Privacy Policy
CompSesh ("we," "us," or "our") is a climbing session logging and social application. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use CompSesh (the "App"). We are committed to transparency and to protecting your privacy.
We do not sell your personal information. We do not display ads. We do not use third-party analytics SDKs. We do not engage in cross-context behavioral advertising or cross-app tracking.
1. Who We Are
CompSesh is the data controller responsible for your personal information. If you have questions about this policy or your data, contact us at:
CompSesh
Email: [email protected]
We have not appointed a Data Protection Officer as we do not currently meet the thresholds requiring one under GDPR Article 37. For all data protection inquiries, contact [email protected]. For purposes of Brazil's LGPD, this contact also serves as our designated Encarregado. For purposes of South Korea's PIPA, this contact serves as our Chief Privacy Officer. For purposes of South Africa's POPIA, this contact serves as our Information Officer.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address — for authentication, account recovery, and service communications. If you use Apple Sign-In with the "Hide My Email" feature, we receive and treat your Apple relay address (@privaterelay.appleid.com) identically to a standard email address. If you use Google Sign-In, we receive the email address associated with your Google account.
- Display name — shown to other users on your profile and during sessions.
- Profile photo (optional) — displayed on your profile and in social features. If you use Google Sign-In, your Google profile photo may be imported as your initial profile photo.
- Password (email/password users only) — stored as a bcrypt hash. We never store or have access to your plaintext password.
- Apple Sign-In identifier (Apple Sign-In users only) — a unique, app-scoped token provided by Apple.
- Google Sign-In identifier (Google Sign-In users only) — a unique identifier provided by Google through the OAuth authentication flow. We do not receive or store your Google password.
2.2 Climbing Performance Data
When you log sessions and climbs, we collect:
- Session timestamps (start and end times)
- Gym associations (which gym you climbed at)
- Boulder and route information (grades, names, identifiers)
- Attempt counts and send status (flash, send, attempts)
- Scores and performance metrics calculated from your climbing activity
- Skill ratings and progression data, including the rating estimate you give during onboarding
- Your rating division (Beginner, Intermediate, Advanced, or Elite), which we derive from your Skill Index
- When you last logged a boulder in a session that is in progress, which we use to remind you about, and end, sessions left running (see Section 3)
2.3 Photos and Videos
When you upload photos or videos of boulders, routes, or climbing sessions, we collect:
- The media files themselves — photos (JPEG) and videos (MP4) uploaded through the App, stored in our cloud infrastructure (Supabase Storage on AWS).
- File metadata — file size, format, dimensions, and upload timestamp.
- EXIF and embedded metadata — photos and videos taken by phones and cameras often contain hidden metadata including GPS coordinates, device make and model, camera settings, and timestamps. Uploaded photos and videos are re-encoded (compressed and resized) on your device before upload, which removes embedded EXIF metadata including GPS coordinates from the stored media. We may retain non-identifying technical metadata (such as image dimensions) for display purposes.
Profile photos are similarly compressed and re-encoded on upload, removing EXIF metadata. Crew and league photos are resized to at most 512 pixels and re-encoded as JPEG on your device before upload, and the group's colors are picked from its photo on your device.
Important: While the re-encoding process removes EXIF data from the version stored on our servers, the original file on your device is not modified. If you share photos outside CompSesh, those files may still contain location data.
Access to stored files. Photos and videos of boulders and sessions, profile photos, and crew and league photos are served from web addresses (URLs) that anyone who has the address can open without signing in. We do not publish or list these addresses, but if someone copies and shares one, people outside CompSesh can view that file.
2.4 Social and Multiplayer Data
When you use social features, we collect:
- Follow and follower relationships
- Community feed activity and interactions, including reactions to session posts and to crew and league challenges
- Multiplayer session participation, including real-time climbing data visible to session participants
- Session invitations sent and received
- Live session data — while a session is in progress, the boulders you log, your running score, and any photos and videos you attach, which we show to the people who can watch it live (see Section 5.1)
- Comments and replies you post on session posts and on crew and league challenges — the comment text, what it was posted on, the timestamp, and the account that posted it
- Likes you give to comments
- Live chat messages you send in a session's chat — the message text, the session, the timestamp, and the account that sent it
- Your sharing and notification settings, such as "Share live sessions" and which notifications you receive
2.5 Crews, Leagues, and Challenges
When you create, join, or take part in a crew or league, we collect:
- Crew and league details that you or other members with editing rights provide — name, description, photo, colors, gyms, rating divisions, and whether a league is public or private.
