Privacy Policy

Version 1.1 — 12 September 2026 · previous: v1.0, 3 July 2026

Cordada is a climbing app for iPhone and iPad: a collaborative guide to crags and routes, a logbook of your ascents, a conditions forecast, social features and training tools. This policy explains, with no beating about the bush, what data we handle, what for, and what control you have over it. It covers the app and also the cordada.eu website: the website part, which is a much smaller affair, is at the end, in section 13.

The 30-second summary

1. Data controller

The controller of your data is Pawel Kadziolka, developer of Cordada (Spain).

Contact for anything to do with privacy: privacidad@cordada.eu

2. What data we handle and what for

CategoryDataWhat forLegal basis (GDPR)
Account Email and password (stored hashed, never in the clear), or a “Sign in with Apple” identifier (if you choose to hide your email, Apple gives us a relay address). Creating your account, signing you in and keeping it safe. Performance of the contract (art. 6.1.b)
Public profile Username, display name, bio, profile picture and, if you add them, links to social networks (Instagram, YouTube, TikTok, Strava, 8a.nu, theCrag, personal website). Your identity within the community. Visible to other users. Performance of the contract (art. 6.1.b)
Private profile (optional) Height, weight, wingspan, date of birth or age, biological sex. Calibrating the biomechanical video analysis and the training features (real-world scale for the skeleton, heart-rate zones). They are not shown to other users. They are entirely optional: without them the app works with population averages. Consent (art. 6.1.a) — you enter them yourself and you can delete them whenever you like
Logbook Your ascents: route, date, style, grade, attempts, notes, rating; optionally the location where you logged the ascent. Your climbing history, your grade pyramid and — depending on the privacy you choose — the activity feed and each crag’s season calendar. Performance of the contract (art. 6.1.b)
Location Your device’s position, only while the app is in use (“while using the app”). (a) Centring the map and showing you nearby sectors — this position is processed on your device and is not stored on our servers. (b) “My crew”, if you switch it on: your last position is stored so it can be shown only to the friends you pick, one by one; it only updates with the app open and you can switch it off whenever you like. (c) Anonymous busyness, on by default and switchable off in Settings → “My crew”: when you are near a climbing crag (less than 1.5 km away), we store only an aggregated, anonymous counter per crag — never your identity, your name or your exact position. The busyness map only shows a crag when there are at least 2 people there at the same time, so it can never give away someone climbing on their own. The signal expires by itself after 90 minutes without activity and, if you switch the option off, your presence is deleted straight away from our servers. Consent (art. 6.1.a)
Photos The images you upload: photos of routes and sectors, topos, your avatar and the photos you send in chats. Showing them according to the privacy level you choose when you upload them (private / friends / public). Performance of the contract (art. 6.1.b)
Social Friendships and requests, meetups on the board that you create or sign up to, messages in meetup chats and in Cordada Match, kudos, tags in photos (between friends only; you can remove a tag someone has put on you). Making the social features work. Performance of the contract (art. 6.1.b)
Notifications Your device’s push notification token (Apple’s APNs). Letting you know about friend requests, messages and relevant activity. Only if you grant the notifications permission. Consent (art. 6.1.a)
Contributions to the catalogue Crags, sectors, routes and corrections you propose; your votes on other people’s suggestions. Keeping and improving the collaborative guide. Performance of the contract (art. 6.1.b)
Approach breadcrumb trails The GPS track of the walk-in you record up to the foot of the route: the points along the way, the distance, the duration, the sector and the date. Building the approach map between all of us. If you mark it public, your track is merged with other people’s to draw that sector’s path: what gets published is the shared path, not your track with your name on it. You can keep it private or delete it. Consent (art. 6.1.a) — you record it yourself, every time
Belay trust The endorsements you give or receive: who endorses whom and the tags describing how that person belays. So your profile shows that someone vouches for the way you belay. They are positive only, there is no score and no ranking, and only your friends or someone you have met up with can endorse you. Consent (art. 6.1.a) — you can withdraw an endorsement you have given
Route bolters If you apply for the bolter role for a crag: the crag, whatever you provide as accreditation and your role note. Plus the sector condition reports you send, with their category, severity and comment. Showing who bolts each crag and flagging the real state of the fixed gear. An administrator reviews the application. Consent (art. 6.1.a) for the application; legitimate interest (art. 6.1.f) in the safety of people climbing, for the reports
Climbing gyms The gym you sign up to and the date, and the messages you write in its room. So the others who have signed up can see you are going and you can all write to each other. Visible to anyone signed up to that gym. Consent (art. 6.1.a) — you sign up and sign out yourself
Badges and progress The badges you unlock and the count of sectors and regions you have climbed. Showing your progress on your profile. They are worked out from your logbook. Performance of the contract (art. 6.1.b)
Moderation Reports of content or users that you send; your list of blocked users. Reviewing inappropriate content and keeping the community safe. Only administrators can see the reports queue. Legitimate interest (art. 6.1.f): safety of the service

3. Data that never leaves your device

These categories are processed and stored on your iPhone or iPad only. They are not uploaded to our servers:

This data is deleted when you uninstall the app (the Apple Health data stays in Apple Health, under your control and Apple’s).

