Legal

Privacy Policy

Last updated: 19 August 2026

The short version: the packs, spaces, and items you create stay on your device. There are no accounts and no third-party analytics or advertising SDKs. The one thing that leaves your device is Community Contributed: if you opt in and choose to share a scan, PackPilot sends its dimensions and metadata (never photos, location, or free-typed text) to a moderated catalog. The camera is used live for AR measurement, and no camera frames are recorded or transmitted.

PackPilot is designed to keep the packs you create private to your device. This policy explains what is stored on your device, what the app fetches, and what — only if you opt in — you can choose to send.

What we do not do

  • We do not create user accounts or ask you to sign in for private packs.
  • We do not record, store, or transmit any camera images, video, or audio.
  • We do not use third-party analytics SDKs, and we do not track you across apps or websites. PackPilot does not present an App Tracking Transparency prompt.
  • We do not share data with advertising partners. There is no advertising in PackPilot.
  • We do not read your photos, contacts, location, calendars, or files outside the app.
  • We do not upload the packs, spaces, or items you keep private. Those stay on your device unless you deliberately share a scan through Community Contributed (described below).

What the app connects to

PackPilot makes network connections in three situations:

  • Community Contributed catalog. When the feature is on, the app fetches the moderated public catalog of shared scans so you can browse and reuse them.
  • Community Contributed submissions. Only if you opt in and choose to share a scan, the app sends that submission to our moderation server (see below for exactly what it contains).
  • Purchases. Buying or restoring a purchase goes through Apple's StoreKit to Apple's servers. We never see your payment details.

What is stored on your device

PackPilot keeps the following in its own storage on your iPhone or iPad:

  • Packing sessions you create — the names and dimensions of any containers and items you scan or type in, their packing constraints, and the solved plans.
  • Reusable Spaces and Items libraries, if you save entries to them (a PackPilot Pro feature).
  • Item photos you choose to attach, stored inside the app's own storage — not added to your photo library.
  • Preference flags — whether you've seen onboarding, whether you've dismissed the beta notice, and your unit preference.

All of this lives in PackPilot's storage on the device and is protected by iOS's standard at-rest data protection. Deleting the app removes it entirely.

Camera and AR

PackPilot requests Camera access for one purpose: live AR measurement of spaces and items, and the AR Placement Guide. The camera feed is processed in-app, in the moment, to work out dimensions and to draw overlays on the screen. No frames are recorded, photographed, or sent off the device.

Camera is the only permission PackPilot ever asks for. It does not request photo library, location, contacts, microphone, calendars, reminders, Bluetooth, local network, or push notification access.

Purchases

PackPilot Pro is a one-time, non-consumable in-app purchase handled entirely by Apple's StoreKit. Apple processes the transaction; we receive only the verified entitlement — in effect, the single fact that "Pro is active." We never see your payment details, and we do not store a purchase record of our own. Your entitlement is held by Apple against your Apple ID, which is why you can restore it on any device signed in with the same account.

What actually leaves your device

  • Community Contributed submissions — only if you opt in and share a scan. What a submission contains is listed in detail below.
  • StoreKit purchase and restore requests to Apple's servers, when you buy or restore a purchase.
  • Crash reports to Apple, if you have crash sharing enabled in iOS Settings — these go through Apple's infrastructure, not ours.
  • Anything you explicitly send yourself: exporting a plan as a PDF or a file and sharing it via the iOS share sheet, or emailing us feedback.

Fetching the Community Contributed catalog is a download, not an upload — it does not send us anything about you.

Third parties

PackPilot contains no third-party analytics or advertising SDKs and does not share your data with advertising partners. Apple receives purchase data as a necessary part of operating the App Store and StoreKit. Community Contributed submissions are received and moderated by us to run the shared catalog.

If you contact us

If you email feedback@packpilot.io, or use Send Feedback inside the app, we receive your message and the app version and device model you chose to include. We use that only to answer you and to fix the thing you told us about. We don't add you to a mailing list.

Children

PackPilot is rated 4+ and contains no chat, media playback, or web views. The one form of user-generated content is Community Contributed, which is opt-in, contains only measurements and structured metadata with no photos and no free-typed text, and is reviewed by a person before anyone else can see it. We do not knowingly collect data from children under 13 — or from anyone else, beyond the measurements an adult chooses to share.

