A Stronger Climber

Privacy Policy

Last updated: 2 September 2026 · Version 1.2
The short version

1.Who we are

Klatreskader.dk (CVR 37848506), Denmark, is the data controller for the A Stronger Climber platform (app.astrongerclimber.com and the installable app). Questions and requests: privacy@astrongerclimber.com. Formal company details are available via the public CVR register.

2.How signing in works

You sign in by entering your email address. We send a six-digit code to that address, and entering it proves the address is yours. There is no password. Once you are signed in, your device keeps a token so you do not have to repeat this every time — you can revoke it from the menu (“Sign out everywhere”) if you lose a device.

We hold your email address because it is how you sign in and how we reach you, and the display name you chose because your coach and the app need something to call you. Both are stored in the same EU database as your training records.

Until August 2026 sign-in ran through a separate community platform, and this policy previously described the training data as pseudonymous on that basis. That is no longer how the platform works, and this version corrects it.

3.What we collect, and why

CategoryExamplesWhy (legal basis)
IdentityEmail address, display name, sign-in codes and device tokensTo sign you in and keep you signed in (contract)
Training dataClimbing sessions, finger-training timers, tests, journal entries, workouts, calendar plansTo provide the service (contract)
ProfileBodyweight, age band, climbing grades, training background, goalsTo personalise your coaching (contract)
Health dataInjury logs, pain scores, rehab check-ins, recovery statusOnly with your explicit consent (GDPR Art. 9(2)(a)) — see section 4
Coach chatMessages with your coach, photos and videos you choose to shareTo provide coaching (contract)
BillingWhether you subscribe, your plan and its status, and the Stripe customer and subscription references. We never receive or store your card number.To give you the subscription you paid for (contract) and to keep the accounts (legal obligation)
Withdrawal & cancellationIf you withdraw from a subscription: the date and time we received it, the reference, and whether a refund was dueTo honour your right of withdrawal and to be able to prove when you used it (legal obligation)
App & deviceA hashed sign-in token, push-notification address, consent recordsTo keep you signed in securely and to prove consent (contract, legal obligation)

We do not collect advertising identifiers, analytics profiles, or location data.

4.Health data — your explicit consent

Injury and rehabilitation information is special-category data under GDPR Article 9. We only process it after you explicitly consent, which happens when you activate Rehab mode or log an injury. Your consent is recorded with a timestamp.

You can withdraw consent at any time by switching out of Rehab mode, or by asking us to delete your health data (section 9). Withdrawing stops further processing; it is not the same as deletion, which you can request separately. Our rehab guidance supports your training — it is not medical advice and does not replace a physiotherapist or doctor.

5.Where your data lives

Your identity, training and health data is stored in a database and file storage contractually restricted to the European Union (Cloudflare D1 and R2, EU jurisdiction). Our web pages are hosted in Denmark.

A copy of the database is exported every night to EU file storage as a backup, and those backups are kept for 30 days before being overwritten. This matters for deletion: see section 9.

Some processing necessarily crosses borders. Our infrastructure provider operates a global network, so a request you make while travelling may be handled at the nearest data centre, and our AI provider processes coaching prompts in the United States. Those transfers rely on EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework.

6.Who helps us process your data

ProcessorWhat they doWhere
CloudflareDatabase (EU jurisdiction), media and backup storage (EU jurisdiction), application runtime, and the browser check on the sign-in pageEU storage; global network under SCCs / Data Privacy Framework
ResendSends your sign-in codes. Receives your email address and the code itselfUSA, under SCCs / DPF
NordicWayHosts the web pages themselvesDenmark
AnthropicThe AI that writes your coaching advice from your training (and, with consent, injury) contextUSA, under SCCs — receives a random user ID, never your name or email
BaserowA database we have migrated away from. It still holds historical copies of records written before August 2026; nothing new is written to itEU
StripeTakes payment if you subscribe. Receives your email address and card details — we never see or store a card number. It sees nothing about your training or healthEU/USA, under SCCs
Google / Apple push servicesDeliver notifications to your deviceGlobal

A plainer, always-current list — including what each one sees and whether it touches health data — is at who processes your data.

7.AI coaching — how it works

Your coaching notes, plans and weekly summaries are generated by an AI model (Anthropic's Claude). It receives your training context — recent sessions, scores, profile, and, if you have consented, injury status — identified only by a random user ID. It never receives your name or email address. Its output is advice for your training, not a medical or clinical decision.

8.Chat, photos and videos

Messages with your coach, and any photos or videos you share, are stored in EU-jurisdiction storage and served through unguessable links. Anything you or your coach downloads leaves the platform and is no longer under our control. You can ask us to delete chat content at any time.

9.Your rights

You can at any time ask us to:

One honest detail about deletion: erasing your records from the live database is immediate, but nightly backups already taken still contain them until those backups age out, which takes up to 30 days. Backups are not used to restore individual accounts, only to recover the whole system after a failure.

Write to privacy@astrongerclimber.com. We respond within 30 days. You can also complain to the Danish Data Protection Agency (Datatilsynet).

Who has looked at your record. Your coach can open your dashboard to do their job. Every time that happens we record it — who opened it, whose it was, when, and the network address and browser used. You can ask us for that list. We keep it for 12 months and then delete it automatically. Nobody, including us, can open an athlete’s dashboard without leaving that trace.

10.How long we keep things

We keep your data for as long as you have an account, so your training history and progression work as intended — that history is the product, and a year-old session still shapes the advice you get today.

Two things outlive the account on purpose. Records of payments are kept for five years plus the current year, because Danish bookkeeping law requires it (bogføringsloven). Records of a withdrawal — the date we received it and its reference — are kept for three years, because they are the proof that we honoured your right on the day you used it; erasing them would remove your proof as well as ours. Both are kept minimal: a date, a reference and an amount, not your training data.

If you stop using the platform, your data stays until you ask us to remove it. We would rather say that plainly than publish an automatic deletion schedule we do not yet run — with one exception, which does run: the record of who opened your dashboard (section 9) is deleted automatically after 12 months. You can ask for deletion at any time (section 9) and we act on it within 30 days. Resolved injuries older than 12 months are already excluded from AI coaching automatically, whether or not you ask.

11.Cookies and storage on your device

The dashboard uses no advertising or analytics cookies. It stores only what is strictly necessary on your device: your preferences, unsent drafts, and — if you install the app — a secure sign-in token so it opens without signing in again. Fonts and charting code are served from our own domain, so opening the dashboard contacts nobody but us. The exception is a demonstration video: if a session or exercise includes one, your browser fetches it from the video host, which sees your IP address and nothing about your training.

12.Changes

If we make meaningful changes to this policy, we will tell you in the app before they take effect.

A Stronger Climber · by Klatreskader.dk · CVR 37848506 · privacy@astrongerclimber.com · This page: app.astrongerclimber.com/privacy