top of page

Privacy Policy

LAST UPDATED: December 15, 2025

Quick Summary ​

  • What we collect: Your account information (name, email, phone), learning progress, voice recordings (if you use voice chat), text interactions, and website usage data.

  • How we use it: To run our AI coach (Goldi), track your learning, improve our services, provide support, process payments, and send important notifications.

  • How we protect it: AES-256 encryption, TLS 1.2+ for transmission, multi-factor authentication for staff, and regular security reviews.

  • Your rights: Access, correct, or delete your data anytime by contacting us.

  • Voice chat: Voice recordings kept for 90 days, then permanently deleted. Transcripts retained like other conversation data.

  • Conversation history: Stays with you while your account is active. Deleted 12 months after account becomes inactive.

  • AI governance: No training on your data, regular bias audits, transparent AI practices.

  • Questions? Contact us at privacy@climbtogether.co.

 

Your Consent

By using Climb Together services, you agree to this Privacy Policy. If you disagree, please don't use our services. When you sign up, we'll ask you to explicitly consent by checking a box that says "I have read and agree to the Privacy Policy." You can withdraw your consent at any time by deleting your account, though this won't affect our previous lawful use of your information.

Introduction

At Climb Together, we believe in being transparent about how we collect and use your data. This policy explains what information we collect, how we use it, and the choices you have regarding your data. We've written this in plain language to make it easier to understand.

What Information We Collect

We collect several types of information when you use our services:

Account Information

  • Your name, phone number, email address, and other personal data that can reasonably be linked to you or your household ("Personal Data")

  • Login information (password is encrypted using bcrypt hashing)

  • Profile information you provide (career goals, work history, educational background)

  • User archetype (one of five personas based on your pre-survey responses)

 

Learning Data

  • Your course progress and completion rates

  • Assessment results and readiness scores

  • Interactions with learning materials

  • Time spent on different coaching sessions

  • Skills developed and learning objectives achieved

 

AI Coaching Data

  • Text conversations with Goldi (our AI coach)

  • Voice recordings and transcripts (if you use voice chat)

  • Emotional tone and expression analysis from voice interactions

  • Feedback you provide on AI responses

  • Assessment scores and coaching effectiveness metrics

 

Usage Data

  • How you use our platform (pages visited, features used)

  • Device information (browser type/version, operating system)

  • IP address and general location (not precise geolocation)

  • Time spent on different features

  • Date and time stamps of your visits

  • Duration of visits

  • Unique device identifiers and diagnostic data

 

Tracking & Cookies Data 

We use first-party cookies and similar tracking technologies, such as web beacons and pixels, to track activity on our Service, hold certain information, including usage and demographic information about visitors over time, to track new visitors to our websites, to prevent fraud, to understand interactions with our websites and emails, and improve the performance of our Services and websites.

 

Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, pixels, and scripts to collect and track information and to improve and analyze our Service. We do not use this information to personally identify you.

 

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. See www.allaboutcookies.org to learn how to disable cookies on your browser or otherwise opt out of cookies. However, if you do not accept cookies, you may not be able to use some portions of our Service.

Examples of Cookies we use: 

  • Session Cookies: We use Session Cookies to operate our Service.

  • Preference Cookies: We use Preference Cookies to remember your preferences and various settings.

  • Security Cookies: We use Security Cookies for security purposes.

  • Necessary Cookies: We use Necessary Cookies to provide the Site(s) and authenticate users.

 

Some cookies may be active during the time you are viewing a website ("Session cookies"). Other cookies may remain on your computer after you have closed your browser or turned off your computer ("Persistent or Preference cookies"). We also deploy "Necessary" cookies to provide the websites and Services, such as to authenticate and identify returning users. We do not use cookies to serve online advertising, whether on our websites or on other websites.

 

The cookies sent by our websites are used only by the websites and are not used to collect Personal Data without your permission. If you choose to provide us with personal information (such as your email address), that information could be linked to the data stored in the cookie. We reserve the right to change our use of cookies and our practices regarding linkage to Personal Data without prior notification.

