Privacy Policy

DrillMark is designed to work without an account. Your original target recordings and audio stay on your device. Cloud backup is optional and contains drill metadata, not original media.

Effective and last updated: September 29, 2026

English · 한국어

1. Scope

This policy explains how the DrillMark iOS app, its optional cloud backup, and the DrillMark Performance website handle information. “We,” “us,” and “DrillMark” refer to the independent developer operating DrillMark from South Korea. Questions can be sent to drillmarkapp+support@gmail.com.

2. Information handled by DrillMark

Information stored on your device

DrillMark stores the information needed to create and review your history, including session dates, drill and target settings, firearm profile details you enter, shot coordinates and timing, analysis confidence information, edits, and notes.

Camera video, target imagery, and recorded audio are processed for shot analysis and review. Original recording media is stored only on your device and is not included in cloud backup. Media you explicitly export is handled by the destination you choose.

Optional account and cloud backup

If you choose Sign in with Apple or Google Sign-In, DrillMark uses Firebase Authentication and stores an account identifier and any email address the provider returns for authentication. Apple or Google can also provide basic profile information, such as a name; Google Sign-In can provide a profile photo reference. Apple lets you choose whether to share your email address or use Hide My Email.

After sign-in, DrillMark can back up the following metadata to Google Cloud Firestore:

Original videos, audio recordings, target images, screenshots, diagnostic archives, and local file paths are not uploaded as part of cloud backup.

Optional app improvement data

App improvement data sharing is optional and off by default in Settings → Privacy & Diagnostics. The app decides on your device which choices apply, using your App Store account’s country and your device’s time zone. If your App Store account is in the United States and your device is not set to Korea’s time zone, you can enable sharing without a separate overseas transfer consent choice. Otherwise, including when the App Store country cannot be read, both sharing and separate overseas transfer consent must be on. You do not need a backup account. The last App Store country read, the resulting consent flow, and any overseas consent state, version, and last change time are stored on your device. The App Store country and time zone are not sent as app improvement events or user properties. If a later change means a separate overseas transfer consent you have not given is now required, sharing turns off and you must make the applicable choices again. Determining the consent flow never turns sharing on. An earlier sharing choice alone does not count as overseas transfer consent.

If you enable it, Google Analytics for Firebase receives feature interactions, training-day and revisit information, operation outcomes and durations, counts of planned and automatically detected shots, saved result corrections, and categorical drill/setup choices such as drill, target, distance, firearm type, caliber, optic use, ready position, and effective holster. Set-level identifiers and analysis and workflow identifiers link events for the same activity. Firebase Crashlytics receives crash stack traces, app and device information, and predefined technical error codes. These services use app installation and session identifiers, and Analytics can derive an approximate region from the network IP address. This is not fully anonymous data. We do not send your name, email, Firebase account ID, firearm names, firearm profile IDs, notes, shot coordinates, recordings, or local file paths as app improvement data. Advertising identifiers, vendor identifiers, and advertising personalization are disabled.

Turning sharing off stops future Analytics collection and crash report submission, and deletes unsent crash reports. Crash information can still be temporarily stored on your device by the SDK; the app discards unsent reports when sharing is off and when you turn it back on. Turning sharing off does not automatically delete information already received or exported. You can request access to or deletion of that information by contacting us; we handle requests to the extent we can identify the information and as required by applicable law. We also use Google Cloud BigQuery to analyze exports of the same optional analytics and diagnostic data.

Service requests

Firebase Authentication and Google Sign-In process network, device, SDK-version, and sign-in usage information to provide and secure authentication and maintain service quality. This includes technical requests made during sign-in and session refresh, independently of the optional app improvement sharing setting. Firebase Hosting receives network information, including your IP address, when the app checks update notices or you visit our privacy and support pages. These service requests help deliver the service and prevent abuse. Our website does not include analytics scripts or advertising cookies.

Our website does not use cookies or scripts to track browsing across other websites. Browser Do Not Track signals do not change how the website works because it does not perform that tracking. We do not enable third-party advertising or analytics scripts to collect website activity across other sites. Firebase Hosting still handles technical requests as described above.

We apply Firebase App Check to Cloud Firestore backup requests to reduce unauthorized requests. It uses Apple’s App Attest and processes attestation information generated on your device and short-lived App Check tokens. Tokens can also accompany requests to supported Firebase services. App Check does not replace account authentication or Firestore security rules. App Check does not retain the attestation information, and its tokens expire within 7 days.

