Privacy Policy
Last updated: 14 September 2026
This policy explains what the ClimberBase mobile app collects, why, and how you can delete your account and data.
1. Who We Are
ClimberBase is operated by Atelier Elyes, a company registered in Denmark under CVR no. 46635825 (atelierelyes.com). Atelier Elyes is the data controller for personal data processed through the ClimberBase app.
You can reach us at [email protected].
2. How to Delete Your Account and Data
You can delete your ClimberBase account and its associated data at any time, directly in the app. You do not need to contact us first.
Deleting from within the app
You need to be signed in to delete your account, as the settings screen is only available to signed-in users. If you have been signed out, sign in first with your email address and a one-time code, then follow the steps below.
- Open the ClimberBase app and go to the Explore tab.
- Tap the settings (gear) icon in the top-right corner to open Settings.
- Scroll down to the Account section.
- Tap Delete Account ("Permanently delete your account and data").
- In the confirmation dialog, type your account email address to confirm, then tap Delete.
Deletion runs immediately and cannot be undone. If your account has been suspended, the same Delete Account option remains available to you.
Requesting deletion by email
If you cannot access the app, email [email protected] from the address associated with your account and ask us to delete your account. We will verify the request and action it within 30 days.
What is deleted
- Your name, email address, profile photo, and gender.
- Your login credentials and authentication record.
- Your profile photo file, erased from our image storage.
- Your contact entry at our email provider (name and email address), so you receive no further announcements from us.
- Your notification settings, saved session alerts, and the link between your account and your devices — after which the device record, including its push notification token, is no longer associated with you.
- You are removed from upcoming sessions you had joined, and sessions you were hosting are cancelled.
- Your Brew Crew badge and the purchase record held for you by our purchase-management provider, which we ask to permanently delete your customer record (see How Long We Keep It).
What is kept, and why
Some records cannot be removed without destroying other people's history or undermining the safety of the community. After deletion these are no longer linked to your name, email, or photo — your account is anonymised and appears only as "Deleted User":
- Chat messages you sent, so conversations remain readable for the other participants.
- Past session records and participation history.
- Reports and blocks involving your account, retained for the safety of other users and to prevent abuse.
- Feedback you submitted to the in-app feedback board, detached from your identity.
- An anonymised erasure record, kept so that a deleted account is not accidentally restored.
Anonymous analytics and crash reports are never linked to your identity in the first place, so there is nothing to remove from them. If you want to discuss the removal of any retained record, email [email protected].
3. What We Collect
- Name — the display name you choose during profile setup.
- Email address — used to sign you in, or provided by Google or Apple if you sign in that way. Once you complete your profile, your name and email address are also added to our email provider's contact list for product announcements (see Service Providers).
- User ID — an account identifier we generate for you.
- Age — the age you enter during profile setup, and the date of birth we infer from it so your age stays current. Other users only ever see your age group (such as 25–34), never your exact age.
- Other personal info — your gender (optional) and the date you accepted our terms.
- Photos — the profile photo you upload.
- In-app messages — the messages you send in session chats, and the session descriptions you write.
- App interactions — anonymous product analytics about how the app is used, such as which screens are opened and whether a session was created or joined. These events contain no name, email, message text, or account identifier.
- Crash logs — anonymous diagnostics when the app crashes or errors, including the app version and a stack trace. Personal details are stripped before the report is sent.
- Device or other IDs — an installation identifier generated on your device and a push notification token, used to deliver notifications to the right device.
- Session activity — the climbing sessions you create or join, the gym, and the time.
- Purchase history — if you buy the optional “Buy me a coffee” donation, the fact that you bought it. The payment itself is handled by Apple or Google; we never receive your card or bank details. Our purchase-management provider, RevenueCat, holds the store receipt for the purchase together with your user ID, your device model and operating system, and the app version. On our own systems, the only thing recorded is a yes/no supporter flag on your account, which is what shows the Brew Crew badge.
- IP address — processed temporarily in memory to rate-limit requests and prevent abuse. It is never written to our database.
ClimberBase does not collect your device's location, does not use advertising identifiers, contains no advertising SDKs, and does not sell or share your personal data with third parties for their own purposes.
4. Why We Collect It
- App functionality — your name, gender, age group, photo, messages, session activity, and device identifiers make the core product work: showing you to other climbers, running session chat, and delivering notifications.
- Account management — your name, email, user ID, photo, and device identifiers are used to create and secure your account and sign you in.
- Developer communications — your email, user ID, and device identifiers let us send you sign-in codes, a welcome email when you create your account, notifications relevant to your sessions, and occasional product announcements by email, which you can unsubscribe from at any time.
- Analytics — anonymous app interaction data and crash logs help us find bugs and understand which features are used.
- Age — entering it confirms that you meet the 16-and-over requirement, and the age group derived from it is shown on profiles to help climbers choose the sessions and partners that suit them.
