Data Security
Jag Stories is designed primarily around local device storage and direct user-controlled workflows.
Local-first records
Weapon, DOPE, training, match, Stage Video and hunting records are designed to live on the user’s device unless the user invokes a backup, export, sharing or Match Director workflow.
Encrypted Match Director payloads
Current local Match Director protocol payloads use AES-256-GCM authenticated encryption. This protects both confidentiality and integrity of supported payload data during the local exchange.
Permission boundaries
Camera, microphone and other sensitive capabilities are requested only when required by a feature and remain subject to Android permission controls.
User-controlled backups
Backup and restore are deliberate user actions. Users should protect exported files and store them only in locations they trust.
What AES-GCM does
AES-GCM combines encryption with integrity authentication. This means supported Match Director payloads are not simply readable network JSON, and tampering with an authenticated encrypted payload should cause validation to fail.
What it does not do
No security measure eliminates every risk. Local network availability, device compromise, screenshots, exported files, malicious software, rooted devices or unsafe sharing can still expose information. Keep Android and Jag Stories updated and protect your device with an appropriate screen lock.
Security reports
If you believe you have found a security problem in Jag Stories, contact support@jagstories.com and include the app version, device model, steps to reproduce and screenshots or logs that do not expose unnecessary personal information.