4. What we do NOT do

5. Who your data is shared with

5.1 With other users — according to your settings

Cordada is a social app: part of your data is shown to other users exactly according to the privacy you choose:

5.2 With infrastructure providers (processors)

We do not share your data with anyone else, apart from the providers strictly needed for the app to work:

ProviderWhat it doesWhere
Supabase Database and authentication (all the data in section 2). Servers in London, United Kingdom (AWS eu-west-2 region). The United Kingdom has an adequacy decision from the European Commission.
Cloudflare Storage and delivery of the images you upload (R2), through a proxy of our own with authenticated upload. Global network. Cloudflare is certified under the EU-U.S. Data Privacy Framework and applies standard contractual clauses.
Apple “Sign in with Apple”, push notifications (APNs) and weather data (Apple Weather). Apple takes part in the EU-U.S. Data Privacy Framework.

For the weather forecast, the app sends Apple Weather the coordinates of the climbing sector you are looking at — not your personal position. The same goes for terrain (IGN) and geology (IGME) queries: they are sector coordinates, not yours.

We would only disclose data to the authorities if a legal obligation required us to.

6. International transfers

Your data is stored mainly in the United Kingdom (Supabase), which has an adequacy decision from the European Commission. Images are served through Cloudflare’s global network and some Apple services may process data in the United States; in both cases the transfers rely on the EU-U.S. Data Privacy Framework and on the standard contractual clauses approved by the European Commission, which form part of the data processing agreement we have signed with each provider. You can ask us for a copy of those safeguards by writing to privacidad@cordada.eu and we will send it to you.

7. How long we keep your data

8. Your rights

You have the right of access, rectification, erasure, portability, restriction and objection. The two most common ones are built into the app:

For all the other rights, or if something is not working, write to privacidad@cordada.eu. We reply within one month at the most (art. 12.3 GDPR).

If you think we have not handled your data properly, you can complain to the Agencia Española de Protección de Datos, the Spanish data protection authority (aepd.es). (If you live in another EU country, you can also complain to the supervisory authority of your own country, or of the place where the problem happened — art. 77 GDPR.)

Withdrawing your consent

Several of the things described in this policy rely on your consent: the physical data in the private profile, the location behind “My crew” and busyness, the notifications, the approach breadcrumb trails, the endorsements and the climbing gym you sign up to. You can withdraw it whenever you like, without explaining yourself, from the same settings where you switched it on, or by writing to us. Withdrawing it is as easy as giving it. Whatever we had processed before you withdraw it remains lawful, but from that moment on we stop processing it.

Right to object

You can object, on grounds relating to your particular situation, to the processing we carry out on the basis of legitimate interest: the moderation and safety of the service, and the audience measurement on the website. If you object, we will stop unless we have compelling grounds that override yours or we need it to defend legal claims. Write to us at privacidad@cordada.eu.

9. Minimum age

Cordada requires you to be at least 14, the digital age of consent in Spain (art. 7 of LO 3/2018, the Spanish data protection act). We do not knowingly create accounts for under-14s; if we spot one, we will delete it. If you are a parent or guardian and believe a child under 14 has created an account, write to us.

10. Security

11. Changes to this policy

If we change this policy substantially (new processing, new providers), we will announce it inside the app before the change takes effect and we will update the version date on this page. The version in force will always be published at this URL.

12. Contact

Pawel Kadziolka — privacidad@cordada.eu

If you write to hola@cordada.eu or through any other channel, your request is handled just the same and the clock starts the moment we receive it.

13. The cordada.eu website

The sections above are about the app. This one is about this website, which handles far less data and deserves an explanation of its own.

There are no cookies. None.

cordada.eu does not install cookies, does not use your browser’s local storage, and does not use persistent identifiers of any kind. There is nothing to store on your machine and nothing to delete afterwards. That is why you will not see a cookie banner: asking your permission for something we do not do would be theatre.

What we handle when you visit the website

WhatWhat forWho receives itLegal basis (GDPR)
Audience measurement — page viewed, page you came from, browser type, country and IP address. Knowing how many people come in and which pages are any use. These are aggregate figures: we do not build profiles, we do not follow you between sessions or across websites, and we cannot recognise you on a later visit. Cloudflare Web Analytics, as processor. Legitimate interest (art. 6.1.f): understanding how our own site is used. You can object (section 8).
Hosting — the IP address and the technical data of each request end up in the server logs. Serving the page, protecting it from attacks and diagnosing faults. This includes the automatic network error reports the browser sends. Cloudflare, as processor. Legitimate interest (art. 6.1.f): security and operation.

And that is that: there are no forms, we do not collect email addresses, there are no adverts, there are no social buttons tracking you. The links to Instagram and the App Store are ordinary links and do nothing until you tap them. The catalogue figures you see on the home page are written into the page, they are not queried live.

The climbing gym directory

The listings at cordada.eu/rocodromos gather the name and the address of climbing facilities from public OpenStreetMap data and contributions from the community, not supplied by each gym. In some cases a small gym may be one person’s own business, and then that data is their personal data: we publish it on the basis of legitimate interest (art. 6.1.f) in keeping a useful directory of where you can climb. If it is your gym and you want to correct the listing or have us take it down, write to us at hola@cordada.eu and we will do it.

Transfers

Cloudflare is a US company with a global network: it is certified under the EU-U.S. Data Privacy Framework and we have standard contractual clauses signed with it. You can ask us for a copy as explained in section 6.