Documentation
On this page
Your reloading data lives on your device. We run no server that stores your recipes, firearms, or range-day sessions. We don't track what you do in the app, and there is no analytics SDK in it. Several connections run without a switch — the anonymous sign-in identity, the app-integrity check, catalog and wording updates, and crash reports, which are on by default and switch off under Privacy & Data. The features that send your own content — Cloud Backup and Cloud Sync, AI Smart Import, Siri Voice Commands, and the weather pull — are off until you use them.
That paragraph is the promise. What follows is every connection the app makes, so you can check the promise against the details. The LoadOut Privacy Policy is the authoritative document; where this page and the policy differ, the policy governs.
What reaches the network
| Connection | When | What it carries | Switch |
|---|---|---|---|
| Anonymous sign-in | First launch | A random guest identity so the app can restore a Pro purchase and, if you ever choose to, sign in. No reloading data. | None; it is how the app starts |
| App integrity check | Every launch | A device attestation token. No reloading data. | None |
| Sign-in with Google, Apple, or Microsoft | When you sign in | Your email address and sign-in token; Apple also requests your name. | Only when you tap Sign In |
| Crash reports | After an unhandled error, on the next launch | A stack trace, the screen you were on, the app and schema version, and stable row ids. Never the text you typed: no recipe names, firearm names, or notes. | On by default; off under Privacy & Data |
| Purchases | When you buy or restore Pro | The store receipt, matched to your guest or signed-in identity so Pro follows you across devices. | Only when you buy or restore |
| Match Day sealed briefs | When you open a sealed course of fire (free) | The match id and its key id, sent to LoadOut's own proxy with your sign-in token (a guest account has one too), which answers with the content key or that it is not released yet. Nothing from your database travels. If the proxy cannot be reached the app tries a public release file next, and a code from the match director works with no network at all. | Only when you open a sealed brief |
| Live Weather Pull and Automatic Altitude | When you tap them (Pro) | Your coordinates, sent to a public weather service to fetch conditions for where you stand. No identity travels with them. | Only on the tap |
| AI Smart Import | When you tap Improve with AI (Pro) | Either the text read off a page you just photographed, or one cropped picture of a chronograph screen together with a one-line summary of what that import has read so far, which can include values from the other screens you added. Never your recipes, firearms, or notes. Sent through LoadOut's own proxy to the model provider, or straight to a provider with your own key. | Off until you turn it on; asks on every use |
| Cloud Backup and Cloud Sync | When you turn them on (Pro) | Your data, encrypted on the device with your passphrase before it leaves, written to your own iCloud Drive, Google Drive, or OneDrive. LoadOut runs no server that receives it and holds no key that could open it. | Off until you turn them on |
| Catalog, announcement, wording, and model downloads | On launch, with a connection | Read-only pulls of newer catalogs, announcements, published wording corrections for the languages the app already ships, and, if you enable them, the on-device search model and the Standard voice. Nothing of yours is uploaded. | Downloads of models are asked for first |
| Siri Voice Commands | When you speak to Siri | Your spoken request and LoadOut's spoken answer are handled by Apple's assistant under Apple's terms. LoadOut publishes a small summary of your holds into a private container on the device for Siri to answer from; we receive nothing. | Off until you turn it on; turning it off erases the summary |
| Spoken Output | When the app reads a target aloud | The sentence is handed to the device's own speech engine and then dropped. Which voices the platform synthesizes locally is the platform's business; LoadOut operates no server in this path. | The phone's Target Card readout is off until you turn it on. On a paired Apple Watch or Wear OS watch the after-shot readout starts on; the switch is under Settings › Voice & AI › Spoken Output on the phone, and the watch carries the same switch. |
What we do not have: no product analytics of any kind, no advertising SDK, no attribution SDK, and no LoadOut-operated server that receives your database.
What is stored, and where
How the cloud copy is encrypted
Cloud Backup and Cloud Sync encrypt on the device with AES-256-GCM under a key derived from your passphrase with PBKDF2-HMAC-SHA256 at 600,000 iterations and a fresh random salt per copy. Passphrases are at least eight characters. The encrypted copy is written to your own cloud account, so the only parties who can read it are you and anyone who holds both your cloud account and your passphrase.
So that your other devices can open the copy without you retyping it, the passphrase is saved to your own Apple or Google account's protected store, the same place the platform keeps your other keys. LoadOut never sees it and runs no server that could. If you lose the passphrase and the platform store no longer has it, the copy cannot be recovered, by design; the app says so in red when you set it.
The two ways to erase
| Operation | What it removes | What it keeps |
|---|---|---|
| Reset This Device | Every record on this device, the search index, cached photos, and stored credentials such as an AI key. | Your account, your Pro purchase, your encrypted cloud copies, and the passphrase that opens them, so you can restore later. |
| Delete My Account & All Data | Your account, the encrypted copies in every cloud you connected, the link between your purchase and your identity, every credential, and every record on this device. | Nothing. It may ask you to sign in again first, and nothing is destroyed until that succeeds. |
Both are under Settings › Privacy & Data. Both tell every paired watch to discard the shots it is still holding, and both leave a small timestamp behind for 90 days so a shot a watch delivers late is refused rather than quietly re-creating data you erased. The timestamp says only that an erasure happened, never what was erased.
What a crash report can and cannot contain
A report carries a stack trace, the name of the screen, the app and database version, the platform and OS version, whether you were signed in, and the numeric ids of rows involved. It never carries the contents of a row, anything you typed, your email address, or your account identifier. If you want no network traffic from the app beyond what you start yourself, turn crash reports off under Privacy & Data; the app then sends no crash data, while the sign-in identity, the integrity check and the catalog and wording updates still run.
Privacy requests
Deleting your data needs no email: both operations above are in the app, and the account and data deletion page explains what to do if you no longer have the app installed. For anything else, write to support@johnsondigitalsystems.com.