DYNOCLUB← Back to the site

Privacy

Privacy policy

Last updated: 28 September 2026

Who we are

Dyno Club is operated by its developer, based in Budapest, Hungary. We are the data controller for the personal data described here. Write to us at official@dynoclub.app about anything on this page.

What we collect

To run your account: your email address, the display name you choose, a profile picture if you upload one, your date of birth, and optionally your gender and answers to a short climbing questionnaire. Both optional answers can be skipped and neither changes how the app works.

What you log: your climbs and their outcomes, the notes you attach, photos you take of climbs — a photo you attach to a climb is uploaded and shown to climbers at that gym, and when the app reads a tag off a photo to suggest a colour and grade, that reading happens on your phone, not on a server — the problems, gyms and set batches you add, your sessions, grade votes, beta you write, condition reports, and the crews, groups, events and challenges you create or take part in.

How you use the app: your language, your grade scale, your home gym, your visibility settings, and who you follow, block or report.

What we never collect

We do not collect your weight, and we do not collect your contacts.

Location works like this: nothing about your position is read until you tap Find gyms near me in the app, and iOS asks you first. When you do, your position is used once, for that one search. You can also search by typing the name of a town, and that always works without location.

Either search leaves your device, and you should know where it goes. The position or the town is sent to the public Overpass API at overpass-api.de, which answers with the climbing gyms mapped in OpenStreetMap around it; its servers are paid for and run by FOSSGIS e.V. in Germany. Like any request to any website, it carries your device’s IP address. We send nothing else with it — not your name, not your email address, not your account, and none of your climbs — and what comes back describes buildings rather than you. Your position never reaches our servers, is never stored, and is never shared with other climbers; the list of gyms that comes back is kept briefly on your device so a repeat search does not re-ask the map, filed under your position rounded to about a kilometre — that rounded area label is the only trace of where you searched, it stays on the device, and it never syncs. You can switch location off for Dyno Club in your device Settings at any time.

The app uses no third-party analytics or advertising trackers of any kind. This website uses none either: its only third-party script is the cookie-consent banner described in the next section.

The app records a small number of usage events on your device so it can behave sensibly. Those events never leave your phone: they are not synced, not uploaded, and not readable by us.

Cookies and this website

The app sets no cookies. This section is about dynoclub.app, the website you are reading.

The site loads one third-party script: Cookiebot, the consent banner, provided by Cybot A/S in Denmark — part of Usercentrics — as our processor. It is the only third party this site talks to.

Cookiebot stores your choice in a cookie called CookieConsent, so the banner does not ask again on every page. Cookiebot’s documented default is to keep that choice for 12 months and then ask afresh; some browsers shorten it on their own, in which case the banner returns sooner.

It also keeps a record of the consent on Cookiebot’s own servers, so that we can show it was given. That record holds what you chose and when, your browser’s user agent, and your IP address with the last part cut off so it no longer points at one device. Cookiebot keeps those records for a year.

We set no other cookies here and run no analytics on the site.

The pages a confirmation or password-reset link lands on do not load Cookiebot at all, and carry no third-party script of any kind. A consent dialogue thrown over a password form is a good way to get a reset abandoned, and there is nothing on those pages that consent would gate.

Why we process it, and on what basis

To provide the service you asked for, which is the legal basis of contract: your account, your logbook, syncing it between your devices, and the gym feeds and boards you take part in.

To keep the community safe, which is our legitimate interest: moderating reports, enforcing blocks, and acting on content that breaks our guidelines.

To meet legal obligations, including checking that you are old enough to hold an account.

Where we ask for something optional — your gender, the questionnaire, your profile picture — the basis is your consent, and you can withdraw it by removing the answer.

Where your data lives

On your device first, always. The app is built so that logging a climb never waits for a network.

With an account, a copy syncs to our servers in the European Union — Supabase, hosted in Frankfurt, Germany (eu-central-1). Your data is stored in the EU.

