LoadOut
Privacy Policy
LoadOut Privacy Policy
Effective date: 2026-09-10
What this app is
LoadOut is a local-first reloading reference and tracking application for iOS, Android, macOS, and the web. It enables you to record your loads, firearms, and components, and to consult cartridge specifications. Reference catalogs (cartridges, powders, bullets, primers, brass, firearms, parts) are bundled with the application for offline browsing.
The short version
- We do not track you. We do not use analytics. The application contains no advertising. We do not sell your data.
- Your reloading data (loads, firearms, components, batches, brass logs, and ballistic profiles) resides on your device. We do not operate a server that stores it.
- The only information we transmit to our service providers is that which is required for sign-in (email address and OAuth tokens) and for the processing of in-app purchases (anonymous purchase records).
- If you opt in to cloud backup (a Pro feature), your data is encrypted on your device with a passphrase known only to you, and is then uploaded to your own iCloud Drive, Google Drive, or Microsoft OneDrive. We never receive the encrypted file.
- If you turn on Siri Voice Commands (free, and off until you do), your spoken question and LoadOut's spoken answer are handled by Apple's assistant under Apple's privacy terms. We still receive nothing: we operate no server that gets your reloading data.
What we collect
Account & authentication (Firebase Authentication)
We use Firebase Authentication (Google Cloud) to identify you and to enable sign-in across devices. Firebase stores the following on Google's servers:
- Your email address.
- A Firebase-assigned anonymous user ID (UID).
- OAuth tokens for any third-party providers you use (Google, Apple, Microsoft).
- Sign-in metadata (timestamps, last sign-in IP) maintained by Firebase.
We use this data solely to authenticate you, and not for marketing or analytics purposes.
In-app purchases (RevenueCat)
If you purchase LoadOut Pro, the App Store or Google Play processes the transaction. We use RevenueCat to verify your purchase and to unlock Pro features across devices. RevenueCat receives the following:
- Your Firebase UID (so your purchase follows your account).
- The store-level transaction record (product ID, purchase date, expiration if applicable).
- Anonymous device and platform metadata RevenueCat needs to validate receipts.
RevenueCat does not receive your email address or any reloading data.
Diagnostics (Firebase Crashlytics: on by default, opt-out)
LoadOut includes Firebase Crashlytics to record crash and error reports. Collection is enabled by default so that we may identify and correct crashes promptly. You may disable it at any time from Settings → Send crash reports.
While collection is enabled, crash reports include:
- Technical metadata Crashlytics needs to diagnose the crash: device model, operating-system version, app version, stack traces, the name of the screen you were on, and the database schema version. We do not attach your Firebase UID or any other account identifier to a crash report.
- Non-fatal errors the app catches and reports for diagnostic purposes.
Crash reports do not include your reloading data or any user-typed text. If you subsequently disable collection, it ceases immediately.
Data we download (read-only catalog updates)
When the application starts, it makes a one-way read request to Firebase Storage to determine whether the bundled reference catalog has been corrected or expanded since the version you installed. If a newer catalog is available, it is downloaded and cached on your device. No information about you, your device, or your reloading data is uploaded when this check runs. The catalog files are identical for every user.
What we don't collect
- Reloading data. Your loads, firearms, custom components, batches, brass logs, ballistic profiles, and shots-fired counts remain in the on-device SQLite database. We do not operate a server that receives them.
- Photos. The photo-import feature reads images on the device so that you may scan handwritten reloading notes. Images and parsed text never leave your device.
- Location: we operate no server that receives it. We use your location only when you ask for it: when you pull current conditions for a ballistics calculation, or when you save a range location. Your coordinates go to the weather provider for that one request with no account or identity information attached, and no LoadOut server ever receives them. They are also saved on your device, alongside the records that use them: the ballistic profile's Coriolis latitude, your range-day and atmosphere entries, and any range location you save. Because they are part of those records, they are included in the unencrypted JSON file that the local export action produces, and, if you enable cloud backup or Cloud Sync, inside the encrypted blob uploaded to your own cloud, which is unreadable without the passphrase we never have. You may review and clear them with the records that hold them.
- Microphone. The application does not request microphone access.
- Bluetooth. Bluetooth is used only to connect to devices you already own: a Kestrel 5-series weather meter, a WeatherFlow WEATHERmeter, or a Shooters Global SG Timer. Each connection is established directly between your phone and that device; readings and shot times are delivered to the application on your phone and are never transmitted to us. On Android, the scan permission is declared never-for-location, so pairing does not disclose your location.
- Contacts, calendar, health data, advertising identifiers, and browsing history. The application does not request access to any of these.
