Legal
Privacy Policy for Climb
Last updated: August 29, 2026
This Privacy Policy describes how Climb (“Climb,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use the Climb iOS application and related services (the “Service”), including this website at climbapp.co.
Climb is a job-search organization app. Job-search content you enter is stored on your device. After onboarding, continued use of the iOS app requires an active Climb Pro subscription or free trial. Optional Sign in with Apple enables cloud sync; paid access is processed as described below.
Some capabilities (including Gmail connection and related AI classification) are not currently offered in the live app and are labeled Coming Soon. Related processing described below does not apply until that feature is enabled for you.
1. Scope
This Policy applies to information processed through the Climb iOS app (bundle ID `io.climb.Climb`), backend services we operate for Climb (including Supabase-hosted APIs and Edge Functions), and the Climb website at climbapp.co. It does not apply to third-party websites, career platforms, or email providers you connect or visit outside Climb.
2. Information We Collect
2.1 Information you provide
Depending on how you use Climb, this may include:
- Job-search content you enter: company names, job titles, application status, dates, locations, work type, salary notes, recruiter names, job descriptions, notes, timeline events, and reminders.
- Onboarding preferences: answers about your job-search stage, application volume, sources, frustrations, tracking habits, weekly goals, and reminder preferences (stored on device).
- Account information (optional): if you Sign in with Apple, we receive an Apple-provided user identifier and, when you choose to share it, your name and/or email (or Apple’s private relay email).
- Cloud sync (optional): core tracking features store job-search content on your device. If you Sign in with Apple, that on-device content—including applications, notes, salary information, recruiter names, timeline events, reminders, and related company logo/domain identifiers—is uploaded to our servers (hosted by Supabase) so it can sync across your devices. Signing out leaves that on-device content on this device. Signing in with a different Apple ID replaces this device’s applications and related records with that account’s cloud data. If you do not sign in, that content stays on your device.
- Support communications: if you email us, we receive the content of that correspondence.
2.2 Email connection (Coming Soon — not currently offered)
Gmail connection and inbox scanning are not currently available in the live Climb app (shown as Coming Soon pending provider approval). When that feature is enabled and you choose to connect an email account, we would request access needed to identify recruiting-related messages and may store structured fields such as sender display/address, subject line, a short snippet, classification metadata, and hashed message identifiers for deduplication.
We do not store full email bodies as part of normal Climb processing. OAuth tokens would be stored encrypted on our servers and would not be exposed to the mobile client. Until the feature is enabled for you, Climb does not request Gmail OAuth access or scan your inbox.
2.3 Information created by AI processing
Climb does not currently send your content to a language-model provider for typical app use. If email scanning or related AI suggestion features are later enabled, limited message metadata (such as subject/snippet) and related context (such as your application list) may be sent to our server-side language-model provider to help classify recruiting-related mail or generate suggestions. Model outputs can be incorrect; you would control whether suggested updates are applied.
2.4 Device and usage information
- Local app preferences and notification settings
- Notification permission state (if you enable reminders or related alerts, including trial-ending reminders)
- Basic technical diagnostics you or Apple may surface when reporting crashes. We do not currently operate a separate third-party analytics SDK in Climb unless listed in a future update to this Policy.
- Apple may present an in-app App Store rating prompt. That prompt is provided by Apple; we do not receive your star rating or written review through Climb unless you choose to leave a public App Store review.
2.5 Website information
If you visit climbapp.co, standard server logs and hosting providers (such as Vercel) may process technical data such as IP address, browser type, and request metadata needed to deliver and secure the site. We also use Vercel Web Analytics, a cookieless first-party analytics tool, to measure aggregate site usage such as page views, referrers, and approximate geography. We do not use this information for advertising, and we do not run third-party advertising or cross-site behavioral tracking pixels on this website.
Do Not Track: Some browsers send a “Do Not Track” (DNT) signal. We do not currently respond to DNT signals. Vercel Web Analytics is used for first-party site measurement, not targeted advertising. Our website host may still process standard server logs as described above, which are used to deliver and secure the site—not for targeted advertising.
2.6 Purchases and subscriptions
After onboarding, using Climb on iOS requires an active Climb Pro subscription or free trial (a hard paywall). Climb Pro is an auto-renewing subscription (currently marketed as a weekly plan). Purchases and free trials are processed by Apple. We use RevenueCat to check whether your subscription or free trial is active and to restore purchases.
RevenueCat and Apple may process: an app user identifier (an anonymous identifier before you sign in, and your account identifier after you Sign in with Apple); product and entitlement identifiers; trial and subscription status; and device identifiers commonly used to restore purchases (such as an Identifier for Vendor). We do not receive your full payment card number; Apple processes payment.
2.7 Company logos and search
When you search for or display company information, Climb may request logo/brand metadata from Brandfetch (or a similar provider) using a public client identifier. Queries may include company names or domains you enter.
