Trust & security

Data Security

Jag Stories is designed primarily around local device storage and direct user-controlled workflows.

Local-first records

Weapon, DOPE, training, match, Stage Video and hunting records are designed to live on the user’s device unless the user invokes a backup, export, sharing or Match Director workflow.

Encrypted Match Director payloads

Current local Match Director protocol payloads use AES-256-GCM authenticated encryption. This protects both confidentiality and integrity of supported payload data during the local exchange.

Permission boundaries

Camera, microphone and other sensitive capabilities are requested only when required by a feature and remain subject to Android permission controls.

User-controlled backups

Backup and restore are deliberate user actions. Users should protect exported files and store them only in locations they trust.

What AES-GCM does

AES-GCM combines encryption with integrity authentication. This means supported Match Director payloads are not simply readable network JSON, and tampering with an authenticated encrypted payload should cause validation to fail.

What it does not do

No security measure eliminates every risk. Local network availability, device compromise, screenshots, exported files, malicious software, rooted devices or unsafe sharing can still expose information. Keep Android and Jag Stories updated and protect your device with an appropriate screen lock.

Security reports

If you believe you have found a security problem in Jag Stories, contact support@jagstories.com and include the app version, device model, steps to reproduce and screenshots or logs that do not expose unnecessary personal information.