Privacy Policy for Khazna
Khazna (خزنة) is a personal vault: links you want to come back to, notes you jot down, and checklists you tick off. It has no accounts and no backend of ours. This page explains what it keeps on your device, the two requests that leave it, and how to switch both of them off.
The short version
Everything you save lives in the app's own storage on your phone. There is no account to create, no server of ours to sync to, and no way for us to read what is in your vault.
Two requests, both optional
The app fetches the title of a link you already saved, and sends usage measurements that contain no vault content. Each is a switch in Settings.
What you write is never sent
Titles, notes, URLs, checklist items and search text never appear in a measurement — not truncated, not hashed, not "just the domain".
Uninstalling is the erase button
Removing the app removes the vault with it. There is no copy anywhere else to ask us to delete.
1. Who we are and what this covers
Khazna is built and published by Mohamed Gado, an individual developer, reachable at boogado@yahoo.com. In the language of data protection law, that person is the data controller for the small amount of information described in section 5. There is no company, no team and no third party with access.
This policy covers the Khazna mobile application, identified as
com.khazna.vault, on Android and iOS. It does not cover the websites you
open from inside it — once you tap a saved link you are on someone else's page, under
their policy, and section 7 explains exactly what the app does and does not do at that
moment.
2. No accounts, no server of ours
There is nothing to sign up for. Khazna has no login, no profile, no cloud, no sync and no API of ours anywhere in the picture. We do not operate a server that your vault touches, which means there is no database of items, no backup of your notes, and nothing for us to hand over, lose, or be compelled to produce.
This is a design decision with a cost, and it is worth stating plainly: because there is no server, there is no automatic recovery. If you lose the phone without having exported a backup (section 10), the vault is gone. We consider that the correct trade for a private notebook.
Two requests do leave the device, and neither is a server of ours: a page title fetch that goes straight to the site you saved, and an anonymous usage measurement sent to PostHog. Both are described below and both can be switched off.
3. What stays on your device
All of it. Khazna stores its data in the app's private storage, which the operating system isolates from other apps. Nothing in this list is uploaded anywhere.
| What | Contains |
|---|---|
| Your vault | Every item you save: kind, title, URL, note body, checklist entries and their ticked state, tags, pin and archive flags, the time each was created and last changed, and whether a link has been opened |
| Settings | Theme, language, haptics, sort order, app lock and its auto-lock delay, screen privacy, and your two network switches |
| Lock timing | A single timestamp recording when the app last went to the background, so the lock knows whether to re-arm. No credentials of any kind are stored |
| Scheduled reminders | Held by the operating system's own alarm scheduler, on the device, along with the text it will display |
There is no analytics copy of any of this, no crash report that captures screen contents, and no diagnostic log that includes what you wrote.
4. The two requests the app makes
Khazna's own code opens exactly two kinds of network connection. Adding a third would require changing this page first, which is a rule the project holds itself to.
Request 1 — the title of a link you saved
When you save a link without typing a title, the app can fetch the page's own title so the item is readable later instead of being a bare URL. What that involves, precisely:
- It happens only for a link already saved, and only while that item is on screen or when you ask for it. Nothing is fetched while you type, and nothing is fetched from your clipboard.
- The request goes straight to the site. It does not pass through any service of ours or anyone else's, and there is no key or account involved. To that website, it looks like a visit — because it is one.
- It reads the markup only: the first 64 KB of the page, from which the title is taken. No images, scripts or stylesheets are downloaded, and no cookies are stored.
- It is attempted once per link. A page with no title is not asked again, and failure is silent — the link simply keeps whatever you typed.
- Switch: Settings → Links → Fetch page titles. Off means no request is ever made.
One honest consequence: the site you saved sees a request from your IP address at the moment you save or view the item, the same as if you had opened it in a browser. If that matters for a particular link, turn the setting off before saving it.
Request 2 — usage measurement
The app sends anonymous product measurements to PostHog, hosted in the European Union, so that decisions about what to build are based on how the app is actually used. Section 5 describes exactly what an event may contain — the short version is counts, durations, screen names and yes/no flags, and never a single character of what you wrote.
Switch: Settings → Privacy → Usage measurement. Off means nothing is sent.
5. Usage measurement, in detail
Most apps promise that analytics are "anonymous" and leave you to take it on faith. Here is the actual mechanism, because it is checkable rather than a promise.
