JoeLog Home

Policy

Privacy Policy

Last updated: September 5, 2026 · Revision: 2026-09-05

JoeLog is built to hold private firearm collection records. That can include locations, identity details, documents, and regulated Form 4473 information. Those records deserve deliberate handling, and this page describes what the current application does without promising controls or policies that are not yet in place.

Scope and current status

This policy covers information handled through JoeLog. The legal operator name, business address, operating jurisdiction, and geographic availability have not yet been published. Send privacy questions and requests to aubergine@joelog.com. Do not include identity documents, firearm data, credentials, or Form 4473 information unless JoeLog first provides an approved way to transmit it.

Information you provide

JoeLog can store account names and email addresses; organization and collaboration details; firearm descriptions, serial numbers, acquisition and disposition records; contacts and physical locations; uploaded documents; audit history; and information entered into Form 4473 workflows. Form 4473 responses may include highly sensitive identity information and an optional Social Security number.

Only enter information you are authorized to provide. Firearm locations and Form 4473 data are especially sensitive. Avoid optional sensitive fields unless they are necessary for your lawful purpose.

Information collected during use

JoeLog uses browser cookies for sessions, organization selection, and CSRF protection. Application logs record request details such as method, a redacted path, response status, duration, and request ID. Infrastructure, database, storage, and mail providers may also process operational metadata; the production providers, regions, and retention periods are not yet published.

Pages currently request font files from Google Fonts. That request lets Google receive ordinary connection metadata such as an IP address and browser information. Font delivery should be included in the final provider review or replaced with self-hosted files before launch.

How information is used and disclosed

Information is used to authenticate users, operate organizations, maintain collection and regulated-record workflows, provide reports and exports, store documents, send service email, and record security-relevant activity. Organization members, collaborators, guests, or inspectors can see information permitted by their role and the access granted to them.

Service providers may process information needed to run database, object storage, hosting, and mail functions. Information may also need to be preserved or disclosed when legally required. A final subprocessor list and legal-request policy have not yet been published. JoeLog does not currently publish an advertising, sale, or data-sharing commitment beyond these operational facts.

Storage, retention, and security

Access is organization-scoped and role-based. Passwords are hashed with Argon2id. Sensitive Form 4473 response payloads use application-level encryption. Documents use private S3-compatible object storage with server-side encryption requests and integrity verification. These controls do not mean that every field, log, or storage layer is universally encrypted.

A final retention schedule, backup policy, and deletion procedure have not yet been published. Closing an account must not be understood as immediate or complete erasure: regulated records, audit history, provider records, or legally retained material may need to remain.

Access, correction, and policy changes

JoeLog supports record review and export in parts of the application. Email aubergine@joelog.com to begin an access, correction, closure, deletion, regional-rights, or appeal request. Verification and fulfillment procedures are still being finalized, so do not send sensitive supporting material until you receive instructions.

This policy will change as operator details, providers, retention rules, launch regions, and request procedures are finalized. Material changes should be reviewed before relying on the service for sensitive or regulated records.