Your data, respected.
This policy explains what data GPADLAB collects, why we collect it, and what we do with it. We've tried to write it in plain English rather than the usual legalese, because a privacy policy nobody can understand isn't really a privacy policy.
Last updated: September 5, 2026
Four things worth knowing
Core controller results stay local
Controller states, measurements, and GPADLAB scores are processed in your browser. GPADLAB does not currently upload core diagnostic results to a community-results database.
Some tools use local browser storage
Recent benchmark or test history, battery readings, and controller-mapping presets may be saved in localStorage on your device. That browser storage is not the same as a server-side GPADLAB account.
Analytics are separate from diagnostics
GPADLAB can use Plausible and Google Analytics 4 for site measurement. Plausible is cookieless; GA4 can use first-party analytics cookies and browser identifiers to distinguish visits and sessions.
Forms intentionally send data
Contact and contributor forms send the information you enter to GPADLAB. Their server endpoints also use the request IP address for abuse prevention and include it with the emailed submission.
In detail
1. What data GPADLAB processes
GPADLAB is a browser-based diagnostic platform. When you run a controller test, controller state and measurements exposed by supported browser APIs are processed locally in JavaScript. Core controller diagnostic results are not currently uploaded to a GPADLAB community-results database.
Some tools intentionally save limited information in your browser's localStorage, such as recent benchmark or test history, controller-mapping presets, and battery-health readings. This local browser storage stays on your device unless you clear it, your browser removes it, or the tool overwrites it. GPADLAB does not receive those locally stored records merely because they are saved in localStorage.
When site analytics are enabled, analytics providers may receive standard website-usage information such as page paths, referrers, device or browser information, approximate geographic information, and timestamps. Analytics are separate from controller diagnostic processing.
When you use the contact form, GPADLAB receives the name, email address, optional subject, and message you submit. When you use the contributor form, GPADLAB receives the information you submit with your pitch, including contact details, role or expertise, profile URL if provided, proposed title, pitch, qualification and evidence information, company or commercial-relationship information, and requested links where provided.
Contact and contributor endpoints also read the request IP address for basic abuse and rate-limit protection. The current implementation includes that IP address in the email copy of the submitted form.
2. What GPADLAB does not do
GPADLAB has no public user-account or login system for the diagnostic tools. We do not assign an account identifier to controller-test users and do not currently maintain a server-side history of their core diagnostic results.
We do not sell, rent, or trade contact, contributor, or controller diagnostic data. GPADLAB does not run an advertising network or a retargeting system in the application code.
GPADLAB does not currently upload locally stored benchmark histories, mapping presets, battery readings, or similar tool records simply because they exist in your browser storage.
3. Analytics
GPADLAB's application can load Plausible Analytics and Google Analytics 4 when the corresponding deployment configuration is enabled. These services measure use of the website; they are not used to upload controller diagnostic results.
- Plausible Analytics - designed to measure aggregate website usage without cookies or persistent browser identifiers. Plausible states that it does not store raw IP addresses and does not track visitors across sites or across days.
- Google Analytics 4 - the Google tag can set first-party analytics cookies such as _ga and _ga_<container-id> to distinguish browser instances and persist session state. GPADLAB does not have user accounts connected to GA4 and the site code does not send a GPADLAB account User ID.
GPADLAB does not currently implement a site-specific Do Not Track switch that prevents the analytics scripts from loading. If you want to prevent GA4 cookie-based measurement, you can block analytics cookies or scripts in your browser or use Google's Analytics opt-out tooling. See the Cookie Policy for browser-storage details.
4. Cookies and local browser storage
GPADLAB's application does not require account, login, shopping-cart, or preference cookies for the controller tools. If Google Analytics 4 is enabled, the Google tag may set first-party analytics cookies, commonly including _ga and _ga_<container-id>.
GPADLAB also uses localStorage in specific tools. localStorage is not a cookie and is not automatically attached to every web request. It is used for features such as recent run history, controller mappings, and battery-health history.
For more detail on cookies and browser storage, see our Cookie Policy.
Clearing GPADLAB site data in your browser can remove locally saved tool history and presets. Blocking analytics cookies does not prevent the core controller diagnostic tools from running.
5. Contact and contributor submissions
Information submitted through /contact or /contribute is intentionally transmitted to GPADLAB. The server-side form handlers validate the submission and send it through the email-delivery service configured for GPADLAB.
The request IP address is used by an in-memory rate limiter to reduce automated abuse. The contact endpoint currently uses a short one-minute rate-limit window and the contributor endpoint uses a ten-minute window. Serverless instances may reset this temporary in-memory state. The current implementation also includes the request IP address in the email copy of a valid submission.
We use contact submissions to respond to inquiries. Contributor submissions are used to assess pitches, communicate with prospective contributors, review disclosed commercial relationships, and maintain reasonable editorial records. We do not automatically add form submitters to a marketing mailing list.
If you want GPADLAB to delete a form submission that can reasonably be located in our records, contact us at contact@gpadlab.com.
6. Your privacy rights
Depending on where you live, applicable privacy law may give you rights to request access to, correction of, deletion of, or information about personal data GPADLAB holds about you, and in some circumstances to object to or restrict processing.
Because GPADLAB does not maintain user accounts or a server-side controller-results database, many requests will relate primarily to contact or contributor correspondence. Send requests to contact@gpadlab.com and we will respond within the timeframe required by applicable law.
7. Children's privacy
GPADLAB is a general-audience site and does not knowingly solicit personal information from children through its contact or contributor forms. If you believe a child has submitted personal information to GPADLAB, contact us at contact@gpadlab.com so we can review and, where appropriate, remove it.
8. Data retention
Local tool data stored in your browser remains there according to your browser's storage behavior until it is cleared, removed by the browser, or overwritten by the relevant tool.
Analytics retention is controlled by the analytics service and the settings applied to the relevant analytics property. GPADLAB does not describe those provider-side retention settings as shorter than they actually are.
Contact and contributor messages are retained for as long as reasonably needed to handle the inquiry, evaluate or manage the editorial relationship, maintain appropriate records, resolve disputes, or meet legal obligations. Because the current form emails include the request IP address, that IP follows the retention of the corresponding email record.
9. Service providers and international processing
GPADLAB is operated from Karachi, Pakistan. Website hosting, analytics, and email-delivery providers may process request or submission data in other countries as part of providing their services. Those providers apply their own privacy, security, retention, and international-transfer terms.
Where Plausible is enabled, Plausible states that its hosted analytics service processes and stores its analytics data in the EU. Google Analytics and the configured hosting or email providers may process data through infrastructure in multiple jurisdictions.
10. Changes to this policy
This policy may be updated when GPADLAB changes its tools, analytics, forms, hosting, or legal practices. The "last updated" date at the top of this page reflects the latest revision. Material product changes that affect controller-data handling will be documented before they are presented as current functionality.
11. Contact
Questions about this policy or requests concerning personal information held by GPADLAB should be sent to contact@gpadlab.com.
This privacy policy is provided for transparency and information. It is not a contract and does not constitute legal advice. For questions about how it applies to your specific situation, consult a qualified legal professional in your jurisdiction.