Who owns what
Setboard holds two kinds of data, and they belong to two different people. This page says plainly which is which, what each side can do with theirs, and what happens when a gym leaves. It is the short version and it is the real version — there is no longer document behind it that says something else.
The gym owns the gym's data
Your routes are yours. So is everything around them: your locations, your walls, the map of each building and the outline of every wall on it, which walls your setters flagged as coming down soon, every setting cycle you have ever run, the grades and hold colors your setters chose, the tag tokens printed on your QR tags, the problems climbers reported with your routes and what your setters did about them, and the aggregate of what climbers did with them — how many ascents each route saw, how it was rated, and what the community graded it.
You can take all of it, at any time, without asking us. An admin opens Admin → Export, clicks once, and gets a zip: every table as both JSON and CSV, with a README explaining each file. It includes archived routes, because stripping a wall in Setboard sets a date on the routes rather than deleting them — your history is still there five years later.
Adding a building, a wall, a building's map or a custom domain is the one thing you ask us for: those are set up by Setboard's platform team. The map is yours all the same, and it is in your export (each building's map and each wall's outline). The picture of your printed map that the team traces over is kept privately for that work only: no climber sees it, it is not shared, and it is deleted when the map is removed or the picture replaced. Admin → Settings names the address to write to, and a rename is a one-minute favor.
We do not charge for an export, we do not rate-limit it to make a point, and we do not require notice. It is your record of your own gym.
The climber owns the climber's data
A climber has one Setboard account across every gym on the platform. Their logbook — every ascent, at every gym — is theirs, not any one gym's. So are their star ratings, their suggested grades, and the comments they leave on routes.
A climber can download the lot as a CSV from their account settings, and they can close their account from the same page. Closing an account anonymizes them: their display name becomes "former member" everywhere it appeared, their sign-in is removed (with their entries in the sign-in service's log, which hold their email address), and nobody can sign in as them again. What they sent your gym stays with it without their name (problem reports, feedback and flags), and your moderation record keeps its entries about them (a removal, a mute) under "former member".
A climber's private notes and goals
A climber can keep a private note on any route (beta for next time, where they fell) and set a few goals in their logbook ("ten ascents at V4 or harder this month"). These are theirs alone, in a stronger sense than the rest of their data:
- Nobody else sees them. Not other climbers, not the gym's setters, managers or admins, and not the gym's export: the database lets only the climber who wrote a note or set a goal read, change or delete it. Setboard's platform team has no tool that opens them; the only software that touches them without the climber is what acts for them (merging a duplicate account, closing theirs), and they sit in the database provider's backups like everything else until those age out.
- They are in the climber's own CSV download.
- Closing an account deletes them. Unlike ascents and ratings, they are nobody's climbing record but the climber's, no gym ever counted them, and there is nobody left to read them. Merging a duplicate account moves them to the account the climber keeps (where both accounts wrote a note on the same route, the kept account's note stands).
A climber's logbook figures (their pyramid, sessions, projects, grading and milestones) are worked out for them alone, from their own logs, and shown to nobody else.
What closing an account does not do is erase your gym's history. Their ascents and their ratings stay in your numbers, because those rows carry no name — they are counts and medians, and a wall's traffic is not rewritten because one climber left. Their comments stay on your routes as beta, under "former member".
When a gym removes something
A gym's walls are its own, and so are its rules. A gym's managers and admins may remove a comment, a link to a video, a suggested grade or a rating that breaks those rules — abuse, spam, a joke grade meant to drag a route's number. Setters can hide a comment, which removes nothing and can be undone; removal is for the people who run the gym.
- Every removal is recorded: who removed it, whose it was, which route, when, and the reason they gave. The record does not keep the text of a removed comment. For a removed link it keeps the link's address, so the gym can say which video it took down; the video itself lives wherever you posted it and is not touched.
- Staff never remove a climber's ascents. Your logbook is yours, at every gym, and no gym's staff can take a tick out of it.
- Clearing a suggested grade keeps the stars you gave. Everything else above stands: the rest of your data is yours, and closing your account works the same way.
When a climber flags something
Any signed-in climber may flag a comment or a video link on a gym's route — as spam, as abusive, as being about a different route, or for another reason, with an optional line of their own. A flag asks the gym's managers and admins to look; it hides nothing and removes nothing by itself.
- The gym sees who flagged and why: the flagger's display name, the reason and their note, on the moderation page, for the managers and admins of the gym that owns the route. Nobody else sees a flag — not the author, not other climbers, not the flagger once it is sent, and not another gym.
- The author is not told. If staff then hide or remove the item, that is the ordinary, recorded removal above; dismissing a flag changes nothing.
- A climber can flag an item once until the gym has dealt with it, and only so many items an hour.
- Closing an account removes the name. The flag stays with the gym, and the moderation page shows "Former member" as the flagger; merging a duplicate account moves the flags to the account the climber keeps.