- Time zone — when you create a crew or league, we store your device's time zone setting (for example, "America/New_York") as the group's time zone. It sets when weekly challenges start and end and when challenge reminders are sent. We do not use it to determine your location.
- Membership — your role (owner, admin, or member), when you joined, and when you last opened the group's page (used to show which groups have new activity).
- Invites and join requests you send, receive, approve, or decline.
- Challenge entries and results — for each challenge you enter, a snapshot of your Skill Index, rating division, and handicap multiplier taken when the challenge starts (or when you join it), your standings, and your final rank and totals.
- Trophies and challenge points you earn. A trophy keeps a copy of the crew or league name and the challenge name, so it still makes sense if the group is later renamed or deleted.
2.6 Information About Guests
When you add a guest (someone climbing in your multiplayer match who does not have a CompSesh account), you provide their name (2–30 characters) and an estimate of their climbing level, and you log their boulders (grade, attempts, and score) for them. We store this with the match. Please add someone as a guest only with their permission, and consider using a first name or nickname. A guest can ask us to remove their information by emailing [email protected].
2.7 User-Created Gym Data
When you submit gym information, we collect:
- Gym name, city, state or region, and country
- Geographic coordinates (latitude and longitude of the gym)
- Any additional gym details you provide
This data is factual information about businesses and is treated as a community resource.
2.8 Push Notification Tokens and In-App Notifications
If you enable push notifications, your device provides a push notification token. This token is used solely to deliver notifications about session invitations, social activity (comments, replies, reactions, and new followers), crew and league invites and join requests, challenges, session reminders, and service updates. With the token we store your App's build number and the notification types your version of the App supports. A token belongs to one account at a time: if a different account signs in on the same device, the token moves to that account, and signing out turns it off.
We also keep a list of your recent in-app notifications (comments, replies, reactions, and new followers) so they can be shown in the App.
2.9 Subscription Data
If you subscribe to CompSesh Pro, subscription purchases are processed entirely by Apple through the App Store. We do not collect or store your payment information (credit card numbers, billing address, etc.).
When you buy a subscription, the App attaches your CompSesh account identifier to the purchase (Apple calls this an "app account token") so that Apple's records of the purchase can be matched to your account. The App sends us Apple's signed record of your current subscription, and Apple's servers notify us when your subscription renews, has a billing problem, expires, or is refunded. From these we receive and store:
- Subscription status — whether your subscription is active, in a billing retry period, expired, or refunded (used to enable Pro features).
- Plan and expiration — which subscription product you have and when the current period ends.
- Transaction identifiers — Apple's original transaction ID for your subscription, used to verify the purchase and match later notifications to it.
- Environment — whether the purchase was made in Apple's live App Store or its test (sandbox) environment.
We do not store the full records Apple sends us. Whether you have Pro is visible to other signed-in users who view your profile (see Section 5.1).
2.10 Technical and Usage Data
We collect limited technical data necessary to operate the service:
- IP addresses — recorded in connection with account creation, agreement acceptance, and authentication events. IP addresses in authentication logs are retained for 90 days.
- Authentication logs (login timestamps, authentication method) — retained for 90 days for security purposes
- Error logs and crash data generated by the App — used to diagnose and fix bugs
- App version, build number, and iOS version — used to ensure compatibility and to send each version of the App only the features and notifications it supports
We limit the collection of personal information to what is necessary for the purposes identified in this policy. We do not collect device advertising identifiers, IP-based geolocation for profiling, browsing history, or any data from other apps on your device.
2.11 Locally Cached Data
The App caches certain data on your device for performance and offline access, including your profile information, recent session data, gym information, downloaded media, and which chat messages you have read. This data remains on your device and is cleared upon account deletion or app removal.
