OpenManual Privacy Policy
Plain language about the iPhone and iPad app and these Gunzino support pages. Last updated October 6, 2026.
1. Scope and who operates OpenManual
OpenManual is published by Gunnar Hostetler through Gunzino. This policy covers the OpenManual iOS app and the OpenManual pages on Gunzino.me. It does not replace the policies of Apple, a government registry, a search provider, a document host, a manufacturer, or any destination you choose when sharing a document.
2. No account, and nothing you keep is shared
OpenManual does not require an account or login. The publisher does not receive the contents of your camera frames, imported PDFs, saved PDFs, or the questions you ask about a manual, and the app contains no analytics, crash-reporting, or advertising code. That does not mean nothing leaves your device. OpenManual looks things up by itself, without a tap, as you scan, type, or open a device, and it sends those requests directly from your device to the outside services that answer them (section 4). A search also checks a shared list of manuals people kept with earlier versions of OpenManual (section 5). Since version 1.3, nothing you keep is added to that list.
3. Information processed and stored on your device
- Camera and photo input: Camera frames and selected images are processed on-device to read labels, barcodes, and device details. The app does not upload those images.
- Device library: Saved devices can include manufacturer, model, catalog or REF number, normalized device identifier, verification state, timestamps, and a compact on-device visual fingerprint used to recognize a saved device again.
- Documents: A PDF you choose to keep is stored locally with its source URL, document metadata, hashes, and page data.
- Questions and evidence: OpenManual keeps local question history, answer state, citations, quoted passages, warnings, and abstention reasons so you can inspect why an answer was or was not available.
- Preferences: App settings, including the optional on-device search-refinement preference and, through version 1.6, the “Check manuals others kept” switch, are stored locally.
4. What is sent, and when
OpenManual sends nothing to the publisher. It makes requests directly from your device to public services, and most of them start by themselves. These start without a tap:
- A retail barcode is read (camera, photo, or screenshot): the barcode digits go to ENERGY STAR, in up to four zero-padded forms, then to UPCitemdb if ENERGY STAR does not name the product, and a product-category word, never the brand or model, goes to the CPSC recall search.
- A VIN is read: from version 1.5, the first eight characters, the model-year and plant characters (10 and 11), and a star in place of the check digit go to NHTSA, and versions up to 1.4 sent all 17 characters. In versions up to 1.5, a VIN that NHTSA could not decode can be passed on as the product's model number and then appears in a document search; from version 1.6 it is not, and a line of label text that holds a VIN the app recognizes stays out of searches too. From version 1.7 a decoded vehicle is searched for by its year and model, with the make as the maker; through version 1.6 the search used the year, make, model, and trim as one name.
- A UDI barcode is read: the device identifier goes to AccessGUDID, and the device page opens by itself. It then asks openFDA about recalls, adverse-event reports, and registration, using numbers and names the registry returned: 510(k) and PMA numbers, a product code, the reference or model number, the brand or description, and the first words of the maker's name. Lot, serial, and expiration do not leave your device. The one exception was versions up to 1.4 with a HIBCC barcode that carries data after a slash: they sent it to AccessGUDID almost whole, lot, serial, and expiration data included. From version 1.5 only the device identifier is sent. Opening a saved medical device repeats these lookups each time.
- A label looks like a medical device's: its maker, model, and reference number go to openFDA to find the record, a moment after the reading settles. A model or reference number that was read but not yet confirmed is sent too.
- You type in the FDA registry search: the part of the reference number or maker name you have typed goes to openFDA a quarter of a second after you pause.
- The documents screen opens for a device the app has identified: the document search starts, as described below.
The services are AccessGUDID at the U.S. National Library of Medicine; openFDA and the FDA's clearance records; ENERGY STAR; UPCitemdb; the Consumer Product Safety Commission's recall search; NHTSA's vehicle decoder; the Internet Archive; DuckDuckGo, Bing, and Brave (and, through version 1.6, Mojeek, Startpage, and Marginalia); manufacturer and other public document sites; and, through version 1.6 only, for the shared list in section 5, Apple's CloudKit.