Every event the app is allowed to send is declared in one file in the source, together
with the exact shape of what it carries. A value in that file may be a number, a true/false
flag, or one of a fixed list of words that we chose (a screen name such as
feed, an item kind such as link). It may not be
free text. A title, a URL, a note, a checklist label and a search query are all free text,
so none of them can be placed in an event without changing that rule — and an automated
test refuses to build the app if the rule is changed.
| Sent | Never sent |
|---|---|
| Which screen was opened, by our name for it | The title of any item |
| That an item was created, and of which kind | Any URL, or any part of one, including the domain |
| How many characters it had — the number, not the text | The body of a note |
| How many results a search returned | What you searched for |
| How many entries a checklist has and how many are ticked | What any checklist entry says |
| Whether a title fetch succeeded, and how long it took | Which page was fetched |
| Whether an unlock succeeded, failed or was cancelled | Anything about your fingerprint, face or passcode |
| How many items the vault holds, rounded into a band | Anything that identifies you personally |
Counts that could grow without limit are rounded into bands before sending, because "this vault holds 1,247 items" is close to a fingerprint while "1000+" answers the same product question and is not.
PostHog assigns a random identifier to the installation so that a sequence of events can be recognised as one session. It is not derived from your device id, your phone number or any account, it is not shared with anyone, and reinstalling the app produces a new one. Session replay and autocapture — the PostHog features that record the screen and the text of whatever is tapped — are permanently disabled in the code and are not offered as a setting.
The legal basis, where the GDPR applies, is legitimate interest in understanding how the app is used, and the measurement is on by default. If you would rather not take part, one switch in Settings ends it.
6. Saving things into Khazna
There are four ways in, and none of them watches you.
- The share sheet. Khazna accepts shared text and web links from other apps. It deliberately does not accept images or files, so nothing from your photo library or storage can arrive. The app receives what you shared, at the moment you shared it, and nothing else.
- Pasting. When you open the capture sheet, the app may offer what is on your clipboard so you can save it in one tap. The clipboard is read at that moment to show you the offer; it is not monitored in the background and its contents are not stored or sent anywhere unless you choose to save them.
- Quick actions. Long-pressing the app icon offers shortcuts to start a new item. These are handled entirely by the operating system's launcher.
- Typing. Directly, in the app.
The app has no access to your browsing history, your other apps' data, your contacts, your photos, your location, your microphone or your camera — several of those are explicitly blocked in the app's manifest (section 12).
7. Opening a saved link
Tapping a link opens it in an in-app browser tab, or in your default browser when that is not available. From that point you are visiting the site normally: it sees your IP address and whatever your browser sends it, exactly as it would if you had typed the address. Khazna does not inject anything into the page, does not read its contents, and does not track where you go next. It records one thing locally, on your device: that the link has been opened, so it can stop showing as unread.
8. Reminders
You can ask an item to resurface at a chosen time. The reminder is scheduled with the operating system's own alarm scheduler and fires on the device. No push service is involved, no push token is requested, and the reminder's text — which may include your item's title — never leaves the phone. Denying notification permission simply means reminders are unavailable; nothing else in the app changes.
9. App lock and screen privacy
Two optional protections, both off by default and both entirely local.
App lock puts your device's own authentication — fingerprint, face, or PIN and pattern — in front of the vault. The check is performed by the operating system; the app is told only whether it passed. No biometric data is ever available to the app, and no PIN or password of ours exists to be stored, guessed or reset. The app remembers a single timestamp of when it was last backgrounded, so it can re-lock after the delay you chose. A cold start always locks.
If the lock becomes impossible to satisfy — you removed your device screen lock after enabling it, for instance — the app turns the setting off and lets you in rather than leaving you shut out of your own notes. A vault its owner cannot open is a loss, not security.
Screen privacy asks the operating system to block screenshots and screen recording, and to hide the app's preview in the task switcher. On Android this is the standard secure-window flag. The settings screen reports whether the block is actually in force rather than merely what you asked for, because a privacy control that claims to be on while it is not is worse than not having one.
10. Backup and restore
A backup is a plain JSON file containing your items, produced on demand and handed to your device's share sheet. Where it goes is entirely your choice — a cloud drive, a chat with yourself, a cable. It is not uploaded anywhere by the app, and no copy is kept by us. The file is not encrypted, because it is yours to place somewhere you trust; treat it as you would a document containing the same notes.
Restoring reads a file you pick and merges it into the vault. It never wipes what is already there, and restoring the same file twice changes nothing. You can also copy a backup to the clipboard and paste it back, which is useful for moving between two devices with nothing in between.
11. App updates
Two update mechanisms exist, and neither is a request the app's own features make.
- The app store. Google Play or the App Store handles installation and updates under its own privacy policy, as it does for every app on the device.
-
Over-the-air updates. The app can fetch a corrected JavaScript bundle
from Expo's update service (
u.expo.dev) so a fix can ship without a store release. That request carries the app's version and platform in order to receive the right bundle. It carries nothing from your vault, and it is a platform mechanism rather than a feature — it is listed here for completeness, not hidden behind the count of two in section 4.