Device permissions
LoadOut requests the following device permissions only when you use the relevant feature. You may decline any of them and continue to use the remainder of the application.
- Camera. To photograph handwritten reloading notes for the photo-import feature. The image remains on the device.
- Photo library. To select an existing photograph of reloading notes for import. The image remains on the device.
- Location (when in use). To retrieve current conditions for ballistics calculations when you request them, and to record a range location when you choose to save one. Your coordinates are transmitted only to the weather provider, and only for a conditions request.
- Bluetooth. To connect to a device you already own and read from it: current conditions from a Kestrel 5-series weather meter or a WeatherFlow WEATHERmeter, or split times from a Shooters Global SG Timer. This applies to Android 12 and newer only. LoadOut never uses Bluetooth to determine your location.
Backups & exports
There are two methods by which you may transfer your data off your device. Both are designed so that we never see the contents.
Local export (free)
You may export your full reloading database to a JSON file using the in-app export action. LoadOut passes the file to your device's share sheet, and you select its destination: saving it to Files or Downloads, transferring it by AirDrop, sending it by email, or sending it to any other application. Nothing is written outside the application until you select a destination. Our infrastructure is not involved.
Your device's own backup does not include this data
LoadOut excludes its reloading database from the backup your phone makes of itself: iCloud Backup on iOS, Auto Backup on Android. That is deliberate, because those backups are made with your platform account's key rather than the passphrase you chose, so including your data would put it somewhere we had promised it would not be. The consequence is worth stating plainly, because it is the one that can cost you: if you replace or wipe your phone, restoring it from the platform's own backup will not bring your reloading data back. Your copies are the local export above, which is free, and cloud backup or Cloud Sync if you have Pro. Your settings (units, language, theme) do ride the platform backup, so they follow you to a new device.
End-to-end encrypted cloud backup (Pro, opt-in)
If you have LoadOut Pro and you enable cloud backup, the application does the following:
- Prompts you to set a passphrase. Your data is encrypted on the device, with that passphrase, before any upload.
- Uploads the encrypted backup to your own cloud storage — iCloud Drive (iOS), Google Drive (any platform), or Microsoft OneDrive (any platform). You sign in to your cloud provider directly; we never handle your cloud credentials.
- Stores nothing on LoadOut servers. No LoadOut backend is involved in this process. The encrypted file travels between your device and your cloud provider.
We cannot read your backup, and we cannot recover a lost passphrase. If you forget it, the backup is unrecoverable. You should record the passphrase and retain it in a secure location.
Continuous Cloud Sync (Pro, opt-in)
Cloud Sync uses the same encryption model as the one-shot backup described above: encrypted on this device with your passphrase, and written to the same cloud folder you selected. The difference is that the upload occurs automatically a few seconds after each save, and the download occurs on application launch and upon your use of the manual "Sync Now" button. We never see the encrypted file, and we operate no backend that receives reloading data.
Your passphrase is kept in your device's keychain, and the platform may synchronize it to your own Apple or Google account so your other devices can use it; LoadOut never receives it. On iOS and macOS this is the iCloud Keychain, and on Android it is Google's Block Store. Both are encrypted, both are scoped to this application alone, and neither of them is a saved login you will find under your device's password list. It is your platform account, not ours: no LoadOut server distributes the passphrase, holds it, or can read anything encrypted with it. Where that account synchronization is unavailable, which is the case on the web and on a device signed out of its platform account, you enter the same passphrase on the other device instead, exactly as before. If you lose the passphrase and no synchronized copy reaches your new device, the synchronized data is unrecoverable, which is why you should still record it and retain it in a secure location.
AI Smart Import (Pro, opt-in per use)
Pro users may opt in to AI Smart Import to improve a difficult read. The feature is disabled by default and operates only upon an explicit per-use action: the "Improve with AI" button on a recipe import, or โ for a difficult-to-read Garmin chronograph screen โ the "Improve with AI" last resort.
- Only what you have just produced for that single import is sent: the OCR'd text from a recipe photograph, or (for the Garmin "Improve with AI" last resort) a cropped image of the chronograph screen alone — never the raw full photo, and nothing else from the application. We never see your saved recipes, firearms, batches, brass logs, or any other reloading data.
- The Garmin image escalation operates only after on-device reading and guided capture have already proved insufficient, and only after you accept a disclosure shown before any image is sent — on every import, never silently. It is subject to a per-import cap.
- The LoadOut proxy logs only timestamp, a short anonymous identifier, response status, and token counts. Your request body — the OCR text or the cropped image — is not logged by us. The image is processed transiently to read the numbers and is not stored.
- Hosted mode uses Anthropic, whose API terms state they do not train on API requests.
