Privacy policy
Effective 8 September 2026
Who this is about
Romanesku is a community climbing map for Spain, operated by [LEGAL ENTITY / OPERATOR NAME]. This page explains what the app stores about you, what it deliberately doesn't, and how to get rid of it. Questions: [CONTACT EMAIL].
What we store
Only what an account needs to work:
- Your email address — identifies the account and receives verification and password-reset codes.
- The name you chose — a username you pick yourself. It is public: it is shown on everything you write and on your climber page. We never ask for your real name, and you can change the one you chose at any time.
- Your password, if you signed up with one — stored only as a bcrypt hash. We cannot read it.
- Which sign-in methods you use (email/password, Google), and timestamps: when the account was created, verified, and last signed in.
- Short-lived verification codes, stored hashed with an expiry, for confirming your email and resetting your password.
That is the whole list. There is no analytics, no advertising, and no tracking or profiling SDK.
The app does include one third-party SDK: error reporting. When something breaks, it sends the error message and a stack trace so it can be fixed. It is configured to send errors only — no page views, no session recording, no performance tracing — and the report is stripped before it leaves: request bodies, cookies, headers and your account details are removed, so it never carries your password, a verification code, or your email address.
Your location never reaches us
The map's “locate me” button uses your device's own location service, and the position stays on your device — it is used to move the map and nothing else. We never receive it, store it, or share it.
When you pan the map, the app asks our server for the climbing areas inside the rectangle you're looking at. That request contains the map's corners, never your position.
Others who see a request
Some parts of the app are fetched directly by your device, so those services see your IP address and what you asked for, as with any web request:
- Map tiles — OpenFreeMap (the base map), Mapterhorn and AWS Open Data (the terrain shading and contour lines). Which tiles you load reveals roughly which area you're viewing, at tile resolution.
- Google, only if you choose Google sign-in. Google tells us your email address; we ignore everything else it sends, including your Google account name.
- Our email provider, to deliver verification and reset codes.
- Supabase, which hosts the database and image storage in the EU (Ireland).
- Sentry, our error-reporting provider, which receives a message and a stack trace when something in the app fails — with your details stripped out, as described above.
We do not sell your data, and we don't share it for advertising.
What other people can see
Some of what you do in Romanesku is shown to other climbers — the app is a shared guidebook, so this is the point of it. This is the full list:
- The name you chose, on everything below and on your climber page at
/u/your-name. - Comments, condition reports and access edits, with your name against each one. Access info keeps a public revision history, so every past version stays visible with its author.
- Star ratings, but only inside an average. Nobody sees how you personally rated a route.
- Ascents you mark as shared. New entries are shared by default and you can turn that off, per ascent, before or after logging it. A private ascent is counted in a route's totals and never named, and its notes are never shown to anyone but you.
- Your contribution counts and level, on your climber page.
Never shown to anyone: your email address, your saved favourite areas, your ascent notes, and any ascent you kept private.
Cookies
One essential cookie holds your sign-in session, plus two that protect the sign-in form against cross-site request forgery. All are strictly necessary — there are no advertising or analytics cookies. Your light/dark preference is kept in your browser's local storage, not sent to us.
How long we keep it, and deleting it
Account data is kept while your account exists. You can delete your account at any time — in the app under Settings → Delete account, or from romanesku /account/delete in any browser.
Deletion is immediate and permanent: the account row, your email address, your name, your logbook, your favourites and your star ratings are removed from the database. It cannot be undone, and we cannot restore it.
One thing survives, without your name on it. Comments, condition reports, access edits and their revision history stay in the app, re-labelled “Deleted climber” and no longer linked to you or to any account. A rotten-bolt warning that other climbers rely on must not disappear because its author left, and the entries are of no use without the history that shows how the access answer got there. Nothing in them identifies you once the account is gone.
Your rights
Under the GDPR you can ask for a copy of your data, correct it, have it erased, or object to how it's handled. Three of those you can do yourself, immediately: a copy from the export links on your profile, correction of the one thing we publish about you — change your name under Settings → Your name, and it updates everywhere at once, including on everything you have already written — and deletion with the link above. For anything else, write to [CONTACT EMAIL].
You also have the right to complain to your data protection authority. The applicable authority depends on where the operator is established ([COUNTRY / JURISDICTION]).
Children
Romanesku is not for children under 14 — the age Spanish law sets for consenting to your own data being processed. We don't ask for a date of birth, so we can't check it: if a child under 14 has an account, write to [CONTACT EMAIL] and we'll delete it.
Changes
If this policy changes, this page and the effective date above change with it.
