Privacy Policy
Last updated: September 16, 2026
BoulderBuilder stores your climbing history on your device. Pro status goes to RevenueCat and Apple, and ad measurement may go to Meta if you allow tracking. This policy explains those separate uses.
Climbing Data
Your sends, grades, attempts, styles, gyms, notes, goals, sessions, and pyramids stay on this device. We do not operate a backend for climbing data or send your climbing history to RevenueCat or Meta.
Account
- You can use the App as a Guest without signing in with Apple.
- If you choose Sign in with Apple, Apple handles authentication. The App stores your sign-in identifier, any shared display name, and any shared email address locally in the iOS Keychain. The email address is used only to prefill the optional reply address when you request a feature; it is never sent anywhere by the App.
- Your Apple-provided app user identifier is also sent to RevenueCat to associate your Pro subscription with your sign-in. Guests use a RevenueCat-generated anonymous identifier. Signing in does not upload or sync climbing history.
- We do not send your name or email address to Meta, or set them as RevenueCat customer attributes.
- You can delete your account and data at any time from Settings; see Account and Data Deletion.
Subscriptions
Apple processes purchases of BoulderBuilder Pro. RevenueCat receives subscription and transaction information, purchase history, and an app user identifier to validate purchases, provide and restore Pro access, and report subscription performance. The App does not receive your card details or billing address.
RevenueCat also receives device and attribution information such as the vendor identifier, IP address, tracking-consent status, and Meta anonymous identifier. The advertising identifier is available only when iOS tracking permission allows it. These identifiers do not contain your climbing history.
Optional Ad Measurement
We use Meta (Facebook) to measure whether ads lead to BoulderBuilder Pro. If you allow tracking, Meta may receive app activation and subscription events, app and device information, and identifiers used to match those events to ads. RevenueCat may send subscription events to Meta for this purpose. We do not send Meta custom events about climbs, sends, grades, gyms, sessions, styles, or pyramids.
The App asks for tracking permission after the first-run experience. You can decline and continue using the App, purchase Pro, or restore purchases. You can change your choice in iOS Settings > Privacy & Security > Tracking. When tracking is not allowed, we do not authorize cross-app advertising tracking or RevenueCat's subscription-event delivery to Meta. Meta's SDK may still process limited app or device information under its platform privacy controls.
More information is available in the RevenueCat Privacy Policy, Meta Privacy Policy, and Apple Privacy Policy.
Optional Features
- Face ID / Touch ID: Used as a local app lock. The App never receives your biometric templates.
- Profile photo: A photo you select is stored on your device.
- Climb photos (Pro): You can attach one photo to a climb from your camera or photo library. Photos are downscaled and stored only in the App's storage on your device. They are never uploaded, synced, or shared. You can remove a photo without deleting the climb; deleting a climb, its gym, or your account removes the photo.
- Share cards (Pro): You can turn a climb or a period of progress into a simple image card. The card is drawn on your device and handed to the iOS share sheet; you choose where it goes, and the App never posts it or sends it to us. Your gym's name is left off the card unless you turn on "Include gym name".
- Weekly target (Pro): The number of pyramid slots you aim to fill each week is a preference stored only on your device; progress toward it is computed from your local climbing log.
- Weekly check-in (Pro): If you turn on the weekly check-in, the App schedules one local notification on your device every Sunday at 6:00 PM. Notifications are scheduled by iOS on the device; there is no server or push notification service, and nothing about your climbing is sent anywhere. Turning the setting off or letting Pro lapse cancels the scheduled notification.
- Feature requests: Settings > Support > Request a Feature opens a draft email in your mail app addressed to us. The draft contains only the text you typed, an optional reply address you choose to include, the App version, and your iOS version. It does not include any climbing data, and nothing is sent unless you send the email yourself.
- Gym search: Text you enter for gym suggestions is sent to Apple Maps. This does not request your device's location or upload your saved gyms or climbing history.
- Apple Health (Pro): If you turn on Health sync, the App saves each climb you log as a climbing workout in Apple Health on your device and reads your most recent body weight from Health to estimate calories. Health data stays in Apple Health under your control; we never receive it and never send it to RevenueCat, Meta, or anyone else. You can turn sync off in Settings or revoke access in the Health app at any time.
Account and Data Deletion
Open Settings > Account > Delete Account & Data in the App and confirm. Deletion is immediate and works for Sign in with Apple and Guest accounts. The App will:
- Delete your RevenueCat customer record, including the purchase history, entitlements, identifiers, and attribution attributes RevenueCat holds for your app user identifier. The App sends only your app user identifier to a deletion service we operate, which asks RevenueCat to erase the record. If that request fails, nothing is deleted and you can try again.
- Remove everything stored on this device: your climbing log, climb photos, goals, sessions, gyms, profile photo, weekly check-in preference and scheduled notification, weekly target preference, app-lock preference, and the saved sign-in identifier, display name, and email address in the Keychain.
- Sign the App out of RevenueCat. If you keep using the App, RevenueCat assigns a new anonymous identifier with no history.
Some information is outside the App's control and is not deleted by this action:
- Your Apple subscription and App Store transactions. Billing is between you and Apple. Deleting your account does not cancel a subscription; manage or cancel it in Apple Account settings or at apps.apple.com/account/subscriptions. Restoring purchases later re-links your Apple receipt to a new record.
- Sign in with Apple authorization. The App has no server and holds no Apple tokens to revoke. To stop sharing your Apple Account with BoulderBuilder, open Settings > your name > Sign in with Apple > BoulderBuilder > Stop Using. The App detects revocation and signs you out.
- Ad-measurement events already delivered to Meta (only if you allowed tracking). These are governed by Meta's privacy policy and controls; see the Meta Privacy Center. This page also serves as the data-deletion instructions for the Meta integration.
- Aggregated statistics that are not tied to your identifier, and records a provider must keep to meet legal obligations.
If you can no longer open the App, email support.boulderbuilder@gmail.com and we will delete your RevenueCat record within 30 days. We do not hold your name or email on any server, so include any details that help us locate the record, such as the approximate purchase date and Apple order information.
Contact
Questions about this policy or privacy requests can be sent to support.boulderbuilder@gmail.com.