Last updated: July 25, 2026
Johnson Digital Systems builds software with privacy as a foundation, not a feature. This policy covers johnsondigitalsystems.com and gives an overview of the products we publish. Where a product ships its own privacy policy, that policy is the authoritative one for the product and takes precedence over the summary here.
johnsondigitalsystems.com is hosted on Firebase. We do not add tracking, advertising pixels, or third-party analytics to this site.
If you submit a contact form, the information you provide (name, email, message) is used solely to respond to your inquiry. We do not sell or share this information.
LoadOut is built local-first. Your reloading data — loads, firearms, components, batches, brass logs, range sessions, ballistic profiles — lives in a database on your device. We do not operate a server that receives it. We do not use general analytics, we do not sell your data, and we do not track what you do in the app.
The LoadOut privacy policy is maintained with the app, and that document governs. It is the complete and authoritative statement of how LoadOut handles your data — including your rights, retention periods, sub-processors, and international transfers. What follows on this page is a short orientation only. Where the two differ, the app policy is correct.
In outline, these are the only things that leave your device, and each one is tied to a feature you choose to use:
Sign-in (optional)
If you sign in, Firebase Authentication receives your email address, your name where your sign-in provider supplies it, OAuth tokens for that provider, and sign-in metadata. Used to authenticate you — not for marketing or analytics.
Purchases
If you buy Pro, RevenueCat receives your account identifier, the store-level transaction record, and anonymous device metadata needed to validate receipts, so your purchase follows your account across devices. It does not receive your email address or any reloading data.
Diagnostics
Firebase Crashlytics receives crash reports and non-fatal error reports the app catches for diagnostic purposes. Reports carry technical metadata only — no reloading data, no user-typed text, and no account identifier is attached. On by default; you can turn it off in Settings.
Cloud backup (Pro, opt-in)
Your data is encrypted on your device with a passphrase we never receive, then uploaded to your own cloud storage. Nothing is stored on our infrastructure. We cannot read your backup and cannot recover a lost passphrase.
AI Smart Import (Pro, opt-in per use)
In hosted mode, the text read from your import photo is sent to Anthropic through our proxy. For a chronograph screen that on-device reading and guided capture have both failed on, a cropped image of just that screen — never the raw full photo — may be sent as a last resort, only after you accept a disclosure shown before any image leaves the device, and capped per import. You can instead enter your own Anthropic, OpenAI, or Google Gemini key in Settings, in which case the request goes directly from your device to that provider and that provider's terms govern it rather than Anthropic's.
Live Weather (Pro, opt-in per use)
Your coordinates are sent to open-meteo.com for that one request, with no account or identity information attached. Those coordinates are also saved on your device alongside the records they belong to, because the ballistic solver and your range-day and atmosphere entries use them — and so they travel inside the encrypted backup if you turn cloud backup on. We operate no server that receives them.
Favorites, Vault, journey progress, reflections, and journal entries are stored locally on your device. None of this data is transmitted to our servers.
Daily Alignment uses Firebase Crashlytics, which receives crash reports and non-fatal error reports for diagnostic purposes. Audio content is served from Firebase Storage.
Privacy & data requests
support@johnsondigitalsystems.com
To access, correct, export, or delete your data, or to exercise any privacy right, email us here from the address tied to your account. This is the same address our app privacy policies and account-deletion pages use.
Everything else
hello@johnsondigitalsystems.com
General questions, including questions about this policy itself.
If you cannot open the LoadOut app, you can delete your LoadOut account and all of its data from the LoadOut account-deletion page.