Privacy Policy
Effective February 27, 2026
ClimbWith ("we", "us", "our") is a mobile app that helps climbers coordinate gym sessions with friends. This policy explains what data we collect, how we use it, and your choices.
1. Data We Collect
When you use ClimbWith, we collect:
- Account information — your email address and display name. If you sign in with Google or Apple, we receive an account identifier from that provider.
- Schedule data — gym sessions you create, including the gym, date, time, and any notes you add.
- Friend relationships — who you have connected with as friends within the app.
- Check-in events — when you check in at a gym (manually or via auto-check-in). We record which gym and when, not your GPS coordinates.
- Device tokens — a push notification token so we can send you notifications.
- Age confirmation — a timestamp recording that you confirmed you are 13 or older.
2. How We Use Your Data
- Authentication — to verify your identity and maintain your session.
- Friend coordination — to show your friends your schedule and check-in status, and vice versa.
- Push notifications — to notify you about friend requests, check-ins, and session activity.
- Transactional email — to send password reset emails when you request them.
3. What Other Users Can See
Only your accepted friends can see your schedule entries, check-in status, and display name in context. Non-friends cannot see your activity. There are no public profiles.
4. Third-Party Services
We use the following third-party services to operate ClimbWith:
- SendGrid — for sending transactional emails (password resets). SendGrid receives your email address when we send you a message.
- Firebase Cloud Messaging — for delivering push notifications to your device. Firebase receives your device token.
- Google Sign-In / Apple Sign-In — if you choose social login, the respective provider handles authentication. We receive a unique identifier and your email address.
We do not sell your data to third parties.
5. Data Storage and Security
Your data is stored on servers hosted by Fly.io. All data is encrypted in transit (HTTPS) and at rest. Access to production systems is restricted to the development team.
6. Data Retention
We retain your account data for as long as your account is active. Check-in records may be pruned after 90 days. If you delete your account, all of your data is permanently removed.
7. Account Deletion
You can delete your account at any time from the Settings screen within the app. Account deletion removes all your data, including your profile, schedule entries, friend connections, check-in history, and device tokens. This action is permanent and cannot be undone.
8. Children's Privacy
ClimbWith requires users to confirm they are 13 years of age or older before creating an account. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, please contact us and we will promptly delete it.
9. Changes to This Policy
We may update this privacy policy from time to time. If we make significant changes, we will notify you through the app or by email.
10. Contact Us
If you have questions about this privacy policy or your data, contact us at team@climbwith.app.