Privacy

Privacy

What the app stores, what other climbers can see, and how this information is used.

What we store

We store account and profile information, climb data and activity, direct messages, notifications, feedback, gym requests, support-payment records, and uploaded photos needed to operate the app.

  • Email and account details for sign-in and moderation
  • Profile details like username, display name, bio, and home gym
  • Climb interactions such as attempts, sends, comments, votes, and reports
  • Messages, notifications, feedback, gym requests, and support-payment records
  • Photos you upload for climbs, gym materials, or photo logging

What other climbers can see

Public profile and community contributions may be visible to other climbers. Private notes are excluded from community activity and public profile displays.

  • Your public profile identity and visible climbing activity
  • Community-facing comments, climb data, and shared ratings or votes
  • Feedback and gym-request submissions are for the team, not for public display

Payments

Stripe processes payment details. Climb Stump stores the payment status, amount, and identifiers Stripe returns; it does not store full card details.

Feedback and gym requests

When you send feedback or request a gym, we use that information to improve the app, understand demand, and follow up if we need more detail.

Product analytics

We use privacy-masked product analytics and session replay to understand which flows work, find bugs, and debug behavior. Replay masks form inputs and sensitive surfaces, and analytics events should not include raw emails, comments, invite codes, image links, filenames, or free-text form contents.

Tag photo scanning

When you use the tag scanner, the photo is processed by a configured third-party AI provider to read the visible tag fields. Climb Stump keeps short-lived private scan metadata for reliability and matching, normally for 14 days. Raw scan images and raw AI-provider responses are not retained by Climb Stump unless diagnostic capture is explicitly enabled; the selected AI provider handles requests under its own service terms.