Climb Companion — how your data is handled
The data controller is Alessandro Sposito — [email protected]. Climb Companion has no legal department nor a Data Protection Officer (DPO): none is required for processing at this scale, but you can still write to this address with any question about this policy.
Climb Companion has no server of its own: your profile, projects, photos, training history, Challenges, and everything else you enter stay exclusively on your device, in a local database (SwiftData) that the app creates and manages by itself. No data is ever sent to a developer server — no such server exists.
If you take a photo of a route or boulder, the image is saved only in the app's local database, never in the system photo library or anywhere else. If you pick an existing photo instead, the app uses iOS's system picker (PhotosPicker): it only receives the photo you pick, without ever requesting or obtaining access to the rest of your photo library.
Challenge reminders are local notifications, scheduled and managed entirely by your device: they never go through any server, neither the developer's nor a third party's (unlike push notifications, which would require a server).
Purchases and subscriptions are handled entirely by Apple through StoreKit: payment, card details, and billing never pass through the developer, who only receives confirmation from Apple that a purchase is valid — never your payment data. For details on data Apple collects during purchase, see Apple's own privacy policy.
Climb Companion does not integrate any analytics, advertising, or tracking tools of any kind, whether the developer's own or third-party (no Facebook SDK, Google Analytics, ad framework, or similar). We have no way of knowing how you use the app, how often you open it, or what you do inside it: that data stays only on your device and we never see it.
From Settings ▸ Data & Backup you can export all your data to a file you choose where to save (Files, iCloud Drive, AirDrop...): it's entirely under your control, not an automatic upload. The same file can be re-imported to restore your data on another device or after reinstalling the app. The developer never has access to this file unless you choose to share it yourself.
Your data stays on the device until you uninstall the app or delete it yourself from individual screens (e.g. deleting a project or an attempt). Uninstalling the app permanently erases everything, unless you previously saved a manual backup — that's why periodic export is recommended before switching devices.
A future version may introduce syncing across your devices via private iCloud (CloudKit): even then, data would remain in your own personal Apple account, never on a developer server. This policy will be updated before that feature becomes active.
Climb Companion is not specifically directed at children under 16 and does not require account registration, so it does not knowingly collect identifying data from minors. If you are a parent and believe your child has used the app and entered personal data, you can delete it at any time by removing the app or the individual content from settings.
Since your data stays on your own device, you already have full direct control: you can view, modify, or delete it at any time from within the app's screens, with no need to request this from the developer. If you'd still like to formally exercise your GDPR rights (access, rectification, erasure, portability, objection) by writing to the controller, you can do so at the address above.
If this policy changes substantially (for example with the introduction of iCloud sync), the updated version will always be available here, with the last-updated date shown.
For any question about this policy or how your data is handled, write to [email protected].
Last updated: draft of July 22, 2026 — the date will be confirmed at publication time