Privacy Policy
Last updated: July 26, 2026
1. Introduction
Welcome to Climbr (“we”, “us”, “our”). We built this app to help you read routes and get better at climbing, and we have tried to keep the amount of data involved as small as the app allows.
This policy explains what happens to your information when you use Climbr: what stays on your phone, what goes into your own iCloud, and the few things that are sent to services we depend on. Wherever something leaves your device, we say so and name who receives it.
The short version: your logbook is yours. It lives on your device and in your personal iCloud, and we cannot read it. Your photos and videos stay on your phone — the only exception is the wall photo you choose to scan, which is sent for analysis and then discarded. Nothing you do in the app is used for advertising, profiling or tracking.
The data controller is:
Ugur Küten
Zum Ganswieschen 8
54516 Wittlich, Germany
Email: app.climbr@gmail.com
If you have any questions about data protection, you can contact us at any time using the email address above.
2. Overview
The App has no user account with us and requires no registration.
| Feature | What leaves your device | Who receives it |
|---|---|---|
| iCloud sync | Your logbook, form scores, saved gyms, your name | Apple, into your own iCloud |
| Route scanning (“Find the way”) | The photo you take of the wall | Our analysis server, then OpenAI |
| Nearby map | Your location and any place searches you type | Apple, OpenBeta |
| Subscriptions | A random identifier and your purchase status | RevenueCat, Apple |
Photos and videos you record never leave your device. We use no analytics tools, no advertising networks, no advertising identifier, and no cross-app tracking.
3. iCloud Sync
So that your logbook is available on all your devices and survives reinstalling the App, the App stores it in your personal iCloud account, in a private area reserved for this App.
This is your iCloud, not ours. We have no access to it and cannot read, export or delete anything stored there. Apple provides the storage under your existing iCloud agreement.
What is synced:
- your logged routes: name, gym, grade, hold colour, style tags, and any notes you write
- the AI route analysis belonging to a route, including the hold positions and the suggested sequence
- your recorded attempts: the form score, the individual metrics, and the coaching feedback
- the name and the answers you give during onboarding
- your saved gyms, including their coordinates
- the date you started using the App
What is never synced:
- the photos you take for route analysis
- the videos you record of your climbing
- the body-position data from form analysis, which is discarded immediately after scoring
- your subscription status and the identifier used for it
How sync is switched on: the App uses the iCloud account already signed in on your device. There is no separate login. If your device is not signed into iCloud, the App works entirely locally and nothing is transmitted.
Legal basis: Art. 6 (1) (b) GDPR — keeping the logbook you create available to you across your devices.
Deleting synced data: because this data sits in your own iCloud, we cannot delete it for you. When you delete a route in the App, its content is overwritten and no longer readable. To remove everything, open the iOS Settings app, tap your name at the top, then iCloud → Manage Account Storage → Climbr → Delete Data. Deleting the App alone does not remove data from iCloud.
Apple’s privacy policy: https://www.apple.com/legal/privacy/
4. Route Scanning (Photos and AI Analysis)
When you use the route scanning feature, the photo you take of the climbing wall — together with the holds you marked, the route colour and the grade — is transmitted to our analysis server and forwarded from there to OpenAI, which generates the route reading. The photo itself stays on your device afterwards; only the resulting analysis text is saved and synced.
Our analysis server
Operated by us and hosted with Fly.io, Inc., 2261 Market Street, San Francisco, CA 94114, USA, acting as our processor for hosting. We do not store your photos permanently; they are held only for as long as the request takes to complete.
OpenAI
Provider: OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland
Privacy policy: https://openai.com/policies/privacy-policy
OpenAI processes your photo to generate the analysis and acts as our processor under a data processing agreement. Under OpenAI’s API terms, data submitted through the API is not used to train their models. However, OpenAI retains API inputs for up to 30 days in order to detect misuse, after which they are deleted.
