Privacy policy
What ClimbX collects, why we need it, where it lives, and the rights you have over it.
Last updated: 2026-08-04
Who we are
ClimbX (“we”, “us”) is operated by D. Smidstrup Holding ApS (CVR 45751937), trading as Random Code, Havnegade 12, 3. 1, 5000 Odense C, Denmark. Contact us at daniel@danielsmidstrup.com. We are the data controller for your personal data under the EU General Data Protection Regulation (GDPR).
What we collect
- X profile data:returned by X's OAuth flow when you sign in - your X user id, handle, display name, profile image URL, public follower / following counts, and verified-type (free / Premium / Business).
- X access tokens: a bearer token and refresh token issued by X when you authorize ClimbX. Encrypted at rest and used only to call the X API on your behalf.
- Your recent X posts:text, engagement metrics (likes, replies, impressions, views), and posting time. We use these to learn your voice and to compute your analytics. We re-fetch a small window periodically. We do not store your X DMs, drafts you didn't publish, or anyone else's posts beyond the public cohort outliers we surface as examples - and those are stored without any link to your account.
- Account data you provide: onboarding answers (goal, niches, aspirational creators), drafts you write, posts you schedule, chats you have with the AI assistant, and bookmarks you save.
- Usage data: the actions you take in the app (page views, button clicks), AI credit consumption, and the number / cost of API calls we make on your behalf. We use this to operate the service, enforce plan limits, and bill correctly.
- Payment data: handled by Stripe, our payment processor. We never see your card number. We receive only the minimum needed for support - your email, plan, and payment status.
ClimbX may also process public X profile, post, and engagement data received through X or service providers that supply access to public X data. We use it for product features such as discovery, examples, and aggregated analytics. Publicly available information may still be personal data. It is not used to access private posts or direct messages.
How we use your data
- To run the drafting, voice-coach, and analytics features when you use them.
- To enforce plan limits (AI credits, scheduled-post quotas).
- To display your usage and analytics on your dashboard.
- To send transactional emails (receipts, security notices, plan changes).
- To produce aggregated, anonymized baselinesacross users so we can surface “what works in your niche at your size band.” Baselines require at least 30 users with identifiers stripped. These aggregates do not identify an individual user; public example posts may be displayed separately as part of the service.
We do not sell your data. We do not share it with third parties for advertising. We do not train external AI models on your content.
Legal bases (GDPR)
- Contract performance (Art. 6(1)(b)): to deliver the ClimbX service you signed up for. Without your X data, we cannot do the work.
- Legitimate interests (Art. 6(1)(f)): to improve the service via aggregated analytics, to prevent abuse, and to bill accurately.
- Consent (Art. 6(1)(a)): for any future marketing emails, only after you opt in. Service and billing emails are not marketing and do not require consent.
Storage and service providers
Core account and application data is primarily stored using EU-hosted database infrastructure. We also use service providers where needed for hosting, X connectivity, AI features, payments, transactional email, product analytics, and affiliate attribution. Depending on the provider and feature, limited personal data may be processed outside the EEA. Any such transfers are subject to the protections required by applicable law. We do not claim that every system or provider is located exclusively in the EU.
Cookies
Strictly necessary: a Supabase Auth session cookie to keep you signed in, plus a small set of preference cookies (theme, last visited page). These fall under the ePrivacy exemption.
Attribution (first-party): if you reach ClimbX through an affiliate link or a tagged marketing campaign, we may store a first-party cookie that remembers the source for up to 90 days. This allows us to credit referrals and understand which channels work. It is httpOnly and cannot be read by other websites, but it is not classified as strictly necessary.
Affiliate tracking cookie (consent required): our affiliate partner Anderro loads its browser tracking and sets its own referral cookie only after you accept in the cookie banner, kept for up to 60 days. If you decline, that browser tracking cookie is not set. First-party or server-side attribution may still be used to credit an eligible referral where permitted. If you sign up after an affiliate referral, we may pass the signup details needed to record the referral. This data is not sold or used for third-party advertising.
We do not use third-party advertising cookies, and our product analytics (Vercel Analytics) is cookieless.
Data retention and deletion
Account data (X profile, drafts, scheduled posts, chats, bookmarks, usage counters, billing records) is retained while your account is active.
When you ask us to delete your account, we delete or anonymize account data through a reviewed process, normally within 30 days. This generally means three things:
- Deleted: drafts, scheduled posts, stored post data and metrics, chat history, bookmarks, saved library, and X access tokens associated with your account.
- Stripped of identifiers: your account record, X profile (handle, name, avatar, X user id), and sign-in identity are emptied so the remaining row cannot be linked back to you in ordinary use.
- Kept only where the law requires: billing and invoice records are retained for as long as tax law requires (typically 5 years in Denmark), and aggregated, anonymized baselines persist because, with identifiers stripped, they cannot be linked back to you.
If you held a founding-member spot, the spot stays counted toward the first-100 cohort but is shown anonymously - without your name or avatar.
Posts analyzed from other public X accounts are stored separately from your account data, so deleting your ClimbX account does not automatically remove those records. Public X data may still be personal data relating to the person behind that X account. If public content is corrected, deleted, or made private on X, our copy may not update immediately. The relevant account holder may contact us to request correction or removal.
Your rights (GDPR)
Under GDPR you have the right to:
- Access the personal data we hold about you
- Correct data that is inaccurate
- Deleteyour account - we anonymize your data as described under “Data retention and deletion” above
- Export your data in a machine-readable format
- Restrict certain processing
- Object to processing based on legitimate interests
- Withdraw consent for any consent-based processing
To exercise these rights, email daniel@danielsmidstrup.com. We aim to respond within 30 days. You also have the right to lodge a complaint with your local data protection authority (in Denmark: Datatilsynet).
Children
ClimbX is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has signed up, contact us and we will delete the account.
Changes
We may update this policy. Material changes will be posted here with an updated date and announced by email or in-app banner with at least 30 days notice.
Contact
D. Smidstrup Holding ApS - daniel@danielsmidstrup.com
Need a Data Processing Agreement? Email the address above and we will provide one on request.