Privacy Policy
Short version. AmmoTracker stores the inventory, firearm, usage and range-session data you enter so the app can show it back to you. We don't sell it, we don't run ads, and you can delete everything yourself from your account page at any time.
1. Who we are
AmmoTracker ("we", "us") provides an ammunition inventory web app and iOS app. This policy explains what we collect, why, and what control you have. Questions go to support@example.com.
2. What we collect
- Account data — your email address and a salted password hash (never the password itself). If you sign in with Google we store the Google account identifier and email Google gives us. Optional profile fields (display name, nickname, location, bio, time zone, avatar URL) are stored only if you fill them in.
- Security data — whether two-factor authentication is on, the encrypted authenticator secret, hashed one-time backup codes, public keys for any passkeys you register, hashed "remember this device" tokens (expire within 24 hours), failed sign-in counts, and lockout timestamps.
- Inventory data — everything you enter: ammunition entries, purchases, firearms, usage logs, wishlist items, notes, and any photos you attach. Photos and scanned box labels you upload are stored as images; text extracted from a scan is used only to pre-fill the form.
- Shot Session audio — if you use the Shot Session feature, short audio recordings from your microphone are uploaded so we can detect and classify shots. Raw audio is stored privately under a hashed account identifier and automatically deleted after 30 days. Calibration data is kept as numeric sound signatures, not audio, so the classifier can learn your firearms.
- Device data — if you enable notifications on iOS we store your push-notification token so we can deliver low-stock alerts.
- Audit and operational logs — a record of state-changing actions (for example "ammo entry created", "password changed") with your email, IP address, timestamp and outcome, kept for one year for security investigation. Request bodies are never stored in the audit log. Application logs and performance metrics may include your email address in sign-in and security events.
3. Why we use it
- To run the service: show your inventory, calculate usage and burn rates, and send the alerts you turn on.
- To keep your account safe: enforce sign-in, two-factor authentication, lockouts, and detect abuse.
- To improve the Shot Session classifier for your account. Your audio and calibration data are not used to train models for other users.
- To send transactional email: confirmation, password reset, and security alerts (new remembered device, new passkey, password change, two-factor changes, account deletion). We do not send marketing email.
4. Who else sees it
We use these providers to run the service. Each processes data only on our instructions:
- Amazon Web Services — hosting (App Runner), database (DynamoDB), file storage (S3), and email delivery (SES).
- Google — only if you choose "Sign in with Google", to verify your identity.
- Cloudflare Turnstile — bot protection on the sign-in and sign-up forms.
- Grafana Cloud — application logs, metrics and traces for reliability monitoring.
- Apple — push-notification delivery to the iOS app.
We do not sell personal data, share it with advertisers, or disclose it to third parties except as described above or when required by law.
5. Cookies and local storage
On the web app we set a session cookie and a CSRF cookie to keep you signed in and protect forms, plus an optional "remember this device" cookie if you tick that box during two-factor sign-in. We also use browser local storage for your session token, theme and design preference. No advertising or cross-site tracking cookies are used.
6. How long we keep it
- Account and inventory data: until you delete it or delete your account.
- Shot Session audio: 30 days after upload.
- Remembered-device tokens: up to 24 hours.
- Audit log entries: one year.
- Uploaded images that are no longer referenced by any entry may persist in storage until routine cleanup.
7. Deleting your account
Go to Account → Delete account. After you confirm your password (and two-factor code, if enabled) we immediately and permanently delete your account together with your ammunition, firearms, usage history, wishlist, shot sessions, calibration data, passkeys, remembered devices and push tokens. Audit-log entries naming your email are retained for the remainder of their one-year window for security purposes, and previously uploaded image files may remain until routine cleanup. There is no undo.
8. Your rights
You can view and edit your data in the app at any time and export your inventory as CSV. Depending on where you live you may also have rights to access, correct, port, restrict, or object to processing of your personal data, and to complain to a supervisory authority. Contact us at the address above to exercise any of these.
9. Children
AmmoTracker is not directed at children under 18 and we do not knowingly collect data from them.
10. Changes
If we make material changes to this policy we will update the effective date above and, where appropriate, notify you by email.