Payment Information

  • We use Stripe to process payments and don't store your complete credit card information.

  • Stripe is PCI-DSS Level 1 certified (highest level of payment security).

  • Only last 4 digits of card and expiration date stored for reference.

  • We reserve the right to change our payment processor without prior notification.

 

How We Use Your Information

We use your information to:

  • Provide and personalize our Services: Operate Goldi AI coach, deliver curriculum content, allow access to interactive features

  • Improve AI coaching capabilities: Enhance Goldi's responses, assessment accuracy, and personalization (never using your data for training AI models)

  • Track your learning progress: Maintain conversation continuity across coaching sessions, monitor skill development

  • Keep our platform secure: Prevent fraud, detect security threats, protect against attacks

  • Communicate with you: Send important updates, necessary service notifications, optional educational content, and marketing (opt-out available)

  • Remember your preferences: Username, account settings, coaching progress

  • Process payments: Handle subscription and transaction processing via Stripe

  • Analyze and improve: Gather insights to improve our Service, better understand user needs, protect the Services

  • Monitor usage: Track Service usage to optimize performance

  • Detect and prevent issues: Address technical problems, security threats

  • Provide support: Respond to your questions and help requests

  • Measure effectiveness: Understand traffic and usage trends using third-party analytics tools

  • Comply with legal requirements: Meet regulatory obligations, resolve disputes, enforce agreements

 

AI Technologies & Governance

AI Systems We Use

Climb Together uses artificial intelligence to power Goldi, your career networking coach. Here's how:

 

1. Conversational AI (HumeAI Empathic Voice Interface + Anthropic Claude)

 

  • Powers Goldi's voice and text conversations

  • Understands your questions and provides personalized coaching

  • Adapts responses based on your learning progress and goals

  • Current models: HumeAI EVI3, Anthropic Claude Sonnet 4.5

 

2. Voice Processing (HumeAI)

 

  • Converts your speech to text

  • Analyzes emotional tone and expression

  • Generates natural-sounding voice for Goldi's responses

  • Helps Goldi respond empathetically to your emotional state

 

3. Content Retrieval (RAG System)

 

  • Retrieves relevant coaching content from our curriculum

  • Ensures responses are grounded in proven career development methodology

  • Personalizes learning paths based on your progress and archetype

 

4. Assessment System (LLM-as-Judge)

 

  • Evaluates your coaching session readiness

  • Scores conversations against learning rubrics

  • Provides feedback on areas for improvement

  • Uses Anthropic Claude Sonnet 4.5

 

Our AI Commitments

No Training on Your Data:

 

  • HumeAI and Anthropic contractually commit to NOT training AI models on your conversations

  • Your data is processed to provide coaching, not to improve publicly available AI systems

  • Voice recordings and transcripts are never sold to third parties

  • Exception: Anonymized, aggregated data may be used for product improvement only

 

Bias Monitoring & Fairness:

 

  • Regular bias audits across our five user archetypes (starting Q1 2026)

  • Assessment accuracy validated against expert human scorers

  • Fairness metrics tracked continuously

  • No archetype systematically disadvantaged

 

Transparency:

 

  • You always know when you're interacting with AI (Goldi is clearly identified)

  • Model information disclosed in this policy

  • Regular transparency reports (starting Q2 2026)

  • Updates communicated when AI systems change

 

Human Oversight:

 

  • Monthly review of conversation samples (10% random sample)

  • Expert panel reviews AI coaching quality

  • Escalation triggers for safety concerns

  • Product team addresses patterns and issues

 

Security:

 

  • Input validation prevents prompt injection attacks

  • Rate limiting prevents abuse

  • Master prompt protections maintain coaching boundaries

  • Continuous monitoring for suspicious activity

 

For more information about our AI governance, see climbtogether.co/ai-governance (coming Q1 2026).

