Privacy Policy
Last updated · June 2026
This Privacy Policy describes how SENDO (“we”, “us”, or “our”) collects, uses, and shares information when you use the SENDO mobile application and website (together, the “Service”). The Service is operated by the party identified in our Commercial Disclosure, who is the data controller for the purposes of EU/UK GDPR and the personal information handling business operator (個人情報 取扱事業者) for the purposes of Japan's APPI. The short version: your climbing log lives on your device first, we collect the minimum we need to run the Service, and we never sell your personal information.
1. Information we collect
- Account information. SENDO works without registration: when you tap “Get started” we create an anonymous account identifier so features like presence and avatars can work. If you later sign in with Apple, Google, or an email code, we also store your email address and the authentication identifiers those providers give us.
- Climbing data — ascents, grades, attempts, sessions, session context (energy, focus, notes), move tags, achievements, and the gyms you associate with them.
- Route photos. Photos you attach to climbs are stored on your device only. They are not uploaded to our servers. If you share a card or video, the image is composed on your device and handed to the app you share it to.
- Profile avatar. If you set one, it is uploaded to our storage provider and served from a publicly addressable URL so it can be shown next to your presence at the gym; anyone with the URL can fetch the image. You can replace or remove it at any time, and deleting your account deletes the file.
- Presence data. When you start a session at a gym, the gym you are currently checked into is visible to other climbers at the same gym. Presence is symmetric (you only see climbers who are also visible, and vice versa) and is on by default; you can turn it off at any time in Settings → Privacy.
- Location. If you use gym discovery, your device location is used to search for climbing gyms near you (see “Service providers” below). We use it to run that search; we do not build a history of your location.
- Purchase status. If you buy SENDO Pro, our billing provider processes the store purchase and tells us which entitlements are active. Payment itself is handled by the App Store or Google Play — we never see your card details.
- Device and diagnostic data — device model, OS version, app version, and crash reports, used solely to keep the app working.
- Usage analytics.Pseudonymous events about how the app is used — for example that a session was started, a climb was logged, or a screen was opened — so we can see which features matter and where the app falls short. Events are tied to a random device identifier (and, if you sign in, to your account's internal ID); they never include your notes, name, email, photos, or anything you type. You can turn them off at any time (see “Usage analytics and your choices” below).
- Feedback. Anything you send through the in-app feedback form or by email.
- Website page views. When you visit getsendo.app, our hosting provider Vercel records aggregate page views (page path, referrer, country, browser/device family) without setting cookies or storing personal identifiers. A short-lived daily hash of your IP address and user agent is used only to deduplicate visits within a 24-hour window and is then discarded; we do not see your IP address.
2. How we use information
We use the information described above for the following specified purposes (利用目的 under APPI Art. 17):
- To provide, maintain, and develop the Service, including (for subscribers) syncing your log across devices.
- To compute your statistics, grade conversions, achievements, and progress analytics — this happens on your device.
- To show live presence to other visible climbers at the same gym (visible by default; can be turned off in Settings → Privacy).
- To find climbing gyms near you when you ask for it.
- To process subscription purchases and manage entitlements via Apple App Store / Google Play and RevenueCat.
- To diagnose crashes, detect and prevent abuse, and keep the Service secure.
- To understand, in aggregate, which features are used and where people get stuck, so we can decide what to build and fix next.
- To respond to your inquiries and support requests.
- To comply with applicable laws, including tax and accounting record-keeping obligations.
We do not use your data for advertising, and we do not sell it to anyone.
3. Offline storage and sync
SENDO is offline-first. Your climbing log is stored in a local database on your device and is fully usable without an account or a connection. Cloud sync is an optional, subscription-only feature with its own switch: when it is active, your sessions, ascents, and settings are synchronized to our servers so they can follow you across devices. Local data remains on your device until you delete the app or clear its data.
4. Usage analytics and your choices
We use PostHog to collect the pseudonymous usage events described above. By default, events are tied to a random identifier generated on your device — not to your name or email. If you sign in with an account, events are associated with your account's random internal ID so we can understand usage across your devices; they still never contain personal details or the content of your log. Under EU/UK GDPR, this identifier constitutes personal data even though it is pseudonymous; our legal basis is your consent (the “Share usage data” toggle below), which you can withdraw at any time. Analytics data is processed on PostHog's US cloud (see section 9 on international transfers).
Analytics is on by default and entirely optional: turn it off in the app under Settings → Privacy → “Share usage data”, and the app stops sending events immediately. Crash reporting and analytics are separate — disabling one does not affect the other.
5. Legal basis for processing (EU/UK)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under GDPR Article 6:
- Performance of a contract (Art. 6(1)(b)): to operate the Service for signed-in users, synchronise your climbing log across devices when cloud sync is active, and manage your subscription.
- Consent (Art. 6(1)(a)): for opt-in features such as gym discovery using your device location, and for usage analytics. You can withdraw consent at any time in Settings → Privacy.
- Legitimate interests (Art. 6(1)(f)): to keep the Service secure, diagnose crashes, prevent abuse, and improve the Service in ways that do not override your rights. You can object to processing based on legitimate interests by contacting us.
- Legal obligation (Art. 6(1)(c)): to retain billing and tax records as required by Japanese and other applicable law, and to respond to lawful requests from authorities.
6. Service providers
We share data only with providers who process it on our behalf to run the Service, under their own contractual and security obligations:
- Supabase (United States) — authentication, database, and storage for synced data, avatars, presence, and feedback.