3. How We Use Your Information
We use your information for the following purposes:
To provide and operate the App — authenticating your identity, logging climbing sessions, calculating performance metrics, displaying your profile and activity, enabling multiplayer sessions, showing your live sessions to the people who can watch them, running crews, leagues, and challenges, delivering live chat messages, showing your comments and replies to users who can view what they are posted on, verifying your subscription, and delivering push notifications.
To end sessions left running — a session that is left open keeps counting time. If an untimed session goes an hour with no boulder logged, we may send you a reminder. If you were reminded and log nothing more within two hours of your last boulder, we end the session and save it as of your last boulder. Any solo session that goes eight hours with no boulder logged, and any multiplayer match still open eight hours after it started, is ended the same way. A session with no boulders is discarded rather than saved.
To maintain and improve the service — diagnosing technical issues, fixing bugs, and improving App functionality based on aggregated, non-identifying usage patterns.
To communicate with you — sending service-related emails such as account verification, password reset, material changes to this policy or our Terms of Service, and responding to your support requests.
To help you get the most out of CompSesh — sending a short series of emails while you get started (for example, how to log your first session, how multiplayer sessions and Balanced mode work, and how to start a crew or a challenge), a monthly recap of your climbing, and a few reminders if you stop logging sessions for a while (at most three per break). These emails use your first name, your email address, your time zone, and information about your activity in the App, such as how many sessions and sends you logged, your hardest send, your rating division, your multiplayer results, and activity in your crews, so that each email is relevant and is only sent when it applies to you. Every one of these emails has an unsubscribe link, and onboarding tips and monthly recaps can be unsubscribed from separately. Unsubscribing does not stop the service-related emails described above. So that we can tell whether these emails are useful, a randomly chosen group of users does not receive some of them.
To enforce our terms and protect users — moderating user-generated content (including photos, videos, comments, chat messages, crew and league names, descriptions, and photos, and gym data), investigating reports of abuse or policy violations, and taking action against accounts that violate our Terms of Service or Community Guidelines.
To comply with legal obligations — responding to lawful requests from authorities, complying with applicable laws, and protecting our legal rights.
We use automated calculations to generate climbing performance scores, Skill Index ratings, rating divisions, handicap multipliers, challenge standings and results, and leaderboard rankings based on your logged climbing data. Your Skill Index places you in a rating division, and a league or challenge can be limited to certain divisions, so your rating can determine which leagues you can join and which challenges you can enter. Handicaps adjust challenge and match scores based on each climber's rating. These calculations are part of the App's recreational competition features. They do not produce legal effects or similarly significant effects concerning you, and they do not affect your access to your account or to the App's other features.
We do not use your personal information for advertising, profiling, automated decision-making that produces legal effects, or any purpose not described in this policy.
Necessity of data provision. Providing your account information (email address, display name) is a contractual requirement necessary to use the Service. If you do not provide this information, you cannot create an account or use the App. Providing climbing data, photos, videos, comments, chat messages, crew and league details, guest information, and gym data is voluntary but necessary to use the corresponding features.
4. Legal Bases for Processing (EU/EEA, UK, and Similar Jurisdictions)
Where applicable law requires a legal basis for processing your personal data, we rely on the following:
Contractual necessity (GDPR Article 6(1)(b)) — Processing your account information, climbing data, social data, session and live session data, crew, league, and challenge data, comments, chat messages, subscription data, and photos/videos is necessary to provide you the service you signed up for.
Consent (GDPR Article 6(1)(a)) — Push notification delivery requires your affirmative consent, obtained through the iOS system permission prompt. You may withdraw consent at any time through your device settings. We also obtain your consent before processing any data that falls outside the scope of contractual necessity.
Legitimate interest (GDPR Article 6(1)(f)) — User-created gym data (factual information about businesses) is processed under legitimate interest, as it is voluntarily submitted, has minimal privacy impact, and supports the shared gym directory that benefits all users. We have conducted a Legitimate Interest Assessment for this processing. Security logging and fraud prevention are also processed under legitimate interest.
We also rely on legitimate interest to process information about guests, which a match host provides about people who do not have an account, so that groups can include friends who don't use CompSesh in their matches. We keep it minimal (a name, an estimated level, and the boulders logged for them), and a guest can ask us to remove it. Keeping reported content for moderation, and ending sessions left running so that forgotten sessions don't distort scores, challenges, and leaderboards, are also processed under legitimate interest.