12. Permissions
Khazna asks for very little, and explicitly blocks several permissions that its libraries would otherwise be free to declare.
| Permission | Why |
|---|---|
| Internet and network state | The two requests in section 4, and app updates |
| Notifications | Requested only when you set your first reminder. Optional |
| Biometric authentication | Only when you turn app lock on. Optional |
| Vibrate | Haptic feedback on save and on ticking a checklist. Optional in Settings |
| Boot completed and wake lock | So a reminder scheduled before a restart still fires afterwards |
Explicitly blocked in the app's own configuration, so they cannot be present in a released build: microphone, camera, precise location, approximate location, physical activity recognition, reading images and reading video from your library.
Also absent, because nothing in the app has any use for them: contacts, SMS, call logs, the list of installed apps, and background location.
13. How your data is secured
Your vault sits in the app's private storage area, which Android and iOS keep isolated from other applications. On a device with a screen lock, that storage is covered by the operating system's own encryption at rest. App lock and screen privacy (section 9) add a second layer if you want one.
The two outbound requests use HTTPS. Beyond that, the strongest security property here is structural rather than technical: there is no server holding your items, so there is no breach of ours that could expose them.
A caveat worth stating: a device with no screen lock, or one that has been rooted or jailbroken, does not provide the isolation described above, and no app can restore it.
14. Retention and deletion
Your items are kept until you delete them. Deleting an item removes it; there is no hidden trash, and no copy is retained anywhere else. Archiving keeps an item out of the feed while leaving it searchable, and is not deletion.
To erase everything: uninstall the app, or clear its storage from your device settings. Both remove the vault and every setting with it, immediately and permanently. Export a backup first if you want to keep anything.
Usage measurements are held by PostHog for up to twelve months and then expire. They are not tied to your identity, so there is nothing personal to delete — but if you want the installation's measurement history removed anyway, email us from the address in section 19 and it will be deleted. Turning the switch off stops any further measurement immediately.
15. Your rights
Where the GDPR, the UK GDPR or a similar law applies, you have rights of access, rectification, erasure, restriction, portability and objection. Their shape here is unusual, because of how little exists:
- Access and portability are immediate and need no request: everything we could possibly hold about your content is on your device, and the backup export (section 10) is a machine-readable copy of all of it.
- Erasure is uninstalling, plus an email if you also want the anonymous measurements dropped.
- Objection to the measurement is a switch in Settings, effective at once, with no loss of any feature.
We cannot identify you from anything we receive, so we cannot search for "your" data on request — that is a consequence of collecting so little, not an evasion. You also have the right to complain to your local data protection authority.
16. Children's privacy
Khazna is a general-purpose notebook and is not directed at children. It contains no ads, no advertising identifiers, no in-app purchases and no social features, and it does not knowingly collect information from anyone. If you believe a child's information has somehow reached us, write to the address in section 19 and it will be removed.
17. Third-party services
| Who | What they receive | When |
|---|---|---|
| The website of a link you saved | A page request from your IP address, like any browser visit | Only if title fetching is on, once per saved link |
PostHog (EU region, eu.i.posthog.com) |
Anonymous events as described in section 5: counts, durations, screen names, flags. No content, ever | Only if usage measurement is on |
Expo (u.expo.dev) |
App version and platform, in order to serve the right update bundle | On launch, to check for an update |
| Google Play / Apple App Store | Whatever the store platform itself collects, under its own policy | Installation and updates |
There are no advertising networks, no attribution or install-tracking SDKs, no social logins, no crash reporter that captures screen contents, and no data broker relationship of any kind. Nothing is sold or shared for advertising, and nothing about you is used to train a model.
18. Changes to this policy
If the app starts doing something this page does not describe, this page is updated first, in the same working session as the change — not afterwards. The date at the top changes with it, and the full history of every edit is public in this repository's git log. Material changes will also be noted in the app's release notes.
19. Contact
Any question about privacy, or to have this installation's measurement history deleted: boogado@yahoo.com
Developer: Mohamed Gado · App: Khazna (com.khazna.vault)
سياسة الخصوصية لتطبيق خزنة
خزنة دفتر شخصي: روابط تريد العودة إليها، وملاحظات تدوّنها، وقوائم مهام تشطبها. لا حسابات فيه ولا خادم لنا خلفه. تشرح هذه الصفحة ما يبقى على جهازك، والطلبَين الوحيدَين اللذَين يخرجان منه، وكيف تُوقف كلًّا منهما.
باختصار
كل ما تحفظه يعيش في مساحة التطبيق الخاصة على هاتفك. لا حساب تُنشئه، ولا خادم لنا يتزامن معه، ولا سبيل لنا لقراءة ما في خزنتك.
