BetaVision privacy policy
Effective date: 8 October 2026. Policy version 2026-10-07. Contact: privacy@betavision.app.
BetaVision is a training log and movement-analysis app for climbers. This policy says what it does with your information. In short: everything happens on your phone unless you choose to sign in, and what you then send us is limited to what the feature you turned on needs.
1. Without an account (the default)
You can use the whole free app without signing in: the training log, planner, interval timer, recording and on-device analysis of climbing clips, compare, assessments, trends and local export.
- Your log, plans, journal, body measurements and assessments are stored in the app's private storage on your phone.
- Videos you record stay on your phone. Pose analysis (finding body positions in each frame and measuring your movement) runs on the phone's own processor with models that are part of the app. No frame is sent anywhere.
- The optional language-model coach runs on the phone from a model file you install yourself.
- The app makes no network requests in this mode, except those made by Google Play itself (for example, to show subscription prices if you open the upgrade screen), a Mountain Project tick list if you paste your public profile link under Connections and tap Fetch (the app then downloads that list from mountainproject.com; nothing about you is sent to us), and, in beta builds only, feedback you choose to send (see "Beta feedback" below). Sharing a clip through your phone's share menu hands it to the app you pick, under that app's own policy.
2. With an account
Signing in is optional. You can sign in with Google (we receive your Google account's email address, name and a Google account identifier, verified by Google) or with an email link (we receive the email address you type). We use these to identify your account, to send sign-in links and to answer you if you contact us. Your name is stored encrypted (see section 7); your email address is stored readable, because it is how you sign in.
Your devices
When you sign in, the app tells our server which device it is on, so you can see and sign out your devices under Settings > Account, and so we can apply the device limit. We store, for each installation of the app: a random identifier created for that installation (not an advertising identifier, not tied to the hardware), the phone's make and model (stored encrypted), the Android version, the app version, and when the device first and last signed in or refreshed its session. We do not store the device's IP address with it. We use this for account security only.
A free account can be signed in on one device at a time; Premium on up to five. Signing in on another device when the account is at its limit explains this and lets you sign the other device out (its data stays on it). A device you sign out loses access to your account at once.
Free: encrypted backup
With an account and a backup passphrase, the app uploads a backup of your database (your log, plans, journal, measurements and assessments; not your videos). The backup is encrypted on your phone before it is sent, with a key derived from your passphrase (AES-256-GCM, key from PBKDF2). We store only the encrypted file and an identifier of the key; we cannot read your backup, and we cannot recover it if you forget the passphrase. We keep the two most recent backups and delete older ones.
Cloud sync (optional, any plan, off until you turn it on)
Cloud sync is a switch under Settings > Account. It is off unless you turn it on, on each phone, after a screen that explains what it uploads. While it is on, and only while you are signed in, the app uploads:
- Your training log: sessions, sets with their loads, reps, durations and grades, sends, plans and how far you are through them, assessments and their results (including your answers to the mental and tactics questionnaire), technique-check results, imported Mountain Project ticks, journal entries, body measurements, notes, clip analysis results, and your athlete profile (experience, goals, equipment, target grades).
- Your clips with their sound, if you recorded with the microphone on. Clips upload on Wi-Fi only unless you allow mobile data, and wait while the battery is low.
- App usage: which screens you open and which features you use (for example "a session was finished, with an effort rating of 7"), with the time, the app version and your device identifier. Never text you type, never the content of your log or clips.
We use this to keep your data in your account, to restore it to a new phone, to keep your devices in step (Premium), and to understand how the app is used so we can improve it.
How it is stored: the parts of your log that are numbers, categories and dates (loads, grades, durations, plan structure, assessment scores, the ratings and multiple-choice answers you give in the mental and tactics questionnaire, analysis measurements) and the usage events are stored readable on our server, because that is what makes them useful for analysis. Everything you write or that describes your body is encrypted by our server before it is stored: notes, journal text, your written questionnaire answers and the coach's summaries of them, names and titles you give things, locations, body weight, height and other body measurements, and any field we have not classified. Clips are stored privately (see section 7). Unlike the free backup, our server holds the key to this encryption, because it has to give your data back to your devices; the database does not hold the key.
Turning cloud sync off stops all uploads from that phone at once. It also offers to delete everything cloud sync uploaded from our server (your synced log, usage events and uploaded clips). Without that, what was already uploaded stays until you delete it or your account.
Model training (optional, a separate choice)
Separately from cloud sync, you can tick "Let BetaVision use my synced clips and training data to improve its models." It is unticked unless you tick it, and you can untick it at any time in Settings > Account. We record when you made the choice and under which version of this policy. Synced data from accounts that have not ticked it is marked so it is excluded from every set of data we use to train or evaluate models; unticking it marks everything you have synced the same way from then on. Models already trained cannot "unlearn" data used before you unticked it, but it is not used again. We never use your data for model training without this choice, and the free encrypted backup is never used (we cannot read it).
Premium: cloud features
If you subscribe to BetaVision Premium:
- More devices and storage. Up to five signed-in devices kept in step by cloud sync, and more space for clips (20 GB instead of 2 GB).
- Cloud 3D analysis. When you ask for a 3D reconstruction, the two clips involved are processed on our server to compute a 3D model of your climb. The result is kept with your account until you delete it or your account.
