LoadOut

Privacy Policy

LoadOut Privacy Policy

Effective date: 2026-09-10

What this app is

LoadOut is a local-first reloading reference and tracking application for iOS, Android, macOS, and the web. It enables you to record your loads, firearms, and components, and to consult cartridge specifications. Reference catalogs (cartridges, powders, bullets, primers, brass, firearms, parts) are bundled with the application for offline browsing.

The short version

What we collect

Account & authentication (Firebase Authentication)

We use Firebase Authentication (Google Cloud) to identify you and to enable sign-in across devices. Firebase stores the following on Google's servers:

We use this data solely to authenticate you, and not for marketing or analytics purposes.

In-app purchases (RevenueCat)

If you purchase LoadOut Pro, the App Store or Google Play processes the transaction. We use RevenueCat to verify your purchase and to unlock Pro features across devices. RevenueCat receives the following:

RevenueCat does not receive your email address or any reloading data.

Diagnostics (Firebase Crashlytics: on by default, opt-out)

LoadOut includes Firebase Crashlytics to record crash and error reports. Collection is enabled by default so that we may identify and correct crashes promptly. You may disable it at any time from Settings → Send crash reports.

While collection is enabled, crash reports include:

Crash reports do not include your reloading data or any user-typed text. If you subsequently disable collection, it ceases immediately.

Data we download (read-only catalog updates)

When the application starts, it makes a one-way read request to Firebase Storage to determine whether the bundled reference catalog has been corrected or expanded since the version you installed. If a newer catalog is available, it is downloaded and cached on your device. No information about you, your device, or your reloading data is uploaded when this check runs. The catalog files are identical for every user.

What we don't collect

Device permissions

LoadOut requests the following device permissions only when you use the relevant feature. You may decline any of them and continue to use the remainder of the application.

Backups & exports

There are two methods by which you may transfer your data off your device. Both are designed so that we never see the contents.

Local export (free)

You may export your full reloading database to a JSON file using the in-app export action. LoadOut passes the file to your device's share sheet, and you select its destination: saving it to Files or Downloads, transferring it by AirDrop, sending it by email, or sending it to any other application. Nothing is written outside the application until you select a destination. Our infrastructure is not involved.

Your device's own backup does not include this data

LoadOut excludes its reloading database from the backup your phone makes of itself: iCloud Backup on iOS, Auto Backup on Android. That is deliberate, because those backups are made with your platform account's key rather than the passphrase you chose, so including your data would put it somewhere we had promised it would not be. The consequence is worth stating plainly, because it is the one that can cost you: if you replace or wipe your phone, restoring it from the platform's own backup will not bring your reloading data back. Your copies are the local export above, which is free, and cloud backup or Cloud Sync if you have Pro. Your settings (units, language, theme) do ride the platform backup, so they follow you to a new device.

End-to-end encrypted cloud backup (Pro, opt-in)

If you have LoadOut Pro and you enable cloud backup, the application does the following:

We cannot read your backup, and we cannot recover a lost passphrase. If you forget it, the backup is unrecoverable. You should record the passphrase and retain it in a secure location.

Continuous Cloud Sync (Pro, opt-in)

Cloud Sync uses the same encryption model as the one-shot backup described above: encrypted on this device with your passphrase, and written to the same cloud folder you selected. The difference is that the upload occurs automatically a few seconds after each save, and the download occurs on application launch and upon your use of the manual "Sync Now" button. We never see the encrypted file, and we operate no backend that receives reloading data.

Your passphrase is kept in your device's keychain, and the platform may synchronize it to your own Apple or Google account so your other devices can use it; LoadOut never receives it. On iOS and macOS this is the iCloud Keychain, and on Android it is Google's Block Store. Both are encrypted, both are scoped to this application alone, and neither of them is a saved login you will find under your device's password list. It is your platform account, not ours: no LoadOut server distributes the passphrase, holds it, or can read anything encrypted with it. Where that account synchronization is unavailable, which is the case on the web and on a device signed out of its platform account, you enter the same passphrase on the other device instead, exactly as before. If you lose the passphrase and no synchronized copy reaches your new device, the synchronized data is unrecoverable, which is why you should still record it and retain it in a secure location.

