Privacy Policy
Last updated 9 September 2026
Who we are
Crescive is a training app for climbers, run by Berg Climbing, a sole proprietorship registered in Norway.
Berg Climbing
Fougstads gate 41A
0173 Oslo, Norway
Org. nr. 838 214 932
Berg Climbing is the data controller for everything described here. Questions about your data go to post@crescive.app.
The short version
- We store your logged exercises, plus the basics needed to run an account.
- Logging recovery data is optional (sleep, HRV, mood, soreness).
- We do not sell your data, we do not run ads, and no other user can see anything of yours.
- Your data is stored in Frankfurt.
- You can download your training history whenever you want. To delete your account, email us and we will permanently delete it.
What we collect, and why
Your account
Email address, password, display name, time zone and the date you accepted the terms. If you sign in with Google, we receive your name, email address and profile picture from Google instead of a password. Your password is hashed by our authentication provider and we never see it.
Legal basis: performance of our contract with you.
Your training data
Sessions and exercises: date, session type, duration, effort (RPE), how it felt, hang times, added weight, sets and rest. Test results such as max hangs and critical force.
Training goals: the grade you are chasing, where, and roughly when. The rough picture of recent training you give during onboarding.
We use this to calculate your training load, track your ACWR, and generate and adapt your weekly plan.
Legal basis: performance of our contract with you.
A max hang number says what you can pull, not what your health status is, so we treat test results as performance data rather than health data.
Where you train
Session location is a free text field. If you enter a crag you are recording where you were on a given day. We store it as you typed it and use it for nothing except showing it back to you.
The app never asks for your device location and we do not collect GPS. Our analytics does read a rough location from your IP address, accurate to a city. That is covered under Technical data below.
Recovery, which is health data
Sleep quality, sleep duration, heart rate variability, mood, finger soreness, body soreness, and any injury, sickness or tweak you record.
In the EEA and the UK this is special category health data, because we use it to work out how recovered you are and to change what we ask your body to do next. That needs your explicit consent, separately from everything else.
Logging recovery is optional and opt in, and Crescive works without it. We ask you to agree the first time you open the recovery form, separately from anything you agreed to when you signed up. You can withdraw in your profile at any time. Withdrawing deletes what you have already logged, because once consent is gone we have no basis to keep it. It does not affect the rest of your account.
Legal basis: your explicit consent, under Article 9(2)(a) GDPR.
Notes fields
Session notes and recovery notes are free text, capped at a thousand characters. Skip reasons are capped at five hundred.
We do not analyze them or feed them into anything. They are stored and shown back to you. If you write about an injury there, you are putting health data into a text box, so write only what you want stored. Leaving them blank changes nothing about how the product works.
Technical data
Browser and device type, pages visited, and errors. Our host and our database also see your IP address. Our analytics does not store it, but reads a rough location from it first, down to a city. Our error monitoring is configured not to collect it at all.
We use this to keep the service running, fix crashes, and see which parts of the app people use. We do not build advertising profiles and we do not sell any of it.
Legal basis: our legitimate interest in operating a working product.
Checking the load model still works
We look at training and recovery data in aggregate to test whether the load model behaves the way it claims to. This is what stops a broken calculation from quietly shipping to everyone. Results are statistical and are not traced back to any person.
Legal basis: our legitimate interest in keeping the model honest.
The waitlist
If you signed up on the landing page we hold your email address and which form you used, and we use it to tell you when Crescive is available. Once we have told you, we delete it. If Crescive has not opened within a year we delete it anyway, and you can ask us to remove you before then.
Legal basis: your consent.
How your plan gets written
Crescive generates your weekly targets automatically. It reads the sessions and recovery data you logged, applies established sport science methods (EWMA, ACWR, sRPE), and produces a prescription. A scheduled job runs this once a week.
You are the one deciding. Crescive does the load math. It does not know you slept badly for reasons you did not log, or that your shoulder has been grumbling. Its output is a forecast, not a verdict. Edit it or ignore it.
It is not medical advice. Crescive is a training tool, not a healthcare service. If you are injured or in pain, talk to a physiotherapist or a doctor.
Because the plan is generated rather than decided by a person, you can ask us to explain how a particular week was calculated. Write to post@crescive.app.
Who else touches your data
Supabase, PostHog and Sentry are processors working under contract for us. They act on our instructions and may not use your data for their own purposes.
Vercel runs and serves the app. Your data passes through their machines as pages are built and sent to you, and their request logs hold details like IP addresses. They do not hold your training history. That sits in the database.
