Last updated 31 August 2026
Privacy policy
Comp Setter is a climbing-competition setting app published by Comp Setter. This page describes exactly what the app collects, why, and how you can get it back or erase it.
01What we collect
Three categories, and nothing else.
Your account
- Your email address. Required — it is the account identifier. Comp Setter uses no passwords: you receive a six-digit code each time you sign in. No password is ever created, transmitted or stored.
- Sign-in codes are stored hashed, never in clear text, and the database deletes them automatically 10 minutes after they are issued.
- A display name, optional, that you choose. Other members of the competitions you join can see it.
What you create in the app
Competitions and everything in them: name, dates, gym, federation, wall and zone plans, boulders and their positions, hold colours, grades, styles, setting states, notes, plus the member list and their roles. The people you invite to a competition can see this, according to their role.
Boulder photos are optional. If you add one it is uploaded to our server and attached to that boulder. Do not photograph identifiable people without their consent.
Crash reports
When the app crashes, a report goes to Firebase Crashlytics (Google): the stack trace, the device model, the OS and app version, and an installation identifier generated by the SDK. The report contains neither your email nor the contents of your competitions.
Comp Setter contains no analytics tooling, no advertising trackers and no ad networks. We do not sell or rent your data, to anyone, ever.
02Why we process it
- Your email and the codes — to sign you in and secure access to your account. Legal basis: performance of our contract with you (GDPR article 6(1)(b)).
- Your competition content — this is what the app is for. Legal basis: performance of the contract.
- Crash reports — to fix bugs. Legal basis: our legitimate interest in shipping an app that works (article 6(1)(f)). You can object by writing to us.
03Who we share it with
Three technical providers, each for a single task. None is permitted to use your data for its own purposes. Each is bound by a processing agreement requiring it to protect your data to a standard at least equal to the one described in this policy.
- Resend — sends the email containing your sign-in code. Receives your email address and the code.
- Google (Firebase Crashlytics) — receives the crash reports described above.
- Our hosting provider — hosts the database and the photos, on servers located in the European Union (Strasbourg, France).
Beyond that, your data goes to nobody, except where we are under a legal obligation we cannot refuse.
Transfers outside the European Union
The database and the photos never leave France. Two of the providers above are, however, established in the United States: Resend, which receives your email address and your sign-in code, and Google, which receives the crash reports. Those transfers are covered by the EU-US Data Privacy Framework, under which both companies are certified.
04How long we keep it
- Account and competitions — for as long as your account exists. See the deletion page.
- Sign-in codes — deleted automatically 10 minutes after they are issued.
- Backups — we keep 14 days of rolling backups. Deleted data can therefore persist in a backup for up to 14 days before it is gone for good.
- Crash reports — retained by Google under Crashlytics’ own retention policy (roughly 90 days).
05Your rights
The GDPR gives you rights of access, rectification, erasure, portability, restriction, and objection to processing. To exercise one, write to comp.setter.app@gmail.com from your account’s email address. We respond within 30 days.
If our answer does not satisfy you, you can lodge a complaint with your national data protection authority — in France, the CNIL at cnil.fr.
06Security
All traffic between the app and our servers goes over HTTPS or WSS. Sign-in codes are hashed. Database access is restricted to the application server.
No system is perfectly secure. In the event of a breach likely to create a risk to your rights, we will notify you and the supervisory authority within the deadlines the GDPR sets.
07Children
Comp Setter is a tool for route setters and organisers. It is not designed for minors under 15 — the age of digital consent in France — and we do not knowingly collect their data. If you believe that has happened, write to us and we will delete the account.
08Changes
If this policy changes substantively, the date at the top of the page is updated and we flag it in the app. Continuing to use Comp Setter after a change means you accept the version then in force.
09Contact us
The data controller is Florian Do, publisher of Comp Setter, established in France. For any question about this policy or about your data:
comp.setter.app@gmail.com — or on our Discord.