Deleting your data

Deleting PackPilot from your device removes all of its on-device data. There is no account to close. The one thing that can exist off your device is a Community Contributed submission you chose to share — to remove that, follow "Removing something you shared" above. Your purchase remains recorded by Apple against your Apple ID so you can restore it later.

Community Contributed

Community Contributed is an optional, opt-in feature. It lets you share the measurements of a space or item you scanned — for example the trunk of a specific car — so other PackPilot users can start from real numbers instead of guessing. You are never sharing automatically. Nothing is sent unless you choose to share a saved scan and confirm it.

What a submission contains. When you choose to share a scan, the approved scan record includes:

  • The dimensions of the space or item — width, depth, and height — plus any obstruction shapes you marked and the opening size, if you measured it.
  • The type and category of the thing (for example, a vehicle compartment such as trunk, frunk, bed, or cargo area; or an item category such as cooler or suitcase).
  • A model label chosen from menus — for a vehicle, the year, make, model, and an optional trim or body style.
  • Provenance and quality metadata: whether it was captured with Live Scan, AR Trace, or entered by hand, a scan confidence score, and the app version.
  • Its verification state and the approved contributor attribution (a pseudonym, if you set one) shown alongside the entry.

What a submission does not contain. A submission never includes any photo or camera image, never includes your location, never includes free-typed text that other people can read, and does not include a precise personal identity. You pick the identity from menus, not by typing a caption. There is no field in a submission for anything personal.

A submission becomes public once it is approved. Every submission is moderated by a person before anyone else can see it. If it is approved, the record it contains becomes part of the public Community Contributed catalog that the app fetches, combined with other people's scans of the same thing. Once a submission has been approved and published, treat it as public.

Moderated, retained, and correctable. Approved entries are retained so the catalog stays useful, and they can be corrected, reported, or removed. Anyone can Suggest a correction or Report an entry; we review reports and act on them.

There is no account and no personal identifier. A submission carries a random id that your device generates the first time you share something. It is not an account, it is not your Apple ID, and it is not the advertising identifier (IDFA). It is a random string that lets us group submissions from the same device so we can apply fair rate limits and honour a removal request. It cannot be used to identify you.

Removing something you shared. If you want a submission taken down, email feedback@packpilot.io and tell us what you shared — the space or item and roughly when you sent it, or the device id shown on the Community Contributed screen in the app. We will remove your submission and recompute any entry it fed into so your numbers no longer contribute. Because approved submissions are combined with others and may already have been downloaded by other users, we cannot recall copies that have left our server, but we will stop distributing your contribution.

You can turn Community Contributed off entirely in the app's settings. With it off, PackPilot does not fetch the catalog and never offers to share a scan.

App Store privacy label

PackPilot does not use your data to track you across apps or websites, and the random device id described above is not tied to your identity. Private packs, spaces, and items are not collected — they stay on your device. The opt-in exception is Community Contributed: when you choose to share a scan, the dimensional measurements and structured metadata in that submission are sent to our moderated catalog. Nothing is uploaded unless you deliberately share a scan. The App Store privacy label is filed to reflect this opt-in submission behavior.

Changes to this policy

If we change this policy in a way that affects what is collected, we will update the "Last updated" date at the top of this page and surface a notice in the app on next launch. Adding anything that transmits data — analytics, crash reporting, cloud sync, an account system — would trigger that.

Governing law

This policy is governed by the laws of the State of California, United States. If you live elsewhere, this does not remove any rights you have under the data protection or consumer laws of your own country — including, where they apply to you, the GDPR and the CCPA. PackPilot does not collect personal data about you: private packs stay on your device, and the only thing you can send us is a Community Contributed submission, which contains dimensions and structured metadata rather than personal information. If you have shared a scan and want it removed, email us (see "Removing something you shared") and we will take it down. Deleting the app removes everything it stored on your device.

Contact

Questions about privacy, or anything else: feedback@packpilot.io.

PackPilot is built by Ryan Houston / Eternalist.