Privacy Policy
DrillMark is designed to work without an account. Your original target recordings and audio stay on your device. Cloud backup is optional and contains drill metadata, not original media.
1. Scope
This policy explains how the DrillMark iOS app, its optional cloud backup, and the DrillMark Performance website handle information. “We,” “us,” and “DrillMark” refer to the independent developer operating DrillMark from South Korea. Questions can be sent to drillmarkapp+support@gmail.com.
2. Information handled by DrillMark
Information stored on your device
DrillMark stores the information needed to create and review your history, including session dates, drill and target settings, firearm profile details you enter, shot coordinates and timing, analysis confidence information, edits, and notes.
Camera video, target imagery, and recorded audio are processed for shot analysis and review. Original recording media is stored only on your device and is not included in cloud backup. Media you explicitly export is handled by the destination you choose.
Optional account and cloud backup
If you choose Sign in with Apple or Google Sign-In, DrillMark uses Firebase Authentication and stores an account identifier and any email address the provider returns for authentication. Apple or Google can also provide basic profile information, such as a name; Google Sign-In can provide a profile photo reference. Apple lets you choose whether to share your email address or use Hide My Email.
After sign-in, DrillMark can back up the following metadata to Google Cloud Firestore:
- session date, drill type, target and region settings, distance, duration, and set counts;
- firearm profile names and settings;
- shot coordinates, timing, order, confidence and analysis metadata;
- notes and manual result edits; and
- record ownership, update, deletion, schema, app build, and analysis version metadata.
Original videos, audio recordings, target images, screenshots, diagnostic archives, and local file paths are not uploaded as part of cloud backup.
Optional app improvement data
App improvement data sharing is optional and off by default in Settings → Privacy & Diagnostics. The app decides on your device which choices apply, using your App Store account’s country and your device’s time zone. If your App Store account is in the United States and your device is not set to Korea’s time zone, you can enable sharing without a separate overseas transfer consent choice. Otherwise, including when the App Store country cannot be read, both sharing and separate overseas transfer consent must be on. You do not need a backup account. The last App Store country read, the resulting consent flow, and any overseas consent state, version, and last change time are stored on your device. The App Store country and time zone are not sent as app improvement events or user properties. If a later change means a separate overseas transfer consent you have not given is now required, sharing turns off and you must make the applicable choices again. Determining the consent flow never turns sharing on. An earlier sharing choice alone does not count as overseas transfer consent.
If you enable it, Google Analytics for Firebase receives feature interactions, training-day and revisit information, operation outcomes and durations, counts of planned and automatically detected shots, saved result corrections, and categorical drill/setup choices such as drill, target, distance, firearm type, caliber, optic use, ready position, and effective holster. Set-level identifiers and analysis and workflow identifiers link events for the same activity. Firebase Crashlytics receives crash stack traces, app and device information, and predefined technical error codes. These services use app installation and session identifiers, and Analytics can derive an approximate region from the network IP address. This is not fully anonymous data. We do not send your name, email, Firebase account ID, firearm names, firearm profile IDs, notes, shot coordinates, recordings, or local file paths as app improvement data. Advertising identifiers, vendor identifiers, and advertising personalization are disabled.
Turning sharing off stops future Analytics collection and crash report submission, and deletes unsent crash reports. Crash information can still be temporarily stored on your device by the SDK; the app discards unsent reports when sharing is off and when you turn it back on. Turning sharing off does not automatically delete information already received or exported. You can request access to or deletion of that information by contacting us; we handle requests to the extent we can identify the information and as required by applicable law. We also use Google Cloud BigQuery to analyze exports of the same optional analytics and diagnostic data.
Service requests
Firebase Authentication and Google Sign-In process network, device, SDK-version, and sign-in usage information to provide and secure authentication and maintain service quality. This includes technical requests made during sign-in and session refresh, independently of the optional app improvement sharing setting. Firebase Hosting receives network information, including your IP address, when the app checks update notices or you visit our privacy and support pages. These service requests help deliver the service and prevent abuse. Our website does not include analytics scripts or advertising cookies.
Our website does not use cookies or scripts to track browsing across other websites. Browser Do Not Track signals do not change how the website works because it does not perform that tracking. We do not enable third-party advertising or analytics scripts to collect website activity across other sites. Firebase Hosting still handles technical requests as described above.
We apply Firebase App Check to Cloud Firestore backup requests to reduce unauthorized requests. It uses Apple’s App Attest and processes attestation information generated on your device and short-lived App Check tokens. Tokens can also accompany requests to supported Firebase services. App Check does not replace account authentication or Firestore security rules. App Check does not retain the attestation information, and its tokens expire within 7 days.