Only on a tap: Fetch requests the link you pasted, directly from your device. Search the web for this manual opens a DuckDuckGo search in Safari or an in-app Safari view. From version 1.7, Search the web yourself opens the same kind of search in Safari, and a page listed under Where the manual is opens in Safari, where its site sees your request as it would any visit. Links to registry records, manufacturer portals, phone numbers, and mail open in the system. Copy puts a value on the pasteboard, which other apps can read. Sharing or saving a PDF hands a temporary copy to the app you choose. Unlock and Restore go through Apple's StoreKit.
The document search starts when the documents screen opens for a device the app has identified, and it asks, directly from your device: through version 1.6, the shared list in section 5, if its switch is on (version 1.7 has no shared list); for a medical device, the FDA's clearance records and summary files; the Internet Archive, with the maker, model, and catalog words; and, from version 1.7, three search engines (through version 1.6, up to seven search addresses), with queries built from the maker, the model and the catalog number (through version 1.6, the catalog number alone when the device had one), any description words you typed or it read, an FCC ID, and words such as manual or pdf. From version 1.7, for a device found in the FDA's registry, a query can use the registry's brand name where the model goes, and the maker's name without its legal form. When that first pass fails, a second pass names the maker and the number exactly and leaves out the model numbers of look-alike devices whose manuals it found. It also asks the search engines for pages on the maker's own site, using a domain read from the label, from a curated list, or guessed from the maker's name. About eight seconds in, unless the first lanes have already finished with a document in hand, it also uses an isolated, nonpersistent browser component to load the maker's own pages and the search addresses it builds for that site (ones the site's search form or search description names, which can be on another host, common patterns such as /search?q=, and the fixed paths some site platforms use, each with the catalog or model number in the address), the search pages again, and up to 24 result pages on up to 12 sites, which can run their own scripts and load content from other sites. When a result page holds instructions as text and links no file, it makes a PDF of that page, as Print to PDF does in Safari, and checks that like any other candidate; it is kept only if you keep it. It also fetches a site's published search description, a small file, with a user agent that names OpenManual. It downloads up to 28 candidate files, three at a time, from the public https addresses it finds, and validates each before offering it. For an address it found itself, with no query string or fragment, that its site refuses or reports missing, it asks the Internet Archive for its saved copy. (Up to version 1.4 it also asked the Internet Archive about a link you had pasted or shared. From version 1.5 it never does.) The search stops when you leave the screen, though the hidden browser can keep loading pages for the maker's site for up to about 35 seconds, and versions up to 1.4 kept searching after you left. If you leave the app while it runs, it can keep going in the background for a while. It keeps no browser history, cookies, or signed-in sessions after a search, does not sign in, reuse credentials, type into forms or click buttons (it only opens addresses), solve CAPTCHAs, bypass paywalls, work around download gates, or evade other access controls, and does not recursively crawl sites. If a result needs an interactive page, sign-in, payment, approval, or another authorized step, OpenManual does not proceed through it; that step stays with you in Safari.
What is never sent: camera frames, photos, imported PDFs, saved PDFs, the questions you ask about a manual, and a UDI's lot, serial, and expiration. (Through version 1.5, a line of printed label text that gave an expiry or production date could go into a search as a description word; from version 1.6 it does not.) The words you type to describe a device are not such a question: they go to search engines and, for a medical device, to the FDA. The device identifier goes only to the registries, never to a search engine. The services see ordinary network-request information, such as your IP address and a user agent, and apply their own privacy policies and retention practices. The app's own connections to document sites, including file downloads from the Internet Archive, present a standard iPhone Safari user agent as a compatibility header. The registries and the Internet Archive's own search see the system's default, which names the app, and so does the fetch of a site's published search description. The hidden browser presents WebKit's own user agent, with a Safari application name on its search-engine and result pages.