 

 

About Voice Recordings

If you use voice chat with Goldi:

 

Real-Time Processing:

 

  • Your voice is processed in real-time to generate coaching responses

  • Analyzed for emotional tone and expression to enable empathetic coaching

  • Never sold or shared beyond our essential service provider (HumeAI)

 

Data Retention:

 

  • Voice recordings (audio files): Retained for 90 days, then permanently and automatically deleted

  • Transcripts: Retained like other conversation data (as long as your account is active)

  • Why 90 days? Audio files are large and primarily used for quality improvement. After 90 days, transcripts serve the purpose of maintaining conversation history.

 

Your Control:

 

  • You can choose to use text-only chat instead

  • No penalty for not using voice features

  • All coaching capabilities available via text

 

Security:

 

  • Voice data encrypted in transit (TLS 1.2+) and at rest (AES-256)

  • Access limited to authorized personnel only

  • Processing by HumeAI under strict security and privacy requirements

 

How We Protect Your Information

Your security is important to us. We protect your data by:

 

Encryption:

 

  • Data at rest: AES-256 encryption (industry-standard strong encryption)

  • Data in transit: TLS 1.2 or higher (protects data traveling over internet)

  • Password storage: bcrypt hashing and salting (passwords never stored in plaintext)

 

Access Controls:

 

  • Multi-factor authentication (MFA) required for all staff with system access

  • Role-based access control (RBAC) - employees only access data necessary for their job

  • Least privilege principle - minimum necessary access granted

  • Quarterly access reviews to remove unnecessary permissions

 

Security Monitoring:

 

  • Regular testing of our security systems

  • Continuous monitoring for suspicious activity

  • Automated alerts for security threats

  • Incident response procedures documented and tested

 

Vendor Security:

 

  • All service providers must meet strict security standards

  • Required certifications: SOC 2, ISO 27001, GDPR, CCPA compliance

  • Annual security audits of vendors

  • Vendor contracts include security requirements and breach notification obligations

 

Business Continuity:

 

  • Daily encrypted backups

  • Disaster recovery procedures tested quarterly

  • 99.9% uptime guarantee with failover systems

 

Important Note: While we implement strong security measures, no system is 100% secure. We cannot guarantee absolute security but commit to industry-leading practices and continuous improvement.

 

Who We Share Your Information With

Lawful Basis for Processing

We have lawful bases for processing your Personal Data:

 

Consent: By using our services, you consent to our collection, use, and sharing of your Personal Data as described in this Privacy Policy.

 

Legitimate Interests: We process your Personal Data for our legitimate interests (balanced against your rights and freedoms), including:

 

  • Safeguarding our IT infrastructure and intellectual property

  • Improving our Services and user experience

  • Preventing fraud and ensuring platform security

 

Contractual Necessity: Processing necessary to provide Services you've requested and fulfill our obligations to you under our Terms of Service.

 

Legal Compliance: Processing required or permitted by law, including:

 

  • Complying with government inspections, audits, and valid requests

  • Responding to legal process such as subpoenas

  • Meeting regulatory requirements (GDPR, CCPA, FERPA, COPPA)

 

Protecting Rights: Processing necessary to protect our interests, pursue legal rights and remedies, defend litigation, prevent fraud, and manage complaints or claims.

Service Providers

We may employ third-party companies and individuals to facilitate our Service ("Service Providers"), provide the Service on our behalf, perform Service-related services, or assist us in analyzing how our Service is used.

 

These third parties have access to your Personal Data only to perform tasks on our behalf and are obligated not to disclose or use it for any other purpose.

