Back to HawkHero Support
GritWerk

HawkHero Privacy Policy

HawkHero by GritWerk — Fox Lake, IL — Last updated: July 2026

The short version: HawkHero sends your photos to a server you set up and control — not one GritWerk operates for you. Photos are stored on that server until you delete the listing. We never sell your data, share it with advertisers, or use it for AI training. HawkHero has no user accounts, no ads, and no tracking.

Contents
  1. Information We Collect & How It's Used
  2. We Do Not Sell Your Data
  3. Your Rights & Choices
  4. Children's Privacy
  5. Data Security
  6. International Users
  7. Changes to This Policy
  8. Contact Us

1. Information We Collect & How It's Used

On your device. HawkHero requests:

  • Camera access — to photograph items and scan barcodes for product identification. Barcode scanning is decoded locally on your device and is not transmitted anywhere.
  • Photo library access — to select existing photos instead of taking new ones.

Your Server URL, API Key, and theme preference are stored locally using your device's encrypted secure storage (iOS Keychain). This stays on your device and is sent only as an authentication header to the server address you configured — never to GritWerk.

Sent to the server you configure. When you photograph or select an item, the photo uploads over HTTPS to your configured backend. That server:

  • Sends the photo to Google's Gemini API for AI analysis, which returns a generated title, description, condition assessment, price range, category, and related listing details.
  • Stores the photo and generated listing data in its own database.
  • Retains the photo and listing data until you delete that listing (or bulk-delete) from within the app — deletion is immediate and permanent on that server. If AI analysis fails, the uploaded photo is deleted automatically and no listing is created.

Because this server is configured — and typically operated — by you or your organization, GritWerk has no visibility into or access to this data unless the server you're connected to happens to be one GritWerk itself operates.

Third-party AI processing. Photo analysis is performed by Google's Gemini API. Google processes the photo to generate listing content and is subject to its own data handling and retention terms, which we do not control. Review Google's API terms directly for details on how Google handles submitted images.

CSV export. You can export your listing data (not photos) as a CSV file at any time; it's created on your device and shared via your device's native share sheet to a destination you choose. We have no access to this file.

HawkHero does not require account creation. There is no email, name, or personal profile collected by the app itself.

2. We Do Not Sell Your Data

GritWerk does not sell, rent, or trade personal information, and does not use your data for advertising or cross-app tracking. HawkHero contains no advertising SDKs, analytics SDKs, or tracking technologies.

3. Your Rights & Choices

Depending on where you live — including under the California Consumer Privacy Act and, where applicable, the EU General Data Protection Regulation — you may have rights to access, correct, delete, or export your data.

  • Delete a listing (including its photo) — use the delete option on any listing, or bulk-delete from the history screen. This removes the data from your configured server immediately.
  • Disconnect — use "Disconnect Server" in Settings to remove your locally stored Server URL, API Key, and credentials from your device. Your listings on the server itself are not affected — delete them separately if you also want those removed.
  • Export — use "Export CSV" in Settings to download a copy of your listing data.
  • Server-side data — because your photos and listings live on the server you configured, requests to access, correct, or delete that data at the source should go to whoever administers that server. If that administrator is GritWerk, contact us at [email protected].

4. Children's Privacy

HawkHero is not directed to children under 13 (or the relevant minimum age in your jurisdiction), and we do not knowingly collect information from children.

5. Data Security

Data in transit between the app and your configured server is protected via HTTPS when your server is configured for it — we recommend against unencrypted HTTP outside local testing. Your API Key and Server URL are stored using your device's encrypted secure storage, and server access requires a valid API key. No method of transmission or storage is 100% secure. If you operate your own server, its security is your responsibility.

6. International Users

If your configured server or Google's Gemini API processes data outside your country of residence — including in the United States — your information may be transferred to and processed in those locations.

7. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated Effective Date at the top of this page.

8. Contact Us

Questions about this Privacy Policy or GritWerk's data practices:

  • Email: [email protected]
  • Mailing address: MACCAM LLC (dba GritWerk), 123 S US Highway 12 #76, Fox Lake, IL 60020
  • Support page: gritwerk.com/hawkhero/support

This policy describes GritWerk's practices as the publisher of the HawkHero app. It does not describe the practices of any third-party server you or your organization configures HawkHero to connect to — review that server operator's own policies for how they handle your data.

Privacy Policy Support GritWerk Privacy Terms of Service
© 2026 GritWerk