in request we store the IP address it came from, and with a session the browser or app description (user agent) and when it was last used. These are kept to detect misuse. A record is deleted once it is more than 30 days old and no longer valid (used, expired or signed out).
- Our servers keep ordinary technical logs (IP address, time, the address requested) for troubleshooting and security. They rotate by size and are overwritten automatically, typically within about two weeks, and cleared whenever a new version is installed.
On your phone
The app keeps a copy of each outing's raw samples on the phone itself (position, speed, heading, accuracy, battery level). This copy protects your outing if the connection drops, and it stays on your phone until you delete the app. It is sent to anyone only if you choose to share it from the Diagnostics screen.
What we do not do
No advertising, no analytics or tracking scripts, no selling or renting of data, and no profiling beyond the training figures you can see yourself. The coach map uses one cookie, the sign-in session, which is strictly necessary. Display preferences are kept in your browser's local storage and never sent to us.
Legal basis
- Your account, outings and sign-in: providing the service you signed up for through your club (GDPR Art. 6(1)(b)), and our legitimate interest in keeping it secure (Art. 6(1)(f)).
- Heart rate: your explicit consent (Art. 9(2)(a)).
Who can see your data
- Members of your club can see the club's outings: live positions on the map, tracks, splits, and the heart rate stored with an outing. Showing the boats to the club is what Lairo is for, so recording an outing, or claiming it as yours, shares it with your club. The app says this when you sign in and when you claim an outing. Membership comes from your club's join code, which is why the code is only handed out within the club, and why admins remove people who leave.
- Club admins can also see the member list with names and email addresses, change roles and remove members.
- Nobody outside your club. An outing of another club answers exactly as if it did not exist.
Service providers
These process data on our behalf, or unavoidably see some of it on the way:
| Provider | What for | What they see | Where |
|---|---|---|---|
| Oracle Cloud | the server and database | everything we store | Stockholm, Sweden (EU) |
| Expo | delivering app updates | when the app checks for an update: the phone's IP address, its operating system, the app's project and a random installation token; no device identifier | USA, under the EU–US Data Privacy Framework |
| OpenFreeMap (Hyperknot Software Kft., Hungary), delivered through Cloudflare | map tiles on the coach map and in the app | your IP address and which map area you are viewing. OpenFreeMap keeps no IP addresses by default and no cookies; Cloudflare, which serves the tiles, sees the IP address of every request | OpenFreeMap: EU. Cloudflare: global network, the nearest edge (Stockholm, from Finland), under the EU–US Data Privacy Framework |
| Cloudflare | the domain name system for lairo.fi, and forwarding mail sent to [email protected] | name lookups; the messages you send to [email protected], passed on to the controller's inbox and not stored by Cloudflare | global network, under the EU–US Data Privacy Framework |
Your phone's operating system provides the location itself. On Android that is Google's location service, which works under Google's own terms and your device settings, not ours.
Backups. The database is backed up every night, encrypted, to a storage device under the controller's control in Finland.
Testing copy. New versions are tested on the same server against a copy of the database, with every sign-in credential removed. It is refreshed from the live data and follows the same deletion rules.
How long we keep it
We keep data for as long as it serves its purpose, and the limits below are the longest we keep it. We do not promise to keep any data for any period. Outings can be lost or deleted earlier, so export anything you want to keep: every outing downloads as GPX or CSV.
| Data | Kept at most |
|---|---|
| Outings (positions, speed, stroke rate) | as the club's training history, while the club uses Lairo. When you leave the club, or ask us, what ties an outing to you is removed (see below) |
| Heart rate | until you leave the club or ask for deletion, then deleted within 12 months of leaving, or within one month of your request |
| Account (email, name, memberships) | while you are a member; deleted within 12 months of leaving the club, or within one month of your request |
| Sign-in records | 30 days after they stop being valid |
| Server logs | overwritten as they fill up, typically within about two weeks (measured 2026-09-21: 30 MB per service at about 2 MB a day), and cleared at every new version |
| Backups | anything deleted is gone from the backups within about 12 months, as old backups are pruned |
What "removing what ties an outing to you" means. The outing stays in the club's history as a boat's outing. Your claim on it, your heart rate and the nickname typed on the phone are deleted. A single scull's outing is one person's however it is labelled, so for a single, the outing itself is deleted.
Children
Lairo is for people aged 18 and over. Do not create an account, record outings or claim them if you are under 18. If we learn that an account belongs to someone under 18, we delete it and its data.
Your rights
You have the right to:
- access the data we hold about you;
- correct inaccurate data;
- delete your data ("right to be forgotten");
- restrict or object to processing;
- receive your data in a portable format. Outings export as GPX and CSV;
- withdraw consent (heart rate) at any time, without affecting what was done before.
Email [email protected]. We answer within one month. Deletion is currently done by hand on request; there is no self-service button yet.
If you think we handle your data unlawfully, you can complain to the Finnish supervisory authority, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi.
Changes
When this policy changes, the new version is published here with a new date. A change that affects what we collect or who sees it is also announced in the app or by email before it takes effect.