Setboard is route logging for climbing gyms: a gym's setters put routes on its walls and print a QR tag for each, and climbers scan a tag to log a climb, rate it and see what others made of it. This page says what Setboard collects when you use it, why, who sees it, how long it is kept, and what you can do about it. It is written from what the software actually does, and it is the whole policy: there is no longer version behind it.
Who we are
Setboard is a product of Bad Beta LLC, a company operated from the United States. "We" and "us" on this page mean Bad Beta LLC. You can reach us at support@badbeta.app about anything on this page.
Setboard runs under each gym's own name, colors and address, so the page you are reading may be wearing a gym's brand. The gym chose Setboard to run its climbing pages; Bad Beta LLC runs the software and the servers behind them.
Who is responsible for what
Setboard holds two kinds of information, and they belong to two different people. Who owns what explains this in full; in short:
- Your account is yours, and we are responsible for it. One Setboard account works at every gym on Setboard. Your email address, your display name, your logbook across every gym, your private notes and goals: we decide how these are handled, under this policy, and no gym can change them.
- A gym's records are the gym's. Its routes and walls, its moderation record, the problems climbers report on its routes and the feedback sent to it belong to the gym. For those, the gym decides and we handle them on its behalf, under our agreement with the gym. A question about how a gym uses what it sees of you goes to that gym; we will help you reach it.
What we collect
Your account
- Your email address. You sign in with a link or a code emailed to you, so the address is how you sign in and how we reach you about your account. It is never shown to a gym, its staff or other climbers.
- A display name. Every new account gets a generated one ("Climber 0427"), whichever way you signed up; you choose your own when you first sign in, and can change it at any time. It is shown next to what you post.
- Your grade scale preference (V, Font, YDS or French), and your settings: "hide beta until I tap", and, if you are gym staff, whether you get the weekly summary email. (Light, Dark or Automatic is not kept with your account: it is a cookie on your device, below.)
- When you accepted these terms, and which version (see Changes to this policy).
- If you sign in with Google or Apple (where a gym's sign-in page offers it), that company tells us your email address and confirms who you are, and may send your name as you set it up with them. We use it only to sign you in: it never becomes your display name.
- If you signed up from a gym's page, the name of that gym, so your first email can greet you in its name.
- An address nobody went on to use. Typing an email address into the sign-in page, or a gym inviting it, creates an account for it before the email is opened. If the link or code is never used, that account (the address and its generated name) is deleted after 30 days.
What you add at a gym
- Ascents you log (flash, send or project), with the date and number of tries.
- Ratings: the stars you give a route and the grade you suggest for it.
- Comments you post on routes.
- Video links you add to a route. When you add one, our server fetches a still picture and the video's title and length from the video's provider (YouTube, Vimeo or TikTok; nothing is fetched for Instagram or other sites) and stores the still with the link, so the route page can show it without contacting the provider. A link cannot be changed once added, but you can delete your own from the route page, and its still goes with it.
- Flags you raise on a comment or a video link (the reason and your note), which go to the gym's managers.
- Problem reports about a route (a spinning hold, a missing tag), with the reason you picked and your note, which go to the gym's setters.
What you keep private
- Private notes on routes and goals in your logbook. Only you can read them: not other climbers and not any gym, and the database refuses every account but yours. Our support tools cannot open them either; the only software that touches them without you is what acts for you (merging a duplicate account into yours, or deleting them when you close your account), and like everything else they are in our database provider's backups until those age out.
- Your logbook's figures (pyramid, sessions, projects, milestones) are worked out from your own logs and shown to nobody else.
What you send a gym
- Feedback sent from "Send feedback" at the foot of a gym's pages: the topic, your message, the page you sent it from and when. Signed in, your account goes with it, so the gym sees your display name (never your email address). Signed out, nothing about you is kept unless you choose to leave an address for the gym to write back to.
- To stop one visitor flooding a gym with signed-out messages, the server keeps a scrambled, keyed fingerprint of your IP address (a hash that cannot be turned back into the address) for two hours and then deletes it. It is never stored with your message and never shown to anyone.
If you work at a gym
If a gym makes you one of its staff, it also holds: your role there; the setter name printed on the tags of routes you set; the routes you set, the tags you printed and bound, and the staff-only notes you write; the moderation actions you take and the reasons you give; and, while an invitation is open, the email address the gym invited. Head setters, managers and admins get a weekly summary email, which you can turn off in Settings.
What we measure
To tell a gym how its tags and pages are used (how many tags were scanned, how many scans became a logged climb, how many sign-ins were finished), the server records events: a tag scanned, a route or wall viewed, a climb logged, a sign-in started or finished, a tag printed or bound, a share opened, and the searches and filters used (the words typed into a route search, lowercased and cut to 64 characters, and which filters were applied). Each event has the gym, the building and the route or wall it was about, the time, and a random visitor id from a cookie (sb_sid, below).