3. How We Use Information
We use information to:
- Provide, maintain, and improve Climb (pipeline tracking, reminders, optional cloud sync, and—when available—optional email-assisted suggestions)
- Authenticate you and secure accounts
- Process and display subscription / trial status (including Climb Pro)
- Schedule local notifications you enable on this device (for example, follow-up or interview reminders, and reminders before a free trial ends). Climb does not currently send remote push notifications via Apple Push Notification service (APNs).
- Troubleshoot, prevent abuse, and enforce our Terms
- Comply with law and respond to lawful requests
We do not sell your personal information. We do not use email content to build advertising profiles or to contact your employers on your behalf.
4. Legal Bases (EEA/UK users)
Where GDPR/UK GDPR applies, we process personal data on these bases as applicable:
- Contract — to provide the Service you request
- Consent — for optional features such as email connection (when available) and certain notifications (you may withdraw consent by disconnecting email or changing iOS/Settings permissions)
- Legitimate interests — securing the Service, preventing fraud/abuse, and improving reliability, balanced against your rights
- Legal obligation — when we must retain or disclose information to comply with law
5. Third-Party Services
We share information only as needed with service providers who help us operate Climb. Your use of those services may also be governed by their own terms and privacy policies.
We do not share your job-application notes or email snippets with other Climb users.
| Recipient | Purpose |
|---|---|
| Apple | Sign in with Apple, App Store purchases, operating system services, and in-app rating prompts |
| Supabase | Optional authentication, database, and Edge Functions hosting for cloud sync when you sign in, and for email-related features when those features are enabled |
| Email OAuth and API access only when email connection is enabled and you authorize it | |
| OpenAI (or successor LLM provider) | Not used in the current live app for typical users; may process limited metadata if email scanning / AI suggestion features are enabled later |
| RevenueCat | Subscription entitlement management, free-trial status, restore purchases, and related app/device identifiers |
| Brandfetch | Company logo/brand lookup |
| Vercel | Hosting, delivery, and privacy-friendly web analytics for climbapp.co |
| Professional advisors / authorities | Only if required by law or to protect rights, safety, and security |
Processors act under instructions and appropriate contractual protections where required.
6. Data Retention
- On-device data remains until you delete it, uninstall the app, or clear app data. Signing out of cloud sync does not delete that on-device data.
- Account switch: if you Sign in with a different Apple ID, this device’s local applications and related records are replaced with that account’s cloud data.
- Cloud account data is retained while your account is active. If you delete your account in-app, we delete associated cloud user data subject to short backup/technical residual periods and any legal retention requirements, and we remove synced data from this device.
- Email connection (when available): disconnecting email revokes/stops use of tokens; you may choose to purge related email-event records where that option is available.
- Subscriptions: Apple and RevenueCat retain purchase and trial records as needed for billing, tax, and fraud prevention.
7. Security
- On-device data: Applications and related content can live in local storage on your device (SwiftData) even without an account.
- Cloud data (optional): If you sign in, synced content may be stored with access controls (including row-level security patterns) intended to isolate users.
- Tokens: When email features are enabled, email OAuth tokens are encrypted at rest on the server.
- Transmission: We use HTTPS/TLS for network calls to our backends and major providers.
No method of transmission or storage is 100% secure. You are responsible for controlling physical access to your device and your Apple ID.
8. Your Rights
Depending on your location, you may have rights to access, correct, delete, export, or restrict certain personal data, and to object to or withdraw consent for certain processing.
In Climb you can typically:
- Edit or delete applications and related records on device
- Export applications (JSON) from Settings where available
- When email connection is available: disconnect email and optionally delete email-derived events
- Sign out (keeps on-device data) or delete your cloud account (Settings). Signing in with a different Apple ID replaces this device’s local applications with that account’s cloud data
- Disable notifications in iOS Settings or in-app reminder toggles
- Manage or cancel subscriptions and trials in Apple’s subscription settings
To exercise privacy rights or ask questions, contact support@climbapp.co. We may need to verify your request. You may also lodge a complaint with your local data protection authority.
California residents: We do not “sell” or “share” personal information as those terms are commonly defined for targeted advertising. You may request know/delete rights via the contact above. As described in Section 2.5, we do not currently respond to browser Do Not Track signals.
Children’s privacy: Climb is not directed to children under 13 (or under 16 where that is the applicable digital consent age). We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.
9. International Transfers
We and our processors may process data in the United States and other countries. Where required, we use appropriate safeguards (such as standard contractual clauses) for transfers from the EEA/UK/Switzerland.
10. Changes to This Policy
We may update this Policy from time to time. We will revise the “Last updated” date and, when changes are material, provide additional notice in the app or by other reasonable means. Continued use after the effective date constitutes acceptance of the updated Policy where permitted by law.
11. Contact
Questions about privacy:
Contact: support@climbapp.co
Operator: Rohan Wilmot
Postal address: 12555 Foothill Avenue, San Martin, California