 

We currently share your Personal Data with:

Service Provider
Purpose
Data Access
Security Certification
Vercel
Platform hosting and infrastructure
Infrastructure data
SOC 2 Type II, ISO 27001
Stripe
Payment processing
Payment information (PCI-DSS compliant)
PCI-DSS Level 1, SOC 2, ISO 27001
TalentLMS
Learning content hosting and progress tracking
Course data, completion status
Security certified
PostHog
Anonymous usage analytics
Behavioral data (anonymized after 12 months)
SOC 2
Langfuse
AI monitoring and performance tracking
Conversation logs, assessment data
Security framework
Anthropic
Text generation for AI responses
Conversation text (via HumeAI)
SOC 2 Type II, ISO 27001
HumeAI
AI-powered voice and text interactions
Conversations, voice recordings, emotional analysis
Security framework
Clerk
Secure login and authentication
Email, password hash, MFA tokens
SOC 2 Type II

Vendor Requirements:

 

  • All vendors must comply with SOC 2, ISO 27001, GDPR, and CCPA (or equivalent security standards)

  • Must implement encryption, access control, and monitoring tools

  • Complete annual security audits and risk assessments

  • Delete all Climb Together data within 30 days of contract termination

  • Provide Certificate of Destruction or cryptographic erasure confirmation

 

We NEVER:

 

  • Sell your data to third parties, advertisers, or data brokers

  • Share your data beyond the service providers listed above (except as required by law)

  • Use your data for targeted advertising

  • Allow vendors to train publicly available AI models on your data

 

Business Transactions

If Climb Together is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.

Links To Other Sites

Our Service may contain links to other sites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.

 

Your browsing and interaction on any third-party website or service are subject to that third party's own rules and policies. We are not responsible and have no control over any third-parties that you authorize to access your Personal Data. If you use a third-party website or service and allow them to access Personal Data, you do so at your own risk.

 

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Data Minimization & Purpose Limitation

Our Commitment

Climb Together adheres to data minimization principles, collecting only the information necessary to provide our AI-powered career coaching services and comply with legal obligations.
 

What We Don't Collect

  • Social Security Numbers or government ID numbers

  • Credit card information (processed by Stripe, not stored by us)

  • Precise geolocation data (only general location from IP address)

  • Biometric data beyond voice tone analysis

  • Information about family members or household contacts

  • Financial account information beyond payment processing

  • Medical or health information

  • Criminal history or background checks

  • Social media credentials or passwords

  • Browsing history outside our platform
     

Purpose Limitation Principles

We collect data ONLY for these purposes:

 

  1. Service Delivery: Operate Goldi AI coach and provide learning platform

  2. Account Management: Authenticate users and manage access

  3. Learning Progress: Track course completion and skill development

  4. Platform Improvement: Analyze usage patterns and optimize features (anonymized)

  5. Communication: Send necessary service updates and optional educational content

  6. Payment Processing: Handle transactions via Stripe

  7. Legal Compliance: Meet regulatory requirements and respond to legal requests

  8. Security: Prevent fraud and protect platform integrity

 

We do NOT use your data for:

 

  • Selling to third-party advertisers or data brokers

  • Training publicly available AI models (our providers contractually commit to this)

  • Profiling for discriminatory purposes

  • Targeted advertising outside our platform

  • Sharing with employers without your explicit consent

  • Background checks or employment verification

  • Any purpose not disclosed in this policy
     

Data Collection Decisions

Before collecting any new data type, we evaluate:

 

  • Is it necessary for core service functionality?

  • Can we accomplish the goal with less data?

  • Do users expect us to collect this information?

  • What are the privacy risks?

  • How will we protect it?

  • When should we delete it?

 

Regular Data Audits

  • Annual review of all data collection practices

  • Quarterly assessment of data retention policies

  • Continuous evaluation of third-party data sharing

  • User feedback integration for privacy concerns

 

Your Control Over Data Collection

  • Opt out of voice chat (use text-only instead)

  • Opt out of marketing communications (service notifications still sent)

  • Opt out of analytics cookies (may limit functionality)

  • Request early deletion of your data anytime

  • Export your data for portability

Data Type
Retention Period
Purpose
Account information
Duration of active account
Maintain your profile, preferences, and authentication
Assessment scores
Duration of active account
Track skill development, determine session readiness, provide feedback
Course progress & learning data
Duration of active account
Track your achievements, maintain learning records, provide personalized coaching based on your history
Conversation transcripts
Duration of active account
Enable conversation continuity, allow you to reference previous coaching sessions, support your ongoing learning journey

