Legal

Privacy Policy

Last updated September 15, 2026

Who we are

Crockett is a hunting and fishing license app operated by WorldTech Miami (WTM Trading LLC). This policy covers the Crockett mobile app and this website.

What we collect

We collect only what the app needs to do its job. You choose what to enter.

InformationWhy
Email addressTo send your sign-in code. If you sign in with Apple or Google instead, we receive the email address that service gives us.
Phone numberAn optional value saved to fill state checkout forms. Sign-in by text message is switched off in this version of the app, so we do not send you a text.
Profile detailsName, date of birth, address, driver license number, hunter education number, and customer number, when you add them, so the app can fill them into a state's official checkout for you.
License recordsLicenses you add, or import from a photo, PDF, or the iOS share sheet: state, license name, type, expiration, and barcode. A license photo you import is saved with the record.
Harvest logEntries you save, including species, notes, an optional photo, and, if you allow location, GPS coordinates.
LocationUsed for the map, local weather, tides, sunrise and sunset, harvest pins, and area alerts you turn on. A saved hunt location may be stored for alerts.
Draw points and hunt plansThe states and species you track, saved to your account.
CampsA camp name and invite code you create or join, and your membership.
Shared linksSharing a pin, waypoint, parcel or saved area from the map creates a link on gocrockett.com. The link carries the coordinates or area, the name, and the kind of place. It carries nothing about your account, and nobody can tell who shared it from the link itself. We store it until you delete it from the app's Shared links list or delete your account, which removes every link you created.
Ask Davy questionsThe question you type or dictate, plus context from your screen. The next section lists exactly what that context is.
FeedbackAny message or photo you submit through the in-app feedback form, plus your app version and device browser string.
Automatic error reportsIf the app hits an error, it sends the error message, stack trace, screen name, app version, platform, and time. When you are signed in, each report is linked to your account_id. Guest reports are not linked to an account id. A hashed client context (ua_hash) can also be stored so we can tell reports apart. Reports are kept for 90 days. This is used only to find and fix crashes. It is not used for ads or tracking.
WaitlistOn this website, your email if you join the waitlist, plus the referring site and country.

What Ask Davy sends

Ask Davy is the in-app assistant. Every question you send carries context from your screen so the answer fits where you are. That context is:

Crockett's own server picks which answer service handles the question. The app never picks. This version uses Cloudflare Workers AI, which runs on Crockett's own server. The other choice is Google Gemini, which would receive the same question and the same context if the server were set to it.

If you dictate a question instead of typing it, your phone's Apple speech services receive the audio.

How your information is used

We do not sell your information. We do not show ads. We do not use your information for cross-app tracking.

Where a purchase happens

When you buy a license, the purchase completes on the state's own official system. Crockett opens that system and can fill in your saved details. Crockett does not sell licenses and does not take payment.

Who receives your information

This is every outside service Crockett can reach, and what reaches it. Some are reached by the app on your phone. Some are reached by Crockett's own server on your behalf. The address in each row is the exact one your phone or our server connects to.

Where a row says a location is rounded to two decimal places, that means it is cut back to about a mile before it leaves your phone. It points at an area, not at you.