Legitimate interest (GDPR Article 6(1)(f)) — Sending you onboarding tips, monthly recaps, and reminders about the App you signed up for is processed under legitimate interest (and, where the ePrivacy rules apply, the exemption for messages about our own service to existing users). You can object at any time by using the unsubscribe link in any of these emails or by contacting us, and we will stop.
Legal obligation (GDPR Article 6(1)(c)) — We process certain data to comply with applicable laws, including responding to lawful data access requests and maintaining records required by law.
5. How We Share Your Information
5.1 With Other Users
Certain information is visible to other CompSesh users by design. "Signed-in users" means anyone with a CompSesh account.
- Your display name and profile photo
- Whether you have CompSesh Pro (visible on your profile to signed-in users, including if your account is private)
- How many followers you have and how many accounts you follow (visible on your profile to signed-in users, including if your account is private). The lists themselves are visible to signed-in users if your account is public, or only to your approved followers if it is private. If you follow a public account, you appear in its list of followers.
- Your climbing scores and activity on community feeds
- Your display name, profile photo, and best session scores on gym leaderboards (visible to signed-in users, including if your account is private)
- Your real-time climbing data during multiplayer sessions (visible to session participants). Every climber in a match can see every climber's and guest's sends.
- Live sessions — while a session is in progress, your followers can watch it live: the gym, when you started, your score, each boulder you log (grade, attempts, and score), and any photos or videos you attach. In a multiplayer match, anyone who follows any climber in the match can watch it, including your boulders, score, and media, unless your account is private and they don't follow you. Climbers who leave a match early stay visible to people watching it until it ends. You can turn this off with "Share live sessions" in Settings.
- Live chat — messages you send in a session's chat, with your display name and profile photo, are visible to the climbers in that session and to everyone who can watch it live, who can also post. In a multiplayer match this includes followers of the other climbers, even if your account is private.
- Crews and leagues — members of a crew or league you belong to can see your role, your rating division (in leagues), and your standings and results in its challenges, including your handicap multiplier and the sessions that counted (with their date, gym, and score, linking to your session posts). They can also see the group's rankings, which use all of your sessions (only those at the group's gyms, if it is limited to certain gyms), including sessions from before you joined. This applies even if your account is private. The final results of a challenge stay visible to the group's members if you leave.
- Crew and league details — a public league's name, photo, gyms, divisions, and member count are visible to signed-in users in Browse and Search. Anyone signed in who has a link to a crew or league, public or private, can see its name, description, photo, gyms, and member count in the join preview.
- Trophies — trophies you earn appear on your profile to anyone who can view your profile. For a private crew or league, people who are not members see "A private crew" or "A private league" instead of the group's and challenge's names, and only the day the trophy was awarded.
- Gym data you submit (visible to all users as part of the shared gym directory)
- Photos and videos you upload of boulders and routes (visible to users viewing those boulders/routes, and to the people who can watch your session live)
- Comments and replies you post, and the comments you like. On a session post, they are visible to anyone who can view the post — if your account is private, that means your approved followers. On a crew or league challenge, they are visible to the current members of that crew or league.
- Guest information you add to a match (visible to the match's climbers, to people watching it live, and to anyone who can view the completed match)
Share links and link previews. When you or another user shares a link to a session, a match, a profile, or a gym, anyone who opens it can see a summary on our website, whether or not they have a CompSesh account, and the summary appears in link previews (for example, in messaging apps). A session link shows the climber's display name, the gym and its city, the score, the number of boulders, the average grade, and the duration. A match link shows the gym, the winner's display name and score, and the number of climbers. A profile link shows the display name, profile photo, Skill Index, high score, average grade, total sends, session count, and follower count. If your account is private, links to your profile and your sessions show only a generic page, and a match link leaves out your name and score if you won. These pages are not listed in our sitemap, but a search engine may find and index one if a link is posted publicly. Links to crews and leagues open a generic page that shows nothing about the group.
5.2 With Service Providers (Data Processors)
We share your data with the following service providers, who process it solely on our behalf and under contractual obligations to protect your data:
- Supabase, Inc. — Backend infrastructure (database, authentication, file storage, real-time functionality). Data is stored on AWS infrastructure. Supabase acts as a data processor under a signed Data Processing Agreement covering GDPR, UK GDPR, Swiss law, and US state privacy laws. Supabase's sub-processors include AWS, Fly.io, Cloudflare, and Google Cloud/BigQuery (for logging).
