DEV Community

Sunil Kumawat
Sunil Kumawat

Posted on

TrailShield: a quick-check outdoor safety buddy with a Privacy Proof screen

Hacktoberfest Open-Source AI Challenge Week 1: Touch Grass Submission 🌿

This is a submission for the Hacktoberfest Open-Source AI Challenge Week 1: Touch Grass

What I Built

Most AI apps want you to stay on the screen. TrailShield is built to do the opposite.

It is a small web app for short outdoor checks. You tap Start Trail, and when something on the path looks uncertain (a rocky patch, a fallen branch, a muddy slope), you take a photo. Gemma looks at it and gives a short, cautious note. Then the app tells you: "📵 Put your phone away and continue your trail."

That is the whole interaction: a few seconds on the screen, then back outside. There is no chat, no feed, no account and no gamification. TrailShield never says a place is "safe" or "dangerous". It says "possible" and "appears", and always ends with "Use your judgment".

I built it entirely from my phone, as a beginner, with no laptop.

TrailShield home screen with Start Trail button

Demo

Live app: https://sunilkumawat-ai.github.io/trailshield/

The free server sleeps when idle, so the first photo check can take up to a minute.

Here is a real response from my phone. I tested with an indoor photo of an air cooler. Gemma described it correctly and flagged it as an unexpected environment, instead of pretending it was a trail:

Gemma's cautious answer for an indoor photo

Code

https://github.com/sunilkumawat-ai/trailshield

How I Built It

Model. Gemma (gemma-4-26b-a4b-it), an open-weight model that accepts images. It is the only AI in the app. It looks at the photo and writes the advice.

Page. A single index.html hosted on GitHub Pages. Before anything is sent, it shrinks the photo and re-draws it on a canvas, which removes GPS and other hidden metadata.

Server. A roughly 30-line Flask app on Render's free plan. It keeps the API key in an environment variable (never in the page or the repo) and forwards the photo to Gemma.

Prompt. Under 60 words: a short title, what the image appears to show, one "Consider..." tip, and never a claim of absolute safety.

Check-in reminder. A simple timer that asks "Are you okay?" while the page is open. It is a reminder, not an emergency alert.

The honest part: it is not offline

My first plan was to run Gemma inside the phone's browser so nothing would leave the device. I dropped that idea because I did not want to push a multi-gigabyte model through my own phone's memory and chip, and I only had a few days. So the AI runs in the cloud, and I chose not to hide it.

Privacy Proof

Instead of a "we care about your privacy" line, the app has a Privacy Proof screen with real counters from its own code:

Item Value
Photos sent to cloud Counted every time you tap Check
Cloud AI requests Counted the same way
Location collected 0 (the app never asks for it)
Account required No
AI processing CLOUD (not on device)
Trail session data This browser only

Privacy Proof screen showing 4 photos sent, location 0

It also explains what really happens: one resized photo with no GPS goes to my Render server, then to Google's hosted Gemma. My code does not store photos, but Render and Google may keep request logs under their own policies. Delete Trail Data clears the local session and counters, but it cannot remove anything already sent to the cloud, and the app says so.

What I tested, and what I did not

I ran the full loop several times from my phone: photo, server, Gemma, answer, Privacy Proof counters and Delete. The screenshots above are from that testing, and the counters show 4 photos and 4 requests because I tapped Check four times.

I did not get to do a proper outdoor trail test before the deadline, so I cannot claim how accurate Gemma is on real trails. The indoor test only shows that it describes what it sees and does not force a hazard onto a photo that has none. A real outdoor test is the first thing I would do next.

Things that went wrong along the way:

  • "Failed to fetch" errors, because the server's default 30-second limit was too short for image requests. I raised it to 120 seconds.
  • Render had a paid $7 plan selected by default. I switched it to the free plan.

Why Does Open Innovation Matter?

Because Gemma is open-weight, the biggest weakness of my app is something anyone can fix, including me.

My server is tiny and the model is swappable. Someone who wants zero upload can run the same code against a self-hosted copy of Gemma, and the Privacy Proof counters would then honestly show 0 cloud requests. With a closed API, that option would not exist: the photo would always go to a vendor I cannot inspect or replace.

Open weights also let me choose a model by what fit the job, and explain in plain words what it is, instead of treating the AI as a black box.

Prize Categories

  • Best Use of Gemma: Gemma does all the image understanding and writes every piece of advice in the app.
  • Best Use of Render: the Flask server that protects the API key and forwards photos runs on Render's free plan.

Safety note: TrailShield is not a replacement for your own judgment, trail signs or emergency services. In an emergency, call your local emergency number (India: 112).

Top comments (0)