When a climber reports a problem with a route
Any signed-in climber may report a problem with a route on the wall: a spinning hold, a missing tag, tape that has come off. They pick one of the gym's own reasons and may add a line. It is about the wall, not about anybody, and it goes to the gym's setting team to fix.
- Reports are the gym's record, like its moderation record: they stay with the gym, fixed or dismissed, and they are in the gym's export. They are not in the climber's own CSV.
- The gym's setters see who reported it: the reporter's display name, the reason and their note, for the setters, head setters, managers and admins of the gym that owns the route. Nobody else sees who reported or what they wrote: not other climbers, not another gym, and not the reporter once it is sent.
- Everyone sees that a problem is open, and nothing more. While a report is open, the route page warns anyone who opens it, signed out too: the reason, how many climbers reported it and since when ("Reported: spinning or loose hold · 2 climbers · since Tue"), and the gym's route lists mark a route with an open safety report. Never who, never the note, and never anything once the setters close it. There is no list of a climber's own reports anywhere, and nobody is emailed about a report or told when it is fixed.
- Closing an account removes the name. The report stays with the gym as "former member"; merging a duplicate account moves the reports to the account the climber keeps.
When someone sends the gym feedback
Every page of a gym carries Send feedback at the foot. Anyone may use it, signed in or not: they pick a topic (the gym, routes and setting, the app, or something else) and write up to 2,000 characters.
- What is kept: the gym, the building the page was for, the topic, the message, the page it was sent from, and when. Signed in, which account sent it, so the gym sees the sender's display name and never their email address. Signed out, nothing about who sent it, unless they chose to leave an address to be written back to.
- Who sees it: the gym's managers and admins, on Admin → Feedback, and nobody else at the gym: not setters, not other climbers, not another gym. The sender does not see it again once it is sent. Messages under "The app" are also read by Setboard's platform team, with the gym's name, so the people who build the app hear about it.
- A signed-out sender's address is shown to that gym's managers and admins only, as a link that opens their own email. Setboard never writes to it and never replies from the app.
- The visitor's IP address is never stored. To stop one visitor flooding a gym, the server keeps a scrambled, keyed fingerprint of the address (a hash that cannot be turned back into it) for two hours and then deletes it. It is never shown to anyone, never exported and never kept with the message.
- It is the gym's record, in the gym's export, not in the climber's own CSV. Closing an account keeps the message and removes the name ("former member"); merging a duplicate account moves it to the account the climber keeps. Nobody is emailed when a message arrives; the weekly digest says how many are new.
A gym's notices
A gym's managers and admins can put a short notice at the top of its pages ("Closed Tuesday for setting"). A notice is the gym's own words, not anybody's climbing record, so removing one really deletes it and leaves no log. Nothing a climber made is ever removed that way. Dismissing a notice is remembered on the climber's own phone only; the gym is not told.
When a gym mutes a climber
A gym's managers and admins may also mute a climber at their gym: for as long as the mute lasts, that climber cannot post comments or links to videos on that gym's routes. It is the step before removing things one by one.
- It is one gym only. A mute changes nothing at any other gym, and nothing about the climber's account: not their name, not their email, not their sign-in. No gym can change those.
- It stops new posts; it removes nothing. What the climber posted before stays until someone removes it the ordinary, recorded way. They can still log ascents and rate routes at that gym.
- The climber is told plainly. If they try to post, they see "Posting is turned off for your account at this gym", not an error.
- Every mute and unmute is recorded, like a removal: who did it, whose account, when, and the reason they gave. A mute can have an end date, and it stops applying by itself once that date has passed.
What your gym sees about a climber
At your gym, and only at your gym:
- their display name — the name they chose, not their legal name (a new account starts with a generated one, and a Google or Apple sign-in never supplies it);
- the ascents they logged on your routes;
- the ratings and suggested grades they gave your routes;
- the comments and video links they left on your routes;
- the flags they raised on your routes' comments and links, with the reason and note they gave, for your managers and admins;
- the feedback they sent your gym from its pages, with their display name, for your managers and admins;
- on the Members page, for your managers and admins: when they first logged or rated at your gym, when they were last active there, how many of each of the above, and whether they are muted there. Somebody muted at your gym who never logged or rated there is listed too, while the mute lasts, so it can be lifted.
That is the whole list. You do not see their email address, their grade scale or when they created their account (staff pages get a climber's names only), their private notes, their goals or their logbook's figures. You do not see what they climbed or rated at any other gym, or when they were last there: nothing another gym has — its ratings, comments, video links or visits — can be read with an account attached, so nothing at your gym leads there. The one thing that travels is the display name: another gym's route pages show it next to comments and video links, as they show it to everybody, so a name you recognize there may be the same climber. Your gym's export goes further still: it contains no account ids and no per-climber ascent rows, only the aggregate — how many ascents on which day — and no climber's account email. The one kind of email address in it is a signed-out sender's reply address, in the feedback file, when they chose to leave one for you to write back to.
