TrailShield: a quick-check outdoor safety buddy with a Privacy Proof screen A developer built TrailShield, a phone-only web app that uses Google's open-weight Gemma model (gemma-4-26b-a4b-it) to give short, cautious notes on trail photos and then prompts users to put their phone away. The app strips GPS and hidden metadata by resizing photos on a canvas before sending them to a roughly 30-line Flask server on Render, and includes a "Privacy Proof" screen with live counters showing photos sent to the cloud, cloud AI requests, and zero location collected. The developer reports testing only with an indoor photo and did not complete an outdoor trail test before the deadline. This is a submission for the Hacktoberfest Open-Source AI Challenge Week 1: Touch Grass https://dev.to/challenges/hacktoberfest-week1-2026-10-05 Most AI apps want you to stay on the screen. TrailShield is built to do the opposite. It is a small web app for short outdoor checks. You tap Start Trail , and when something on the path looks uncertain a rocky patch, a fallen branch, a muddy slope , you take a photo. Gemma looks at it and gives a short, cautious note. Then the app tells you: "📵 Put your phone away and continue your trail." That is the whole interaction: a few seconds on the screen, then back outside. There is no chat, no feed, no account and no gamification. TrailShield never says a place is "safe" or "dangerous". It says "possible" and "appears", and always ends with "Use your judgment". I built it entirely from my phone, as a beginner, with no laptop. Live app: https://sunilkumawat-ai.github.io/trailshield/ https://sunilkumawat-ai.github.io/trailshield/ The free server sleeps when idle, so the first photo check can take up to a minute. Here is a real response from my phone. I tested with an indoor photo of an air cooler. Gemma described it correctly and flagged it as an unexpected environment, instead of pretending it was a trail: https://github.com/sunilkumawat-ai/trailshield https://github.com/sunilkumawat-ai/trailshield Model. Gemma gemma-4-26b-a4b-it , an open-weight model that accepts images. It is the only AI in the app. It looks at the photo and writes the advice. Page. A single index.html hosted on GitHub Pages. Before anything is sent, it shrinks the photo and re-draws it on a canvas, which removes GPS and other hidden metadata. Server. A roughly 30-line Flask app on Render's free plan. It keeps the API key in an environment variable never in the page or the repo and forwards the photo to Gemma. Prompt. Under 60 words: a short title, what the image appears to show, one "Consider..." tip, and never a claim of absolute safety. Check-in reminder. A simple timer that asks "Are you okay?" while the page is open. It is a reminder, not an emergency alert. My first plan was to run Gemma inside the phone's browser so nothing would leave the device. I dropped that idea because I did not want to push a multi-gigabyte model through my own phone's memory and chip, and I only had a few days. So the AI runs in the cloud, and I chose not to hide it. Instead of a "we care about your privacy" line, the app has a Privacy Proof screen with real counters from its own code: | Item | Value | |---|---| | Photos sent to cloud | Counted every time you tap Check | | Cloud AI requests | Counted the same way | | Location collected | 0 the app never asks for it | | Account required | No | | AI processing | CLOUD not on device | | Trail session data | This browser only | It also explains what really happens: one resized photo with no GPS goes to my Render server, then to Google's hosted Gemma. My code does not store photos, but Render and Google may keep request logs under their own policies. Delete Trail Data clears the local session and counters, but it cannot remove anything already sent to the cloud, and the app says so. I ran the full loop several times from my phone: photo, server, Gemma, answer, Privacy Proof counters and Delete. The screenshots above are from that testing, and the counters show 4 photos and 4 requests because I tapped Check four times. I did not get to do a proper outdoor trail test before the deadline, so I cannot claim how accurate Gemma is on real trails. The indoor test only shows that it describes what it sees and does not force a hazard onto a photo that has none. A real outdoor test is the first thing I would do next. Things that went wrong along the way: Because Gemma is open-weight, the biggest weakness of my app is something anyone can fix, including me. My server is tiny and the model is swappable. Someone who wants zero upload can run the same code against a self-hosted copy of Gemma, and the Privacy Proof counters would then honestly show 0 cloud requests. With a closed API, that option would not exist: the photo would always go to a vendor I cannot inspect or replace. Open weights also let me choose a model by what fit the job, and explain in plain words what it is, instead of treating the AI as a black box. Safety note: TrailShield is not a replacement for your own judgment, trail signs or emergency services. In an emergency, call your local emergency number India: 112 .