- RevenueCat (United States) — subscription and purchase entitlements for SENDO Pro.
- Sentry (United States) — crash reporting (device and diagnostic data only).
- PostHog(United States) — pseudonymous usage analytics (see “Usage analytics and your choices” above), with an in-app opt-out.
- Google Places(United States, third-party API) — gym search results when you use gym discovery; your search coordinates are sent to Google as part of the lookup and are subject to Google's own privacy terms.
- Vercel(United States) — hosts getsendo.app and provides cookieless first-party website analytics (page views only — see “Website page views” in section 1). Vercel Analytics respects the browser “Do Not Track” header.
Beyond these providers, we disclose information only when required by law or with your explicit consent.
7. Retention schedule
- Local device data — retained on your device until you uninstall the app or clear its data.
- Synced climbing data, profile, and avatar — retained for the lifetime of your account and deleted within 30 days of account deletion.
- Anonymous accounts — automatically deleted after a prolonged period of inactivity (currently 12 months).
- Crash reports— retained per Sentry's default retention (typically 30 days).
- Pseudonymous analytics events— retained per PostHog's retention (typically up to 7 years; we do not need that horizon for product analytics).
- Billing and tax records — retained for the period required by Japanese tax law (currently seven years).
- Feedback and support correspondence — retained for as long as necessary to address the matter and a reasonable period thereafter.
8. Export and deletion
- Export: you can export your complete climbing log as CSV or JSON at any time from the app — no paywall, no truncation.
- Deletion: you can delete your account and synced data in-app (Profile → Your data) or by emailing us. Deletion removes your data from our servers within 30 days, except where retention is required by law.
9. International data transfers
Our service providers listed above are located in the United States. If you are in the EEA, the UK, Switzerland, or Japan, your personal data will therefore be transferred outside your country of residence.
For EEA / UK / Swiss users:we rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) with our US service providers as the appropriate safeguard under Chapter V GDPR. Where a provider is self-certified under the EU-U.S. Data Privacy Framework, we may additionally rely on that decision. You can request a copy of the relevant SCCs by contacting us at contact@getsendo.app. The United States does not have an omnibus federal data-protection law equivalent to GDPR; we maintain a transfer-impact assessment documenting the supplementary measures (encryption in transit and at rest, access controls, minimisation) that apply to these transfers.
For Japan users:by using the Service you consent under APPI Art. 28 to the transfer of your personal data to the United States for the purposes listed in section 2. The United States is not on Japan's adequacy whitelist; the US data-protection regime is sector-specific rather than omnibus, and the providers above are bound by their own contractual privacy commitments to us. You may withdraw this consent at any time by deleting your account, which will stop further transfers.
10. Security
Personal data in transit is protected with TLS. Personal data at rest on our service providers' infrastructure is protected by their platform-level encryption and access controls. Avatars are served from a publicly addressable URL; do not upload an image you would not want others to see. We do not store payment-card data — that is handled entirely by Apple App Store and Google Play.
11. Your rights
In-app tools cover most rights directly: export and deletion are available from Profile → Your data; analytics, presence, and gym discovery are controllable in Settings → Privacy. For anything else, contact us at contact@getsendo.app.
EEA / UK / Switzerland (GDPR & UK GDPR). You have the right to request access to your personal data; rectification of inaccurate data; erasure; restriction of processing; data portability; and to object to processing carried out on the basis of our legitimate interests. Where processing is based on your consent, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal. You also have the right to lodge a complaint with your local supervisory authority (e.g. the Irish Data Protection Commission, the UK ICO, or your member-state authority).
California (CCPA / CPRA). California residents have the right to know what personal information we collect, use, disclose, sell, or share; to request deletion or correction; to opt out of any sale or sharing of personal information; and to limit the use of sensitive personal information. We do not sell or share your personal information for cross-context behavioural advertising, and we do not use or disclose sensitive personal information for purposes that would require a right to limit. You will not be discriminated against for exercising any of these rights. We honour Global Privacy Control (GPC) signals as a valid opt-out request. To exercise your rights, email us at contact@getsendo.app or use the in-app deletion / export tools. The categories of personal information we collect, as enumerated in Cal. Civ. Code §1798.140, are: identifiers; internet or other electronic network activity information; geolocation data; visual information (avatar); and inferences drawn from the foregoing.
Japan (APPI). You have the right to request disclosure, correction, addition, deletion, suspension of use, suspension of provision to third parties, and records of third-party provision concerning your retained personal data, in accordance with APPI Articles 33–35. Inquiries (個人情報お問い合わせ窓口) should be addressed to contact@getsendo.app; the personal-information handling business operator is identified in our Commercial Disclosure. We will respond without delay.
12. “Do Not Sell or Share My Personal Information” (California)
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA / CPRA. There is no opt-out to exercise because there is no sale or sharing to opt out of. If our practices ever change, we will update this policy and provide a conspicuous opt-out link before any such sale or sharing begins.
13. Children
The Service is not directed to children under 13 (or the applicable minimum age in your jurisdiction — 16 in some EU member states under GDPR Art. 8), and we do not knowingly collect personal information from such children. If we become aware that we have collected personal information from a child below the applicable minimum age without verifiable parental consent, we will delete it promptly. Parents or guardians who believe their child has provided us with personal information may contact us at contact@getsendo.app.
14. Changes to this policy
We may update this policy from time to time. Material changes will be announced in-app before they take effect, and by email if you have provided one.
15. Contact
Questions or requests? Reach us at contact@getsendo.app. The business operator and its address details are listed in our Commercial Disclosure.