Privacy
Cragdiary stores the minimum needed to run a shared climbing journal. No ads, no trackers, no analytics scripts. This page is the information notice required by the GDPR (Articles 13 and 14).
- Who is responsible
Cragdiary is the data controller for everything described here. For any question about your data, or to exercise the rights listed below, write to cragdiary@pm.me — that address reaches the person who runs the site.
- What we store
Your account (username, display name, password hash — never the password itself, optional recovery email), your entries, photos, and profile pictures. That's all.
- Why, and on what legal basis
To provide the journal you signed up for — that is performance of a contract (GDPR Article 6(1)(b)). The recovery email is optional; besides resetting your password, it is used only for the email notifications you switch on yourself, on your notifications page, which is your consent (Article 6(1)(a)) and which every such email carries a one-click link to withdraw. Those emails may include one photo from the outing, loaded from cragdiary.com when you open them — so the server sees the request, as it would for any page. Nothing is recorded about it: no tracking pixel, no open rate, no per-person statistics. Rate-limiting login attempts relies on our legitimate interest in keeping accounts safe (Article 6(1)(f)).
- How long we keep it
Your account and its contents stay for as long as the account exists. Delete the account and everything goes with it, immediately and permanently — there is no grace period and no backup copy kept for later. Login-attempt records are pruned automatically. Emails you send us are kept only as long as needed to answer them.
- Cookies
Two cookies, both needed for the site to work: one keeps you logged in (90 days), the other remembers your language. Your browser also stores two preferences locally (localStorage), which never reach us: the visual theme, and whether you have seen the welcome tour. No analytics, no advertising, nothing shared with anyone — all of it is strictly necessary, which is why there is no cookie banner to click through.
- Photos
Photos are recompressed in your browser before upload, which strips camera metadata such as GPS position. They belong to you.
- Who else processes it
Vercel hosts the site (a US company; the EU–US Data Privacy Framework and standard contractual clauses cover the transfer). Neon runs the database, in Frankfurt. Resend sends password-reset, feedback and notification emails. Nobody else receives your data, and none of them may use it for their own purposes.
- Third-party searches
Route and place searches — in the editor and in Cragseeker — are relayed to Camptocamp, OpenBeta and Photon/OpenStreetMap (your search text, and for Cragseeker the map area you are looking at). Which databases Cragseeker asks is yours to choose, next to the activity. Switching on the shelters layer sends that same map area to refuges.info. Map tiles load from OpenStreetMap. These see the search, never your account.
Camptocamp — privacyOpenBeta — aboutrefuges.infoOpenStreetMap — privacy
- Visibility
You choose per entry (public, link-only, private) and per profile (public, link-only, private) what others can see.
- Your rights
You may ask for access, correction, erasure, restriction, portability, and object to processing. Two of those are buttons rather than requests: export your data from your profile settings, and delete your account there too. For anything else, write to cragdiary@pm.me. If you think your data is mishandled you can complain to the CNIL, the French supervisory authority.
- Age
Cragdiary is not intended for children under 15. If you are younger, ask a parent or guardian before creating an account.
- Deleting
You can delete any entry, and delete your whole account from your profile settings — everything goes with it, immediately and permanently.
Last updated: 14 August 2026