- You may override the hosted proxy by entering your own Anthropic, OpenAI, or Google Gemini API key in Settings → AI. If you do so, the request is transmitted directly from your device to that provider (the LoadOut proxy is not involved) and that provider's own terms, rather than Anthropic's, govern it. Your key is stored on this device only, in the iOS Keychain or Android Keystore.
- A monthly cap of 20 AI calls per Pro user limits the cost of the feature for hosted-mode users.
Siri Voice Commands (free, opt-in)
LoadOut can answer questions through Siri on your iPhone and Apple Watch (a firing solution, a cartridge specification, a mil-to-MOA conversion) and can queue a logged shot or a dictated note for you to confirm the next time you open the application. The feature is free, and it is off until you turn it on in Settings → AI Features.
- We receive nothing. LoadOut sends nothing to any LoadOut server when you use this feature. There is no LoadOut backend involved in it at all. Every promise elsewhere in this policy about our own infrastructure is unchanged.
- Your request is handled by Apple, under Apple's terms. When you speak to Siri, your request and LoadOut's answer are processed by Apple's assistant under Apple's privacy policy, not ours. Apple does not publish whether a request of this kind is processed only on your device or also on Apple's private servers, so we do not claim either. If you want to see what your own device sends, your iPhone reports it under Settings → Privacy & Security → Apple Intelligence Report.
- We ask Apple for the smallest surface available. LoadOut does not add your firearms, recipes, or ballistic profiles to the system-wide Spotlight index, does not adopt Apple's shared assistant data schemas, and does not donate a searchable index of your data. When you say the name of a firearm, the matching happens inside the LoadOut process.
- A small answer file is stored on your device. So that Siri can answer without opening the application, LoadOut writes an already-computed summary (the firearms, profiles and solved distances an answer might need) into a private container on your own device, shared only between LoadOut and its own Siri extension. It stays on the device. It is not part of the JSON file the local export action produces, and it cannot be included in a cloud backup or in Cloud Sync.
- Answers are spoken out loud. A firing solution is read aloud on the device you asked, with the same confidence caveats the screen shows. Anyone near you can hear it.
- LoadOut does not ask for your microphone for this. Siri listens; LoadOut does not. This feature adds no microphone access.
- Turning it off erases what was stored. Switching Siri Voice Commands off in Settings → AI Features erases the stored answer file. Commands you queued but haven't confirmed stay in the app until you confirm or delete them.
- Both privacy operations erase it too. Reset This Device and Delete My Account & All Data each erase the stored answer file and any queued commands, along with everything else.
Companion apps on your watch
If you install the LoadOut companion app on an Apple Watch, a Wear OS watch, or a Garmin watch, your phone sends it what it needs to be useful at the firing line: the active load, the firing solution and its holds, your target card, and the shots you log on the wrist. This travels over the paired-device channel the platform provides (Apple's Watch Connectivity, Google's Data Layer, Garmin's Connect IQ), directly between your phone and your watch. No LoadOut server is involved, and we receive none of it.
What the watch holds, it holds on the watch, in that application's own private storage. When you turn the feature off, or run either of the privacy operations below, your phone asks every paired watch to discard what it is holding. That request is best effort, and we would rather say so than imply otherwise: a watch that is switched off, out of range, or unpaired at that moment does not receive it, and the channel returns no acknowledgement, so your phone cannot confirm that any watch acted. A watch that missed the request discards what it holds the next time it connects and hears one. If you are disposing of a watch, unpair it and erase it through its own settings rather than relying on this.
Spoken output
LoadOut can read a firing solution out loud: a target card row on your phone, or the next target on your watch after you log a shot. To do it, the application hands the finished sentence to the speech engine built into the platform: AVSpeechSynthesizer on iOS and macOS, the system text-to-speech service on Android, and the browser's own SpeechSynthesis on the web. No LoadOut server is involved, and we receive nothing.
We cannot tell you whether that sentence stays on your device. Some platform voices synthesize speech locally and others do it over the network, and the platform does not reliably publish which is which. Android exposes a per-voice flag that no part of the system enforces, and iOS and the browser expose nothing at all. LoadOut prefers a voice that reports itself as local where the platform offers that signal, but a preference is not a guarantee and we will not claim one in either direction. If you would rather nothing be spoken, spoken output has its own setting and you can leave it off. Speech is output only: the application does not open your microphone for it, and requests no recording permission.
Sub-processors and third parties
We use the following third-party services to operate LoadOut. Each has its own privacy policy, which governs its handling of the data we send to it.