Our processor is Supabase Pte. Ltd, a Singapore company, and it uses sub-processors including Supabase, Inc. in the United States. Some of them can reach the data to run, support and secure the service, so a transfer outside the EEA can happen. Those transfers are covered by the European Commission’s Standard Contractual Clauses, built into Supabase’s data processing agreement. This website is hosted by Vercel Inc. in the United States, under the same kind of safeguard. Ask us at official@dynoclub.app and we will send you a copy of the safeguards.

Who can see what

Your logbook is visible to other climbers by default — unless you were under 18 when you signed up, in which case it starts private and only becomes visible if you choose to make it so. That is what makes a shared board and a gym feed work, and there is one switch in Settings that turns it off — a single setting covering your whole logbook, everywhere you climb, rather than one setting per gym. With it off, your climbs stop appearing on boards, in feeds and on your profile for everyone else, and our servers enforce that rather than your screen alone.

A note you attach to a climb is part of that climb’s record and travels with it, so climbers who can see the climb can see the note. It is not a private field and the app never describes it as one. If you would rather keep something to yourself, do not put it in a note.

Your display name and profile picture are visible to other climbers. Your email address, date of birth, gender and questionnaire answers are never shown to anyone else.

Problems, gyms and set batches you add are part of a shared catalogue and stay visible to everyone who climbs there.

A challenge you post at a climbing gym can be seen by other signed-in climbers, with your display name as its author and the number of climbers taking part — the app shows it to climbers at that gym. A challenge for a crew can be seen by anyone who can see that crew: every climber for a public crew, its members for a private one. When you join a challenge other climbers can see, they can also see that you have joined. Your progress in a challenge is worked out from your own logbook and shown only to you — nobody sees another climber’s count. A challenge you make just for yourself is visible only to you. Blocking hides posted challenges in both directions, like everything else.

Blocking someone hides each of you from the other everywhere, enforced on our servers rather than only on screen. Reports you file are visible to you and to us, never to the person reported.

How long we keep it

Your account data is kept for as long as you have an account. When you delete it we remove your personal data from our servers and delete your sign-in credentials.

A few things deliberately survive. Problems, gyms and set batches you added remain in the shared catalogue with your name removed, because deleting them would empty other climbers' logbooks at the same wall. A challenge or event you posted at a gym or for a crew stays for the climbers taking part in it, also with your name removed; challenges you made just for yourself are deleted with your account. Blocks are retained in both directions, and reports you filed are too. A block you were subject to protects the other climber and is not yours to revoke by leaving; a block you made stays for the same reason, from their side.

Because the app works offline, a copy of anything another climber already downloaded may remain on their device. We cannot reach into a phone to remove it, and we would rather say so than imply otherwise.

To keep your devices in step we hold a log of changes. Older superseded versions of a record are removed automatically after 30 days, so what we keep is the current version rather than every edit you have ever made. Backups are kept for the period our hosting provider retains them, and a deleted account can persist in a backup until that period passes.

Your rights

You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Export is built into the app, is free, and is never buried — you do not need to ask us for it.

You can delete your account from inside the app at any time.

If you think we have handled your data badly, please tell us at official@dynoclub.app. You also have the right to complain to your national data protection authority.

Age

The minimum age to hold an account depends on where you are, because the age of digital consent differs by country. It is 16 in Germany, the Netherlands, Poland, Croatia, Hungary, Slovakia, Romania, Luxembourg, Ireland and Australia; 15 in France, Czechia, Greece and Slovenia; 14 in Spain, Italy, Austria, Bulgaria, Cyprus and Lithuania; and 13 in most other countries where the app is available.

We ask for your date of birth when you create an account and apply the threshold for your region.

Posting a challenge at a climbing gym, where other climbers can see it, is for over-18s. We check this against the date of birth on your account, and an account with no date of birth cannot post one.

Changes to this policy

If we change this policy we will update the date at the top and, where the change is significant, tell you in the app before it takes effect.