- Cloudflare — Content delivery network and application hosting.
- Resend — Email delivery (account emails, onboarding tips, monthly recaps, and reminders), integrated via Supabase Edge Functions. Resend receives your email address and the content of each email, which can include your first name and climbing statistics.
- Novu — Push notification delivery service. To deliver a notification, Novu receives your device's push token, an internal identifier for your account, and the notification's content, which can include another user's display name, a crew, league, or challenge name, and the first 150 characters of a comment or reply. Novu passes notifications to Apple Push Notification service, which delivers them to your device.
- Apple Inc. — Authentication (Apple Sign-In), in-app subscription purchases via the App Store, notifications about your subscription's status (App Store Server Notifications), and delivery of push notifications (Apple Push Notification service).
- Google LLC — Authentication (Google Sign-In). When you use "Continue with Google," Google processes your authentication and shares your email address, display name, and profile photo with us via the OAuth protocol. Google's use of your data is governed by Google's Privacy Policy.
All processors are bound by data processing agreements that include standard data protection commitments.
5.3 With Authorities
We may disclose your information if required by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
5.4 In Business Transfers
If CompSesh is involved in a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you via email or prominent in-app notice before your information becomes subject to a different privacy policy.
5.5 What We Never Do
We do not sell or share your personal information with third parties for advertising, marketing, or profiling purposes. We do not provide data to data brokers. We do not engage in cross-context behavioral advertising. This applies globally, without exception.
6. International Data Transfers
CompSesh's infrastructure is hosted on AWS, which may process your data in the United States or other regions. If you are located outside the United States, your data will be transferred internationally.
For transfers of personal data from the EU/EEA, we rely on:
- Standard Contractual Clauses (SCCs) — included in our Data Processing Agreements with Supabase, Resend, and Novu, which cover transfers to the US and other third countries.
- EU-US Data Privacy Framework (DPF) — where applicable and to the extent our processors are certified (including Cloudflare, Apple, and Google, which are DPF-certified).
For transfers from the United Kingdom, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, in addition to the UK Extension to the EU-US Data Privacy Framework where applicable.
For transfers from all other jurisdictions, we ensure adequate safeguards are in place through contractual commitments with our service providers that meet the requirements of applicable local law.
7. Data Retention
We retain your data for the following periods:
- Account and climbing performance data — retained for the duration of your account plus 30 days after a deletion request is processed, to allow for completion of the deletion process.
- Photos and videos — retained for the duration of your account. Deleted when you remove them individually or when your account is deleted.
- Social and multiplayer data — follow relationships, feed activity, and session participation data (other than comments and chat messages, which are covered below) are retained for the duration of your account and deleted upon account deletion.
- Live session data — shown live only while the session is in progress. The boulders, photos, and videos you log become part of your saved session. The record of when you last logged a boulder is deleted when the session ends.
- Comments, replies, and comment likes — retained until you delete the comment, until it is removed by someone allowed to remove it (the owner of the session post, the creator of the multiplayer match, or, on a challenge, a member of the crew or the league's owner or admins), or until we remove it through moderation. A deleted comment is hidden from everyone right away; we may keep its text, visible only to us, for moderation and abuse prevention. Challenge comments are deleted when the challenge, or its crew or league, is deleted. Upon account deletion, the text of your comments is replaced with "[deleted]" and the surrounding thread is preserved so that other users' replies keep their context.
- Live chat messages — deleted when the session ends. Messages that have been reported are kept, separately from the session, for moderation, and are deleted 180 days after the most recent report or when the author's account is deleted, whichever comes first.
- Crews and leagues — your memberships, the invites you received, and your join requests are deleted when you leave or delete your account. A crew's or league's details (name, description, photo, and colors) belong to the group and stay with it while it has members, even if the person who added them leaves or deletes their account. A crew or league, its challenges, and its photo are deleted when its owner deletes it or its last member leaves. If an owner deletes their account, ownership passes to the longest-standing admin, or otherwise the longest-standing member.
