Skip to main content
Back to home
Legal

Privacy policy

What ClimbX collects, why we need it, where it lives, and the rights you have over it.

Last updated: 2026-09-12

Who we are

ClimbX (“we”, “us”) is operated by D. Smidstrup Holding ApS (CVR 45751937), trading as Random Code, Havnegade 12, 3. 1, 5000 Odense C, Denmark. Contact us at daniel@climbx.so. We are the data controller for your personal data under the EU General Data Protection Regulation (GDPR).

What we collect

  • X profile data:returned by X's OAuth flow when you sign in - your X user id, handle, display name, profile image URL, public follower / following counts, and verified-type (free / Premium / Business).
  • X access tokens: a bearer token and refresh token issued by X when you authorize ClimbX. Encrypted at rest and used only to call the X API on your behalf.
  • Your recent X posts:text, engagement metrics (likes, replies, impressions, views), and posting time. We use these to learn your voice and to compute your analytics. We re-fetch a small window periodically. We do not store your X DMs, drafts you didn't publish, or anyone else's posts beyond the public cohort outliers we surface as examples - and those are stored without any link to your account.
  • Account data you provide: onboarding answers (goal, niches, aspirational creators), drafts you write, posts you schedule, chats you have with the AI assistant, and bookmarks you save.
  • Usage data: the actions you take in the app (page views, button clicks), AI credit consumption, and the number / cost of API calls we make on your behalf. We use this to operate the service, enforce plan limits, and bill correctly.
  • Payment data: handled by Stripe, our payment processor. We never see your card number. We receive only the minimum needed for support - your email, plan, and payment status.

ClimbX may also process public X profile, post, and engagement data received through X or service providers that supply access to public X data. We use it for product features such as discovery, examples, and aggregated analytics. Publicly available information may still be personal data. It is not used to access private posts or direct messages.

How we use your data

  • To run the drafting, voice-coach, and analytics features when you use them.
  • To enforce plan limits (AI credits, scheduled-post quotas).
  • To display your usage and analytics on your dashboard.
  • To send transactional emails (receipts, security notices, plan changes).
  • To produce aggregated, anonymized baselinesacross users so we can surface “what works in your niche at your size band.” Baselines require at least 30 users with identifiers stripped. These aggregates do not identify an individual user; public example posts may be displayed separately as part of the service.

We do not sell your data or train external AI models on your content. If you accept optional advertising tracking, we share the advertising measurement data described below with Meta.

Legal bases (GDPR)

  • Contract performance (Art. 6(1)(b)): to deliver the ClimbX service you signed up for. Without your X data, we cannot do the work.
  • Legitimate interests (Art. 6(1)(f)): to improve the service via aggregated analytics, to prevent abuse, and to bill accurately.
  • Consent (Art. 6(1)(a)): for any future marketing emails, only after you opt in, and for optional interaction replay when you allow it. Service and billing emails are not marketing and do not require consent.

Storage and service providers

Core account and application data is primarily stored using EU-hosted database infrastructure. We also use service providers where needed for hosting, X connectivity, AI features, payments, transactional email, product analytics, and affiliate attribution. Depending on the provider and feature, limited personal data may be processed outside the EEA. Any such transfers are subject to the protections required by applicable law. We do not claim that every system or provider is located exclusively in the EU.

Cookies

Strictly necessary: a Supabase Auth session cookie to keep you signed in, plus a small set of preference cookies (theme, last visited page). These fall under the ePrivacy exemption.

Attribution (first-party): if you reach ClimbX through an affiliate link or a tagged marketing campaign, we may store a first-party cookie that remembers the source for up to 90 days. This allows us to credit referrals and understand which channels work. It is httpOnly and cannot be read by other websites, but it is not classified as strictly necessary.

Affiliate tracking cookie (consent required): our affiliate partner Anderro loads its browser tracking and sets its own referral cookie only after you accept in the cookie banner, kept for up to 60 days. If you decline, that browser tracking cookie is not set. First-party or server-side attribution may still be used to credit an eligible referral where permitted. If you sign up after an affiliate referral, we may pass the signup details needed to record the referral. This data is not sold or used for third-party advertising.