طلبان، وكلاهما اختياري
يجلب التطبيق عنوان صفحة لرابط حفظته بالفعل، ويرسل قياسات استخدام لا تحمل أي شيء من محتوى خزنتك. لكلٍّ منهما مفتاح في الإعدادات.
ما تكتبه لا يُرسَل أبدًا
العناوين والملاحظات والروابط وبنود القوائم ونص البحث لا يظهر أيٌّ منها في قياس — لا مقتطعًا، ولا مشفّرًا، ولا «النطاق فقط».
حذف التطبيق هو زر المحو
إزالة التطبيق تزيل الخزنة معه. لا توجد نسخة في مكان آخر تطلب منّا حذفها.
١. من نحن ونطاق السياسة
خزنة من تطوير ونشر محمد جادو، مطوّر فرد، ويمكن مراسلته على boogado@yahoo.com. وبلغة قوانين حماية البيانات، هذا الشخص هو المتحكّم في القدر اليسير من المعلومات الموصوف في القسم ٥. لا شركة، ولا فريق، ولا طرف ثالث له صلاحية وصول.
تغطي هذه السياسة تطبيق خزنة للهواتف، المعرّف بـ com.khazna.vault، على أندرويد
و iOS. ولا تغطي المواقع التي تفتحها من داخله — فبمجرد أن تضغط رابطًا محفوظًا تكون في صفحة
شخص آخر وتحت سياسته، والقسم ٧ يوضّح بالضبط ما يفعله التطبيق وما لا يفعله في تلك اللحظة.
٢. لا حسابات ولا خادم لنا
لا شيء تسجّل فيه. لا يوجد في خزنة تسجيل دخول، ولا ملف تعريف، ولا سحابة، ولا مزامنة، ولا واجهة برمجية لنا في الصورة من الأساس. نحن لا نشغّل خادمًا تلمسه خزنتك، ومعنى ذلك أنه لا توجد قاعدة بيانات بعناصرك، ولا نسخة من ملاحظاتك، ولا شيء نسلّمه أو نفقده أو نُلزَم بإخراجه.
هذا قرار تصميمي له ثمن، ومن الأمانة قوله صراحة: لأنه لا يوجد خادم، لا توجد استعادة تلقائية. إن فقدت الهاتف دون أن تكون قد صدّرت نسخة احتياطية (القسم ١٠) فقد ضاعت الخزنة. ونرى أن هذه هي المقايضة الصحيحة لدفتر خاص.
هناك طلبان يخرجان من الجهاز فعلًا، وليس أيٌّ منهما خادمًا لنا: جلب عنوان صفحة يذهب مباشرة إلى الموقع الذي حفظته، وقياس استخدام مجهول يُرسل إلى PostHog. وكلاهما موصوف أدناه وكلاهما يمكن إيقافه.
٣. ما يبقى على جهازك
كل شيء. تحفظ خزنة بياناتها في مساحة التطبيق الخاصة، وهي مساحة يعزلها نظام التشغيل عن بقية التطبيقات. ولا شيء في هذه القائمة يُرفَع إلى أي مكان.
| ماذا | يحتوي على |
|---|---|
| خزنتك | كل عنصر تحفظه: نوعه وعنوانه ورابطه ونص ملاحظته وبنود قائمته وحالة شطبها، ووسومه، وحالتَي التثبيت والأرشفة، ووقت الإنشاء وآخر تعديل، وما إذا كان الرابط قد فُتح |
| الإعدادات | السمة واللغة والاهتزاز وترتيب العرض، وقفل التطبيق ومهلته، وخصوصية الشاشة، ومفتاحا الشبكة |
| توقيت القفل | ختم زمني واحد يسجّل آخر مرة انتقل فيها التطبيق إلى الخلفية، ليعرف القفل هل يعيد التسلّح. ولا تُخزَّن أي بيانات اعتماد من أي نوع |
| التذكيرات المجدولة | يحتفظ بها مجدول المنبّهات في نظام التشغيل، على الجهاز، مع النص الذي سيعرضه |
لا توجد نسخة تحليلية من أيٍّ من ذلك، ولا تقرير أعطال يلتقط محتوى الشاشة، ولا سجل تشخيصي يتضمن ما كتبته.
٤. الطلبان اللذان يجريهما التطبيق
يفتح كود خزنة نوعين اثنين فقط من اتصالات الشبكة. وإضافة ثالث تستلزم تعديل هذه الصفحة أولًا، وهي قاعدة يلزم بها المشروع نفسه.