Time-Limited Data Retention


Certain data types are automatically deleted on a regular schedule:​

Data Type
Retention Period
Deletion Policy
User analytics data
12 months
Deleted after expiration (PostHog)
Backup data
30 days
Rolling backups, older than 30 days purged
Authentication logs
90 days
Automatically deleted (Clerk system)
Voice recordings
90 days
Automatically and permanently deleted

Why we delete voice recordings after 90 days: Voice audio files are large and are primarily used for real-time coaching and short-term quality improvement. After 90 days, the transcripts (which we retain longer) serve the purpose of maintaining conversation history without the storage burden of audio files.

 

Inactive Account Data Retention

If you stop using Goldi, we begin a data retention countdown:

 

  • After 12 months of inactivity: Your conversation transcripts and learning progress data are automatically deleted

  • After 24 months of inactivity: Your account may be archived or deleted

  • Exception: If you have an active subscription or ongoing institutional enrollment, your account remains active

 

What counts as activity: Logging in, having a conversation with Goldi, accessing course materials, or updating your profile.

 

Educational Institution User Data Retention

If you access Goldi through an educational institution or partner organization:

 

  • Conversation transcripts: Retained for the duration of your enrollment/program participation plus 12 months

  • Learning progress data: Retained for the duration of your enrollment/program participation plus 12 months

  • Purpose: Allows instructors to access conversations for grading and assessment, supports program evaluation, enables you to return to your history if you re-enroll

 

Your educational institution may have additional data retention requirements under their own policies. Please consult with your institution regarding their practices.

 

Extended Retention for Legal and Business Purposes

Notwithstanding the foregoing retention periods, we will maintain your data only for as long as necessary for the purposes designated in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to:

 

  • Comply with legal obligations: If required to retain your data to comply with applicable laws, regulations, or legal processes

  • Resolve disputes: Maintain records necessary to resolve disagreements or enforce our agreements

  • Enforce our policies: Retain information needed to enforce our Terms of Service and other agreements

  • Protect rights and safety: Keep data necessary to protect the rights, property, or safety of Climb Together, our users, or others

 

Anonymized Data Retention

Anonymized data may be retained indefinitely. We may retain anonymized or aggregated data that cannot reasonably be used to identify you for:

 

  • Product improvement and development

  • Statistical analysis and research

  • Understanding learning outcomes and coaching effectiveness

  • Industry benchmarking and reporting

 

What is anonymized data? This includes usage patterns, aggregate statistics, and insights that have been stripped of all personally identifiable information. For example: "Students who complete networking practice sessions have 40% better interview outcomes" - without any connection to specific individuals.

 

Our anonymization process:

 

  1. Remove direct identifiers: Name, email, phone, IP address

  2. Generalize quasi-identifiers: Zip code → County/Region, Birth date → Age range

  3. K-anonymity testing: Ensure each data combination appears at least 5 times

  4. Validation: Verify no individual can be singled out

 

Usage Data for Security and Functionality

We will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to:

 

  • Strengthen the security of our Services

  • Improve the functionality of our Services

  • Comply with legal obligations for longer retention periods

 

Your Right to Request Deletion

Regardless of the retention periods above, you can request deletion of your data at any time by contacting privacy@climbtogether.co. We will respond to your request within 30 days, subject to identity verification.