Advertising measurement (consent required): after you accept optional tracking, Meta Pixel measures page visits. When you complete Stripe checkout and start a trial, we may also send Meta a confirmed trial event through its Conversions API. After a subscription invoice is successfully paid, we may send a purchase event with the amount paid and currency, including for subscription renewals. This includes hashed email and account identifiers, available Meta browser and advertising click identifiers, and browser information, including your IP address, to match the event to advertising activity. We record your consent choice and available matching identifiers with the Stripe checkout. The IP address is kept only on that checkout record, which is used for the trial event, and is never carried onto your subscription or onto later renewal events. If you decline optional tracking, we do not send these Meta events.

Our product analytics (Vercel Analytics) is cookieless.

Optional interaction replay

If you choose Allow in the “Help improve ClimbX” prompt, we use Subtext, provided by Fullstory, Inc., to replay interactions in the app after onboarding. We use these sessions to find confusing steps and technical problems. The same optional choice is available to free, trial, and paid accounts. Declining leaves your access unchanged.

Replay captures page structure, visible non-sensitive content, clicks, scrolling, navigation, browser and device information, network timing and status, and console output. Private workspace text is masked, and chat panels, account settings, credentials, and media are excluded. Network request and response bodies, URL query strings, and fragments are redacted. With your consent, we link replay sessions to your account using your stable internal user ID so we can investigate account-specific issues. We do not send names or email addresses as replay identity fields, or link replay URLs to your account analytics. The internal ID is pseudonymous personal data. Browser identifiers and IP addresses may also be processed by the provider; these sessions are not anonymous.

Subtext processes replay data in its EU service for this installation and publishes a 30-day session retention period. Its capture cookies include fs_uid (up to one year), fs_cid when used (up to one year), and fs_lua (30 minutes); _fs_tab_id is stored for the lifetime of a browser tab. See the provider's cookie details and privacy policy.

We save your replay choice on your account so it applies across browsers and devices. It stays in effect until you change it, or we need renewed consent for a material change. A browser copy helps carry over earlier choices and notify other tabs. Change it at any time under Settings → General → Activity recording. Turning it off stops capture in the current tab immediately; other open devices check for changes when focused and every minute while the app is running. It stops future capture; it does not erase sessions already captured. Contact us about deletion requests. We also count prompt displays and choices through our existing cookieless analytics to assess uptake, without attaching account IDs or replay links to those events.

Data retention and deletion

Account data (X profile, drafts, scheduled posts, chats, bookmarks, usage counters, billing records) is retained while your account is active.

When you ask us to delete your account, we delete or anonymize account data through a reviewed process, normally within 30 days. This generally means three things:

  • Deleted: drafts, scheduled posts, stored post data and metrics, chat history, bookmarks, saved library, and X access tokens associated with your account.
  • Stripped of identifiers: your account record, X profile (handle, name, avatar, X user id), and sign-in identity are emptied so the remaining row cannot be linked back to you in ordinary use.
  • Kept only where the law requires: billing and invoice records are retained for as long as tax law requires (typically 5 years in Denmark), and aggregated, anonymized baselines persist because, with identifiers stripped, they cannot be linked back to you.

If you held a founding-member spot, the spot stays counted toward the first-100 cohort but is shown anonymously - without your name or avatar.

Posts analyzed from other public X accounts are stored separately from your account data, so deleting your ClimbX account does not automatically remove those records. Public X data may still be personal data relating to the person behind that X account. If public content is corrected, deleted, or made private on X, our copy may not update immediately. The relevant account holder may contact us to request correction or removal.

Your rights (GDPR)

Under GDPR you have the right to:

  • Access the personal data we hold about you
  • Correct data that is inaccurate
  • Deleteyour account - we anonymize your data as described under “Data retention and deletion” above
  • Export your data in a machine-readable format
  • Restrict certain processing
  • Object to processing based on legitimate interests
  • Withdraw consent for any consent-based processing

To exercise these rights, email daniel@climbx.so. We aim to respond within 30 days. You also have the right to lodge a complaint with your local data protection authority (in Denmark: Datatilsynet).

Children

ClimbX is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has signed up, contact us and we will delete the account.

Changes

We may update this policy. Material changes will be posted here with an updated date and announced by email or in-app banner with at least 30 days notice.

Contact

D. Smidstrup Holding ApS - daniel@climbx.so

Need a Data Processing Agreement? Email the address above and we will provide one on request.