الطلب الأول — عنوان رابط حفظته
حين تحفظ رابطًا دون أن تكتب له عنوانًا، يستطيع التطبيق جلب عنوان الصفحة نفسها ليصبح العنصر مقروءًا لاحقًا بدل أن يكون رابطًا عاريًا. وهذا ما يعنيه ذلك بدقة:
- يحدث فقط لرابط محفوظ بالفعل، وفقط حين يكون العنصر على الشاشة أو حين تطلبه أنت. لا شيء يُجلَب أثناء كتابتك، ولا شيء يُجلَب من حافظتك.
- يذهب الطلب مباشرة إلى الموقع. لا يمرّ عبر خدمة لنا ولا لأحد غيرنا، ولا مفتاح فيه ولا حساب. وبالنسبة لذلك الموقع يبدو الأمر زيارة — لأنه زيارة فعلًا.
- يقرأ الوسوم فقط: أول ٦٤ كيلوبايت من الصفحة، ومنها يُؤخذ العنوان. لا تُنزَّل صور ولا سكربتات ولا أنماط، ولا تُحفظ كوكيز.
- يُحاوَل مرة واحدة لكل رابط. والصفحة التي لا عنوان لها لا تُسأل مرة ثانية، والفشل صامت — يحتفظ الرابط بما كتبته أنت.
- المفتاح: الإعدادات ← الروابط ← جلب عناوين الصفحات. وإيقافه يعني ألّا يُرسَل طلب أبدًا.
ونتيجة واحدة من الأمانة ذكرها: الموقع الذي حفظته يرى طلبًا من عنوان IP الخاص بك لحظة الحفظ أو العرض، تمامًا كما لو فتحته في المتصفح. فإن كان ذلك مهمًّا لرابط بعينه، أوقف الإعداد قبل حفظه.
الطلب الثاني — قياس الاستخدام
يرسل التطبيق قياسات مجهولة عن الاستخدام إلى PostHog، المستضاف في الاتحاد الأوروبي، لتكون قرارات ما يُبنى مستندة إلى كيفية استعمال التطبيق فعليًا. ويصف القسم ٥ بالضبط ما يجوز أن يحمله الحدث — وخلاصته: أعداد ومدد وأسماء شاشات وإشارات نعم/لا، ولا حرف واحد مما كتبته.
المفتاح: الإعدادات ← الخصوصية ← قياس الاستخدام. وإيقافه يعني ألّا يُرسَل شيء.
٥. قياس الاستخدام بالتفصيل
معظم التطبيقات تَعِد بأن تحليلاتها «مجهولة» وتترك لك أن تصدّق. وهذه هي الآلية الفعلية، لأنها قابلة للفحص لا مجرد وعد.
كل حدث يُسمح للتطبيق بإرساله معلَن في ملف واحد في الكود، ومعه الشكل الدقيق لما يحمله. والقيمة
في ذلك الملف يجوز أن تكون رقمًا، أو إشارة صح/خطأ، أو واحدة من قائمة ثابتة من الكلمات
اخترناها نحن (اسم شاشة مثل feed، أو نوع عنصر مثل link). ولا يجوز
أن تكون نصًّا حرًّا. والعنوان والرابط والملاحظة وبند القائمة وكلمة البحث
كلها نص حر، فلا يمكن وضع أيٍّ منها في حدث دون تغيير تلك القاعدة — واختبار آلي يرفض بناء
التطبيق إن تغيّرت.
| يُرسَل | لا يُرسَل أبدًا |
|---|---|
| أي شاشة فُتحت، باسمنا نحن لها | عنوان أي عنصر |
| أن عنصرًا أُنشئ، ومن أي نوع | أي رابط أو أي جزء منه، بما في ذلك النطاق |
| كم حرفًا كان فيه — العدد لا النص | نص أي ملاحظة |
| كم نتيجة أعاد البحث | عمّا بحثت |
| كم بندًا في القائمة وكم منها مشطوب | ما يقوله أي بند |
| هل نجح جلب العنوان وكم استغرق | أي صفحة جُلبت |
| هل نجح فتح القفل أم فشل أم أُلغي | أي شيء عن بصمتك أو وجهك أو رمزك |
| كم عنصرًا في الخزنة، مقرَّبًا إلى شريحة | أي شيء يعرّف بك شخصيًّا |
الأعداد التي قد تنمو بلا حد تُقرَّب إلى شرائح قبل الإرسال، لأن «هذه الخزنة فيها ١٢٤٧ عنصرًا» أقرب إلى بصمة، بينما «أكثر من ١٠٠٠» يجيب عن السؤال نفسه ولا يكون بصمة.