 

Exceptions to deletion requests: We may decline to delete your data if retention is necessary for:

 

  • Completing transactions or providing services you requested

  • Detecting and preventing security incidents or fraud

  • Complying with legal obligations

  • Enabling internal uses that reasonably align with your expectations

  • Otherwise permitted by applicable law

 

When you request deletion:

 

  1. Immediate (within 24 hours):

 

  • Account access disabled

  • Authentication credentials invalidated

  • Active sessions terminated

 

  1. Data Removal (within 30 days):

 

  • Conversation transcripts permanently deleted from Langfuse

  • Account information removed from all systems

  • Learning progress data deleted from TalentLMS

  • Voice recordings deleted from HumeAI (if within 90-day window)

  • Analytics data anonymized or deleted from PostHog

 

  1. Backup Purging (within 90 days):

 

  • Data removed from encrypted backups

  • Cryptographic erasure techniques applied

  • Confirmation of complete removal documented

 

Note: Anonymized data derived from your usage may be retained indefinitely for product improvement.

 

 

Secure Data Destruction Procedures

Automated Deletion Systems

  • Voice recordings: Automated permanent deletion after 90 days

  • Authentication logs: Automated deletion after 90 days via Clerk

  • User analytics: Automated deletion after 12 months via PostHog

  • Scheduled cleanup jobs run daily to enforce retention limits

 

Manual Deletion Requests

When you request account deletion (see process above), we follow strict destruction procedures:

 

Digital Data Destruction Methods:

 

  • Primary Storage: Cryptographic erasure (encryption keys destroyed)

  • Database Records: Secure deletion with overwrite

  • Backups: Removed during next backup cycle, encrypted backups re-keyed

  • Logs: Automated purging after retention period expires

  • Cloud Storage: Deletion commands issued to all service providers

 

Verification:

 

  • Deletion confirmation from each service provider

  • Audit logs of deletion operations maintained for 1 year

  • Annual verification that retention limits are being enforced

 

Third-Party Data Destruction

Vendor Contracts Require:

 

  • Data deletion within 30 days of contract termination

  • Certificate of Destruction or cryptographic erasure confirmation

  • Verification that all backups and replicas are deleted

  • Failure to comply may result in contract termination and legal action

 

Current Vendor Deletion Commitments:

 

  • Clerk: Data deleted per contract termination terms

  • HumeAI: Voice recordings deleted after 90 days automatically

  • Langfuse: Conversation logs deleted per retention policy

  • PostHog: Analytics data deleted after 12 months

  • TalentLMS: Course data deleted per contract terms

  • Stripe: Payment records retained per PCI-DSS requirements (7 years for tax/audit purposes)

 

 

Data Exports and Access Controls

To protect your information:

 

  • Only authorized administrators can export data from our systems

  • Goldi doesn't allow users to download personal conversation data directly

  • Data extraction requests require admin approval and are logged

  • You can request a data export by contacting privacy@climbtogether.co

 

 

Your Rights and Choices

Climb Together endeavors to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data. Whenever made possible, you can update your Personal Data directly within your account settings section or by responding to the opt-out directions in communications sent to you. If you are unable to change your Personal Data, please contact us at privacy@climbtogether.co to make the required changes.

Your Privacy Rights

In certain circumstances, you have the right to:

 

1. Right to Access

 

  • View all data we have collected about you

  • Request detailed explanation of how data is used

  • Receive copy of data in accessible format

  • Contact: privacy@climbtogether.co

 

2. Right to Correction

 

  • Correct inaccurate or incomplete information

  • Update profile details on your behalf

  • Request updates to learning records

 

3. Right to Deletion ("Right to be Forgotten")

 

  • Request deletion of your account and all data

  • Exceptions: legal obligations, ongoing transactions, fraud prevention

  • Expedited process for minors (48 hours)

  • Contact: privacy@climbtogether.co

 

4. Right to Object

 

  • Object to certain data processing activities

  • Opt out of marketing communications

  • Limit how your data is used

 

5. Right to Data Portability

 

  • Download copy of your data

  • Structured, commonly used format (JSON/CSV)

  • Transfer data to another service

 

6. Right to Withdraw Consent

 

  • Withdraw consent for data processing at any time

  • Delete account to fully withdraw consent

  • Does not affect prior lawful processing

 

7. Right to Lodge a Complaint

 

  • File complaint with supervisory authority

  • EU users: Contact your local Data Protection Authority

  • CA users: California Attorney General

 

How to Exercise Your Rights

Email: privacy@climbtogether.co
Response Time: 30 days (may extend for complex requests with notification)
Verification: We may request additional information to verify your identity before responding to requests

Identity Verification

To protect your data, we require identity verification before responding to access, correction, or deletion requests:

 

  • Confirm email address on file

  • Answer security questions

  • Provide additional documentation for sensitive requests

 

This prevents unauthorized access or deletion of your account.