Support communications
If you contact support, we receive your email address, message, and any attachments to respond and manage support history. Our support address uses Gmail, so Google’s email systems process this information. Do not send sensitive recordings unless support specifically asks for them and you are comfortable doing so.
3. How information is used
Information is used to provide app functionality: recording and analyzing drills, displaying and editing history, authenticating an optional account, backing up and restoring metadata, preventing deleted records from returning, securing the service, and responding to support requests.
DrillMark does not sell personal information, show third-party advertising, or use app data to track you across other companies’ apps or websites. When you enable app improvement data sharing, we compare the shots detected automatically in each set with the corrections you save to improve shot detection accuracy. Analytics and diagnostics also help us assess feature demand, reduce correction effort, and resolve reliability problems. DrillMark does not include an advertising SDK.
4. Permissions
- Camera: records the target and detects shot changes.
- Microphone: records audio with the target video and aligns shot timing.
- Photo Library: used only when you choose a feature that saves exported media to Photos.
You can change permissions in iOS Settings. Camera access is required to record a drill.
5. Service providers
DrillMark uses the following services:
- Firebase Authentication for Sign in with Apple and Google account authentication;
- Cloud Firestore for account-scoped metadata backup;
- Firebase App Check, with Apple’s App Attest, for an additional check on backup requests;
- Google Analytics for Firebase for optional product analytics;
- Firebase Crashlytics for optional crash and error reporting;
- Google Cloud BigQuery for analysis of exported optional analytics and diagnostic data; and
- Firebase Hosting for public pages and app update notices.
We receive support messages through Google’s Gmail service. Information processed independently by your Google sign-in provider is also covered by that provider’s privacy policy.
Applicable service terms include the Firebase Data Processing and Security Terms for Firebase, separate Google Ads Data Processing Terms for Google Analytics, and the Google Cloud Data Processing Addendum for BigQuery. Google’s Privacy Policy also applies to processing by the Google sign-in provider and Gmail. Sign in with Apple, App Attest, and other Apple platform services are governed by Apple’s Privacy Policy.
6. Retention and deletion
- Local history: remains until you delete history, delete the relevant session or set, or remove the app. Deleting a backup account removes its account association but leaves that history on the device with backup turned off.
- Local recording media: ordinary recordings are eligible for automatic deletion after 72 hours. A 1.5 GB device budget can remove the oldest ordinary recording sooner. A recording used for an active personal-best comparison may remain longer, until it is replaced, its history is deleted, or the app is removed.
- Cloud backup: remains while the backup account exists, unless you delete backed-up history. When a history deletion finishes syncing, the deleted session or set is replaced with a minimal deletion marker. Deleting a session or all history also removes the contents of its sets, including notes, shot coordinates, edits, and settings. Only the document identity and deletion/synchronization times remain while the account exists, to propagate deletion and prevent old copies from restoring the deleted content.
- Pending deletion: if you delete history while offline or a server request fails, the app retains the deletion request for retry during later synchronization with the same account. Server content can remain until synchronization finishes. Other devices may retain old local copies even after reconnecting. Those copies cannot replace deletion markers for the same records, and deleted content is excluded from a fresh cloud restore. Delete local copies on each device if you want them removed there. Deletions requested in earlier app versions may also require server cleanup before all original content is removed. Contact us if you need help confirming a deletion.
- Account deletion: the in-app Delete account flow deletes account-scoped Firestore history and firearm profiles, then deletes the Firebase Authentication account. For an account using Sign in with Apple, DrillMark also asks Firebase to revoke the freshly confirmed Apple authorization. Local history stays on the device and is no longer backed up. Firebase removes the deleted account’s authentication information from its live and backup systems within 180 days. Provider security and operational records can remain for the periods required by the provider or law.
- Support email: retained only as reasonably needed to answer the request, maintain support history, and meet legal obligations.
Analytics and diagnostics are stored separately from account backup. Google Analytics currently retains event data for 2 months and user data for 14 months, with the user-data period reset on new activity; aggregate reports can remain longer. Firebase Crashlytics retains crash traces and associated identifiers for 90 days before beginning removal from live and backup systems. BigQuery exports are processed in the US in the BigQuery sandbox, which deletes exported tables after 60 days. Exported copies have their own retention and are not automatically erased by deleting data in Analytics or Crashlytics.