What Setboard's own support can see and do with an account
A climber's account spans every gym, so no gym can change it. Setboard's platform team (a handful of named people, each granted by hand) can, on one page that no gym role reaches, and only to help:
- find an account by email address or display name, and see which gyms it belongs to and in what role. This is the one place in Setboard where an email address is shown to anyone but its owner;
- change the email on the climber's behalf, when they have lost access to the old address. Nothing is emailed; the climber signs in with the new address from then on;
- disable an account (sign-in is refused, nothing they posted is removed) and re-enable it;
- delete an account at the climber's request, exactly as closing it from their own settings does ("former member", sign-in removed, history kept);
- merge a duplicate into the account the climber keeps: ascents, ratings, comments, links, gym roles (the higher one at each gym), mutes and flags move across, and the duplicate is then closed. Where both accounts rated the same route, the kept account's rating stands and the duplicate's is dropped, because one person has one opinion per route. A climber's private notes and goals move across too; the team cannot read them.
The same team reads feedback about the app that climbers send any gym (the topic "The app"), with the gym's name, and keeps its own note of what it has read. Its own list shows that topic only; the rest of a gym's feedback is the gym's, and the team sees it only as it sees anything else at a gym, by opening that gym's own admin area when asked to help.
Every one of these changes is logged — who did it, to which account, when, and the detail (for an email change, the old and the new address, so a change made in error can be put back). Searching is not logged, and changes nothing. The log is readable by the platform team only; gyms never see it.
The same team sets up a gym's buildings, walls, building maps and custom domain, which a gym asks for by email rather than changing itself. Each of those changes is logged the same way, against the gym.
When a gym asks for help, a member of the team can open that gym's admin area and see and do there what the gym's admins can. Every change they make there with that access (not with a role of their own at the gym) is logged in the same log, against the gym, with the page it was made on; moderation is also in the gym's own moderation log. Marking a message about the app, or an error report, as read or fixed is triage of the team's own inbox and is recorded on the message, not in the log.
What Setboard does with it
We are the processor. You are the controller of your gym's data; the climber is the controller of their own.
- We do not sell data. Not to anyone, not in aggregate, not "anonymized".
- We do not share one gym's data with another gym. Two Setboard gyms in the same city cannot see each other's routes' analytics, setters, or climbers.
- We do not use your route data to train anything, or to build a product we then sell back to you.
- We use it to run Setboard for you: to serve your pages, to send the emails you ask us to send, and to keep backups so a bad day is not a lost season.
- Error reports hold no personal data. When a page fails, Setboard keeps a short technical note for its platform team: the error, the page (never what follows
?in its address), the kind of browser ("Safari on iOS") and the gym. No name, email address, account or IP address, and anything in the error that looks like an address or a token is removed first. It is deleted within about four months after the error last happened.
Subprocessors — hosting, the database, email delivery — are listed in your agreement and in the Privacy policy, and we tell you before that list changes.
If you cancel
Nothing disappears the day you leave.
- Ninety days. Your data stays exactly where it is and your admins keep access to Admin → Export. Take as many copies as you want. If you need longer, ask; we would rather extend the window than be the reason a gym loses its history.
- Then, within thirty days (or within thirty days of one of your admins asking us in writing, if that comes first), we offboard your gym by hand and confirm by email when it is done:
- every wall is stripped, so your routes are archived and nothing is live;
- your custom domains are removed and stop resolving to Setboard;
- your staff roles and invitations end;
- we delete what your gym wrote or collected: branding and logo, announcements, feedback (with any reply addresses), problem reports and their reasons, setters' notes, maps and map pictures, tags and print runs, flags, mutes, the moderation log, usage figures and your exports.
What stays, and why. Your gym's name, its buildings, walls and archived routes (name, grade, hold color, dates, setter credit) stay, because every climber's logbook entry points at one of them: an ascent logged at your gym stays in that climber's logbook afterwards, with your gym's and the route's names on it. A climber's history should not develop holes because a gym changed software or closed, and the database will not delete a route anyone has climbed. Climbers' own ascents, ratings, comments and video links are theirs and stay, as they do when a wall is stripped. Your gym's pages on Setboard's own address stay reachable with nothing live on them; we cannot take them offline today. Backups age out on their own, typically within a few weeks.
The footer
Every climber-facing page carries a small "powered by Setboard" line in the footer. It is how a climber discovers that their logbook follows them to the next gym, which is the thing that makes the account worth having. It stays on white-label plans. Everything else on the page is yours — your name, your colors, your typeface, your domain — but that one line is the deal.
For climbers: the privacy policy and the terms
This page is written for gyms. What a climber agrees to is in the Terms of use, and everything Setboard collects about a climber, cookie by cookie, who sees it and how long it is kept, is in the Privacy policy. Both are on every gym's own address, linked from the foot of every page, and say the same things this page does.
Questions about anything here go to your account contact, and we will answer in writing. If this page and a contract ever disagree, tell us: this page is what we mean, and the contract is what we will fix.