 

 

Children's Privacy

Under 13 (COPPA Compliance)

Our services are not designed for children under 13. We do not knowingly collect information from children under 13.

 

Age Verification:

 

  • Users must provide birth date at account creation

  • Users under 13 are blocked from creating accounts

  • Age-appropriate message displayed with parent contact information

 

If We Learn a Child Under 13 Has Provided Data:

 

  1. We will delete the account and all associated data immediately (within 48 hours)

  2. We will notify the educational institution (if applicable)

  3. We will not use the data for any purpose

  4. We will document the incident and remediation

 

Parents/Guardians: If you believe your child under 13 has created an account or provided information to Goldi:

 

  • Contact us immediately: privacy@climbtogether.co

  • Subject line: "COPPA - Child Under 13"

  • We will investigate within 24 hours and delete all data

  • No penalty or negative consequences for the child

 

Ages 13-17 (Educational Context)

We may serve minors ages 13-17 through educational institutions with appropriate safeguards.

 

How Minors Access Goldi:

 

  • Through institutional partnerships (schools, community colleges, educational programs)

  • Institutions act as parent/guardian agent for consent

  • Schools responsible for obtaining parental consent per state law

 

Additional Protections for Minors:

 

  1. No Public Profiles: Minors cannot create publicly visible profiles

  2. Limited Data Sharing: Data never sold or shared for marketing

  3. Instructor Oversight: Educational staff have oversight of minor accounts

  4. Content Appropriateness: AI responses filtered for age-appropriate content

  5. Privacy Education: Resources provided to help minors understand their privacy rights

 

Parental Rights (Ages 13-17):

 

Parents and guardians of minor users have the right to:

 

  • Access all data we have collected about their child

  • Request correction of inaccurate information

  • Request deletion of child's account and data (48-hour expedited process)

  • Object to certain data processing activities

  • Limit how child's data is used

 

Contact for Parental Requests:

 

  • Email: privacy@climbtogether.co

  • Subject line: "Parent Request - Minor Account"

  • Include: Child's name, school/institution, your relationship

  • Response time: 48 hours for parent requests (expedited)

 

State-Specific Compliance

California (SOPIPA - Student Online Personal Information Protection Act):

 

  • No targeted advertising to students

  • No sale of student data

  • No profiling for non-educational purposes

 

New York (Education Law 2-d):

 

  • Parents can inspect and review student data

  • Unauthorized disclosure prohibited

  • Data security safeguards required

 

Other States:

 

  • We monitor and comply with student privacy laws as enacted

  • Institutional partners responsible for compliance with state laws

  • Contracts include state-specific requirements where applicable

 

Marketing to Minors

Climb Together Does NOT:

 

  • Market directly to users under 18

  • Serve targeted advertising to minors

  • Share minor data with third-party advertisers

  • Use minor data for behavioral profiling

 

Communication with Minors:

 

  • Limited to essential service notifications

  • Educational content and course reminders only

  • Promotional content requires parent opt-in (if account allows)

 

 

International Data Transfers

Climb Together is located in the United States. Your Personal Data will be stored on our (or our suppliers') servers and data centers located in the United States and other jurisdictions where our service providers operate.

