Privacy
Privacy Policy — LMU Assister
Version 1.7 · updated 2026-07-06
LMU Assister (the "App") is an unofficial, third-party companion that displays data from the game Le Mans Ultimate (schedule, events, leaderboards, your profile and race history) and may also display related public racing/profile data from publicly available third-party sources. The App is not affiliated with or endorsed by the game's developers/publishers, Valve / Steam, or those third-party sources.
The mobile app source code is open source. This means the mobile client code can be inspected publicly. The backend service remains operated by the LMU Assister developer.
The App, website, web app, API and backend are operated by Danylo Perepeliuk. For privacy questions, data access, correction, deletion, or other data requests, contact: [email protected]
The backend is hosted in Roubaix, France.
1. RIGHTS, OWNERSHIP AND THIRD-PARTY CONTENT
Le Mans Ultimate, its name, marks, game data, race/event data, leaderboard data, car and track names, images, artwork, logos, badges, screenshots, and other game-related assets or content belong to their respective developers, publishers, licensors, or other rightsholders. LMU Assister does not claim ownership of those third-party materials.
The LMU Assister website, web app, mobile app, API, backend, original UI, original text, original service logic, and LMU Assister-specific code and design are owned by Danylo Perepeliuk, except for open-source components, third-party materials, and any content or rights owned by others.
2. STEAM SIGN-IN — HOW IT WORKS
Steam sign-in is handled locally on your device or in your browser. Your Steam username, password, Steam Guard code, Steam session, and Steam refresh token are not sent to the LMU Assister backend, are not stored by us, and are not logged by us.
After Steam sign-in succeeds, LMU Assister receives only the temporary confirmation needed to connect your Le Mans Ultimate account and load your profile, ratings, statistics, race history, and leaderboard context. This confirmation does not reveal your Steam password and cannot be used by us to learn your Steam credentials.
For convenience, the web version may keep Steam sign-in material in your browser storage so you do not have to sign in again every time. This stays in your browser and can be removed by signing out or clearing this site's data in your browser.
3. WHAT WE STORE
The server stores access tokens tied to your game account id, needed to read your game data on your behalf.
To make the profile faster and reduce repeated requests to the game backend, the server stores a game-profile snapshot for your account: your game account id, game account email address when returned by the game backend, in-game display name, nationality, profile badge, current Driver Rating and Safety Rating rank/tier/progress/score, career total statistics such as races, wins, podiums, top-5 finishes, pole positions, DNFs, fastest laps, laps led and laps completed, suspension counts, and the time when the profile was first stored and last synced.
If the game backend returns an email address for your game account, we may store it as part of your profile snapshot. We use it only for service-related messages, such as profile sync confirmation, data deletion confirmation, or important account/data notices. We do not use it for marketing.
The server also caches a compact race-history summary for your account: event ids, dates, split number, track/car labels, finishing position, lap/rating changes, category flags, per-track lap/distance statistics, best laps, favorite cars, recent race summaries, and the compact race cards/statistics the App displays.
We do not cache the large raw race-history payload, full per-driver race classifications from history, your Steam username, Steam password, Steam Guard codes, Steam session, Steam refresh token, private game access tokens in any public response, payment information, or the detailed list/reasons/timing of suspensions. Detailed suspension information may be shown to you when you are signed in and the game backend returns it for your own account, but it is not stored as part of the public profile snapshot. Public profile data may show only suspension counts, such as active suspensions and total suspensions.
Game data is fetched from the game's official backend when you request it through the App and then reused from this stored profile/history cache where possible. Access tokens are not renewed in the background or on a schedule — they are renewed only when you actively request your data through the App, and they expire on their own when you are not using it.
The App may also fetch publicly available profile, rating, statistics, and race-history data from third-party racing/profile sources to improve public profile search and external public profile pages. Data from those sources is marked as external/public-source data where the App displays it. The App does not use your Steam credentials or private game access tokens to fetch that external public-source data.