AI Smart Import (Pro, opt-in per use)

Pro users may opt in to AI Smart Import to improve a difficult read. The feature is disabled by default and operates only upon an explicit per-use action: the "Improve with AI" button on a recipe import, or โ€” for a difficult-to-read Garmin chronograph screen โ€” the "Improve with AI" last resort.

Siri Voice Commands (free, opt-in)

LoadOut can answer questions through Siri on your iPhone and Apple Watch (a firing solution, a cartridge specification, a mil-to-MOA conversion) and can queue a logged shot or a dictated note for you to confirm the next time you open the application. The feature is free, and it is off until you turn it on in Settings → AI Features.

Companion apps on your watch

If you install the LoadOut companion app on an Apple Watch, a Wear OS watch, or a Garmin watch, your phone sends it what it needs to be useful at the firing line: the active load, the firing solution and its holds, your target card, and the shots you log on the wrist. This travels over the paired-device channel the platform provides (Apple's Watch Connectivity, Google's Data Layer, Garmin's Connect IQ), directly between your phone and your watch. No LoadOut server is involved, and we receive none of it.

What the watch holds, it holds on the watch, in that application's own private storage. When you turn the feature off, or run either of the privacy operations below, your phone asks every paired watch to discard what it is holding. That request is best effort, and we would rather say so than imply otherwise: a watch that is switched off, out of range, or unpaired at that moment does not receive it, and the channel returns no acknowledgement, so your phone cannot confirm that any watch acted. A watch that missed the request discards what it holds the next time it connects and hears one. If you are disposing of a watch, unpair it and erase it through its own settings rather than relying on this.

Spoken output

LoadOut can read a firing solution out loud: a target card row on your phone, or the next target on your watch after you log a shot. To do it, the application hands the finished sentence to the speech engine built into the platform: AVSpeechSynthesizer on iOS and macOS, the system text-to-speech service on Android, and the browser's own SpeechSynthesis on the web. No LoadOut server is involved, and we receive nothing.

We cannot tell you whether that sentence stays on your device. Some platform voices synthesize speech locally and others do it over the network, and the platform does not reliably publish which is which. Android exposes a per-voice flag that no part of the system enforces, and iOS and the browser expose nothing at all. LoadOut prefers a voice that reports itself as local where the platform offers that signal, but a preference is not a guarantee and we will not claim one in either direction. If you would rather nothing be spoken, spoken output has its own setting and you can leave it off. Speech is output only: the application does not open your microphone for it, and requests no recording permission.

Sub-processors and third parties

We use the following third-party services to operate LoadOut. Each has its own privacy policy, which governs its handling of the data we send to it.

How long we keep data

How to delete your data

Your privacy rights

Depending on your jurisdiction of residence, you may have additional rights over your personal information.

To exercise any right, send a request to support@johnsondigitalsystems.com from the email address associated with your account. We will respond within the period required by law in your jurisdiction.

Children

LoadOut is not directed at children. We do not knowingly collect personal information from any person under 18 years of age. Reloading is for adults only; refer to the in-app safety disclaimer.

International data transfers

Firebase Authentication and RevenueCat may process your data in the United States and other countries. Where required, we rely on Standard Contractual Clauses or equivalent mechanisms to safeguard cross-border transfers.

Security

We use TLS for any data in transit between the application and our service providers. Cloud backups are encrypted on your device with your passphrase before upload, using authenticated encryption. We do not, however, guarantee absolute security; no system is invulnerable. If we discover a breach affecting your personal information, we will notify you as required by law.

Changes to this policy

If we make material changes, we will update the effective date and provide notice within the application (typically by re-prompting the disclaimer or privacy dialog).

Contact

Johnson Digital Systems — LoadOut

support@johnsondigitalsystems.com