LoadOut
Privacy Policy
LoadOut Privacy Policy
Effective date: 2026-05-07
What this app is
LoadOut is a local-first reloading reference and tracking app for iOS and Android. It helps you record your loads, firearms, and components, and read SAAMI cartridge specifications. Reference catalogs (cartridges, powders, bullets, primers, brass, firearms, parts) ship with the app for browsing offline.
The short version
- We don't track you. No analytics. No advertising. No selling of your data.
- Your reloading data — loads, firearms, components, batches, brass logs, ballistic profiles — lives on your device. We don't run a server that stores it.
- The only thing we send to our service providers is what's needed for sign-in (email, OAuth tokens) and for processing in-app purchases (anonymous purchase records).
- If you opt in to cloud backup (a Pro feature), your data is encrypted on your device with a passphrase only you know, and uploaded to your own iCloud Drive or Google Drive. We never receive the encrypted blob.
What we collect
Account & authentication (Firebase Authentication)
We use Firebase Authentication (Google Cloud) to identify you and let you sign in across devices. Firebase stores, on Google's servers:
- Your email address.
- A Firebase-assigned anonymous user ID (UID).
- OAuth tokens for any third-party providers you use (Google, Apple, Microsoft).
- Sign-in metadata (timestamps, last sign-in IP) maintained by Firebase.
We use this data only to authenticate you, not for marketing or analytics.
In-app purchases (RevenueCat)
If you buy LoadOut Pro, the App Store or Google Play processes the transaction. We use RevenueCat to verify your purchase and unlock Pro features across devices. RevenueCat receives:
- Your Firebase UID (so your purchase follows your account).
- The store-level transaction record (product ID, purchase date, expiration if applicable).
- Anonymous device and platform metadata RevenueCat needs to validate receipts.
RevenueCat does not receive your email address or any reloading data.
Diagnostics (Firebase Crashlytics — on by default, opt-out)
LoadOut includes Firebase Crashlytics to record crash and error reports. Collection is on by default so we can catch and fix crashes quickly. You can turn it off at any time from Settings → Send crash reports.
While enabled, crash reports include:
- Technical metadata Crashlytics needs to diagnose the crash: device model, OS version, app version, stack traces, the name of the screen you were on, the database schema version, and whether you were signed in or using the app as a guest. We do not attach your Firebase UID or any other account identifier to a crash report.
- Non-fatal errors the app catches and reports for diagnostic purposes.
Crash reports do not include your reloading data or any user-typed text. If you turn the toggle off again, collection stops immediately.
Data we download (read-only catalog updates)
When the app starts, it makes a one-way read request to Firebase Storage to check whether the bundled reference catalog has been corrected or expanded since the version you installed. If a newer catalog is available, we download and cache it on your device. We do not upload anything about you, your device, or your reloading data when this check runs. The catalog files are identical for every user.
What we don't collect
- Reloading data. Your loads, firearms, custom components, batches, brass logs, ballistic profiles, and shots-fired counts stay in the on-device SQLite database. We don't operate a server that receives them.
- Photos. The app's photo-import feature reads images on-device so you can scan handwritten reloading notes. The images and parsed text never leave your device.
- Location — we operate no server that receives it. We use your location only when you tap "Get current weather" inside the app, to fetch local temperature, pressure, humidity, and wind for ballistics calculations. Your coordinates go to the weather provider for that one request with no account or identity information attached, and no LoadOut server ever receives them. They are saved on your device alongside the records that use them — the ballistic profile's Coriolis latitude, and your range-day and atmosphere entries — so if you turn on cloud backup or sync they travel inside the encrypted blob, unreadable without the passphrase we never have. You can see and clear them with the records they belong to.
- Microphone. The app does not request microphone access.
- Bluetooth. The app does not request Bluetooth access.
- Contacts, calendar, health, advertising IDs, browsing history. The app does not request any of these.
Device permissions
LoadOut asks for the following device permissions only when you use the relevant feature. You can decline any of them and continue using the rest of the app.
- Camera. To photograph handwritten reloading notes for the photo-import feature. The image stays on-device.
- Photo library. To choose an existing photo of reloading notes to import. The image stays on-device.
- Location (when in use). To fetch current weather for ballistics calculations when you tap "Get current weather". Your coordinates are sent only to the weather provider for that request.
Backups & exports
You have two ways to get your data off your device. Both are designed so we never see the contents.
Local export (free)
You can export your full reloading database to a JSON file using the in-app export action. LoadOut hands the file to your device's share sheet, and you choose where it goes — save it to Files or Downloads, AirDrop it, email it, or send it to any app you like. Nothing is saved outside the app until you pick a destination. Our infrastructure is not involved.
End-to-end encrypted cloud backup (Pro, opt-in)
If you have LoadOut Pro and you turn on cloud backup, the app:
- Asks you to set a passphrase. Your data is encrypted on the device, with that passphrase, before any upload.
- Uploads the encrypted backup to your own cloud storage — iCloud Drive, Google Drive, or Microsoft OneDrive. You sign in to your cloud provider directly — we never handle your cloud credentials.
- Stores nothing on LoadOut servers. There is no LoadOut backend in this flow. The encrypted blob travels between your device and your cloud provider.
We can't read your backup, and we can't recover a lost passphrase. If you forget it, the backup is unrecoverable. Write the passphrase down somewhere safe.
AI Smart Import (Pro, opt-in per use)
Pro users can opt in to AI Smart Import to improve a hard read. The feature is off by default and only fires on an explicit per-use action: the "Improve with AI" button on a recipe import, or — for a hard-to-read Garmin chronograph screen — the "Enhance with AI" last resort.