Events have no account, no IP address, no browser details and no referring site attached, and there is nothing to join them to your account. Gyms see them only as totals: nobody at a gym can read the events themselves. To count a share only once, and not a flood of them, the server also keeps a keyed fingerprint of the network a share came from (a hash that cannot be turned back into the address) for two hours, apart from the event. Raw events are kept for 13 months; after that they are rolled up into a count per gym, building, day and event, and the raw rows, visitor ids included, are deleted.
A search is free text, so if you type a name into a route search, that word is stored with the search event like any other.
Error reports
When a page fails, the server or your browser reports the error to us so we can fix it. Error reports are grouped by error and carry no personal data. Each describes what broke: the page's address (never what follows ? in it), the kind of error and its message (with anything that looks like an email address, a token or an account id removed first), and a few samples, each with when it happened, the kind of browser ("Safari on iOS"), the gym whose page it was and the version of the app. An error is deleted within about four months after it last happened, and a sample older than 90 days is dropped from one that keeps happening. A hashed IP address is used, for two hours, to stop one browser flooding the reports and to tell whether an error happens to more than one visitor; it is never shown or kept with a report. The email that tells our team about a new error names only the page and how often it happened, never the error's message.
What the sign-in service and our hosts record
- Signing in. Our sign-in service (Supabase, below) records, for each signed-in session, the IP address and browser description (the "user agent") it was created from, and keeps a log of sign-in events (a link sent, a sign-in, a sign-out, a change of email) with the IP address. The sign-in log also records the email address an event was for. These are used to keep accounts secure and to investigate abuse. A session ends after 30 days unused, and after 90 days at most, and ended sessions are deleted within a day. The sign-in log is kept for 30 days, and your entries in it are deleted at once when you close your account.
- Rate limits. To stop abuse, the database notes each climb, rating, comment, link, note, goal, flag, report and message an account writes (which account, which route and gym, and when) for two hours; and each attempt to enter a sign-in code, against a keyed hash of the email address and of the network it came from (made with a secret key, so neither can be turned back into the address), for a day. A daily sweep deletes these on time even when nothing new arrives.
- Our hosts' logs. Like any website, our hosting and database providers log the requests they serve, including IP addresses and browser descriptions, and keep those logs for a short time under their own policies.
Cookies and storage on your device
Setboard uses a few first-party cookies and a little browser storage. None of them is used for advertising or to follow you across other websites, and no third party sets a cookie on Setboard's pages. (Playing an embedded video is the exception: see Services we use.)
Cookies:
- Your session (
sb-…-auth-token, sometimes split into several parts): keeps you signed in. Set when you sign in; lasts until you sign out, up to about 400 days. A short-lived companion (sb-…-auth-token-code-verifier) exists only while a Google, Apple or email sign-in is completing. - Where to go after signing in (
setboard_auth_next): the page you were on when you asked for a sign-in link. 15 minutes. - What you tapped before signing in (
setboard_pending_action): if you tapped Flash, Send or a rating while signed out, what it was and on which route, so it can be saved once you are signed in. 15 minutes. - The anonymous visitor id (
sb_sid): a random value with nothing about you in it, used only to count events as described above. 30 days. - Light or dark (
setboard_color_scheme): your choice of Light, Dark or Automatic. One year; not set until you choose. - Installed app (
setboard_display): whether Setboard was opened from your home screen, so sign-in can offer a code instead of a link. Until you close the browser. - Your building (
setboard_climber_location): at a gym with several buildings, the id of the one you last looked at, so the Routes tab goes straight back to it. 180 days. - For gym staff only: the building whose wall board you last opened (
setboard_board_location, 180 days), and the routes you are putting up on set day (setboard_set_day, 6 hours).
Browser storage (it stays on your device and is never sent to us):
- Dismissed notices: which of a gym's notices you closed, and when.
- The install suggestion: how many visits you have made to a gym and whether you logged a climb there in this browser, so "Add to your home screen" is offered only to regular climbers, and when you last said "Not now". Plus two marks that last until you close the browser.
- In the installed app: the pages you moved through, for the back button, until the app is closed; and when you first opened it.
- Offline copies: the installed app keeps copies of public pages you opened while signed out (route and wall pages) so they load with one bar of signal. A page shown to you while signed in, with your notes, climbs or name on it, is never stored this way, and neither are your logbook, settings, staff or platform pages. Signing out or closing your account deletes the copies on that device. (On Android the phone's browser shares them with the installed app; a browser that never installed the app keeps none.)
Blocking cookies stops sign-in from working; everything else carries on without them.