يمنح PostHog التثبيت معرّفًا عشوائيًّا حتى يمكن التعرّف على سلسلة أحداث كجلسة واحدة. وهو غير مشتق من معرّف جهازك ولا رقم هاتفك ولا أي حساب، ولا يُشارَك مع أحد، وإعادة تثبيت التطبيق تُنتج معرّفًا جديدًا. أما إعادة تشغيل الجلسة والالتقاط التلقائي — وهما ميزتا PostHog اللتان تسجّلان الشاشة ونص ما يُضغط — فمعطّلتان في الكود بشكل دائم ولا تُعرضان كإعداد.
والأساس القانوني، حيث تنطبق اللائحة الأوروبية، هو المصلحة المشروعة في فهم كيفية استعمال التطبيق، والقياس مفعّل افتراضيًّا. وإن كنت تفضّل ألّا تشارك فمفتاح واحد في الإعدادات ينهي الأمر.
٦. كيف تدخل الأشياء إلى خزنة
أربع طرق للدخول، ولا واحدة منها تراقبك.
- قائمة المشاركة. تقبل خزنة النصوص وروابط الويب المشارَكة من تطبيقات أخرى. ولا تقبل عمدًا الصور ولا الملفات، فلا يصلها شيء من معرض صورك أو تخزينك. يستقبل التطبيق ما شاركته، لحظة مشاركتك له، ولا شيء غير ذلك.
- اللصق. عند فتح ورقة الالتقاط قد يعرض التطبيق ما في حافظتك لتحفظه بضغطة واحدة. تُقرأ الحافظة في تلك اللحظة لعرض الاقتراح؛ ولا تُراقَب في الخلفية ولا يُخزَّن محتواها ولا يُرسَل إلى أي مكان ما لم تختر أنت حفظه.
- الإجراءات السريعة. الضغط المطوّل على أيقونة التطبيق يعرض اختصارات لبدء عنصر جديد، ويتولّاها مشغّل نظام التشغيل بالكامل.
- الكتابة. مباشرة، داخل التطبيق.
لا يملك التطبيق وصولًا إلى سجل تصفّحك، ولا بيانات تطبيقاتك الأخرى، ولا جهات اتصالك، ولا صورك، ولا موقعك، ولا ميكروفونك، ولا كاميرتك — وعدد منها محظور صراحةً في إعداد التطبيق (القسم ١٢).
٧. فتح رابط محفوظ
الضغط على رابط يفتحه في تبويب متصفح داخل التطبيق، أو في متصفحك الافتراضي عند تعذّر ذلك. ومن تلك اللحظة أنت تزور الموقع زيارة عادية: يرى عنوان IP الخاص بك وما يرسله متصفحك، تمامًا كما لو كتبت العنوان بنفسك. لا تحقن خزنة شيئًا في الصفحة، ولا تقرأ محتواها، ولا تتعقّب إلى أين تذهب بعدها. وتسجّل شيئًا واحدًا محليًّا على جهازك: أن الرابط فُتح، لتتوقف عن عرضه كغير مقروء.
٨. التذكيرات
يمكنك أن تطلب عودة عنصر إلى السطح في وقت تختاره. يُجدوَل التذكير عبر مجدول المنبّهات في نظام التشغيل ويُطلَق على الجهاز. لا خدمة إشعارات دفع في الأمر، ولا رمز دفع يُطلب، ونص التذكير — وقد يتضمن عنوان عنصرك — لا يغادر الهاتف أبدًا. ورفض إذن الإشعارات يعني ببساطة أن التذكيرات غير متاحة؛ ولا يتغير شيء آخر في التطبيق.
٩. قفل التطبيق وخصوصية الشاشة
حمايتان اختياريتان، كلتاهما متوقفة افتراضيًّا وكلتاهما محلية بالكامل.
قفل التطبيق يضع مصادقة جهازك نفسها — بصمة أو وجه أو رمز أو نقش — أمام الخزنة. يجري الفحص في نظام التشغيل؛ ولا يُبلَّغ التطبيق إلا بنجاحه أو فشله. لا تتاح بيانات حيوية للتطبيق مطلقًا، ولا يوجد رمز أو كلمة مرور خاصة بنا تُخزَّن أو تُخمَّن أو تُستعاد. ويتذكّر التطبيق ختمًا زمنيًّا واحدًا لآخر انتقال إلى الخلفية، ليعيد القفل بعد المهلة التي اخترتها. والبدء البارد يقفل دائمًا.
وإن صار القفل مستحيل الاستيفاء — كأن تكون قد أزلت قفل شاشة جهازك بعد تفعيله — يُطفئ التطبيق الإعداد ويسمح لك بالدخول بدل أن يتركك محبوسًا خارج ملاحظاتك. فخزنة لا يستطيع صاحبها فتحها خسارة لا أمان.
