CaliberBase Carry
Privacy Policy
Effective September 20, 2026
1. The short version
We do not sell your information and we do not share it with advertisers or data brokers. We hand it to no one except the service providers listed in Section 8, who run the infrastructure this app is built on, and where the law compels us. If your sign-up showed you a recovery code, your permit details are encrypted on your device before they reach us and we cannot read them.
We will not claim to know nothing about you. Some information has to be readable on our side for the Service to work at all, and pretending otherwise would be easy to disprove from our own documentation. Section 3 lists what that is.
2. Which kind of account you have
CaliberBase Carry has two kinds of account, and which one you have changes what we can see.
If your sign-up showed you a recovery code, your account is end-to-end encrypted. The Permits screen in the app also tells you which kind you have. Everything in Section 3 below applies; the items in Section 4 are ones we genuinely cannot read.
Older accounts, created before we introduced end-to-end encryption, work differently. For those accounts, each permit's issuing state and expiration date are stored unencrypted so the app can list and sort them. The rest of the permit — its name, number, issue date, date of birth if you entered one, the name and address printed on the card, your notes — and all of its photographs are encrypted on our servers under a key we hold. That protects them from anyone who steals the database, but it does mean we are technically able to read them, and that we could be compelled to produce them. Those accounts also reset their password by email, which an end-to-end account cannot do.
3. What we can see
The items below are what CaliberBase can read for any Carry account:
- Your email address, whether it has been confirmed, and the cryptographic values that let us verify your password without ever holding it — an authentication hash and salt, never the password.
- Your home state, if you set one. It is stored unencrypted because the reciprocity map is built around it.
- Your first and last name, if you provide them. These are encrypted at rest under a key we hold, which means we can read them — they exist so a person on our side can tell whose account is whose when you write in for help.
- How many permits you have, and when each was created or last changed. The app cannot list your permits without knowing that they exist.
- For each photograph: which permit it belongs to, whether it is an image or a PDF, its stored size, and when it was uploaded — but not what it shows, on an end-to-end account.
- When you were last active, and the encrypted key material that lets your password unlock your own data.
- Sign-in records. For each sign-in we store the time, the IP address, the browser or device details your app or browser reports, and the country and region that IP resolves to. We do not store a city, coordinates, your network provider, or which of our data centres served you. We keep your last 20 sign-ins in one place, and a longer-lived record for security and capacity planning. These are staff-facing records; there is no screen in the app that shows them to you, so ask us if you want a copy.
- Anything you send us in a support message, including attachments, and any note a staff member writes on your account. Support messages are not encrypted and are readable by our support staff — please do not paste permit numbers into one.
4. What we cannot read (end-to-end accounts)
If your sign-up showed you a recovery code, none of the following ever reaches us in readable form:
- The name you give a permit, its permit or license number, and the state that issued it.
- Its issue date, expiration date, and the date of birth printed on it, if you entered one.
- The name and address printed on the permit.
- Photographs or PDF scans of the permit.
- Any notes you attach to it.
- Your password, and the encryption key derived from it.
- Your recovery code. It is generated on your device and shown once. We store only a value that lets us check a code you present later; the code itself cannot be reconstructed from it.
This has a consequence worth stating plainly: if you lose both your password and your recovery code, we cannot recover your permits for you, because we do not hold the key.
5. In the CaliberBase Carry iPhone app
- The camera is used through Apple's own document scanner and text recognition, entirely on your device, to read a card's state and expiration date. Nothing is sent anywhere to do that. If you save the permit, the scanned image is attached to your account — encrypted on the device first, on an end-to-end account.
- Reminders are local notifications that the app schedules on your device. They appear on your lock screen and name the state. No push service is involved and no reminder leaves your phone.
- An encrypted copy of your permits is kept on the device so the app works offline. It is excluded from device backups.
- Your session token — and, on an end-to-end account, your key — are kept in the iOS Keychain on that device only.
- The app contains no analytics or advertising code, and never reads your location. "Near me" hands the search to Apple Maps.
6. How we use it
To operate your account and show you your own records; to answer your support requests; to keep the Service secure and detect abuse; and to meet legal obligations. We do not use your information to build an advertising profile, and there is no third-party advertising or tracking code in the app or on the website.