- Supabase. Database and authentication. Everything you log is stored here. Frankfurt.
- Vercel. Hosts and serves the app. Sees request data such as IP addresses. Frankfurt, on a global edge network.
- PostHog. Product analytics and session recording. EU cloud, Frankfurt.
- Sentry. Error monitoring. EU region, Frankfurt.
- Google. Only if you choose to sign in with Google. Google's own infrastructure.
Google is the exception. When you sign in with Google we receive your profile details from them, but Google is not working under contract for us and decides its own uses of your data. We do not control that and we are not responsible for it. Read Google's privacy policy to see what they do and to change your settings.
We do not share your data with other users, gyms, coaches, advertisers or AI services. We would share it if the law required it, or if the business or its assets were transferred to someone else, and we would tell you before anything moved.
Cookies and analytics
Cookies. We use only cookies necessary, and as few as possible. We use them for two things: keeping you logged in, and remembering small interface choices, like which panels you collapsed. No advertising cookie, no tracking pixel, no third party dropping anything on your device.
Analytics. PostHog records how the app is used: which pages, which clicks, how far people scroll. It runs without cookies, keeps nothing on your device between page loads, and never links what it sees to your account.
Session recording. PostHog also records screens as you move through them. Anything you type is masked as you type it, so passwords, emails and typed values do not appear. Once a value is saved and shown on screen, the recording captures it as rendered, which can include your notes, weights and grades.
Where your data lives
Your database, analytics and error logs are in Frankfurt, which is where the app is hosted.
All services we use are American companies, so your data can be reached from outside the EEA even though it is stored in Europe. For the database, the analytics and the error monitoring, those transfers run on the European Commission's Standard Contractual Clauses, and we will send you a copy on request.
Requests to the app are handled at whichever of our host's locations is nearest you before they reach Frankfurt.
How long we keep your data
While your account is open we store all your training history.
When you ask us to delete your account we remove your data from the live database, and it is permanently deleted. We keep no shadow copy and no anonymised profile of you.
Some things sit outside your account and expire on their own rather than when you delete it. Our host keeps request logs, IP addresses included, for one hour. PostHog deletes session recordings after thirty days, and Sentry deletes error reports after thirty days.
One exception. We keep aggregated statistics that cannot be traced to any person, which is how we check the load model still behaves.
How we protect it
Traffic is encrypted in transit and data is encrypted at rest. Every query the app makes is scoped to the account that made it, and the database refuses direct outside access to your rows on top of that. Passwords are hashed by our authentication provider.
No system is unbreakable. If there is a breach that puts your data at risk, we notify the Norwegian Data Protection Authority within 72 hours and tell you directly if the risk to you is high.
Your rights
You can:
- See your data. Ask for a copy of everything we hold on you.
- Correct it. Most of it you can edit in the app.
- Delete it. Email us and we delete your account.
- Take it with you. Download your training history as a CSV from your profile.
- Restrict or object. Tell us to stop processing something and we will, unless we have a legal reason not to, which we will explain.
- Withdraw consent. For recovery data, in your profile. For waitlist email, by contacting us directly.
- Ask about the algorithm. How a week was calculated, and ask a human to review it.
Write to post@crescive.app. We will try to answer as soon as possible and no later than within one month, which is the legal limit. If a request is genuinely complicated we can take longer, and we will tell you why.
Wherever you live
Crescive is run from Norway, so this policy is built on European rules. Rather than write a separate section for every country, we give everyone the same rights wherever they log in from.
If we get it wrong
Tell us first, at post@crescive.app.
If we do not sort it out, you can complain to the Norwegian Data Protection Authority:
Datatilsynet
Postboks 458 Sentrum, 0105 Oslo
postkasse@datatilsynet.no
datatilsynet.no
You can also complain where you live, where you work, or where you think the problem happened. In the EEA that is your own national data protection authority. In the UK, the Information Commissioner's Office (ico.org.uk). In Canada, the Office of the Privacy Commissioner (priv.gc.ca). In Australia, the Office of the Australian Information Commissioner (oaic.gov.au). In New Zealand, the Office of the Privacy Commissioner (privacy.org.nz).
Age
You need to be 18 to use Crescive. We do not knowingly hold data on anyone younger, and if we find out we have, we delete the account.
If you are under 18 and training seriously, work with a coach who can watch you climb.
Changes to this policy
If we change something that affects you, we will tell you in the app or by email before it takes effect. The date at the top reflects the current version.