4. COOKIES, BROWSER STORAGE AND WEB ANALYTICS
The web version uses essential browser storage to keep you signed in, protect forms, and remember sign-in state. This may include a session cookie for the signed-in web session, a security cookie for request/form protection, analytics identifiers when web analytics is enabled, and browser localStorage used for Steam sign-in convenience and the local-device access permission flag.
If web analytics is enabled, we use it to understand how the web app is used, improve features, diagnose problems, and measure product usage. Analytics may include screen views, clicks, form submissions, login outcome categories, whether a user is signed in, platform, rating-rank properties, query length, race ids, leaderboard ids, and similar product-usage information. We do not send Steam credentials, Steam Guard codes, Steam sessions, Steam refresh tokens, game-backend session tokens, raw race-history payloads, or payment information to analytics.
You can remove web sign-in data by signing out from the profile screen. You can also clear this site's data in your browser settings. To delete server-side profile and race-history data, use the clear-data button on the profile screen or contact [email protected].
5. RETENTION AND DELETION
Server-side game access tokens are kept until you sign out, the tokens become invalid/expire, or you ask us to delete them. Signing out removes the server-side access token and clears web sign-in state where applicable, but it does not necessarily delete the stored public profile/history snapshot.
The stored game-profile snapshot and compact race-history summary are kept until you delete them from the profile screen, ask us to delete them by contacting [email protected], they are no longer needed for the App, or they are removed as part of operational cleanup.
Deletion through the profile screen or by email request removes the server-side account, access-token, profile, and history data controlled by LMU Assister. It does not remove information that remains available from the game's official backend, Steam, leaderboards, or other public third-party sources outside our control.
The backend writes technical diagnostic logs, such as requested endpoint names, URLs, response status codes, response sizes, and timing information. These logs are used for debugging and performance monitoring. They are not intended to contain Steam usernames, Steam passwords, Steam Guard codes, Steam sessions, Steam refresh tokens, or raw race-history payload bodies.
6. WHAT NEEDS SIGN-IN, AND WHAT DOESN'T
You can use the App without signing in at all. Public content — the schedule on the first screen, events, leaderboards, selected synced player profile/statistics data, and external public-source profile/race data — can be viewed without signing in.
Signing in is required to let the App fetch and update your own game profile, ratings, statistics, race history, and your own position in a leaderboard from the game's online backend. After your profile has been synced, selected game-profile information may be visible to other App users, as described in the "Public profile data" section below.
7. PUBLIC PROFILE DATA
After your profile has been synced, the App may make selected game-profile and race-statistics data visible to other App users. This public data may include your in-game display name, game account id, nationality, profile badge, current Driver Rating and Safety Rating rank/tier/progress/score, career totals such as races, wins, podiums, top-5 finishes, pole positions, DNFs, fastest laps, laps led and laps completed, favorite cars, recent race summaries, per-track lap/distance statistics, best laps, and the date your profile was last updated in the App.
Public race pages may show selected race-result details for races included in synced or public-source history, such as event, split, position, class, timing/lap information, and classification context.
Public profile search and public profile pages may also include external public-source results for drivers whose data is available from third-party racing/profile sources. External public-source data may include a driver's public display name, external profile id/link, avatar, team, nationality, public badge, Driver Rating / Safety Rating, career totals, rating history, and paginated race-history summaries. These entries are marked as external/public-source data in the App where applicable.
Public profile data does not include your Steam username, Steam password, Steam Guard code, Steam session, Steam refresh token, private game access tokens, email address, payment information, or the detailed list/reasons/timing of suspensions. The App may show only suspension counts, such as active suspensions and total suspensions.
If you do not want this selected game-profile data to be visible to other App users, do not sync your profile, or contact us to request deletion of your stored profile/history data.
8. WHY WE USE DATA
We use data to provide the App's features, keep users signed in, load and cache profile/race data, display public profile pages, protect and debug the service, respond to data requests, send service messages, and improve the product through analytics when enabled.
Where applicable, we rely on user request/contract-like necessity for core app features, legitimate interests for security, debugging, service operation and product improvement, and consent where required for optional analytics or similar browser storage.