Processing may take place on servers in the USA. This transfer is based on the European Commission’s Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR, which form part of our agreement with OpenAI.
Legal basis: Art. 6 (1) (b) GDPR — providing the analysis function you have expressly requested.
Please note: photos of climbing walls can unintentionally capture other people. Please make sure not to photograph anyone who has not agreed to it. Where a photo does contain other people, we process that data on the basis of Art. 6 (1) (f) GDPR — our legitimate interest, and yours, in providing the requested analysis. Such data is not used for any other purpose, is not linked to any profile, and is not retained by us.
Access to your camera and photo library is requested by the operating system and can be revoked at any time in your iOS settings.
5. Nearby Map (Location Data)
When you open the “Nearby” tab, the App determines your current position through your device’s location services in order to centre the map and find climbing gyms and outdoor areas near you.
Apple MapKit
The map is provided by Apple. Our server issues the access credential required to load it; your device then communicates directly with Apple. Your position, the visible map area and any location searches you type into the search field are transmitted to Apple in order to render the map and return results.
Provider: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland
Privacy policy: https://www.apple.com/legal/privacy/
OpenBeta
To find outdoor bouldering and climbing areas, we transmit the coordinates of the currently visible map area — not your exact position — to the open climbing database OpenBeta.
Information: https://openbeta.io
Legal basis: Art. 6 (1) (b) GDPR — providing the map function you have expressly requested.
Your location is not stored on our servers and is not used to create any movement profile. If you save a gym, its coordinates are stored with it and synced to your iCloud (see section 3). Location access is requested by the operating system only when you open this feature and can be revoked at any time in your iOS settings.
6. Climbing Form Analysis (On-Device)
When you record a climbing attempt to analyse your technique, the video is processed entirely on your device. Body-position recognition runs locally within the App; neither the video nor the recognised body points are transmitted to us or to any third party, and the body-position data is discarded once the attempt has been scored. The resulting score and feedback are saved and synced to your iCloud (see section 3).
7. Purchases and Subscriptions
7.1 App Store
Downloading the App and all in-app purchases are processed through the Apple App Store. Apple processes the data required for payment (e.g. Apple ID, payment details, purchase history) as an independent controller. We receive no payment data and no real names.
Provider: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland
Privacy policy: https://www.apple.com/legal/privacy/
7.2 RevenueCat
We use RevenueCat to technically manage and verify subscriptions.
Provider: RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA
Privacy policy: https://www.revenuecat.com/privacy/
RevenueCat receives a random, pseudonymous identifier generated by the App — containing no name, email address or advertising identifier — together with App Store purchase receipts, your subscription status, technical device information and your IP address. When a subscription screen is displayed, RevenueCat also records that it was shown and how you interacted with it.
The same pseudonymous identifier is sent to our analysis server when you use route scanning, so that we can confirm your subscription is valid before performing the analysis.
Legal basis: Art. 6 (1) (b) GDPR (performance of the contract covering the paid features).
RevenueCat acts as our processor pursuant to Art. 28 GDPR under a data processing agreement. As processing may take place in the USA, the transfer is based on the European Commission’s Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR.
8. Server Log Data
When your App contacts our server — for route analysis, or to obtain the map credential — the server records your IP address, the time of the request and the endpoint called. This is technically necessary to deliver a response and serves to protect against misuse and overload.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the security and stability of our service).
Retention: 7 days, after which the logs are deleted.
9. Data Stored on Your Device
In addition to what is synced, the following is held on your device only and is never transmitted anywhere: the photos you take for route analysis, your recorded climbing videos, your subscription status, the counter for free analyses, and display preferences such as theme and language.
Storing this information is strictly necessary to provide the functions you have expressly requested and is therefore based on Section 25 (2) no. 2 TDDDG. No consent is required.
10. No Tracking, No Advertising
The App uses no advertising identifier (IDFA), does not track your behaviour across other apps or websites, and displays no advertising. We therefore do not present a prompt under Apple’s App Tracking Transparency framework. We operate no analytics, statistics or crash-reporting services of our own.