Do Not Track
Setboard does not track you across other websites, and no advertising or tracking service runs on its pages, so there is nothing for a Do Not Track signal to switch off. We do not change what we do when a browser sends one; what this page describes is what happens either way. The one outside party that can see your activity is a video provider, and only when you press play on an embedded video.
Who sees what
- Everyone, signed in or not: your display name next to your comments and video links; route ratings as averages and suggested grades as a consensus; that a problem is open on a route, once one of the gym's setters has confirmed it or more than one climber has reported it (never who reported it; the gym's setters see every report at once); and the name a route's setter is credited by. Nobody can list Setboard's accounts, signed in or not: a signed-in climber reads their own account and, of anyone else, only the names setters are credited by on the routes they set. Nobody but you sees your grade scale preference, and nobody but you and our platform team (in its account search) sees when you created your account: a gym's staff see your names only. Who gave a rating, and when, cannot: signed in or not, anyone reads a rating only as its stars and suggested grade, and comments and video links carry your display name but not your account. Because your comments and links show your display name, someone could still connect what you posted at different gyms by that name. Choose a display name you are happy to have public.
- The gym, at that gym only: its setters and above see the ascents you logged on its routes; its staff see your ratings, comments and links (and its managers who gave each rating on its routes); its setters and above see your display name when you have a relation with the gym (you logged or rated there, hold a role there, sent it feedback, reported a problem, or posted a comment or a link on one of its routes); its managers and admins see flags you raised, feedback you sent, and on their Members page when you first and last logged or rated there and whether you are muted there; its setters see the problems you reported. A gym never sees your email address, your private notes, your goals, your logbook's figures, or anything you did at another gym. The full list is in Who owns what.
- Other climbers: what everyone sees, above. Not your ascents, not your flags or reports, not your feedback.
- Our platform team (a handful of named people at Bad Beta LLC, each granted by hand): to help you, they can find your account by email or display name (and see when it last signed in and which gyms it belongs to), change your email when you have lost the old one, disable, close or merge a duplicate account, and they read feedback climbers send about the app and the app's error reports. They set up each gym's buildings, walls, maps and domains. When a gym asks for help they can also open that gym's staff pages and see and do what its admins can there: its members' ascents, ratings, flags, reports and feedback, its moderation, and its export. Every change they make to an account, to a gym's set-up or inside a gym's staff pages is logged in the platform's log (moderation also in the gym's own); marking a feedback message or an error report as read or fixed is recorded on the message itself instead. They cannot read your private notes or goals.
- Nobody else, except the service providers below, and anyone the law requires us to tell (a valid court order, for example), or to protect someone's safety or our rights. If a company takes over Setboard, your information would go with it under this policy.
Services we use
Setboard runs on services from other companies. Each handles your information only to provide its service to us:
- Vercel (hosting): serves every page and runs the server.
- Supabase (database, file storage and sign-in): stores everything described above, the pictures (gym logos, route photos, video stills, building maps), and runs sign-in.
- Resend (email delivery): sends sign-in links and codes, email-change confirmations, a gym's staff invitations (a sign-in link to the invited address), the weekly staff summary, and our platform team's alerts about new errors.
- Cloudflare (DNS): tells browsers where Setboard's addresses point. Your traffic does not pass through it.
- Google and Apple, only if you choose to sign in with them.
- YouTube, Vimeo and TikTok: when someone adds a video link, our server asks the provider for the video's still picture, title and length. No information about you is sent; the request comes from our server.
- Embedded video players (YouTube, through its privacy-enhanced
youtube-nocookie.com, Vimeo, TikTok and Instagram): route pages show our stored still and load nothing from the provider until you press play. When you press play, the video loads from that provider, which then sees your IP address and browser and may set its own cookies and collect information under its own privacy policy. Or open the link on the provider's site instead.
The typefaces are served by Setboard itself; no page loads fonts, scripts or pictures from Google or any other third party, except a video you play.
How long we keep it
- Your account and what you added at gyms: for as long as the account is open.
- Sign-in sessions: until they end, 30 days unused or 90 days at most; then deleted within a day.
- The sign-in log: 30 days.
- When you close your account: your display name becomes "former member" everywhere, your sign-in is removed, your email address is released (and your entries in the sign-in log, which hold it, are deleted) and your gym roles end, as does any mute on you. Your private notes and goals are deleted. Your ascents, ratings, comments and video links stay, under "former member", because they are part of each gym's route history; the reports, feedback and flags you sent stay with the gym, without your name, and a gym's moderation record (a removal, a mute or unmute) keeps its entries about you under "former member". The record of which terms you accepted is kept.
- Rate-limit records: two hours (one day for sign-in code attempts, which keep a fingerprint of the address and of the network they came from, never either one itself), swept daily.