- Safety and abuse prevention — reports, blocks, and temporary IP processing help us protect the community.
- Donations — your purchase history lets us grant the Brew Crew badge to your account, keep it if you reinstall the app or switch phones, and remove it if the purchase is refunded.
5. Legal Basis
Under the GDPR, we process your personal data on these bases:
- Performance of a contract — profile data, messages, session activity, and device identifiers are necessary to provide the service you signed up for. If you buy the coffee donation, your purchase history is necessary to fulfil that purchase and grant the badge.
- Legitimate interest — anonymous analytics and crash reporting, rate limiting, confirming that users meet our minimum age requirement, the retention of safety records (reports and blocks) to keep the community safe, and sending occasional product announcements to registered users, which you can unsubscribe from at any time.
- Consent — push notifications, which you can turn off at any time in the app or in your device settings. Providing your gender is optional.
6. What Other Users Can See
Other climbers can see your display name, profile photo, gender if you provided it, your age group, your aggregate stats, and the sessions you host or join, along with any messages you send in session chats.
If you buy the coffee donation, the Brew Crew badge is shown under your name on your profile, so other climbers can see that you supported the app. The badge is the only thing they see: never the amount, the date, or any other purchase detail.
Your email address is never shown to other users. The climbers you recently climbed with are shown on your profile by default, under “Last climbed with”. You can hide them at any time by setting that section to “Private”, and hiding them also removes you from other climbers’ lists. Your own profile always shows your full list to you.
7. Service Providers
We use the following providers to run ClimberBase. They process data on our instructions under data processing agreements, and are not permitted to use it for their own purposes.
- Supabase — hosts our database and handles authentication, in the EU.
- Cloudflare (R2 and Images) — stores and delivers profile photos. Photo storage is located in the EU.
- Google Firebase Cloud Messaging — delivers push notifications. Notification content, which can include a sender's name and message text, passes through this service in order to reach your device. On iOS this is delivered via Apple Push Notification service.
- Resend — sends transactional email: your sign-in codes, a welcome email when you create your account, and internal safety notices to our team when a report is filed. It also holds a contact list of registered users (name and email address) that we use to send occasional product announcements; every announcement carries an unsubscribe link, and your contact entry is deleted together with your account.
- Sentry — receives anonymous crash and error reports.
- PostHog — receives anonymous product analytics, hosted in the EU.
- Railway — hosts our application server in the EU.
- RevenueCat — manages the optional coffee donation: it validates the store receipt and tells our server when a purchase is made or refunded. It holds your purchase history under your user ID, hosted in the United States. Your payment details never reach RevenueCat or us.
The purchase itself is processed by Apple (App Store) or Google (Google Play) under their own terms and privacy policies. They act as independent controllers for that payment, and refunds are handled by them.
Where a provider processes data outside the EU/EEA, that transfer is covered by the European Commission's Standard Contractual Clauses.
8. How Long We Keep It
- Account and profile data — kept while your account exists, and erased when you delete it (see How to Delete Your Account and Data).
- Contact entry at our email provider — kept while your account exists, and deleted with it. If the provider is unreachable at that moment, the address alone is retained by us only until the deletion has been retried and confirmed.
- Messages, session history, reports, and blocks — retained after account deletion in anonymised form, as described above.
- IP addresses — held in memory only for the length of a rate-limiting window (about one minute) and never stored.
- Push notification tokens and device records — when you delete your account, your devices are unlinked from it, so the remaining record is no longer connected to your identity. A push token is erased once it stops working — for example after you uninstall the app — which happens the next time we attempt to send a notification to that device.
- Analytics and crash reports — retained by our providers under their standard retention periods; they contain no identifying information.
- Purchase history — when you delete your account, we ask RevenueCat to permanently delete your customer record, including the receipt and purchase history it holds. Apple and Google keep their own record of the transaction under their policies, and your purchase can still be restored to a new account through the store.
9. Security
All data transmitted between the app and our servers is encrypted in transit using HTTPS. Sign-in tokens are stored in the secure storage provided by your operating system — the Keychain on iOS, and encrypted preferences on Android. Push notification tokens are readable only by our backend. There are no passwords to steal: sign-in uses a one-time code sent to your email, or Google or Apple sign-in.
10. Your Rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete personal data — you can edit your name, photo, and gender directly in the app.
- Delete your personal data — see How to Delete Your Account and Data.
- Export your personal data in a portable format.
- Restrict or object to processing based on legitimate interest.
- Withdraw consent at any time, for example by turning off push notifications.
- Lodge a complaint with a data protection supervisory authority. In Denmark this is Datatilsynet.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
11. Children's Privacy
ClimberBase is not intended for anyone under the age of 16, and you must enter an age of 16 or over when creating a profile. We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us and we will delete it promptly.
12. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date, and significant changes will be communicated in the app.
13. Contact
Atelier Elyes
CVR no. 46635825
Denmark
[email protected]