Turning sharing off stops future Analytics collection and crash report submission; it does not automatically erase information already received by these services or exported to BigQuery. Account or history deletion does not automatically delete these separate reports or change your sharing choice. We do not use your account ID to identify analytics reports, so an account email alone may not allow us to locate installation-based data. Contact us to request access or deletion; we handle requests to the extent we can identify the information and as required by applicable law. Firebase retains Authentication security logs for a few weeks and Hosting IP information for a few months, as described in its service privacy information.
7. Your choices and controls
- Continue without an account to keep history and media local.
- Change your app improvement sharing choice in Settings → Privacy & Diagnostics. A separate optional overseas transfer consent is shown unless your App Store account is in the United States and your device is outside Korea’s time zone. Withdrawing the separate consent, or a change that newly requires it, turns sharing off.
- Delete individual history items or all history from within the app.
- Delete a backup account in Settings → Account → Delete account.
- Manage Apple or Google sign-in access and account recovery with the provider you selected.
- Ask us to access, correct, or delete your information, or to stop processing it, by email.
- Contact us for privacy or support questions.
8. Security and transfers
DrillMark uses account-scoped Firestore security rules, Firebase App Check, encrypted network connections provided by Firebase, and platform security controls. No system can guarantee absolute security.
DrillMark uses Google services that can process information in the United States and other countries, depending on the feature you use. Optional account and backup information is handled by Firebase Authentication, Cloud Firestore, and App Check. Optional app improvement data is handled by Google Analytics for Firebase and Firebase Crashlytics, with exports analyzed in Google Cloud BigQuery. Optional analytics and diagnostics are sent only when sharing is enabled and any separate transfer consent shown on your device is also enabled. You can decline or withdraw the applicable choices without losing the app’s main features. A United States App Store account does not limit processing to the United States. Visits to our pages and update notices, and support email you choose to send, use separate Google service paths. Our Cloud Firestore backup database and BigQuery exports are located in the United States, and Firebase Authentication processes data only in the United States. Google Analytics, Crashlytics, App Check, Hosting, and Gmail can process information in other countries where Google or its subprocessors maintain facilities. See Google’s published data center locations and Firebase subprocessor information.
Optional analytics and diagnostics transfer
We use Google as a service provider for optional analytics and diagnostics. The app offers a sharing-only choice when your App Store account is in the United States and your device is outside Korea’s time zone. Otherwise, we also request separate overseas transfer consent and use that consent as the transfer basis under Article 28-8(1)(1) of Korea’s Personal Information Protection Act where applicable. How the app determines the consent flow does not waive any rights under applicable law. Sharing remains optional for everyone.
- Information: app installation and session identifiers; set, analysis, and workflow identifiers; the usage, settings, detection, and correction statistics described in Section 1; crash traces, technical error codes, app and device information, network IP address, and approximate location derived from it.
- Countries, time, and method: after you enable sharing and any separate transfer consent shown on your device, data is sent over an encrypted connection during app use or when an error occurs to the United States and countries where Google or its subprocessors maintain facilities. Google does not fix Analytics or Crashlytics processing to one country. BigQuery exports are stored in the United States.
- Service contracting entities: Google LLC for Analytics and Google Asia Pacific Pte. Ltd. for Crashlytics. The BigQuery sandbox, which we use without a billing account, falls under the Google Cloud terms, whose contracting entity for an operator in Korea is Google Cloud Korea LLC. Subprocessors follow the Firebase and Google Cloud subprocessor lists. Use Google’s privacy contact form for Google privacy inquiries.
- Purpose and retention: optional usage analysis, error diagnosis, and BigQuery analysis. Analytics currently retains event data for 2 months and user data for 14 months, with the user-data period reset on new activity. Aggregate reports can remain longer. Crashlytics retains crash traces and related identifiers for 90 days before removal begins. BigQuery sandbox tables expire after 60 days.
- Declining or withdrawing: leave app improvement sharing off during initial setup, or turn it off in Settings → Privacy & Diagnostics. Where a separate overseas transfer choice is shown, declining or withdrawing it also disables sharing. You can still use the app’s main features. Already received or exported data is not deleted automatically; contact us to request deletion.
9. Changes to this policy
We may update this policy when the app or legal requirements change. The updated policy will be posted at this URL with a revised effective date. Material changes will also be communicated in the app or release notes when appropriate.
10. Contact
The DrillMark developer is responsible for protecting personal information. The DrillMark Service Operations Team receives and handles privacy requests and complaints.
Department: DrillMark Service Operations Team
Email: drillmarkapp+support@gmail.com
Support page: drillmarkperformance.com/support