9. SECURITY
The App uses HTTPS for communication with the backend. Steam credentials, Steam Guard codes, Steam sessions, and Steam refresh tokens stay on your device and are not persisted by the backend. Server-side game access tokens are stored in backend storage/cache and access is restricted to the backend service. Selected synced game-profile and race-statistics data may be visible to other App users as described above. No system can be guaranteed perfectly secure, but the App is designed to minimize stored sensitive data and avoid receiving or storing Steam credentials.
Service emails are sent only for account or data-management purposes, such as profile sync confirmation or data deletion confirmation. They are not marketing emails.
10. SHARING AND SERVICE PROVIDERS
We do not sell your data and do not share it for advertising. We use service providers only as needed to operate LMU Assister, such as hosting the backend, delivering service emails, protecting the service, maintaining infrastructure, and measuring web app usage when analytics is enabled.
The App contacts Steam, the game's official online backend, and publicly available third-party racing/profile sources only to the extent needed to provide App features. Selected game-profile and race-statistics data described in the "Public profile data" section may be visible to other App users after your profile has been synced, and external public-source data may be visible when returned by public profile search or external public profile pages.
Some service providers may process data in countries other than where you live. Where required, we rely on available legal safeguards or the provider's applicable data-protection terms.
11. YOUR RIGHTS AND CHOICES
You can request access to, correction of, or deletion of the server-side data we control by contacting [email protected]. You can also delete your stored LMU Assister profile/history data from the profile screen where that option is available.
Depending on where you live, you may also have rights to object to or restrict certain processing, request a copy of your data, withdraw consent where processing is based on consent, or complain to your local data protection authority.
12. OPEN SOURCE MOBILE APP, BACKEND AND API
The mobile part of LMU Assister is open source. You may inspect, build, modify, decompile, analyze, and study the mobile client code and app package, including the Steam sign-in flow and client-side network behavior, subject to the applicable open-source license for that code.
This permission applies only to the mobile client code and app package. It does not grant any right to use, copy, reproduce, emulate, or access the LMU Assister backend, API, server-side logic, infrastructure, service accounts, secrets, server-side operational logs, or non-public systems.
The LMU Assister backend and API are proprietary and are intended to be accessed only through official LMU Assister applications and services. Using the backend or API from third-party clients, unofficial clients, modified clients, scripts, bots, scrapers, automated tools, or any other software that bypasses official LMU Assister applications is strictly prohibited, except where expressly authorized by the author.
Good-faith security research, compatibility analysis, and educational investigation of the mobile client are allowed, provided that such activity does not abuse, overload, scrape, replicate, bypass access controls for, or commercially use the LMU Assister backend or API.
Access to the backend or API outside official LMU Assister applications may be allowed only with the author's explicit permission. To request permission, contact [email protected].
13. RISKS AND YOUR CONSENT
LMU Assister is an unofficial third-party companion and is not approved, sponsored, or endorsed by Steam, Valve, Le Mans Ultimate, Studio 397, Motorsport Games, or RaceControl.
Based on our current understanding of the publicly available terms, we are not aware of a rule that specifically names and forbids this exact LMU Assister sign-in and profile-data helper flow. At the same time, those terms also do not expressly approve it, and they may be interpreted or changed by the relevant service operators. This means using LMU Assister for Steam sign-in or game-data access should be treated as a grey-area third-party use.
Accessing Steam or game-related data through an unofficial companion is done at your own risk. All actions are performed as your account and may be visible to the relevant service operators. Consequences up to and including account restriction or ban are possible. By using the App you confirm that you understand and accept these risks and take full responsibility.
14. AUTOMATED DECISIONS
LMU Assister does not make automated decisions that produce legal or similarly significant effects. Ratings, penalties, suspensions, and account restrictions are provided by the game or Steam-related services, not decided by LMU Assister.
15. DATA INCIDENTS
If we become aware of a data incident affecting your data, we will notify affected users where required by law.
16. CHILDREN
The App is not intended for children under 18.
17. POLICY UPDATES
We may update this policy from time to time. The version and updated date above show the latest published policy. Continued use of the App after an update means you accept the updated policy.