 

Transfer and Processing:

 

  • Information that we collect will be stored and processed in the United States in accordance with this Privacy Policy

  • This Privacy Policy shall apply even if we transfer Personal Information to other countries

  • By accessing our websites and the Services, you consent to this transfer, processing, and storage of your Personal Data in the United States or other jurisdictions

 

Important Notes:

 

  • Privacy laws in the United States and other jurisdictions may not be as comprehensive as those in the country where you reside

  • Your Personal Data may be available to government agencies under legal process in the United States

  • Climb Together will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy

  • No transfer of your Personal Data will take place to an organization or country unless there are adequate controls in place, including the security of your data and other personal information

 

Data Protection Measures for International Transfers:

 

  • Standard Contractual Clauses (SCCs) with EU-based users

  • Adequate security controls with all service providers

  • Data Processing Addendum (DPA) available upon request

  • Compliance with GDPR requirements for international transfers

 

 

Security of Data

The security of your data is important to us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure.

 

Our Security Measures:

 

Climb Together has implemented a security program that includes appropriate administrative, technical, and physical safeguards intended to keep the Personal Data stored in our systems protected from unauthorized access and misuse:

 

  • Encryption: Data encryption at rest (AES-256) and in transit (TLS 1.2+)

  • Firewalls: Industry-standard firewalls configured to protect our systems

  • Authentication: Multi-factor authentication (MFA) for staff system access

  • Access Controls: Role-based access control (RBAC) with least privilege principles

  • Monitoring: Continuous security monitoring and alerting

  • Testing: Regular security testing and vulnerability assessments

  • Vendor Security: All vendors must meet SOC 2, ISO 27001, or equivalent standards

  • Incident Response: Documented procedures for security incident handling

  • Business Continuity: Daily encrypted backups, disaster recovery tested quarterly

 

Security Limitations:

 

Please be aware that no information system is totally secure. While we use reasonable security and monitoring controls in accordance with general industry standards to secure information you provide to us consistent with our legal requirements, we cannot guarantee that such information will not be unlawfully or illegitimately obtained by unauthorized parties.

 

If you have questions about the security of your personal information, you can contact us at security@climbtogether.co.

 

 

"Do Not Track" Signals

We do not support Do Not Track ("DNT"). Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked.

 

You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.

 

 

Changes to This Policy

We may update this policy from time to time. If we make significant changes, we'll notify you by email or by posting a notice on this page. The latest version will always be available at climbtogether.co/privacy.

 

Notification of Changes:

 

  • Significant Changes: Email notification to all users + in-app notice

  • Minor Updates: Notice on website + updated "Last Updated" date

  • Effective Date: Changes become effective 30 days after posting (allows time for review)

  • Change Log: Available upon request showing what was updated

 

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

 

Previous Versions:

 

  • We maintain archived versions of our Privacy Policy

  • Previous versions available upon request

  • Helps demonstrate our commitment to transparency over time

 

 

Policy Review Schedule

Annual Reviews (Minimum):

 

  • Privacy Policy reviewed annually and updated as needed

  • Security Policies reviewed annually by security team

  • AI Governance reviewed annually with bias audit results

  • Vendor agreements reviewed during annual security audits

 

Triggered Reviews:

 

  • Regulatory changes (GDPR, CCPA, FERPA, state laws)

  • Significant product changes or new features

  • Security incidents or data breaches

  • Changes in AI providers or processing methods

  • User feedback indicating policy gaps

 

Review Process:

 

  • Led by Chief Product & Technology Officer

  • Involves legal counsel for compliance verification

  • Security team participation for technical accuracy

  • User testing for readability and comprehension

  • Institutional partner feedback incorporated

 

 

Contact Us

If you have questions about this policy or want to exercise your rights:

 

Privacy Inquiries:

 

 

Security Concerns:

 

 

General Questions:

 

 

AI Governance Questions:

 

  • Email: ai@climbtogether.co (starting Q1 2026)

  • See: climbtogether.co/ai-governance (coming Q1 2026)

 

Transparency Reports:

 

  • Available: climbtogether.co/transparency-report (starting Q2 2026)

  • Quarterly publication schedule

 

Mail: Climb Together
[Physical Address]
Attention: Privacy Team

 

By using Climb Together, you acknowledge you have read and understand this Privacy Policy.

bottom of page