- Hold detection. Premium hold detection uploads a still photo of the wall to our server, where the holds on it are found; only stills of the wall are sent, chosen from a moment of the clip with nobody on the wall, and the photo and its result are kept with your account until you delete them or your account.
- Lending your camera for someone else's 3D climb. A Premium member can pair their phone with yours so your phone films their climb from a second angle. You need to be signed in, on any plan. Your phone's recording of their climb is uploaded straight into their account and deleted from your phone once our server confirms it arrived; it never enters your own log, library or backup, and you keep no copy. It counts against their storage, and they can delete it. Your account is linked to the 3D result so it appears in your "3D climbs" list with the date, their display name (never their email) and its state; opening it needs Premium. The owner can unlink you; deleting your account removes the link only, and deleting theirs deletes the result. They see your display name as the person who lent the camera.
- Cloud coach. If you use the cloud coach, the question you ask and the training summary it needs are processed on our server to produce an answer.
- Purchase verification. Google Play handles payment. We receive a purchase token from the app and confirm it with Google to know whether your subscription is active. We never see your card or payment details.
Beta feedback (beta builds only)
If you joined the BetaVision beta, the app shows a feedback button. When you press Send on it (and only then) the app sends us:
- the category you chose and the text you typed;
- a screenshot of the screen you were on, only if you ticked "Attach a screenshot" (it is unticked every time);
- the name of that screen and of the last 20 screens you visited, the app version, your phone's model, Android version and language setting, your account id if you are signed in, a random identifier made for feedback only, and the last 200 lines of the app's own diagnostic log.
It never sends your videos, your training records or anything you typed elsewhere in the app. Feedback works without an account. If you are offline, the report waits on your phone and is sent when you are back online. We use feedback only to fix and improve the app, and keep it until we no longer need it. If you delete your account, your feedback is anonymised: the link to your account is removed and your screenshots are deleted, while the text stays. To have your feedback deleted entirely, contact us at the address above. Production builds have no feedback button and send none of this.
3. What we do not do
- No advertising, no ad identifiers, no ad networks.
- No third-party analytics or crash-reporting services. The app contains none. The only usage information we receive is our own usage events, and only while cloud sync is on.
- We do not sell your information or share it with anyone for their own purposes.
- We do not use your videos or records to train models unless you tick the model-training box.
- We never make your clips public or give anyone a link to them.
4. Who processes data for us
Our server and storage run on infrastructure we rent from Google Cloud (Google LLC, United States, region us-central1) for the server, and Neon (Neon, Inc., United States, region us-east-2) for the database and stored files. Email sign-in links are sent through an email delivery provider, Resend (Resend, Inc., United States). Google provides sign-in with Google and Google Play billing under Google's own privacy policy. These providers act on our instructions only.
5. How long we keep it
- Account details: until you delete the account.
- Free backup: the two most recent encrypted backups, until you delete them or the account.
- Synced records, usage events and clips uploaded by cloud sync: until you turn cloud sync off and choose to delete them, or delete the account.
- 3D results and the clips sent for them: until you delete them or the account.
- Device records: until you delete the account (a device you sign out is kept, marked signed out, so the list shows what happened).
- Your cloud-sync and model-training choices and the record of when you made them: until you delete the account.
- Server logs (IP address, time, request path; used for security and rate limiting): 30 days.
- Beta feedback: until it is no longer needed to fix or improve the app; anonymised (account link and screenshots removed) when you delete your account.
- After account deletion we keep a single audit record containing a one-way hash of the account identifier and the time of deletion, so that we can show the deletion happened. It does not identify you.
6. Deleting your data
- In the app: Account > Delete account. This deletes your account, every backup, every synced record, every usage event, every uploaded clip, every 3D result, your device records and your consent records from our server immediately. It does not delete the data on your phone; uninstall the app or clear its storage for that.
- Only what cloud sync uploaded: turn cloud sync off and tick "Also delete my synced data from the server".
- By email: write to privacy@betavision.app from the address on the account and we will delete it within 30 days.
- Without the app: https://betavision.app/delete-account describes the email route and works without the app installed.
- Cancelling a subscription is done in Google Play and does not delete data by itself.
7. Security
Traffic between the app and our server uses HTTPS. Session tokens and your derived backup key are stored on the phone encrypted with a key held in the Android Keystore.
On the server, personal and free-text fields (your name, notes, journal text, titles, locations, body measurements, device model, and any field we have not classified as plain training data) are encrypted by our application with AES-256-GCM before they reach the database, using a key kept separately from the database in our hosting provider's secret store. Each encrypted value records which key sealed it, so keys can be replaced. Clips are stored in private object storage under your account, encrypted at rest by the storage provider named in section 4; they are never public, and the app reaches them only through signed links that expire after 15 minutes. The database and its backups are encrypted at rest by the hosting provider. No system is perfectly secure; if we learn of a breach affecting your information we will tell you.
8. Children
BetaVision is not directed at children under 13 (or the minimum age in your country) and we do not knowingly collect information from them. If you believe a child has created an account, contact us and we will delete it.
9. Your rights
Depending on where you live (for example under the GDPR or the CCPA) you may have the right to access, correct, export or delete your information, or object to its processing. The app's local export gives you your data at any time; for anything else, contact us at the address above.
10. Changes
If this policy changes we will update the effective date and, for significant changes, tell you in the app before they apply. The current version is always at https://betavision.app/privacy.