Privacy Policy
Piton is an Apple Watch and iPhone app that helps you track indoor and outdoor rock climbing sessions. Piton records climbing data locally on your devices. Piton's optional AI features run entirely on your iPhone using Apple Intelligence (Apple's on-device foundation models). They require no account, no API key, and no network connection, and your climbing data is never sent to us or to any third-party AI service.
Piton has no user accounts, no servers we operate, and no analytics, advertising, or attribution SDKs. We do not sell your data, share it with data brokers, or use it for advertising or tracking.
This policy describes what data Piton handles, where it lives, and which optional features send data outside your devices. If you have questions, see the Contact section at the bottom.
01
What data Piton handles
Data stored locally on your devices
Piton stores climbing data on your Apple Watch and iPhone. Most app data is stored with Apple's SwiftData framework. Some records live on the device that captured them, while session summaries and related records can be exchanged between your paired Apple Watch and iPhone as described below.
Piton may store:
- Climbing sessions:start and end times, gym name, city-level locality when available, raw session coordinates when location permission is granted, your selected wear configuration, and session type (indoor rope, indoor boulder, outdoor sport, outdoor boulder).
- Climbing laps:individual attempts within a session: time, height reached, grade tag if you provided one, send / fall / flash status, and notes you wrote.
- Sensor samples:altitude readings from the barometric altimeter and motion readings from accelerometer / gyroscope sensor fusion, captured during active sessions to detect lap boundaries and support the in-app sensor inspector.
- Heart-rate and energy summaries:heart-rate readings are sourced from HealthKit during active sessions when permission is granted. Piton stores session-level heart-rate and calorie summaries when available; persistent heart-rate samples remain managed by HealthKit.
- Gym configurations:names, coordinates, match radius, and detector profile preferences for gyms you visit regularly.
- Routes and projects:names, grades, color tags, status, gym names, and your notes for routes you choose to track.
Piton does not maintain a backup or copy of your climbing data on servers we control. If you delete the app, the local app data on that device is removed with it. Apple may include app data in iCloud Backup if you have that enabled; that is controlled by your Apple settings, not by Piton.
Earlier versions of Piton (before 1.0.29) offered AI features powered by a user-supplied Anthropic API key stored in the iOS Keychain. That integration has been removed: current versions make no third-party AI requests, and on first launch after updating, Piton deletes any previously stored API key from the Keychain.
Data exchanged between your watch and your iPhone
Climbing sessions captured on your Apple Watch are synced to your paired iPhone over Apple's WatchConnectivity framework. This can include session summaries, laps, route/project data, session-prep queues, and session coordinates when location permission is granted. The exchange is between your paired devices through Apple's platform channel and does not pass through any server operated by us.
Raw sensor samples are used for detection and diagnostics on the device that captured them. They are never sent off your devices.
Apple HealthKit
Piton requests permission to read HealthKit data used during climbing sessions and to write climbing workout records to Apple Health. When you grant this permission, Piton may:
- Read heart rate, workout, and active-energy data during active sessions so it can display live metrics and store session-level summaries.
- Write a climbing workout record and active-energy data to Apple Health when you end a session, so the workout and calories can appear in Apple Health.
Piton does not write heart-rate samples itself. Heart-rate samples remain managed by HealthKit.
You can revoke Health permissions at any time in Settings > Health > Piton on your iPhone or watch.
Motion sensors
Piton uses Apple's CoreMotion framework to read the barometric altimeter and motion sensors during active sessions. This requires the Motion & Fitness permission, granted separately on the watch and the iPhone. Sensor readings are processed and stored on your devices and are never transmitted anywhere else.
You can revoke Motion permission at any time in Settings > Privacy & Security > Motion & Fitness.
Location
When location permission is granted, Piton requests a single, low-accuracy location reading at the start of a session. Piton uses that reading to:
- Store session coordinates for gym matching.
- Reverse-geocode a city-level locality string, such as "Santa Cruz, CA", for the session record.
- Match against your gym list to auto-tag the session.
Piton does not track your location continuously and does not use your location outside of session-start matching. Coordinates are retained with the session so future gym configuration changes can re-match historical sessions. Reverse geocoding is performed with Apple's system location and mapping services (the one place a coordinate leaves the device, to Apple, as with any app that uses Apple's geocoder). Raw coordinates are never shared with anyone else and are not read by the AI features.
You can revoke location permission at any time in Settings > Privacy & Security > Location Services > Piton.