ServiceWhat it receives, and why
Crockett's own server (Cloudflare)crockett-api.wtmtrading1.workers.devgocrockett.comwww.gocrockett.comHosting, the database that holds your account, file storage, and automatic error reports including the hashed client context. The Ask Davy answer service used in this version, Cloudflare Workers AI, also runs here.
Apple Weatherweatherkit.apple.comThe main weather source. It receives the coordinates of the place you are looking at, rounded to two decimal places, sent through Crockett's own server.
National Weather Serviceapi.weather.govReceives the same rounded coordinates through Crockett's own server, for local observations and forecasts. It also receives the rounded coordinates of a spot you tap on the map, sent straight from the app, to show active weather alerts for that spot.
Open-Meteoapi.open-meteo.comA weather source Crockett no longer calls. Nothing in the app or on our server sends anything to it today. We list it because the app still allows the address and the code path is kept.
Open-Meteo geocodinggeocoding-api.open-meteo.comCity or US ZIP search and reverse-geocode queries. It receives the text you type when you search for a place, and, when Crockett turns a location back into a place name, a coordinate rounded to two decimal places.
NOAA Tides and Currentsapi.tidesandcurrents.noaa.govtidesandcurrents.noaa.govReceives requests for a tide station near a coastal location, to show tide times.
FCC census area lookupgeo.fcc.govReceives the coordinates of a spot you tap on the map, rounded to two decimal places, and returns the state and county that point sits in, so the rules you are shown belong to the right state. The app sends this straight from your phone. It does not pass through Crockett's server.
USGS National Hydrography Datasethydro.nationalmap.govReceives the coordinates of a spot you tap on the map, rounded to two decimal places, plus a small box around that point, and returns the name of the lake, reservoir, river or creek under it. The app sends this straight from your phone. It does not pass through Crockett's server.
AWS Terrain Tiless3.amazonaws.comWhen terrain shading or contour lines are used, the app requests elevation tiles directly from AWS. The requests include tile coordinates that describe the map area being viewed and nearby tiles. They do not include a separate device GPS position or pass through Crockett's server.
USGS The National Mapbasemap.nationalmap.govMap tiles for the topographic layer and the water layer. A tile request shows the map area you are looking at.
National Park Servicedeveloper.nps.govReceives the two-letter state of a national-park spot you tap on the map, sent through Crockett's own server, to show that state's active park closures, hazards and hours.
Google Geminigenerativelanguage.googleapis.comReceives a license image you choose to import, to read the details off it. It would also receive your Ask Davy question and its context if Crockett's server were set to use Gemini as the answer service. In this version the server uses Cloudflare Workers AI instead.
Google Cloud Text-to-Speechtexttospeech.googleapis.comReceives the text of Davy's spoken answer, sent through Crockett's own server, to make the voice you hear.
Apple sign-inappleid.apple.comUsed when you choose Sign in with Apple. Apple tells us the account identifier and the email address you agree to share.
Google sign-inaccounts.google.comwww.googleapis.comUsed when you choose Sign in with Google. Google tells us the account identifier and the email address you agree to share.
AgentMailapi.agentmail.toReceives your email address, to deliver your sign-in email.
Twilioapi.twilio.comWould receive your phone number to send a sign-in code by text. Sign-in by text message is switched off in this version, so no phone number reaches Twilio. We list it because the code path is still there.
Google OAuthoauth2.googleapis.comIssues the token Crockett's server uses to send push notifications through Firebase. It receives Crockett's own credentials, not your information.
Push notification deliveryapi.push.apple.comapi.sandbox.push.apple.compush.apple.comfcm.googleapis.compush.services.mozilla.comnotify.windows.comReceive the alerts you turned on, addressed to your device, so they can reach your phone. A test build of the app registers with Apple's sandbox address instead of the live one.
Apple WalletReceives a license pass when you choose to add one. This happens on your phone.
Google Walletpay.google.comWould receive a license pass when you choose to save one. Save to Google Wallet is switched off in this version, so nothing reaches it. We list it because the code path is still there.
Apple speech servicesReceive the audio when you dictate a question for Davy.
Official state agency sites, and the U.S. Fish and Wildlife Servicewww.fws.govReceive whatever you type, or choose to have Crockett fill in, after Crockett opens their page for you. These are the states' own sites, not ours, and their own privacy policies apply once you are on them.

If a service is not in this table, Crockett does not send it anything. The app on your phone is also locked to a fixed list of addresses, so a connection to anywhere else is blocked by the app itself and not only by our policy.

How your information is protected

Your choices

Data retention

We keep your account information while your account is active. Sign-in codes expire within minutes. Automatic error reports are kept for 90 days, then deleted.

Deleting your account

When you delete your account, we delete your rows from our database straight away. That covers your profile details, your licenses and any license photo, your harvest log and its photos, your saved places, stands and properties, your plans, points and camps, your sign-in codes and sessions, your email address and your phone number. Deleting also clears that account's saved work off the phone you did it on, including property and stand locations.

Automatic error reports are the one thing we do not delete. In the same step we unlink them from your account, so nothing left in a report points to you, and they are deleted 90 days after they were made.

One part is not instant, and you should know about it. Our database is hosted by Cloudflare, and Cloudflare keeps a rolling 30 day history of the whole database so that it can be rolled back after a bad change. We cannot switch that history off. For as long as that history still reaches back past the day you deleted, rolling the database back would bring your rows back with it. Thirty days after you delete, the history no longer reaches that far, and a rollback cannot return your information.

Changes to this policy

We will update this page when our practices change and revise the date above.

Contact

Questions about privacy: sales@worldtechmiami.com.