Email we send. Account mail only — confirming your address, a password reset for an older account, notice that a deletion has been scheduled, a change of email address, and a sign-in code if you have turned on two-factor authentication. We do not send permit-expiration reminders. Permit reminders are notifications the iPhone app schedules on your own device; the website only shows an "Expired" or "Soon" badge when you open it.
7. What we do not do
We do not sell or rent your personal information. We do not share it with data brokers, advertisers, insurers, or firearms retailers. We do not report the existence or contents of your permit records to any government agency, and nothing in the Service functions as a registry. We do not use your records to train machine-learning models — on an end-to-end account we could not, because we cannot read them.
8. Service providers
Our service providers process your information only on our instructions, and are required to protect it to the standard described in this policy.
- Cloudflare hosts the Service, stores its data, and delivers its email. The application, its database and its file storage all run on Cloudflare.
- Cloudflare Turnstile runs a bot check when you create an account on the website. The iPhone app does not use it.
- Google Fonts serves the typefaces this website uses. Your browser requests them from Google when you load a page, which discloses your IP address to Google. The iPhone app does not use it.
- Stripe is involved only if you choose to convert to a CaliberBase Vault account. Carry itself is free and involves no payment processor. We never receive or store your card number.
Our public marketing site records anonymous page-view counts with coarse location, to tell us which pages people read. It sets no advertising cookie and does not link page views to your account.
9. Converting to CaliberBase Vault
Converting is optional and requires an active CaliberBase Vault plan. It moves your permits and photographs into a Vault account, removes the Carry copies once the move completes, and issues a new recovery kit; your old recovery code stops working. It is one-way, and the CaliberBase Carry app can no longer sign in to the account afterwards — you use CaliberBase Vault from then on, under its own Terms and Privacy Policy.
10. Legal process
If we receive a subpoena, warrant, court order, or other legally binding demand, we comply to the extent required. What we can produce is what we actually hold: your email address, your home state and name if you supplied them, sign-in times and IP addresses with their country and region, support correspondence, and your encrypted permit data. On an end-to-end account we cannot decrypt that data. On an older account we can, which means the permit's name, number, issue date, date of birth, printed name and address, notes and photographs could be produced in readable form — and the issuing state and expiration date are not encrypted at all.
Nothing here prevents a court from ordering you to unlock your own account. Whether such an order is lawful is unsettled and varies by jurisdiction; that is a matter between you and your attorney. We will notify you of a legal demand for your data where we are permitted to do so.
11. Data retention and deletion
We keep your account data for as long as your account exists. When you delete your account it is disabled immediately and scheduled for permanent deletion after a fourteen-day cancellation window, during which an emailed link lets you change your mind. After that window your account, your permits and your permit photographs are permanently removed.
Two things deliberately outlive the account, and you should know about both:
- Your email address stays in our security audit log. It is append-only, and the record that an account with that address was deleted is what lets us answer questions about the deletion afterwards. We do not currently expire those rows.
- Support conversations outlive the account. The text of support messages is blanked after a retention window — one year by default — but the conversation records themselves remain.
Sign-in records are kept on a fixed schedule: the most recent twenty in one place, and a longer-lived security record. Backups and our hosting provider's own operational logs age out on their schedules, which are set by Cloudflare rather than by us; write to us if you need the current figures.
12. Your rights
You can view and edit your permits, photographs, name and home state in the app and on the website, export them from Backup & Restore on the website (the iPhone app does not currently export), and delete your account from inside the app or the website.
For anything else we hold — sign-in records, support history, or a copy of everything associated with your account — write to support@caliberbase.us and we will respond within 45 days. Depending on where you live you may also have statutory rights to access, correct, delete, or port your data, and to be free from discrimination for exercising them. One request we cannot fulfil: on an end-to-end account we cannot produce your permit contents, because we do not have them in readable form.
13. Children's privacy
The Service is intended for adults and we do not knowingly collect information from children. If you believe a minor has created an account, contact us and we will remove it.
14. Where your data is held
The Service is operated from the United States and your information is processed there. If you use it from outside the United States, you are transferring your information to the United States, where privacy law differs from your own.
15. Changes to this policy
We may update this policy. If a change materially reduces the protection of information we already hold, we will give notice in the Service or by email before it takes effect. The effective date at the top of this page always reflects the current version.
16. Contact
CaliberBase Carry is operated by CaliberBase. Privacy questions can be sent to support@caliberbase.us, or by post to:
CaliberBase
P.O. Box 244
Crofton, MD 21114
United States