Support communications

If you contact support, we receive your email address, message, and any attachments to respond and manage support history. Our support address uses Gmail, so Google’s email systems process this information. Do not send sensitive recordings unless support specifically asks for them and you are comfortable doing so.

3. How information is used

Information is used to provide app functionality: recording and analyzing drills, displaying and editing history, authenticating an optional account, backing up and restoring metadata, preventing deleted records from returning, securing the service, and responding to support requests.

DrillMark does not sell personal information, show third-party advertising, or use app data to track you across other companies’ apps or websites. When you enable app improvement data sharing, we compare the shots detected automatically in each set with the corrections you save to improve shot detection accuracy. Analytics and diagnostics also help us assess feature demand, reduce correction effort, and resolve reliability problems. DrillMark does not include an advertising SDK.

4. Permissions

You can change permissions in iOS Settings. Camera access is required to record a drill.

5. Service providers

DrillMark uses the following services:

We receive support messages through Google’s Gmail service. Information processed independently by your Google sign-in provider is also covered by that provider’s privacy policy.

Applicable service terms include the Firebase Data Processing and Security Terms for Firebase, separate Google Ads Data Processing Terms for Google Analytics, and the Google Cloud Data Processing Addendum for BigQuery. Google’s Privacy Policy also applies to processing by the Google sign-in provider and Gmail. Sign in with Apple, App Attest, and other Apple platform services are governed by Apple’s Privacy Policy.

6. Retention and deletion

Analytics and diagnostics are stored separately from account backup. Google Analytics currently retains event data for 2 months and user data for 14 months, with the user-data period reset on new activity; aggregate reports can remain longer. Firebase Crashlytics retains crash traces and associated identifiers for 90 days before beginning removal from live and backup systems. BigQuery exports are processed in the US in the BigQuery sandbox, which deletes exported tables after 60 days. Exported copies have their own retention and are not automatically erased by deleting data in Analytics or Crashlytics.

Turning sharing off stops future Analytics collection and crash report submission; it does not automatically erase information already received by these services or exported to BigQuery. Account or history deletion does not automatically delete these separate reports or change your sharing choice. We do not use your account ID to identify analytics reports, so an account email alone may not allow us to locate installation-based data. Contact us to request access or deletion; we handle requests to the extent we can identify the information and as required by applicable law. Firebase retains Authentication security logs for a few weeks and Hosting IP information for a few months, as described in its service privacy information.

7. Your choices and controls

8. Security and transfers

DrillMark uses account-scoped Firestore security rules, Firebase App Check, encrypted network connections provided by Firebase, and platform security controls. No system can guarantee absolute security.

DrillMark uses Google services that can process information in the United States and other countries, depending on the feature you use. Optional account and backup information is handled by Firebase Authentication, Cloud Firestore, and App Check. Optional app improvement data is handled by Google Analytics for Firebase and Firebase Crashlytics, with exports analyzed in Google Cloud BigQuery. Optional analytics and diagnostics are sent only when sharing is enabled and any separate transfer consent shown on your device is also enabled. You can decline or withdraw the applicable choices without losing the app’s main features. A United States App Store account does not limit processing to the United States. Visits to our pages and update notices, and support email you choose to send, use separate Google service paths. Our Cloud Firestore backup database and BigQuery exports are located in the United States, and Firebase Authentication processes data only in the United States. Google Analytics, Crashlytics, App Check, Hosting, and Gmail can process information in other countries where Google or its subprocessors maintain facilities. See Google’s published data center locations and Firebase subprocessor information.

Optional analytics and diagnostics transfer

We use Google as a service provider for optional analytics and diagnostics. The app offers a sharing-only choice when your App Store account is in the United States and your device is outside Korea’s time zone. Otherwise, we also request separate overseas transfer consent and use that consent as the transfer basis under Article 28-8(1)(1) of Korea’s Personal Information Protection Act where applicable. How the app determines the consent flow does not waive any rights under applicable law. Sharing remains optional for everyone.

9. Changes to this policy

We may update this policy when the app or legal requirements change. The updated policy will be posted at this URL with a revised effective date. Material changes will also be communicated in the app or release notes when appropriate.

10. Contact

The DrillMark developer is responsible for protecting personal information. The DrillMark Service Operations Team receives and handles privacy requests and complaints.

Department: DrillMark Service Operations Team
Email: drillmarkapp+support@gmail.com
Support page: drillmarkperformance.com/support