- Google Cloud / Firebase (Authentication, Hosting, Storage for catalog updates). https://firebase.google.com/support/privacy
- RevenueCat (in-app purchase verification and entitlement). https://www.revenuecat.com/privacy
- Cloudflare (the AI Smart Import proxy runs on Cloudflare Workers + KV; only relevant when you opt in to AI Smart Import in hosted mode). https://www.cloudflare.com/privacypolicy/
- Anthropic (AI Smart Import hosted mode forwards your OCR'd text — or, for the Garmin "Improve with AI" last resort, a cropped image of just the chronograph screen — to Anthropic's Messages API via our proxy; also available as a BYOK provider). https://www.anthropic.com/legal/privacy
- OpenAI (only if you choose OpenAI as your BYOK provider in Settings → AI — the request then goes directly to OpenAI under their terms, never via our proxy). https://openai.com/policies/privacy-policy
- Google Gemini (only if you choose Google Gemini as your BYOK provider in Settings → AI — the request then goes directly to Google under their terms, never via our proxy). https://ai.google.dev/gemini-api/terms
- Apple App Store / Google Play for purchase processing and subscription management. https://www.apple.com/legal/privacy/ · https://play.google.com/about/play-terms/
- Apple: Siri and App Intents, only if you turn on Siri Voice Commands. Your spoken request and LoadOut's answer are processed by Apple under Apple's own privacy policy. https://www.apple.com/legal/privacy/
- Sign-in providers if you use them: Google, Apple, Microsoft. We request the minimum scope needed to identify you (typically email and name).
How long we keep data
- Reloading data: we do not hold it. It resides on your device for as long as you retain it there.
- Account record (Firebase Authentication): retained until you request its deletion, or until the account has been inactive for an extended period (we will define a specific retention window in a future revision).
- Purchase records (RevenueCat and the stores): retained for as long as the subscription or lifetime entitlement remains active, and as required by Apple, Google, and applicable tax law.
- Voice-command data: the answer file LoadOut stores for Siri lives on your device only. It is rewritten when your data changes and erased when you turn the feature off. We hold none of it.
How to delete your data
- On-device data: open Settings → Privacy & Data → Reset This Device to clear your loads, firearms, batches, brass logs, and ballistic profiles from this device. Your cloud backup and account remain active, so that you may restore your data at a later time.
- Account & all data: open Settings → Privacy & Data → Delete My Account & All Data to permanently delete your LoadOut account, the data on this device, your encrypted cloud backups across every connected provider, and the linked subscription identity. This action cannot be undone.
- Voice-command data: turn off Siri Voice Commands in Settings → AI Features to erase the stored answers. Commands you queued but haven't confirmed are removed by either of the two operations above.
- Cloud backup: the “Delete My Account & All Data” flow above deletes the encrypted backup files from every cloud provider the app can still reach. If you had already disconnected a provider or revoked LoadOut's access to it, the encrypted file may remain in your own storage — delete it yourself from your iCloud Drive, Google Drive, or OneDrive. It is unreadable without your passphrase, which we never had.
- Uninstalling the application removes the local database and clears any cached catalog updates.
Your privacy rights
Depending on your jurisdiction of residence, you may have additional rights over your personal information.
- European Economic Area / United Kingdom (GDPR / UK GDPR): you have the right to access, correct, delete, restrict, port, and object to processing of your personal data. The lawful bases we rely on are contract (to provide the app and Pro entitlement), consent (for any optional telemetry we add later), and legitimate interest (for security and abuse prevention). You may also lodge a complaint with your supervisory authority.
- California (CCPA / CPRA): we do not sell or share your personal information for cross-context behavioral advertising. You have the right to know, delete, correct, and limit use of sensitive personal information. We do not use sensitive personal information for purposes beyond providing the app.
- Other US states (CO, CT, VA, UT, etc.): we honor analogous consumer rights to access, delete, correct, and opt out, where applicable.
To exercise any right, send a request to support@johnsondigitalsystems.com from the email address associated with your account. We will respond within the period required by law in your jurisdiction.
Children
LoadOut is not directed at children. We do not knowingly collect personal information from any person under 18 years of age. Reloading is for adults only; refer to the in-app safety disclaimer.
International data transfers
Firebase Authentication and RevenueCat may process your data in the United States and other countries. Where required, we rely on Standard Contractual Clauses or equivalent mechanisms to safeguard cross-border transfers.
Security
We use TLS for any data in transit between the application and our service providers. Cloud backups are encrypted on your device with your passphrase before upload, using authenticated encryption. We do not, however, guarantee absolute security; no system is invulnerable. If we discover a breach affecting your personal information, we will notify you as required by law.
Changes to this policy
If we make material changes, we will update the effective date and provide notice within the application (typically by re-prompting the disclaimer or privacy dialog).
Contact
Johnson Digital Systems — LoadOut