If you have consented in your device settings to sharing diagnostic data with app developers, Apple provides us with anonymised crash reports. You can disable this at any time under “Privacy & Security → Analytics & Improvements”.
11. Age
Climbr is not directed at children under 13. The route analysis feature relies on a third-party AI service (OpenAI) whose terms require users to be at least 13 years old.
12. Contacting Us by Email
If you contact us by email, we process your email address and the content of your message in order to handle your enquiry. The legal basis is Art. 6 (1) (f) GDPR, or Art. 6 (1) (b) GDPR where your enquiry relates to a contract. The data is deleted once your enquiry has been dealt with, unless statutory retention obligations apply.
13. Retention Periods
- Data in your iCloud: stored for as long as you keep it. We cannot delete it; see section 3 for how to remove it yourself.
- Photos and videos on your device: until you delete them or uninstall the App.
- Photos for route analysis: not stored permanently by us; retained by OpenAI for up to 30 days for misuse detection.
- Location data: not stored by us.
- Server logs: 7 days.
- Subscription data at RevenueCat: for the term of the subscription and beyond where statutory retention periods require it (under German commercial and tax law generally 6 or 10 years).
- Email correspondence: until your enquiry has been dealt with, subject to statutory retention periods.
14. Your Rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on Art. 6 (1) (f) GDPR (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future (Art. 7 (3)).
An informal message to app.climbr@gmail.com is sufficient.
Two practical notes on how these rights work with this App:
Your logbook. Everything synced is in your own iCloud and on your device, so you already hold it in full. We cannot access it, which also means we cannot copy, correct or delete it for you. Section 3 explains how to delete it yourself.
Your subscription data. Because the App works without an account with us and identifies you only by a random identifier, we are generally unable to identify you. Pursuant to Art. 11 (2) GDPR we therefore need that identifier in order to act on your request. You will find it at the bottom of the settings screen in the App — please include it in your message.
Right to lodge a complaint (Art. 77 GDPR): you may complain to a data protection supervisory authority, in particular the one for your place of residence or for our place of establishment:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34, 55116 Mainz, Germany
https://www.datenschutz.rlp.de
15. Data Security
We take appropriate technical and organisational measures to protect your data against loss, destruction, manipulation and unauthorised access. All communication between the App, our servers and the services named above is encrypted using TLS. Data in your iCloud is protected by Apple’s security measures and is accessible only to your Apple account.
16. Automated Decision-Making
The route analysis is generated by an AI system. It is a suggestion for how to climb a route and has no legal effect on you and no comparable significant impact. It therefore does not constitute automated decision-making within the meaning of Art. 22 GDPR. Results may be inaccurate; please judge for yourself whether a suggested sequence is safe to attempt.
17. This Website
This section covers the website climbrapp.me itself; everything above concerns the App.
Hosting. The website is a set of static files hosted on Cloudflare Pages.
Provider: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA
Privacy policy: https://www.cloudflare.com/privacypolicy/
To deliver a page, the host necessarily processes what your browser transmits: your IP address, the time of the request, the files requested, the referring page, and your browser and operating system. This also serves to protect the site against attacks and overload. Cloudflare acts as our processor under a data processing agreement; where processing takes place outside the EU, the transfer is based on the European Commission’s Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in delivering and securing the site).
No cookies from us, no analytics, no third-party requests. We set no cookies, store nothing in your browser, and run no analytics, statistics, tracking or advertising on this website. Every asset a page loads — the typeface, the images and the App Store badge included — is served from this site itself, so opening a page contacts no other server. Cloudflare may set a technically necessary cookie to protect the site against automated attacks; it holds no information about you and is not used to analyse your behaviour.
18. Changes to This Privacy Policy
We will update this privacy policy whenever the App’s functionality or the legal situation changes. The version published on this page is the applicable one. The date of the most recent update appears at the top.