خصوصية الشاشة تطلب من نظام التشغيل منع لقطات الشاشة وتسجيلها، وإخفاء معاينة التطبيق في مبدّل المهام. وعلى أندرويد هذه هي راية النافذة الآمنة المعتادة. وتذكر شاشة الإعدادات هل المنع سارٍ فعلًا لا ما طلبته أنت فحسب، لأن أداة خصوصية تدّعي أنها مفعّلة وهي ليست كذلك أسوأ من عدم وجودها.
١٠. النسخ الاحتياطي والاستعادة
النسخة الاحتياطية ملف JSON عادي يحوي عناصرك، يُنتَج عند الطلب ويُسلَّم إلى قائمة المشاركة في جهازك. وأين يذهب اختيارك أنت وحدك — سحابة، أو محادثة مع نفسك، أو كابل. لا يرفعه التطبيق إلى أي مكان، ولا نحتفظ نحن بنسخة منه. والملف غير مشفّر، لأنه ملكك تضعه حيث تثق؛ فتعامل معه كما تتعامل مع مستند يحوي الملاحظات نفسها.
والاستعادة تقرأ ملفًا تختاره وتدمجه في الخزنة. لا تمحو ما هو موجود أبدًا، واستعادة الملف نفسه مرتين لا تغيّر شيئًا. ويمكنك أيضًا نسخ نسخة احتياطية إلى الحافظة ولصقها، وهو مفيد للانتقال بين جهازين لا شيء بينهما.
١١. تحديثات التطبيق
آليتا تحديث موجودتان، وليست أيٌّ منهما طلبًا تجريه ميزات التطبيق نفسها.
- متجر التطبيقات. يتولّى Google Play أو App Store التثبيت والتحديث وفق سياسة خصوصيته هو، كما يفعل مع كل تطبيق على الجهاز.
-
التحديثات الفورية. يستطيع التطبيق جلب حزمة جافاسكربت مصحّحة من خدمة
التحديث لدى Expo (
u.expo.dev) لتصل إصلاحة دون إصدار في المتجر. ويحمل ذلك الطلب إصدار التطبيق ومنصّته ليتلقّى الحزمة الصحيحة. ولا يحمل شيئًا من خزنتك، وهو آلية منصّة لا ميزة — ومذكور هنا لاكتمال الصورة، لا مخبّأً خلف عدد الطلبين في القسم ٤.
١٢. الأذونات
تطلب خزنة القليل جدًّا، وتحظر صراحةً عدة أذونات كان بوسع مكتباتها أن تعلنها لولا ذلك.
| الإذن | لماذا |
|---|---|
| الإنترنت وحالة الشبكة | الطلبان في القسم ٤، وتحديثات التطبيق |
| الإشعارات | يُطلب فقط عند ضبطك أول تذكير. اختياري |
| المصادقة الحيوية | فقط عند تفعيلك قفل التطبيق. اختياري |
| الاهتزاز | استجابة لمسية عند الحفظ وعند شطب بند. اختياري من الإعدادات |
| اكتمال الإقلاع وإبقاء الجهاز مستيقظًا | ليُطلَق تذكير جُدوِل قبل إعادة التشغيل بعدها |
ومحظورة صراحةً في إعداد التطبيق نفسه فلا يمكن وجودها في إصدار منشور: الميكروفون، والكاميرا، والموقع الدقيق، والموقع التقريبي، والتعرّف على النشاط البدني، وقراءة الصور، وقراءة الفيديو من مكتبتك.
وغائبة أيضًا لأن لا حاجة لشيء في التطبيق بها: جهات الاتصال، والرسائل، وسجل المكالمات، وقائمة التطبيقات المثبّتة، والموقع في الخلفية.
١٣. كيف تُؤمَّن بياناتك
تجلس خزنتك في مساحة التطبيق الخاصة، وهي مساحة يبقيها أندرويد و iOS معزولة عن التطبيقات الأخرى. وعلى جهاز له قفل شاشة، يغطّي تشفيرُ نظام التشغيل تلك المساحة في حالة السكون. ويضيف قفل التطبيق وخصوصية الشاشة (القسم ٩) طبقة ثانية إن أردتها.
ويستخدم الطلبان الخارجان بروتوكول HTTPS. وما عدا ذلك، فأقوى خاصية أمنية هنا بنيوية لا تقنية: لا يوجد خادم يحمل عناصرك، فلا يوجد اختراق لنا يمكن أن يكشفها.
وتنبيه يستحق الذكر: جهاز بلا قفل شاشة، أو جهاز جرى تجذيره أو كسر حمايته، لا يوفّر العزل الموصوف أعلاه، ولا يستطيع أي تطبيق استعادته.