- An account nobody went on to use (an address typed into sign-in, or invited, whose email was never used): 30 days, then deleted with its entries in the sign-in log.
- The IP fingerprints for signed-out feedback and for error reports: two hours.
- Events: 13 months, then only daily counts.
- Error reports: deleted within about four months after the error last happened.
- A staff invitation: it stops working after 14 days. When it is accepted, the email address on it is cleared, and the gym keeps only the record that it was accepted (the role, the dates and which account accepted it); one never accepted is deleted, address and all, 30 days after it expired or was withdrawn.
- Logs of changes made by our platform team and by gym moderators: kept, because they are the record of who changed what. An email-change entry keeps the old and new address, so a mistake can be put back.
- Backups: our database provider keeps daily backups, so something deleted may survive in a backup until it ages out, typically within a few weeks.
- If a gym leaves Setboard, it has 90 days to take its export. Then, within 30 days (or sooner, within 30 days of the gym asking us in writing), we archive its routes, remove its domains, end its staff roles and delete what the gym itself wrote or collected: its branding and logo, announcements, feedback (with any reply address), problem reports and setters' notes, maps, tags, usage figures and exports. Its name, buildings, walls and archived routes stay, because your logbook entries point at them: your logbook keeps your climbs there, with the gym's and the route's names, and your comments, video links and ratings stay on the archived route pages as before. Its pages on Setboard's own address stay up with nothing live on them.
Your choices: see, correct, download, delete
- See and correct: change your display name, grade scale, email address and settings on your account's Settings page. Your ratings can be changed on the route page.
- Download: Settings has Download my logbook, a CSV file of every climb, rating, private note, goal, comment and video link, at every gym, your profile and settings (display name, setter name, email address, grade scale, weekly summary, beta, light or dark, when you joined), and when you accepted these terms.
- Delete: close your account from Settings, with the effect described above. We do it for you if you write to us, within 30 days.
- Remove something you posted: delete a video link you added yourself, on the route page. A gym's managers can remove a comment or a video link; write to the gym, or to us, and we will help.
- Stop the staff email: turn off the weekly summary in Settings.
- Anything else (a copy of something not in the download, a question, a correction you cannot make yourself): write to support@badbeta.app. We answer within 45 days, and may ask you to write from your account's address so we know it is you.
What we never do
- We do not sell your information, to anyone, in any form, and we do not "share" it for cross-context behavioral advertising.
- We show no ads and use no advertising or tracking services.
- We do not use climbers' data to train artificial intelligence, ours or anyone else's.
- We do not share one gym's data with another gym.
Children
You must be 13 or older to use Setboard. We do not ask your age or your date of birth, and Setboard is not directed at children under 13. If we learn that an account belongs to a child under 13, we close it, as described above. If you believe a child under 13 has an account, write to support@badbeta.app.
California privacy rights
Bad Beta LLC is based in California, and this policy is written to meet California's online privacy law (CalOPPA): it lists what we collect and who we share it with, how you review and change your information, how we announce changes, its effective date, and how we respond to Do Not Track.
The California Consumer Privacy Act (CCPA), as amended by the CPRA, does not apply to us today. It applies to a business with annual revenue above about $25 million (adjusted for inflation), or that buys, sells or shares the personal information of 100,000 or more California residents or households a year, or that earns half its revenue from selling or sharing personal information. Bad Beta LLC meets none of these. We honor these rights anyway, for everyone:
- To know what we hold about you (this page, the download, and anything more on request);
- To delete it (closing your account, as described above);
- To correct it (Settings, or ask us);
- No sale or sharing: we do neither, so there is nothing to opt out of;
- and we will never treat you differently for asking.
Shine the Light: we do not give personal information to anyone for their own direct marketing.
If you are under 18 and live in California, you can ask us to remove a comment or video link you posted. Write to us and we will remove it. (A copy may remain where the law requires it, or where someone else copied or reposted it.)
Where your information is
Setboard is operated from the United States and its data is stored in the United States. During the pilot, Setboard is offered in the United States only.
Security
Everything travels over encrypted connections. The database checks every read and write against who is asking, so a gym's staff reach only their own gym and nobody but you reaches your private notes. Photos a gym uploads are re-encoded before they are stored (in the uploader's browser for route photos and logos, on our server for building maps and video stills), which drops hidden details such as where a photo was taken. No system is perfectly secure; if something goes wrong that affects your information, we will tell you as the law requires.
Changes to this policy
The date this version took effect and what changed are at the top of this page. When we make a material change, we announce it in the app before it takes effect, and the next time you sign in we ask you to review and accept the new version. Earlier versions are available on request.
Contact
Bad Beta LLC, operator of Setboard: support@badbeta.app.