Privacy Policy
Last updated: 12 August 2026
Access is currently invite-only, for a small group of climbers and coaches. This document accurately describes what the service does today, and will be updated when registration opens to the public.
Anabase is a climbing training app that connects a climber and their coach around a shared plan. To work, it records what you climb, how you feel, and how your body handles the load. This page explains exactly what is collected, why, who else can see it, and how to take back control.
Who is responsible for your data
The data controller is Pierrick Terrettaz, a private individual resident in Switzerland, publisher of Anabase.
For any question, or to exercise your rights:
What is collected
Your account
- Email address and password (never stored in clear text — only a bcrypt hash)
- Name, role (climber or coach), avatar, bio
- Year of birth and time zone
Your climbing profile
- Maximum grades indoors and outdoors, discipline preferences
- Ten self-assessed metrics (finger strength, fear of falling, tactical reading…)
- Recovery factor and scheduling constraints
Your training
- Completed sessions, attempts, projects and project diaries
- Daily notes and weekly reflections, as free text
- Daily metrics: training load, fatigue, freshness
Your AI assistant conversations
If you or your coach use the assistant, conversations and messages are kept so the thread can be followed.
Technical
Login sessions, notifications, and anything you send through the feedback form. No analytics tool is installed — no Google Analytics, no equivalent.
Health data: handled separately
Heart rate imported from Strava, training load, fatigue indicators and your year of birth constitute health-related data under Article 9 of the GDPR, and sensitive personal data under the Swiss Federal Act on Data Protection.
They are processed only on the basis of your explicit consent, given when you connect Strava or enter this information. You can withdraw it at any time, without giving a reason, by disconnecting Strava or deleting the relevant data.
Why, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Create and manage your account, sign you in | Performance of a contract |
| Build your plan, log sessions, compute load and freshness | Performance of a contract |
| Share your plan and data with the coach you accepted | Performance of a contract |
| Process heart rate and physiological indicators | Explicit consent (Art. 9(2)(a) GDPR) |
| Import and export your Strava activities | Consent, revocable by disconnecting Strava |
| Answer through the AI assistant | Performance of a contract, at your initiative |
| Secure the service, prevent abuse | Legitimate interest |
Who else sees your data
Anabase sells nothing and shares nothing for advertising purposes. The providers below are involved solely to run the service.
| Provider | Role | Location |
|---|---|---|
| Neon | Database (all your data) | Germany — eu-central-1 |
| Fly.io | Application hosting | France — Paris |
| Cloudflare | Site delivery, DNS, email routing | United States |
| Strava | Imports your activities, exports your sessions — only if you connect your account | United States |
| Anthropic | AI assistant — receives your messages and the relevant athlete's data | United States |
| Gravatar | Receives a SHA-256 hash of your email to look up an avatar | United States |
| Resend | Sends the service's emails | United States |
Your coach
The coach you accepted can see your plan, sessions, notes and your load and freshness indicators. That is the whole point of the service. You can end that link at any time from your settings.
Transfers outside Europe
Your database and the application are hosted in the European Union. Five providers are based in the United States: Cloudflare, Strava, Anthropic, Gravatar and Resend. These transfers rely on the European Commission's Standard Contractual Clauses or on the EU-US Data Privacy Framework, depending on the provider.
How long
- For as long as your account exists — account, profile, training, conversations
- Login sessions — 7 days, then automatic expiry
- After you delete your account — your data is erased from the live database. Encrypted backups may retain a copy for a few weeks before rotation.
Your rights
The GDPR and Swiss law give you the right to access your data, correct it, have it erased, obtain a portable copy, restrict or object to its processing, and withdraw your consent at any time.
Write to and you will get an answer within 30 days. No justification is needed.
If the answer does not satisfy you, you may contact the Federal Data Protection and Information Commissioner in Switzerland, or the supervisory authority of your country of residence in the European Union.
Cookies
Anabase sets a single cookie, named session_id. It keeps you
signed in and expires after 7 days. It is strictly necessary for the service to work, tracks
nothing, and feeds no analytics.
That is why you will never see a cookie banner on Anabase: there is nothing to ask you to accept.
Minimum age
You must be at least 16 to create an account. Anabase does not knowingly collect data about anyone younger. If you become aware that an account was created by someone under 16, report it to and it will be deleted.
Security
- Passwords are hashed with bcrypt — never stored or readable in clear text
- Everything travels over HTTPS; the
.appdomain enforces encryption at the browser level - The session cookie is
httpOnlyandsecure, so JavaScript cannot read it - The database is hosted in the European Union and is not publicly exposed
No system is infallible. In the event of a data breach likely to create a risk to your rights, you will be informed and the competent authorities notified within the legal deadlines.
Changes
This page will evolve alongside the service, particularly when registration opens. The last updated date appears at the top. Any substantial change will be flagged inside the app.