ClimbAI
Account & billing

Your data and privacy

What Climb AI stores, how credentials are protected, what leaves the platform, and how to delete a site or your account.

Updated 2026-09-13

What's stored per site

Each connected website record holds its publishing integration settings (WordPress, Shopify, Webflow, Wix or webhook), the credentials needed to publish to it, and Google Search Console tokens if you've connected GSC, plus your content, audit and keyword settings for that site.

How credentials are protected

Integration credentials — WordPress application passwords, Shopify and Webflow access tokens, GSC OAuth tokens, webhook signing secrets — are encrypted at rest with AES-256-GCM using a server-side key that never leaves the backend. Each value gets its own random IV, so the same password stored twice never produces the same ciphertext.

Outbound requests are restricted

Whenever Climb AI fetches a URL you supply — crawling your site, following a webhook redirect, resolving a GSC property — the request is blocked from reaching private, internal or cloud-metadata addresses, checked at both DNS resolution and connection time. Your site (and ours) can't be tricked into fetching internal infrastructure through a crafted URL.

What a webhook delivery contains

If you use the generic Webhook integration instead of a CMS, each published article is sent to your endpoint as a signed POST containing the article's title, slug, HTML, a Markdown conversion, SEO metadata and image URLs, plus the website's id, URL and name. It's signed with HMAC-SHA256 (X-ClimbAI-Signature), the same scheme Stripe uses, so you can verify it came from Climb AI.

What leaves the platform

  • To your CMS — published articles, images and metadata go to WordPress, Shopify, Webflow or Wix through their APIs, or to your webhook endpoint.
  • To AI model providers — article prompts (built from your title, keywords, tone and content settings) go to the AI models used for text and image generation.
  • To Whop — billing and subscription events for payment processing.
  • To Meta and Microsoft Clarity — only on the public marketing site, for ad attribution and session analytics. Not inside the app itself.

Your content is not used to train AI models

No. Climb AI does not train any model on your content, your keywords, your site data or your support conversations, and the AI providers it calls are used under terms that do not permit training on the data sent to them. Your content goes to a model provider only to do the job you asked for — writing an article, scoring a page, writing alt text — and is not retained for training afterwards.

Deleting a website

Removing a site deletes it and everything scoped to it: articles, content briefs, tracked keywords, keyword clusters and projects, site audits, page reports and link data, content-gap analyses, page analyses, images and image audits, and schema markup. This is permanent.

Deleting your account

You can delete your account yourself from account settings. Deletion first cancels any live Whop subscription tied to your account, so you're never billed after the account is gone — if cancellation fails, the deletion is refused rather than leaving you billed with no account. Once confirmed, it permanently removes every website and its cascaded data, your GEO audits and citation scans, cached keyword searches, notifications and your user record, all in one transaction that rolls back completely if anything fails partway through.

Account deletion requires your password (or, for Google sign-in accounts, typing your account email to confirm) and cannot be undone.

The full policies

For the complete legal terms, see:

Related
Ready to try it on your own site?

5-day free trial, nothing charged until day 6, 30-day money-back after that.

5-day free trial · 30-day money-back · price locked for life

Still stuck? hello@climbai.io

Try Now For $0.00