- Challenge results, trophies, and challenge points — a challenge's final results are kept as part of the group's history and stay visible to its members if you leave. Your challenge entries, results, trophies, and challenge points are deleted when you delete your account. Some internal records, such as which climber was leading a challenge, may keep your account identifier, which no longer links to any profile once your account is deleted.
- Guest information — kept as part of the match's record, including after the host deletes the session, until the host deletes their account or the guest asks us to remove it.
- Subscription data — subscription status, plan, expiration, and transaction identifiers are retained for the duration of your account. Upon account deletion, subscription data is deleted from our systems (Apple retains its own transaction records per Apple's privacy policy). If Apple later notifies us about the same subscription (for example, a renewal of a subscription that was not cancelled), we store its status without any link to an account.
- Push notification tokens — retained until you revoke notification permission, sign out, or delete your account.
- Email preferences and send history — which of these emails you are subscribed to, and a record of which emails we sent you and when (so that no email is sent twice), are retained for the duration of your account and deleted when your account is deleted.
- In-app notifications — deleted after 90 days.
- User-created gym data — retained indefinitely as a community resource. Upon account deletion, your gym contributions are anonymized (disassociated from your identity) but the factual gym data persists.
- Authentication and security logs — retained for 90 days, then permanently deleted.
- Encrypted backups — deleted data may persist in encrypted backups for a limited retention period determined by our infrastructure provider's backup schedule, after which it is permanently overwritten.
8. Your Privacy Rights
8.1 Rights Available to All Users
Regardless of your location, you have the right to:
- Access your personal data — request a copy of the data we hold about you.
- Correct inaccurate data — update or fix errors in your information.
- Delete your account and personal data — request complete deletion of your account and associated data.
- Export your data — receive your data in a structured, machine-readable format (JSON).
- Unsubscribe from onboarding tips, monthly recaps, and reminders — use the unsubscribe link in any of these emails, or contact us.
To exercise any of these rights, contact us at [email protected] or use the account management features within the App (Settings > Export My Data for a copy of your data, and Settings > Account > Delete Account for deletion).
8.2 Additional Rights for EU/EEA and UK Residents
Under the General Data Protection Regulation (GDPR) and UK GDPR, you additionally have the right to:
- Data portability — receive your personal data in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted directly to another controller.
- Restrict processing — request that we limit how we use your data in certain circumstances.
- Object to processing — object to processing based on legitimate interest.
- Not be subject to automated decision-making — not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
- Withdraw consent — where we process data based on consent, withdraw that consent at any time without affecting the lawfulness of prior processing.
- Lodge a complaint — file a complaint with your local data protection supervisory authority. A list of EU data protection authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. In the UK, contact the Information Commissioner's Office (ICO) at https://ico.org.uk.
We will respond to rights requests within 30 days (extendable by 60 days for complex requests, with notice).
8.3 Additional Rights for California Residents
Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), you have the right to:
- Know what personal information we collect and how it is used.
- Delete your personal information.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information — CompSesh does not sell or share personal information as defined by the CCPA/CPRA.
- Non-discrimination — we will not discriminate against you for exercising your privacy rights.
California residents may also designate an authorized agent to submit requests on their behalf.
We do not collect sensitive personal information as defined by the CPRA, with the exception of account login credentials, which are used solely for authentication purposes. CompSesh Pro subscription pricing is based on access to additional features, not on the collection, retention, or sale of your personal information. We do not offer financial incentives in exchange for personal information.
8.4 Additional Rights for Residents of Other US States
Residents of Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Indiana, Iowa, Tennessee, Delaware, New Hampshire, New Jersey, Nebraska, Maryland, Minnesota, Kentucky, Rhode Island, and other states with comprehensive privacy laws have rights that may include access, correction, deletion, data portability, and the right to opt out of the sale of personal data, targeted advertising, and certain profiling. Where your state law provides a right to appeal our decision on a privacy request, you may appeal by contacting [email protected]. We will respond to appeals as required by your state's law.
CompSesh does not sell personal data, does not engage in targeted advertising, and does not profile users for decisions that produce legal or similarly significant effects, under any state's definition of those terms. We will respond to requests from US residents within 45 days, as required by applicable state law, extendable as permitted. If you are a Virginia resident and your appeal is denied, you may contact the Virginia Attorney General at https://www.oag.state.va.us/consumer-protection/index.php/file-a-complaint.
