-
Notifications
You must be signed in to change notification settings - Fork 0
Privacy Policy for Prusik
Version: 2026-08-31
This Privacy Policy explains how Prusik ("Prusik", "we", "us", or "our") collects, uses, shares, and protects personal data when you use the Prusik mobile application and related services.
Controller: Henri van Bavel
Contact: u7148535533@gmail.com
Prusik is a social coordination app for climbers. It helps users create a climbing profile, connect with other climbers, discover climbing sessions and partner requests, join events, coordinate in event chat, participate in the regional Community board, receive functional notifications, and report safety or product issues.
Prusik is not an advertising network, data broker, or general social media feed.
We collect the information needed to operate Prusik and keep the community functional and safe.
- Email address.
- Authentication identifiers from Supabase Auth and, if you choose them, Google, Apple, or Facebook sign-in.
- Username and display name.
- Profile picture URL if you upload an avatar.
- Account timestamps such as creation, update, onboarding completion, and onboarding dismissal.
You may choose to add optional climbing profile details, such as:
- Age range.
- Climbing disciplines and grade-interest range.
- Lead-climbing experience.
- Favourite gyms and local crags.
- Topics you are happy or unhappy to discuss while climbing.
- Website or Instagram profile.
- Roped-climbing weight value where available. This is used for partner-context logic and is not shown on viewed public profiles in the current app.
- Hidden-profile setting and audience preferences for session discovery and notifications.
We process data about:
- Connection requests, including optional short introduction messages.
- Accepted connections and favourite connections.
- Friend-of-friend and mutual-connection signals.
- Suggested climber dismissals.
- Blocks and unblock actions.
Prusik uses location-related data because event discovery is geography-aware.
We may collect and store:
- Your saved discovery-region center point and radius.
- Event location labels.
- Event GPS points resolved from a selected place, an exact custom pin you set, or your saved discovery-region center as an approximate fallback.
- Structured place and venue identifiers attached to events.
- Event details such as date, time, discipline, visibility, capacity, notes, tags, participant status, and approval state.
Prusik does not currently run continuous background location tracking. The app stores the map locations and discovery settings you save or use for event creation.
We collect:
- Event chat messages and system chat entries.
- In-app notification rows and read status.
- Firebase Cloud Messaging tokens for push delivery if notifications are enabled.
- Reports about users, events, and bugs, including report reason and details you submit.
- Moderation status for submitted reports.
Signed-in users may publish Community posts and one-level replies. Posts are visible to authenticated, non-blocked users in the relevant discovery region and include the author's basic identity even when the author's detailed profile is hidden. We store a geographic point for every post, resolved from a selected climbing place, an exact pin, or the author's saved discovery center. That point, its source, place identity, and calculated distance are used only for regional discovery and notification targeting and are never included in published Community responses, stored notification copy, push payloads, or Community analytics.
Community browsing uses at least a 70 km radius around the viewer's saved center; the viewer's own posts remain visible after discovery setup. New-post notifications use each recipient's originally saved radius without the 70 km minimum. Reply notifications go only to the post author, subject to blocking and notification preferences.
Prusik currently stores first-party product analytics events in Supabase, such as app-session starts, searches, profile views, event opens, joins, chat sends, event creation, connection actions, discovery settings saves, place-page opens, blocks, report submissions, and notification opens.
Analytics events may include:
- The event name.
- Your user ID when you are signed in.
- Related event or user IDs when needed to understand app usage.
- Limited event properties such as counts, durations, trigger reasons, success/failure status, or selected location-source type.
- Timestamp.
We use this data to understand whether Prusik is useful, debug product behavior, measure adoption, and prioritize improvements. We do not use analytics for advertising, third-party ad targeting, or sale of personal data.
If Prusik later adds a dedicated analytics provider such as PostHog, we will use it for product analytics, reliability, feature adoption, experimentation, and debugging. We will update this policy before enabling materially different analytics practices, avoid advertising use, configure privacy-respecting retention and access controls, and use appropriate data-processing terms with the provider.
Supabase, Firebase, OAuth providers, app stores, map tile providers, and hosting/network providers may generate technical logs such as IP address, device or browser information, request metadata, crash/error information, or security logs as part of operating their services.
Prusik does not:
- Sell personal data.
- Share personal data for cross-context behavioral advertising.
- Display third-party advertisements.
- Use your profile, chat, event, or location data for ad targeting.
- Import your device contacts.
- Collect continuous background GPS location in the current app.
We use personal data to:
- Create, authenticate, and secure accounts.
- Maintain user profiles and onboarding state.
- Let users search for climbers, connect, block, report, and manage their network.
- Show viewer-appropriate profile, connection, event, roster, chat, and notification data.
- Create, update, cancel, discover, join, and manage climbing events.
- Run geography-aware event discovery and notification targeting.
- Deliver in-app and push notifications.
- Provide event chat and preserve event history where needed.
- Provide the regional Community board, replies, author tools, and Community notifications.
- Review reports, investigate abuse, and enforce the Terms of Service and Community Guidelines.
- Run first-party analytics, growth reports, debugging, and reliability monitoring.
- Comply with legal obligations and respond to valid legal requests.
For users in the European Economic Area, United Kingdom, or similar jurisdictions, we rely on these legal bases:
- Contract: to provide Prusik, including accounts, profiles, connections, events, chat, notifications, and account deletion.
- Legitimate interests: to keep the service secure, prevent abuse, understand product usage, improve reliability, run privacy-preserving analytics, and operate moderation and reporting workflows.
- Consent: where required for optional device permissions such as push notifications, OAuth sign-in selection, or future optional analytics features that require consent.
