Legal

Privacy Policy

Last updated: September 24, 2026

1. Introduction

Gearlogue ("we", "us", "our") is a gear management platform that helps you organise your equipment, build kits, plan projects, and collaborate with teams. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our service.

By creating an account or using Gearlogue, you agree to the collection and use of information in accordance with this policy.

Effective date: September 24, 2026

2. Information We Collect

Account Information

When you sign up, we collect your email address and name. Authentication is managed by a dedicated identity provider — your password is securely hashed and never stored in our application database. A username is optional and only collected if and when you pick one (for example, when you first send a friend request by username).

Profile Information

You may optionally provide additional profile details including a bio, location, date of birth, social media links, creator promo links, verified social account details, and preferred outdoor activities. This information helps personalise your experience and is visible on your public profile if you choose to make it public.

Gear Data

We store the gear items, kits, projects, and teams you create within the platform. This includes item details (name, brand, weight, price, images, videos, and web links), kit configurations, project plans, imports and import previews, and team membership.

Billing Information

If you subscribe to a paid plan or buy prepaid AI credits, Stripe handles checkout, invoices, payment methods, and tax calculations where applicable. Gearlogue stores billing identifiers, subscription tier, subscription status, renewal/cancellation dates, AI allowance usage, prepaid balance, and credit ledger entries so we can provide paid features and enforce plan limits. We do not store card numbers.

Usage Data

We collect limited usage data to enforce rate limits and maintain service quality. This includes last sign-in timestamps, feature usage counts, plan-based allowance usage, and engagement activity on public content. When enabled, our first-party pageview code sends limited usage data to Umami Cloud for aggregate visits, page views, broad location by country, and referring sites. We send page categories rather than individual gear, kit, project, or user IDs; query strings, page titles, email addresses, and AI conversations are not sent. Umami receives the browser request, including its IP address and User-Agent, to calculate visit and location statistics. We do not use analytics reports to identify individual visitors.

AI Interactions

Conversations with our AI assistant are stored to maintain your chat history. If you ask the assistant to remember a preference, we may also store that preference so it can be reused in future sessions. AI conversation data is automatically deleted after 90 days. If you enable Web Search, your search query is sent to our web-search provider to retrieve public results.

Feedback, Support, and Contact Data

When you use the Contact page, we collect the name, email address, and message you provide. When signed-in users submit feedback or bug reports from the app, we collect the report type, title, description, basic diagnostic context (such as page URL, browser user agent, and app version), and any optional screenshots you attach. Screenshots are limited to image files and stored privately for support review.

Security and Anti-Abuse Data

Signup and contact forms use Google reCAPTCHA v3 to reduce spam and automated abuse. reCAPTCHA may process technical information about your browser and interaction with the form in accordance with Google's own privacy terms.

3. How We Use Your Information

  • Provide and improve the service — your gear data powers the core features: inventory management, kit building, project planning, and team collaboration.
  • AI-powered features — gear recommendations, kit analysis, and project planning are powered by AI. During conversations, relevant gear, kit, and project data is sent to the AI model to generate contextual responses. Our AI provider does not use your data to train models.
  • Web search (when enabled) — if you turn on Web Search in the AI assistant, we send your search query to a search provider so the assistant can retrieve public web results.
  • Community features — when you mark kits or projects as "public", or make gear visible publicly, they can appear in community discovery and on your public profile, enabling search, social sharing, and AI community/reference answers where permitted by your source controls.
  • Billing and subscriptions — we use billing, subscription, allowance, and prepaid-credit data to activate paid plans, route you to Stripe checkout or the billing portal, enforce feature limits, and show usage in the app.
  • Support and feedback — we use contact messages, feedback reports, diagnostic context, and optional screenshots to reply to you, reproduce issues, triage bugs, and improve the Service.
  • Security and abuse prevention — we use authentication, rate-limit, reCAPTCHA, and diagnostic data to protect accounts, prevent spam, and keep the Service reliable.
  • Service communications — we may send essential emails related to your account (e.g., password resets, security alerts). We do not send marketing emails.

4. Data Storage & Security

Your data is hosted on secure cloud infrastructure in the United States (US East region). We use industry-standard cloud services for data storage, search, media hosting, private feedback attachments, and email delivery.

All data is encrypted at rest using AES-256 and in transit using TLS. Authentication is managed by a dedicated identity service — passwords are securely hashed and never stored in our application database.

5. Local Storage

We use browser localStorage (not cookies) to store the following on your device:

  • Authentication tokens (for maintaining your session)
  • UI preferences (theme, panel sizes, sidebar state, consent choice)
  • Subscription state cache (to avoid redundant API calls)

We do not use third-party tracking cookies or share data with advertising networks. Our optional Umami pageview integration does not use cookies or localStorage for analytics.

6. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR) and similar data protection laws, you have the following rights:

  • Right to access — you can export all of your data from Settings > Profile as a JSON download when data export is available for your plan. If you need a copy and cannot access the in-app export, contact us.
  • Right to erasure — you can delete your account from Settings > Profile. This permanently removes all your data, including gear, kits, projects, teams, AI conversations, and your public profile. This action is irreversible.
  • Right to rectification — you can edit your profile, gear items, kits, and projects at any time through the application.
  • Right to data portability — the JSON export includes all of your data in a structured, machine-readable format.
  • Right to object — you can opt out of AI processing by simply not using the AI assistant. AI features are entirely optional.

To exercise any of these rights or if you have questions, contact us at contact@gearlogue.com.

7. Data Sharing

We do not sell your personal data.

We share data with the following third-party processors, solely to operate the service:

  • Cloud infrastructure provider — hosting, authentication, database, storage, search, and email services
  • AI processing provider — Amazon Bedrock / Anthropic Claude powers AI assistant and import features for gear recommendations, extraction, and project planning
  • Web search provider — only when you enable Web Search in the AI assistant
  • Stripe — payment processing (only if you subscribe to a paid plan or buy prepaid credits). Stripe handles payment methods, checkout, invoices, and tax calculations where applicable; we do not store credit card information.
  • Google reCAPTCHA — spam and abuse prevention for signup and public contact forms
  • Umami Cloud — aggregate site usage measurement when analytics is enabled; no advertising or cross-site user profiling by Gearlogue
  • Social verification providers — only if you choose to connect a supported social account for public verification

Public data: kits, projects, and gear you mark as public can be visible on community pages, in search results, in AI community/reference answers, and via direct links. Your public profile (for example username, bio, avatar, public social links, creator status, and verified social badges) is visible to other users when you enable those features.

8. Data Retention

  • Account data — retained for as long as your account is active. When you delete your account, all associated data is permanently removed.
  • AI conversations — automatically deleted after 90 days.
  • Feedback reports — retained while needed for support, product quality, and abuse investigation. Optional screenshot attachments automatically expire after 90 days.
  • Billing records — retained for as long as needed to provide subscriptions, resolve disputes, comply with tax/accounting obligations, and maintain accurate ledgers.
  • Rate limit records — automatically expire daily and are not retained.
  • Web analytics — on our current Umami Cloud Hobby plan, analytics data is retained for six months.

9. Children's Privacy

Gearlogue is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.

11. Contact

If you have any questions about this Privacy Policy or your personal data, please contact us:

contact@gearlogue.com