- Only what you just produced for that one import is sent: the OCR'd text from a recipe photo, or (for the Garmin "Enhance with AI" last resort) a cropped image of just the chronograph screen — never the raw full photo, and nothing else from the app. We never see your saved recipes, firearms, batches, brass logs, or any other reloading data.
- The Garmin image escalation runs only after on-device reading and guided capture have already failed, and only after you accept a disclosure shown before any image is sent — every import, never silently. It is capped per import.
- The LoadOut proxy logs only timestamp, a short anonymous identifier, response status, and token counts. Your request body — the OCR text or the cropped image — is not logged by us. The image is processed transiently to read the numbers and is not stored.
- Hosted mode uses Anthropic, whose API terms state they do not train on API requests.
- You can override the hosted proxy by entering your own Anthropic, OpenAI, or Google Gemini API key in Settings → AI. When you do, the request goes directly from your device to that provider — the LoadOut proxy is not involved — and that provider's own terms (not Anthropic's) govern it. Your key is stored only on this device, in the iOS Keychain or Android Keystore.
- A monthly cap of 20 AI calls per Pro user keeps the feature cost-bounded for hosted-mode users.
Sub-processors and third parties
We use the following third-party services to operate LoadOut. Each has its own privacy policy that governs how they handle the data we send them.
- Google Cloud / Firebase (Authentication, Hosting, Storage for catalog updates). https://firebase.google.com/support/privacy
- RevenueCat (in-app purchase verification and entitlement). https://www.revenuecat.com/privacy
- Cloudflare (the AI Smart Import proxy runs on Cloudflare Workers + KV; only relevant when you opt in to AI Smart Import in hosted mode). https://www.cloudflare.com/privacypolicy/
- Anthropic (AI Smart Import hosted mode forwards your OCR'd text — or, for the Garmin "Enhance with AI" last resort, a cropped image of just the chronograph screen — to Anthropic's Messages API via our proxy; also available as a BYOK provider). https://www.anthropic.com/legal/privacy
- OpenAI (only if you choose OpenAI as your BYOK provider in Settings → AI — the request then goes directly to OpenAI under their terms, never via our proxy). https://openai.com/policies/privacy-policy
- Google Gemini (only if you choose Google Gemini as your BYOK provider in Settings → AI — the request then goes directly to Google under their terms, never via our proxy). https://ai.google.dev/gemini-api/terms
- Apple App Store / Google Play for purchase processing and subscription management. https://www.apple.com/legal/privacy/ · https://play.google.com/about/play-terms/
- Sign-in providers if you use them: Google, Apple, Microsoft. We request the minimum scope needed to identify you (typically email and name).
How long we keep data
- Reloading data: we don't have it — it lives on your device for as long as you keep it there.
- Account record (Firebase Authentication): kept until you ask us to delete it, or until the account is inactive for an extended period (we will define a specific retention window in a future revision).
- Purchase records (RevenueCat / the stores): kept as long as the subscription / lifetime entitlement is active and as required by Apple, Google, and applicable tax law.
How to delete your data
- On-device data: open Settings → Privacy & Data → Reset This Device to clear your loads, firearms, batches, brass logs, and ballistic profiles from this device. Your cloud backup and account stay active, so you can restore later.
- Account & all data: open Settings → Privacy & Data → Delete My Account & All Data to permanently delete your LoadOut account, the data on this device, your encrypted cloud backups across every connected provider, and the linked subscription identity. This cannot be undone.
- Cloud backup: the “Delete My Account & All Data” flow above deletes the encrypted backup files from every cloud provider the app can still reach. If you had already disconnected a provider or revoked LoadOut's access to it, the encrypted file may remain in your own storage — delete it yourself from your iCloud Drive, Google Drive, or OneDrive. It is unreadable without your passphrase, which we never had.
- Uninstalling the app removes the local database and clears any cached catalog updates.
Your privacy rights
Depending on where you live, you may have additional rights over your personal information.
- European Economic Area / United Kingdom (GDPR / UK GDPR): you have the right to access, correct, delete, restrict, port, and object to processing of your personal data. The lawful bases we rely on are contract (to provide the app and Pro entitlement), consent (for any optional telemetry we add later), and legitimate interest (for security and abuse prevention). You may also lodge a complaint with your supervisory authority.
- California (CCPA / CPRA): we do not sell or share your personal information for cross-context behavioral advertising. You have the right to know, delete, correct, and limit use of sensitive personal information. We do not use sensitive personal information for purposes beyond providing the app.
- Other US states (CO, CT, VA, UT, etc.): we honor analogous consumer rights to access, delete, correct, and opt out, where applicable.
To exercise any right, email support@johnsondigitalsystems.com from the address tied to your account. We will respond within the legally required window for your jurisdiction.
Children
LoadOut is not directed at children. We do not knowingly collect personal information from anyone under 18. Reloading is for adults only — see the in-app safety disclaimer.
International data transfers
Firebase Authentication and RevenueCat may process your data in the United States and other countries. Where required, we rely on Standard Contractual Clauses or equivalent mechanisms to safeguard cross-border transfers.
Security
We use TLS for any data in transit between the app and our service providers. Cloud backups are encrypted on your device with your passphrase before upload, using authenticated encryption. We do not, however, guarantee absolute security — no system is invulnerable. If we discover a breach affecting your personal information, we will notify you as required by law.
Changes to this policy
If we make material changes, we will update the effective date and surface the change in-app (typically via a re-prompt of the disclaimer / privacy dialog).
Contact
Johnson Digital Systems — LoadOut