8.5 Rights for Residents of Other Jurisdictions
If you reside in a jurisdiction not listed above, we will honor your data protection rights as required by your local law. Contact [email protected] to exercise your rights. You may also contact your local data protection authority, including:
- Brazil: ANPD — https://www.gov.br/anpd
- Canada: OPC — https://www.priv.gc.ca
- Australia: OAIC — https://www.oaic.gov.au
- South Africa: Information Regulator — https://inforegulator.org.za
- Japan: PPC — https://www.ppc.go.jp
- South Korea: PIPC — https://www.pipc.go.kr
9. Children's Privacy
CompSesh is not directed at children. You must be at least 13 years old to create an account (or the minimum age required by your jurisdiction, if higher — for example, 16 in certain EU member states, 13 in the United Kingdom under the Data Protection Act 2018, 16 in Australia as required by the Online Safety Amendment (Social Media Minimum Age) Act 2024, and 14 in South Korea).
We do not knowingly collect personal information from children under the applicable minimum age. If we discover that we have collected data from a child under the applicable age, we will promptly delete that data and terminate the associated account.
We do not accept parental consent as a means to allow children under the applicable minimum age to use CompSesh. Users under the applicable minimum age are prohibited from using the Service. CompSesh does not have an age-gating mechanism beyond the user's self-certification at account creation.
If you believe a child under the applicable minimum age has created a CompSesh account, please contact us at [email protected].
10. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- All data transmitted between the App and our servers is encrypted using TLS (Transport Layer Security).
- Passwords are stored as bcrypt hashes and are never stored or transmitted in plaintext.
- Database access is controlled through Supabase Row Level Security (RLS) policies, ensuring users can only access data they are authorized to view.
- Our infrastructure provider (Supabase/AWS) maintains SOC 2 Type II compliance and ISO 27001 certification.
- GPS/location metadata is removed from uploaded photos and videos through the client-side re-encoding process before storage.
- Authentication tokens are stored securely on your device using the iOS Keychain.
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If we become aware of a security breach affecting your personal data, we will notify you and applicable authorities as required by law, including within 72 hours for EU/EEA authorities under GDPR.
11. Do Not Track and Global Privacy Control
We do not track users across third-party websites or apps. Because we do not engage in any cross-site or cross-app tracking, there is no tracking behavior to modify in response to Do Not Track browser signals.
We honor Global Privacy Control (GPC) signals where required by applicable law. Because CompSesh does not sell or share personal information for advertising purposes, GPC signals do not change our data practices, but we recognize and log them as valid opt-out requests.
12. Third-Party Links and Services
CompSesh may contain links to third-party websites or services (for example, gym websites). We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing them with your information.
Our website (compsesh.app) uses only strictly necessary cookies for site functionality. We do not use advertising, analytics, or tracking cookies on our website. The website loads fonts from Google Fonts, which may result in your IP address being transmitted to Google when you visit the website. The website also hosts the share pages and link previews described in Section 5.1.
12.1 Android Waitlist
If you enter your email address in the "Android is coming" form on our website, we store that address solely to send you a single notification when the CompSesh Android app becomes available. We do not add it to a marketing list, use it for any other purpose, or share it with third parties. The address is stored in our Supabase database alongside the date you submitted it. You can ask us to remove it at any time by emailing [email protected], and we delete the list after the launch notification has been sent.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. For material changes (changes to data collection practices, new third-party sharing, or changes to your rights), we will send you a notification describing the changes, by email, by a prominent in-app notice, or both.
Your continued use of the App after we send that notification constitutes your acceptance of the updated Privacy Policy. If you do not agree to the updated policy, you must stop using the App; you may delete your account at any time as described in Section 8.1.
Where applicable law requires your consent for a particular change, we will obtain that consent before the change applies to you.
For minor changes (formatting, clarification of existing practices, updated contact information), we will update the effective date and post the revised policy. Previous versions are archived at compsesh.app/privacy/archive.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:
Email: [email protected]
We aim to respond to all inquiries within 30 days.
This Privacy Policy was last updated on October 9, 2026.