5. The shared list of kept manuals (versions before 1.7)
From version 1.7 the app has no shared list: it does not read it, it has no switch for it, and it does not use Apple’s CloudKit at all. The rest of this section describes versions 1.0 to 1.6. In versions 1.3 to 1.6, “Check manuals others kept” is on by default, and you can switch it off during setup or later in Settings. While it is on, each document search starts by asking a shared list for manuals filed under the device’s maker and model. What it sends is a key made from the maker and the model number, and another from the maker and the catalog number, each reduced to lowercase letters and digits, or the number alone when no maker is known. Reading the list needs no iCloud account. With it off, the app doesn’t read the list.
Since version 1.3 (September 29, 2026), keeping a document adds nothing to the list, so nothing you keep leaves your device. Versions 1.0 to 1.2 filed a record whenever someone kept a document while their switch, then called “Share what you find”, was on: the maker and model number, the document’s address (for a PDF they imported themselves, its file location on their device), its title, its page count, a SHA-256 fingerprint of the file, and the time it was filed. Copies of the app older than 1.3 keep doing that until they’re updated. A search skips any record whose address points to a file on someone’s device.
The list is a public database in Apple’s CloudKit, kept for OpenManual, and any copy of the app older than 1.7 can read it. A record contains nothing about the person who filed it beyond what a document’s title or file location reveals, and nothing about their location or their device’s serial number. CloudKit also stores the identifier of the iCloud user record that created each entry. That record belongs only to OpenManual, and OpenManual adds nothing to it. Records filed before 1.3 stay in the list until they’re removed, and deleting a document or the app doesn’t remove them. To have a record removed, email the address in section 10. The addresses in the list were filed by older versions, and some may be links people pasted. The app downloads them like any other candidate, so the site at such an address sees your IP address.
6. Apple features and purchases
When Apple Intelligence is available on your iPhone, OpenManual uses Apple’s on-device language model to read the fields on a label. “Refine searches locally” is off unless you turn it on, and only with it on does the same model help a search: it suggests and sorts web searches and plans a difficult one, which can mean searches of its own and search results it picks to open, up to four of each. Since version 1.4 (October 1, 2026), the search uses no Apple Intelligence at all while the setting is off. The model runs on your iPhone, and the searches it suggests go to the same providers as any other search (section 4). Apple processes OpenManual’s one-time unlock through StoreKit; OpenManual does not receive your payment-card details and keeps only the local entitlement result needed to unlock the feature.
7. Storage, deletion, backups, and sharing
OpenManual keeps saved library data until you remove an individual document, delete its saved device, or delete the app. Removing a document also removes bindings and saved citation/history records that depend on it. Deleting a device removes that device’s saved documents and answers. OpenManual does not exclude its data from device backups, so saved devices, kept PDFs, and the questions and answers you saved are included in iCloud and computer backups if you make them, under your Apple and device-backup settings.
Sharing is user initiated. When you use the iOS Share Sheet, OpenManual makes a temporary copy available to the destination you choose. That recipient app or service has its own privacy practices, and its retention is outside OpenManual’s control.
8. Gunzino website traffic and support email
Gunzino.me uses Google Analytics and Google Ads measurement tags for website traffic and conversion measurement. Those tags concern visits to this website, not analytics SDKs embedded in OpenManual. If you email support, the email address, message, attachments, and normal email metadata are handled by your email provider and the publisher’s inbox. Do not send patient data, full UDI production details, passwords, credentials, or copyrighted manuals unless specifically requested.
9. Medical and sensitive information
Do not enter patient information, health records, or other sensitive personal data into a label, lookup, question, or support request. OpenManual locates and quotes documentation; it does not provide diagnosis, treatment recommendations, or patient-specific settings.
10. Contact and changes
For privacy questions or a request to delete support correspondence held by the publisher, email gunnarguy@me.com. This policy may change when the app or its external service use changes; the current date above identifies the latest version.