Privacy & Trust

“We treat your collection like it’s none of our business. Because it isn’t.”

Your collection is encrypted, and it’s never sold, shared, or mined. Ever. Here’s exactly how it works, and where the boundaries are.

RepoNorth is a private inventory tool, not a registry. We are not affiliated with the ATF, any government agency, or law enforcement, and we do not report your collection, your purchases, or your account to anyone.

0 law-enforcement requests received. 0 accounts disclosed. Published quarterly.

Encrypted at rest, 2FA available

Your collection is encrypted at rest on the server. Two-factor authentication (TOTP) protects your account beyond just a password.

Photo location data, stripped on upload

Photos often carry GPS coordinates in their metadata. We strip that data automatically when you upload, so a photo of your item never carries its location.

A published law-enforcement policy

We respond to valid legal process only, a warrant or court order, never an informal request. Disclosure runs through a single logged break-glass decryption that records who, when, and under which order, and we notify you whenever we are legally permitted to. A transparency report, published quarterly.

Your data, always exportable

Full export in open formats, any time, plus a print-ready insurance or estate binder built from only the fields you choose. Delete your account whenever you decide, and it’s gone within 30 days, including backups. Nothing is held hostage.

Never sold, shared, or mined

No ads. No data brokers. No “anonymized insights” sold to insurers, retailers, or anyone else. Your subscription is the entire business model.

Never used to train AI

Your photos and collection details are never used to train AI models, ours or anyone else’s. Not now, not later.

Encryption

Two layers of encryption.
Not one.

Most apps encrypt the disk and stop there. That only protects you if someone physically walks off with a drive. We start there, then wrap a second, separate layer around the fields that would actually matter if anything ever leaked.

01The infrastructure it lives on

Your entire database is encrypted at rest with full-volume LUKS encryption and reachable only over TLS, on U.S. infrastructure. Automated backups are encrypted the same way. RepoNorth runs on DigitalOcean’s SOC 2 Type II and SOC 3 Type II–audited platform, independently examined by Schellman & Company.

02The fields that matter most

Serial numbers, NFA control numbers, and storage locations get a second, independent layer of AES-256-GCM encryption inside RepoNorth, and the key that unlocks them is held outside the database. A copy of the database alone can’t reveal them.

Layer 01 · InfrastructureLUKS · TLS
Layer 02 · Field encryptionAES-256-GCM
Serials · NFA #s · Locations
encrypted before they ever touch the database
Key stored outside the database
+AES-256-GCM field encryption+LUKS full-volume at rest+TLS in transit+Argon2 password hashing+TOTP two-factor+Keys stored outside the database+Encrypted automated backups+EXIF & GPS stripped on upload
The tradeoff

We hold the keys.

Getting back in when you forget your password. A read-only view for your spouse. Emergency Access for your family on the worst day. A binder your insurer will accept. A single logged break-glass under valid legal process, counted and published. Every one of those works because RepoNorth holds the keys: we can decrypt your serial numbers, NFA control numbers, and storage locations. Not because the encryption is weak, but because a service that could never read what you stored could never do any of the above.

So here is the part most privacy pages leave unsaid: this is not zero-knowledge encryption. Zero-knowledge encryption would break every feature above. We chose that tradeoff on purpose, and you should get to see it stated plainly.

If this happens · What it means for your collection
Someone steals a copy of our database
Serials, NFA numbers, and locations stay encrypted. The key is not in the database.
A backup leaks
Same. Backups carry the same encryption, and not the key.
Someone compromises our running server
A live server needs the key to display your data, so an attacker with that level of access could decrypt. This is the limit of what field encryption can do.
Someone at RepoNorth goes looking
Admin tools show account metadata only. Collection contents require the logged break-glass path, which records who, when, and under which order.
Law enforcement asks
Nothing without a warrant or court order, never on request alone. Logged, counted, published.
You forget your password
You get back in, because we hold the keys. Here the tradeoff works for you.
You lose your phone
Your collection is untouched. It was never only on the device.
Transparency report

The numbers, not the promise.

We publish a transparency report every quarter stating how many legal requests we received, how many we complied with, and how many accounts were affected. It is published whether the number is zero or not.

0
Requests received
0
Complied with
0
Denied
0
Accounts affected
No quarter has closed yetNext publication October 1, 20260 in review0 notified
How this is counted

A request is any demand for member data from a law-enforcement agency or a court, counted once when it arrives, whatever form it takes. Complied with means we produced data under valid legal process. Denied means we refused, because the demand was not valid legal process or reached further than the order allowed. In review means it has arrived and we have not finished responding. The open quarter is never shown: we publish on a quarterly close so that no single request is visible in real time, which keeps this page from becoming a live signal about any one account.

What producing data means

Complying takes one logged break-glass decryption, and nothing else can reach your collection contents. It records who ran it, when, and under which order, and everyday admin tools see account metadata only. We notify you whenever we are legally permitted to, which is where the notified count above comes from. The full statement is in our privacy policy.

The alternative

If you want no server at all.

Some inventory apps keep everything on your phone, syncing through your own cloud account, with no company server involved. Against a company breach that is a genuinely stronger position, and if that is your threat model it is a legitimate choice. Here is what it costs: no access from a computer or a browser, no sharing with your spouse or a trusted friend, no emergency access for your family, no estate binder that outlives the device, and if the device is lost with sync turned off, the collection goes with it. We built RepoNorth for the owner who wants those things and wants to know exactly what holding the keys implies.

One thing worth checking in any app you consider, ours included: whether photos are stripped of GPS before they are stored. We strip on upload, server-side, before the file is written.

Two-factor authentication

Front and center, not buried in a menu.

Two-factor authentication is available on every account and encouraged from day one. It lives at the top of Account settings, not three menus deep: a TOTP authenticator app, a password you control, and a plain record of when it last changed.

Security
Two-factor authenticationEnabled
Password••••••••
Last changedMar 2026
Emergency Access

Your collection can outlive a bad day.

Name a beneficiary and set an inactivity window. If your account goes silent that long, we warn you first, repeatedly, and only if you never respond does your beneficiary get in, by confirming the exact email address you chose. There’s no death certificate to file and no judgment call on our end, and you can stop the clock any time just by logging in. It’s opt-in, off by default, and there when estate and family planning need it.

Available on Pro and Platinum plans
© 2026 RepoNorth. All rights reserved.