- Legal obligation: where processing is needed to comply with applicable law.
You can withdraw consent for push notifications through your device settings. Withdrawal does not affect processing that happened before withdrawal.
Prusik is social by design, so some information is visible to other users according to your settings and the app's privacy rules.
- Basic profile details may appear in search, suggestions, connection requests, mutual-friend displays, event organizer views, and event contexts.
- Detailed account profile data is limited to you and accepted connections.
- Public climbing profile fields may be visible to authenticated, non-blocked users unless your hidden-profile setting limits visibility.
- Friend-of-friend discovery shows basic profile cards for another user's connections when allowed.
- Event visibility can be public, connections-only, favourites-only, private, or custom.
- Participant identity in event rosters, chat, and notifications is shaped by organizer status, self-view, connection status, and hidden-profile settings.
- Event chat is available only to users with event chat access.
- Blocks affect discovery, profile, event, and notification eligibility.
- Community posts and replies are signed-in-public within their geographic audience. Their author's basic identity is visible and links to the existing profile view; detailed-profile fields continue to follow profile visibility rules.
- Community post locations are processed for matching but are not displayed after publication.
Do not put information in your profile, events, reports, or chat that you do not want processed as part of the service.
We use service providers to operate Prusik. They may process personal data for us under their own terms, privacy commitments, and data-processing agreements where applicable.
Current provider categories include:
- Supabase: authentication, database, row-level security, RPCs, realtime, storage, and edge functions.
- Firebase Cloud Messaging: mobile push notification infrastructure.
- Google, Apple, and Facebook: optional OAuth sign-in.
- Map tile provider: hosted raster map tiles, attribution, and map display infrastructure.
- App stores and mobile platforms: app distribution, device permissions, and platform services.
- Internal reporting tools: product and growth reporting using Prusik data.
Potential future provider categories include product analytics providers such as PostHog, crash/error reporting, customer support, email delivery, and operational monitoring.
Your information may be processed in countries other than where you live, including the European Union, the United States, or other locations where our service providers operate.
Where required, we rely on appropriate safeguards such as data-processing agreements, Standard Contractual Clauses, adequacy decisions, or equivalent lawful transfer mechanisms.
We keep personal data only as long as needed for the purposes described in this policy, unless a longer period is required or permitted by law.
Current retention practices include:
- Account and profile data is kept while your account exists.
- Connections, blocks, preferences, public climbing profile data, and discovery settings are kept while your account exists or until you change/delete them where supported.
- Active event data is kept while needed for event coordination. Cleanup automation removes certain expired, cancelled, stale, or orphaned operational rows.
- Event chat history may be preserved as part of the event timeline. If an account is deleted, chat actor references may be anonymized rather than deleting the entire historical chat row.
- Community posts and replies remain until their author soft-deletes them or the account is deleted. Deleted posts and their threads disappear from client views; deleted replies are omitted. Prusik does not automatically expire or purge deleted Community content in the initial release.
- In-app notifications may be deleted by users and are also subject to cleanup automation.
- Declined connection requests and certain stale operational records may be cleaned up automatically.
- Reports may be retained as long as needed for moderation, abuse prevention, legal defense, and service safety.
- Product analytics may be retained for product measurement and growth reporting unless deleted according to account deletion, legal request, or future retention configuration.
- Provider logs are retained according to the relevant provider's retention settings and legal obligations.
The current app includes in-app account deletion. Account deletion removes the authenticated account and lets database-owned cleanup rules remove or anonymize dependent data according to the implemented backend contract.
Depending on your location, you may have rights to:
- Access your personal data.
- Correct inaccurate personal data.
- Delete personal data.
- Restrict or object to certain processing.
- Receive a portable copy of your data.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a data protection authority.
To exercise these rights, use the in-app controls where available or contact us at the contact address above. We may need to verify your identity before fulfilling a request.
Some data may be retained when needed for security, moderation, legal compliance, dispute resolution, or preserving anonymized event history.
If you are in Austria, you may lodge a complaint with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, Austria, at dsb.gv.at or dsb@dsb.gv.at. If you are in another country, you may contact the data protection authority competent for your place of residence or work, or for the alleged infringement.
Prusik sends functional push notifications for app activity such as event updates, join requests, chat messages, connection requests, new regional Community posts, and replies to a user's Community post. Community notification copy contains no post title or post location/distance. Notification copy is designed to respect Prusik's blocking, audience-preference, participant-identity, and hidden-profile rules.
Push notifications are delivered through Firebase Cloud Messaging. You can disable push notifications in your device settings. Disabling push notifications does not remove in-app notifications.
Prusik uses Supabase authentication, row-level security, server-side RPCs, storage policies, and viewer-shaped read models to limit access to profile, event, chat, notification, report, and analytics data.
No online service can guarantee perfect security. You are responsible for keeping your login credentials secure and for using caution before sharing personal information with other users.
Prusik is not intended for children under 13. If you are under the minimum age required to use online services in your country, you may not use Prusik without any legally required consent from a parent or guardian.
If we learn that we have collected personal data from a child in violation of applicable law, we will take appropriate steps to delete it.
If you are a California resident, you may have rights to know, access, correct, delete, and limit certain uses of personal information, and to opt out of sale or sharing.
Prusik does not sell personal information and does not share personal information for cross-context behavioral advertising.
California requests can be submitted through the contact address above.
We may update this Privacy Policy when our practices, providers, features, or legal obligations change. We will update the "Last updated" date and provide additional notice when required by law.
Your continued use of Prusik after an update means the updated policy applies from its effective date.
Questions, requests, or complaints about privacy can be sent to: