Effective: April 4, 2026 • Last Updated: October 4, 2026
Gear Guy is built by Warlock Tactical Group ("we," "us," "our"). This Privacy Policy explains how we handle information in the Gear Guy mobile application ("App") and the gearguyapp.com website ("Site"). Our core principle is simple: your data belongs to you, not us.
Your private inventory vault is encrypted on your device. Identify and public build sharing send only the information described below to our services. Otherwise, we do not collect, store, transmit, or have access to:
Your firearms inventory data, serial numbers you enter (Section 4 covers one visible in a photo you send), photographs (except a photo you send for identification, described in Section 2), purchase records, or maintenance logs. Your builds, configurations, or saved loadouts — except a build you choose to share, described below. Your name, address, location, or device identifiers (except as described in Section 3 below). Usage analytics, crash reports, or behavioral telemetry. (Section 3 describes the records we keep only to enforce the identification limits.)
The vault's copies of your inventory data, serial numbers, photographs, and builds are encrypted with AES-256-GCM and stored only on your device. We cannot access them. We cannot recover it for you: if you lose your device, the data on it is gone unless you turned on one of the optional recovery paths described in Section 5. This is by design.
Builds you choose to share. Gear Guy can turn a build into a public link (gearguyapp.com/b/…) or a shareable image. This only ever happens when you tap Share. When you do, two things are uploaded to our Cloudflare storage: the build's parts list — the platform, the name you gave the build, and for each part its slot, catalog id, display name, price and finish — and a rendered image of that build. Nothing else travels with it: no account, no device identifier, no serial number, no photograph from your records, and no part of your inventory beyond the build you shared. Your IP address is seen briefly to limit abuse and is then discarded. Because the build's name is text you write yourself, don't put anything private in it. A shared build stays at its link until we remove it; email us and we will delete it.
On the Website (gearguyapp.com): If you submit your email address for beta access or newsletter signup, we store that email address. We do not use third-party email marketing platforms that track open rates or click behavior. We do not sell or share email addresses with any third party.
On the App — Photo Identification Feature: When you use the "Identify" feature, a downscaled copy of your photograph is transmitted to our secure identification service (hosted on Cloudflare Workers) for processing. The photograph is forwarded to a third-party AI service (Anthropic) for analysis; see Section 6 for how long Anthropic keeps it, including a brief cache that lets follow-up questions reuse the photo. We do not store the photograph, and we do not log it. When the app attaches a scan identifier to an identification request other than a follow-up question, we keep a one-way code computed from the photograph, as described in Section 3; the photograph cannot be recovered from it. Apple's identifier for this vendor on your device (identifierForVendor) is sent with each identification request (or, if the device does not provide one, a random value generated for that request) and is used only to enforce the identification limits described in Section 3. Apple gives every app from the same developer on your device the same value; it changes when all of that developer's apps are deleted from the device and one is later reinstalled, and it can also change for test builds. Deleting the App does not delete the records described in Section 3; they are removed by the cleanup Section 3 describes.
On the App — Record Photos: When you add an identified firearm to your inventory, two images are generated from your photograph and stored on your device: a small thumbnail (about 100 pixels) for lists, and a copy of the photograph re-encoded at reduced resolution for the firearm's record page. Both are AES-256-GCM encrypted at rest alongside your other vault data, and both are deleted when you delete the photo from the record or delete the record. The photograph as originally captured is not retained by the App beyond the identification request. Neither stored image can be read without your device's vault key.
We use a device identifier sent with photo-identification requests to enforce service limits: a per-minute limit, applied through Cloudflare's rate-limiting service, and daily limits on identifications and on identification attempts. The per-minute limit uses the identifier as sent; Cloudflare's rate-limiting service keeps short-lived counters for it. Every identification attempt we accept counts toward the daily attempt limit; only a new scan that produces an identification counts toward the daily identification limit. The daily limits currently apply to all subscription tiers. The identifier is not associated with any user profile and is not used for advertising, analytics, or tracking of any kind.
For the daily limits, we derive a code from the identifier using a secret key. The code changes each UTC day. We store a record under that code in Cloudflare's Durable Objects storage. We do not store the raw device identifier in this record. The record holds the date and the time limit for that day's attempts; a count of identifications counted against the daily limit and a count of identification attempts; while an attempt is in progress, an entry for it with a random reference, its type (a new scan, a follow-up question, or a repeat of an earlier scan) and the time it expires, which also shows when it started; and, for each attempt, a short entry recording how it ended, with no time attached: it produced an identification (for a new scan, this is what counts against the daily identification limit), it ended without one (no match, an error or a timeout), or it expired before its outcome was recorded. So the record notes whether each attempt produced an identification, but not what the identification was.
When the app attaches a scan identifier to an identification request other than a follow-up question, the record also holds a code derived from that scan identifier, not the identifier itself, and a one-way code computed from the submitted photo. Both are made with the same secret key and are specific to the device and the day, so the same photo gives an unrelated code on another device or another day. They are used only to recognise a repeat of the same scan, so that retrying a scan that was already counted does not count it again, and a scan identifier cannot be reused for a different photo. They are kept while that attempt is in progress and, if the scan is counted, until the day's record is cleaned up. One case runs across midnight: in the first few minutes of a UTC day (never more than ten), we also compute the previous day's codes for such a request, to recognise a retry of a scan counted on the previous day; if we accept that retry, the new day's record keeps its codes until that day's record is cleaned up, whether or not the retry produces an identification. The photo code cannot be turned back into the photo. The record never contains the photo, the content of any identification result, or your IP address.
Each in-progress entry is removed once the outcome of its attempt is recorded; if that does not happen, its cleanup is scheduled for the time it expires. Cleanup of the whole record is scheduled for shortly after the UTC day ends. An attempt that has expired can no longer be counted, even before its entry is deleted, and deletion can happen some time after these points. If automatic cleanup fails, a record can remain with no fixed limit; we do not yet run a separate process that finds and removes such records. These records are removed only by this scheduled cleanup, not on request: we have no way to tell which record belongs to you. Separately, Cloudflare's point-in-time recovery for this storage covers up to 30 days, so deleted records may still be recoverable within that period.
Serial numbers you enter in the App are encrypted with AES-256 before being written to local storage. They are masked by default in the user interface (displayed as ****7842). Serial numbers you enter in the App are never transmitted off your device — not to our servers and not to any third party; the App does not attach them to identification requests. A photo you submit for identification is different: if a serial number is visible in it, it travels with the photo to our identification service and to Anthropic, as described in Sections 2 and 6. We instruct the AI model not to record or report a serial number it can see.
Your vault records are encrypted with AES-256-GCM (Apple CryptoKit). The 256-bit vault key is generated on your device and stored in the iOS Keychain with device-only accessibility: it is not synced to iCloud Keychain and does not migrate to another device through a backup. There is no passphrase. By default there is also no recovery path: if the device is lost or erased, nobody — including us — can decrypt the vault. You may optionally turn on a recovery path in Settings: an additional copy of the vault key kept in your Apple iCloud Keychain (end-to-end encrypted by Apple; the vault data itself never leaves your device), or a one-time recovery key that you write down. We have no backdoor and no master key.
Anthropic (Claude AI): Photographs submitted through the identification feature are processed by Anthropic's Claude API. Anthropic's commercial terms say it may not train models on customer content from its services. Anthropic states that it automatically deletes API inputs and outputs within 30 days of receipt or generation, and that it may keep them longer in some cases, including to enforce its Usage Policy (if a request is flagged under that policy, inputs and outputs for up to 2 years and trust and safety classification scores for up to 7 years) and where the law requires. Our service also asks Anthropic to cache the photo briefly, so that follow-up questions about the same photo can reuse it; Anthropic's documentation says this cache lasts 5 minutes by default and is renewed each time it is reused. See Anthropic's data retention page and Anthropic's Privacy Policy.
Cloudflare: Our identification proxy and website are hosted on Cloudflare's infrastructure. The daily-limit records described in Section 3 are stored in Cloudflare's Durable Objects storage. Cloudflare may process standard web request metadata (IP addresses, request headers) as part of their service. See Cloudflare's Privacy Policy.
Apple: The App is distributed through the Apple App Store. Apple may collect its own data as described in its privacy policy. We do not receive personal information from Apple beyond aggregate download counts.
The gearguyapp.com website may add affiliate links to third-party retailers in future; any that appear will be disclosed as such. We earn no commission today, and the site carries no affiliate links. If you click an affiliate link once they exist, the retailer may set cookies on your browser and collect data according to their own privacy policy. Under any program we join we would receive only anonymized commission reports (total sales amount, not individual buyer identity). Affiliate links, where present, appear only on the website. The Gear Guy App contains no affiliate links today; see our Affiliate Disclosure.
Gear Guy is not intended for use by anyone under the age of 18. The App includes an age verification gate that must be completed before accessing any features. We do not knowingly collect data from minors. If you believe a minor has provided data to us, contact us and we will promptly delete it, except the daily-limit records described in Section 3, which are removed only by their scheduled cleanup.
You may export an inventory report as a PDF from within the App. A full encrypted data export is in development. You may delete all data from the App at any time using the "Delete All Data" function in Settings. Deletion is immediate and irreversible. Delete All Data does not reach the daily-limit records described in Section 3; those are removed only by their scheduled cleanup, not on request. To request deletion of your email address from our website mailing list, contact us at the address below.
We will update this policy if our data practices change. Material changes will be communicated through the App and on this page. The "Last Updated" date at the top reflects the most recent revision.
For questions about this Privacy Policy or to request data deletion:
Warlock Tactical Group
Email: chan@gearguyapp.com
Web: www.gearguyapp.com