02
Optional AI features
Piton includes optional AI-assisted features powered by Apple Intelligence, Apple's on-device foundation models, running entirely on your iPhone. They are off by default and enabled with a single toggle in More > AI Helper. There is no account, no API key, and no network request: generation happens locally and works offline. These features require an iPhone that supports Apple Intelligence.
The AI features are:
- Coach's Notes:an observational synopsis of a single climbing session, displayed on the Today / Week / Month / Lifetime views. Once AI is enabled, Piton may automatically request or refresh a synopsis when these views load or when the underlying session changes.
- Ask Piton AI:a question-and-answer surface where you can ask about your own training history.
- AI threshold tuning:natural-language adjustments to the in-app lap-detection thresholds, with explicit confirmation before any change applies.
- AI-formatted bug reports:assembles a bug description plus app/OS/device facts and a summary of recent sessions into a structured report you can share with the developer.
What the on-device model reads when you use AI features
When an AI feature runs, Piton assembles a prompt for the on-device model. The prompt never leaves your iPhone. Depending on the feature, it may include:
- For Coach's Notes: a structured summary of one session, including date, gym name or locality, duration, climb counts, send / fall / flash counts, grade spread, hardest send, heart-rate and calorie summaries when available, effort-zone counts, and highlight or project notes.
- For Ask Piton AI: a structured summary of your climbing history, such as session counts, climb counts, send / fall counts, hardest sends, boulder problem counts, active project counts, and recent session-character classifications, plus your typed question.
- For AI threshold tuning: current lap-detection threshold values and your typed adjustment request.
- For AI-formatted bug reports: your typed bug description, app version, OS version, device model, capture/heart-rate pipeline facts when available, and a small summary of recent sessions, including gym name, climb counts, send / fall counts, duration, and capture mode.
- A system prompt describing how the AI should respond.
The model never reads your contact list, photos, raw sensor samples, or raw latitude/longitude coordinates. Gym names, city-level localities, and the session summaries described above are processed on-device only.
Where the processing happens
All AI generation runs inside Apple's on-device foundation-model framework on your iPhone. Piton makes no AI network requests, operates no servers, and neither Piton's developer nor any third-party AI provider receives your prompts or your climbing data. Generated text (for example a session synopsis) is cached locally on your device like any other app data.
You can turn AI features off at any time with the toggle in More > AI Helper. With the toggle off, no AI generation runs at all.
Earlier versions and the legacy API key
Versions of Piton before 1.0.29 offered AI features through a user-supplied Anthropic API key stored in the iOS Keychain, and sent session summaries to Anthropic's Claude API. That integration has been removed entirely. The current version deletes any leftover key from the Keychain the first time it launches, and no Piton code reads or transmits it.
03
Data we do not collect
Piton does not require, collect, store, or send:
- Account identifiers for a Piton account, because Piton does not have accounts.
- Contacts, calendars, browsing history, or unrelated app data.
- Continuous location history.
- Crash reports automatically through any third-party crash-reporting SDK. Apple may collect anonymized diagnostics with your consent through standard iOS settings; Piton does not control that.
- Usage analytics, telemetry, advertising identifiers, marketing identifiers, or attribution data.
There are no third-party analytics, advertising, attribution, or crash-reporting SDKs in Piton.
Piton includes free-form notes and bug-description fields. If you choose to type personal information into those fields, that information is stored locally; AI features that read those fields process them on-device only. Reports you explicitly share (for example an AI-formatted bug report you email to the developer) contain whatever you chose to include.
04
How long we keep your data
Locally, your climbing data stays on your devices unless you delete it or delete the app. Piton's interface currently lets you delete individual laps and other editable records such as gyms. Deleting the app removes Piton's local app data from that device.
AI features process data on-device and store nothing outside your devices; generated synopses are cached locally and removed with the app.
05
Your rights and controls
You can, at any time:
- Delete individual laps and supported editable records through Piton's interface.
- Revoke HealthKit, Location, or Motion permissions in iOS / watchOS Settings.
- Turn AI features off with the toggle in More > AI Helper.
- Delete the app to remove Piton's local app data from that device.
Because Piton stores no data on servers we control, there is no separate "delete my account" process. Piton has no account system.
06
Children
Piton is not directed at children under 13. If you are a parent or guardian and believe your child has provided personal data through the app, for example by writing identifying information into a notes field or AI bug-description field, please contact the developer to discuss removal.
07
Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page will reflect the most recent revision. If Piton's data-handling practices materially change, especially what data is sent outside your devices, we will update this policy and any related App Store disclosures.
08
Contact
Piton is developed by Jeff Schwerdtfeger. For privacy-related questions, please use the email address below.
- Web
- fieldnotes.cc
- jeff@fieldnotes.cc