١٤. الاحتفاظ بالبيانات وحذفها
تبقى عناصرك حتى تحذفها. وحذف عنصر يزيله؛ ولا توجد سلة مخفية، ولا نسخة محفوظة في مكان آخر. والأرشفة تُبقي العنصر خارج القائمة مع بقائه قابلًا للبحث، وهي ليست حذفًا.
لمحو كل شيء: احذف التطبيق، أو امسح تخزينه من إعدادات جهازك. وكلاهما يزيل الخزنة وكل إعداد معها، فورًا ونهائيًّا. صدّر نسخة احتياطية أولًا إن أردت الاحتفاظ بشيء.
قياسات الاستخدام يحتفظ بها PostHog حتى اثني عشر شهرًا ثم تنتهي. وهي غير مرتبطة بهويتك فلا يوجد شخصي يُحذف — لكن إن أردت مع ذلك إزالة سجل قياسات هذا التثبيت، راسلنا من العنوان في القسم ١٩ وسيُحذف. وإيقاف المفتاح يوقف أي قياس لاحق فورًا.
١٥. حقوقك
حيث تنطبق اللائحة الأوروبية أو البريطانية أو قانون مشابه، لك حقوق الوصول والتصحيح والمحو والتقييد والنقل والاعتراض. وشكلها هنا غير معتاد، لقلّة ما هو موجود أصلًا:
- الوصول والنقل فوريان ولا يحتاجان طلبًا: كل ما يمكن أن نحمله عن محتواك موجود على جهازك، وتصدير النسخة الاحتياطية (القسم ١٠) نسخة منه كاملة بصيغة يقرأها الحاسوب.
- المحو هو حذف التطبيق، مع رسالة بريد إن أردت أيضًا إسقاط القياسات المجهولة.
- الاعتراض على القياس مفتاح في الإعدادات، نافذ في الحال، دون فقدان أي ميزة.
ولا نستطيع التعرّف عليك من أي شيء يصلنا، فلا نستطيع البحث عن بياناتك «أنت» عند الطلب — وذلك نتيجة لجمعنا القليل جدًّا لا تهرّبًا. ولك أيضًا حق الشكوى إلى هيئة حماية البيانات في بلدك.
١٦. خصوصية الأطفال
خزنة دفتر عام الاستعمال وليست موجّهة للأطفال. لا إعلانات فيها، ولا معرّفات إعلانية، ولا مشتريات داخلية، ولا ميزات اجتماعية، ولا تجمع معلومات من أحد عن علم. وإن كنت ترى أن معلومات طفل قد وصلتنا بطريقة ما، فاكتب إلى العنوان في القسم ١٩ وستُزال.
١٧. خدمات الغير
| من | ماذا يتلقّى | متى |
|---|---|---|
| موقع الرابط الذي حفظته | طلب صفحة من عنوان IP الخاص بك، كأي زيارة متصفح | فقط إن كان جلب العناوين مفعّلًا، ومرة واحدة لكل رابط محفوظ |
PostHog (منطقة الاتحاد الأوروبي، eu.i.posthog.com) |
أحداث مجهولة كما في القسم ٥: أعداد ومدد وأسماء شاشات وإشارات. ولا محتوى، أبدًا | فقط إن كان قياس الاستخدام مفعّلًا |
Expo (u.expo.dev) |
إصدار التطبيق ومنصّته، لتقديم حزمة التحديث الصحيحة | عند التشغيل، للتحقق من وجود تحديث |
| Google Play / Apple App Store | ما تجمعه منصّة المتجر نفسها، وفق سياستها هي | التثبيت والتحديثات |
لا توجد شبكات إعلانية، ولا حزم تتبّع تنصيب أو إسناد، ولا تسجيل دخول عبر الشبكات الاجتماعية، ولا مبلّغ أعطال يلتقط محتوى الشاشة، ولا أي علاقة بوسيط بيانات من أي نوع. ولا يُباع شيء ولا يُشارَك لأغراض الإعلان، ولا يُستخدم شيء عنك في تدريب نموذج.
١٨. تعديلات هذه السياسة
إن بدأ التطبيق يفعل شيئًا لا تصفه هذه الصفحة، فهذه الصفحة تُحدَّث أولًا، في جلسة العمل نفسها التي يقع فيها التغيير لا بعدها. ويتغير التاريخ في الأعلى معها، وتاريخ كل تعديل كامل ومتاح للعموم في سجل git لهذا المستودع. كما ستُذكر التغييرات الجوهرية في ملاحظات إصدار التطبيق.
١٩. التواصل
لأي سؤال عن الخصوصية، أو لحذف سجل قياسات هذا التثبيت: boogado@yahoo.com
المطوّر: محمد جادو · التطبيق: خزنة (com.khazna.vault)